Royal Caribbean Group

Lead, Information Risk and GRC

Royal Caribbean Group$100K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's in IT/security or Computer Science (non-technical degrees with tech experience considered).
  • One Information Security certification (e.g., CISSP, CCSP, CEH required).
  • 5-7 years in Information Security, IT, Risk, Audit, or related experience.
  • 5-7 years managing projects or teams.
  • 2-5 years in GRC platform development experience.
  • Proficiency with GRC platforms (RSA Archer, ServiceNow GRC, MetricStream) and risk assessment tools.
  • Strong understanding of information security frameworks (NIST CSF, ISO 27001).

Responsibilities

  • Lead and mature the organization's TPRM program aligning with business objectives and regulatory requirements.
  • Oversee the end-to-end third-party risk lifecycle, including vendor onboarding and risk tiering.
  • Define and enhance third-party risk methodologies including risk scoring and assessment templates.
  • Provide executive-level reporting on third-party risk posture and remediation progress.
  • Partner with Sr. Director and Manager to define the strategic roadmap for GRC and TPRM platforms.
  • Lead configuration and optimization of TPRM workflows within platforms like ServiceNow GRC.
  • Identify automation opportunities for efficiency improvements in TPRM processes.

Benefits

  • Onsite role based in Miramar, Florida.
  • Opportunity to lead and influence third-party risk management practices.
  • Collaboration with senior leadership and cross-functional teams.
  • Access to continuous professional development and training opportunities.
Full Job Description
The Royal Caribbean Group's IT-Global Information Security Team has an exciting career opportunity for a full-time Lead, IS Third Party Risk Management reporting to the Sr Mgr, CyberSecurity Risk Management

The position is onsite and based in Miramar , Florida.

  • Essential Duties and Responsibilities:We are seeking a highly skilled and experienced Lead, Information Risk and GRC with a strong emphasis on Third-Party Risk Management (TPRM) to join the Global Information Security (GIS) team. The ideal candidate will bring deep expertise in managing third-party cyber risk across the vendor lifecycle and enhancing GRC and TPRM programs and platforms.
  • Lead and mature the organization's Third-Party Risk Management (TPRM) program, ensuring alignment with business objectives, vendor strategies, and regulatory requirements.
  • Oversee end-to-end third-party risk lifecycle, including; Vendor onboarding and inherent risk tiering; Security due diligence (cyber risk assessments); Continuous monitoring and reassessment; Offboarding and risk closure
  • Define and enhance third-party risk methodologies, including; Risk scoring models; Standardized assessment templates; Control validation and evidence review processes; Prioritize and assess vendor-related cyber risks, ensuring appropriate mitigation strategies, compensating controls, and risk acceptance processes are implemented.
  • Provide executive-level reporting on third-party risk posture, including; Critical vendor risk exposure; Concentration risk insights; Remediation progress and SLA adherence
  • Partner with Sr. Director and Sr. Manager to define the strategic roadmap for GRC and TPRM platforms, ensuring scalability and alignment to enterprise risk management needs.
  • Lead configuration and optimization of TPRM workflows within platforms such as ServiceNow GRC / Archer / MetricStream; Intake workflows; Automated risk scoring; Evidence tracking; Issue remediation workflows
  • Identify automation opportunities to improve; Vendor onboarding cycle time; Assessment throughput; Reporting and dashboards
  • Oversee ongoing platform maintenance, enhancements, and user adoption across business units.
  • Develop and maintain third-party risk policies, standards, and procedures.
  • Ensure cyclical policy reviews with CISO, CIO, and senior leadership, with updates reflecting evolving supply chain threats.
  • Act as SME for third-party risk during audits, regulatory reviews, and internal risk councils.
  • Partner with Procurement, Legal, Privacy, and Business Owners to embed security requirements in vendor selection and contracting.
  • Provide guidance and training to stakeholders on third-party risk processes and expectations.
  • Support escalation management for high-risk or non-compliant vendors.


  • Qualifications, Knowledge and Skills:Bachelor's in information technology/security, Computer Science is preferred, non-technical degrees with Computer Science fundamentals will be considered combined with technology experience.
  • At least one Information Security certification such as CISSP, CCSP, CEH, CRISC, GIAC, CISM, etc. required.
  • 5-7 years of Information Security, Information Technology, Risk, Audit and/or a combination of experience.
  • 5-7 years of managing projects and/or teams.
  • 2-5 years of experience in GRC platform development.
  • Proficiency in GRC platforms (e.g., RSA Archer, ServiceNow GRC, MetricStream) and risk assessment tools. Strong understanding of information security frameworks (e.g., NIST CSF, ISO 27001).
  • Deep understanding of cyber risk management principles, threat modeling, and risk mitigation strategies.
  • Strong analytical and problem-solving skills. Ability to assess risks, identify solutions, and make data-driven decisions.
  • Previous experience in a lead or managerial role is highly desirable.
  • Executive level written and verbal communications required. Ability to effectively communicate complex security concepts to both technical and non-technical audiences.
  • Takes initiative and anticipates needs before they arise.
  • Pays close attention to detail while maintaining a big-picture perspective.
  • Works well with others and contributes to a positive team culture.
  • Thrives in a fast-paced, dynamic environment.


We know there's a lot to consider. As you go through the application process, our recruiters will be glad to provide guidance, and more relevant details to answer any additional questions. Thank you again for your interest in Royal Caribbean Group. We'll hope to see you onboard soon!

About Royal Caribbean Group

Royal Caribbean Group is a cruise vacation company with a global fleet of 63 ships traveling around the world. The company provides celebrity cruises and silversea cruises. Royal Caribbean Group was established in 1968 in Miami, Florida.

Royal Caribbean Group Careers

There has never been a more exciting time to explore job opportunities with Royal Caribbean Group, a leader in the global cruise industry known for innovation and excellence.

Work You’ll Do

Join Royal Caribbean Group's dynamic team to help redefine the travel experience for millions of guests worldwide. The company's commitment to growth and leadership in the cruise industry offers a unique platform for professionals to advance their careers. Transform the future of travel with Royal Caribbean Group, where diversity, innovation, and a passion for service converge to create extraordinary vacation experiences. Lead in a market where skills in technology, customer service, and operational excellence are prized. Royal Caribbean Group stands at the forefront of the travel industry, offering team members unparalleled opportunities for career advancement. Work alongside a global team of professionals dedicated to pioneering new paths in the cruise sector. Royal Caribbean Group fosters a culture of innovation and leadership, making it an ideal workplace for those aiming to make a significant impact.

Royal Caribbean Group Professional Pathways

The team is actively building a robust professional network, inviting individuals to master their career journey in the vibrant world of cruise travel.

Do Innovative Work

Engage with a diverse team at Royal Caribbean Group—professionals dedicated to reshaping the future of travel through continuous innovation and a deep understanding of the global travel market.

Drive Innovation and Leadership

Deliver targeted solutions and exceptional guest experiences by leveraging deep industry knowledge and a commitment to innovation that’s second to none.

Be Part of a Great Team

Join a workforce that thrives on collaboration and diversity. Royal Caribbean Group offers a variety of job opportunities that harness the capabilities of its expansive global network.

Future-proof Your Career

Royal Caribbean Group provides a wