Royal Caribbean Group

Lead, Information Risk and GRC

Royal Caribbean Group$100K — $130K *
Miami, FL 33132In-Person
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Technology/Security or Computer Science preferred, with optional non-technical degree and tech experience.
  • One Information Security certification (e.g., CISSP, CCSP, CISM) is required.
  • 5-7 years of experience in Information Security, IT, Risk, or Audit.
  • 5-7 years of project or team management experience.
  • 2-5 years in GRC platform development with proficiency in platforms such as ServiceNow GRC or RSA Archer.
  • Strong analytical skills and deep understanding of cyber risk management principles.

Responsibilities

  • Lead and mature the Third-Party Risk Management (TPRM) program, aligning with business and regulatory needs.
  • Oversee the entire third-party risk lifecycle, from vendor onboarding to offboarding.
  • Develop and enhance risk methodologies, assessment templates, and control validation processes.
  • Report on third-party risk posture to executives, highlighting critical exposures and remediation progress.
  • Collaborate on strategic roadmap for GRC and TPRM, managing platforms for scalability and alignment.
  • Identify automation opportunities for enhanced efficiency in risk management processes.
  • Maintain third-party risk policies and conduct cyclical reviews with senior leadership.

Benefits

  • Onsite work opportunity in Miramar, Florida.
  • Collaborative team environment focused on growth and security enhancements.
  • Access to relevant training and professional development resources.
Full Job Description
The Royal Caribbean Group's IT-Global Information Security Team has an exciting career opportunity for a full-time Lead, IS Third Party Risk Management reporting to the Sr Mgr, CyberSecurity Risk Management

The position is onsite and based in Miramar , Florida.

  • Essential Duties and Responsibilities:We are seeking a highly skilled and experienced Lead, Information Risk and GRC with a strong emphasis on Third-Party Risk Management (TPRM) to join the Global Information Security (GIS) team. The ideal candidate will bring deep expertise in managing third-party cyber risk across the vendor lifecycle and enhancing GRC and TPRM programs and platforms.
  • Lead and mature the organization's Third-Party Risk Management (TPRM) program, ensuring alignment with business objectives, vendor strategies, and regulatory requirements.
  • Oversee end-to-end third-party risk lifecycle, including; Vendor onboarding and inherent risk tiering; Security due diligence (cyber risk assessments); Continuous monitoring and reassessment; Offboarding and risk closure
  • Define and enhance third-party risk methodologies, including; Risk scoring models; Standardized assessment templates; Control validation and evidence review processes; Prioritize and assess vendor-related cyber risks, ensuring appropriate mitigation strategies, compensating controls, and risk acceptance processes are implemented.
  • Provide executive-level reporting on third-party risk posture, including; Critical vendor risk exposure; Concentration risk insights; Remediation progress and SLA adherence
  • Partner with Sr. Director and Sr. Manager to define the strategic roadmap for GRC and TPRM platforms, ensuring scalability and alignment to enterprise risk management needs.
  • Lead configuration and optimization of TPRM workflows within platforms such as ServiceNow GRC / Archer / MetricStream; Intake workflows; Automated risk scoring; Evidence tracking; Issue remediation workflows
  • Identify automation opportunities to improve; Vendor onboarding cycle time; Assessment throughput; Reporting and dashboards
  • Oversee ongoing platform maintenance, enhancements, and user adoption across business units.
  • Develop and maintain third-party risk policies, standards, and procedures.
  • Ensure cyclical policy reviews with CISO, CIO, and senior leadership, with updates reflecting evolving supply chain threats.
  • Act as SME for third-party risk during audits, regulatory reviews, and internal risk councils.
  • Partner with Procurement, Legal, Privacy, and Business Owners to embed security requirements in vendor selection and contracting.
  • Provide guidance and training to stakeholders on third-party risk processes and expectations.
  • Support escalation management for high-risk or non-compliant vendors.


  • Qualifications, Knowledge and Skills:Bachelor's in information technology/security, Computer Science is preferred, non-technical degrees with Computer Science fundamentals will be considered combined with technology experience.
  • At least one Information Security certification such as CISSP, CCSP, CEH, CRISC, GIAC, CISM, etc. required.
  • 5-7 years of Information Security, Information Technology, Risk, Audit and/or a combination of experience.
  • 5-7 years of managing projects and/or teams.
  • 2-5 years of experience in GRC platform development.
  • Proficiency in GRC platforms (e.g., RSA Archer, ServiceNow GRC, MetricStream) and risk assessment tools. Strong understanding of information security frameworks (e.g., NIST CSF, ISO 27001).
  • Deep understanding of cyber risk management principles, threat modeling, and risk mitigation strategies.
  • Strong analytical and problem-solving skills. Ability to assess risks, identify solutions, and make data-driven decisions.
  • Previous experience in a lead or managerial role is highly desirable.
  • Executive level written and verbal communications required. Ability to effectively communicate complex security concepts to both technical and non-technical audiences.
  • Takes initiative and anticipates needs before they arise.
  • Pays close attention to detail while maintaining a big-picture perspective.
  • Works well with others and contributes to a positive team culture.
  • Thrives in a fast-paced, dynamic environment.


We know there's a lot to consider. As you go through the application process, our recruiters will be glad to provide guidance, and more relevant details to answer any additional questions. Thank you again for your interest in Royal Caribbean Group. We'll hope to see you onboard soon!

About Royal Caribbean Group

Royal Caribbean Group is a cruise vacation company with a global fleet of 63 ships traveling around the world. The company provides celebrity cruises and silversea cruises. Royal Caribbean Group was established in 1968 in Miami, Florida.

Royal Caribbean Group Careers

There has never been a more exciting time to explore job opportunities with Royal Caribbean Group, a leader in the global cruise industry known for innovation and excellence.

Work You’ll Do

Join Royal Caribbean Group's dynamic team to help redefine the travel experience for millions of guests worldwide. The company's commitment to growth and leadership in the cruise industry offers a unique platform for professionals to advance their careers. Transform the future of travel with Royal Caribbean Group, where diversity, innovation, and a passion for service converge to create extraordinary vacation experiences. Lead in a market where skills in technology, customer service, and operational excellence are prized. Royal Caribbean Group stands at the forefront of the travel industry, offering team members unparalleled opportunities for career advancement. Work alongside a global team of professionals dedicated to pioneering new paths in the cruise sector. Royal Caribbean Group fosters a culture of innovation and leadership, making it an ideal workplace for those aiming to make a significant impact.

Royal Caribbean Group Professional Pathways

The team is actively building a robust professional network, inviting individuals to master their career journey in the vibrant world of cruise travel.

Do Innovative Work

Engage with a diverse team at Royal Caribbean Group—professionals dedicated to reshaping the future of travel through continuous innovation and a deep understanding of the global travel market.

Drive Innovation and Leadership

Deliver targeted solutions and exceptional guest experiences by leveraging deep industry knowledge and a commitment to innovation that’s second to none.

Be Part of a Great Team

Join a workforce that thrives on collaboration and diversity. Royal Caribbean Group offers a variety of job opportunities that harness the capabilities of its expansive global network.

Future-proof Your Career

Royal Caribbean Group provides a wealth of opportunities for personal and professional development, supported by comprehensive training programs and a commitment to promoting from within.

Explore

Discover how Royal Caribbean Group is leading the way in employee satisfaction and guest service, setting new standards in the cruise industry.

The Royal Caribbean Group Advantage

With a focus on diversity, leadership, and professional growth, Royal Caribbean Group helps team members navigate their careers in an ever-evolving industry. The company's global scale and commitment to innovation offer unmatched opportunities for career advancement.

Stay Connected

Join the Team

Search open positions that match your skills and interests. Royal Caribbean Group looks for passionate, curious, creative, and solution-driven team players. SEARCH ROYAL CARIBBEAN JOBS

Keep Up to Date

Stay ahead with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the professionals who work at Royal Caribbean Group.

READ CAREERS BLOG

Job Alert Emails

Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Explore the exciting and rewarding opportunities that await at Royal Caribbean Group.
Learn more about Royal Caribbean Group
Size
10,001 employees
Industry

Similar Jobs

More Jobs at Royal Caribbean Group

More Information Technology Jobs

Find similar Lead, Information Risk and GRC jobs: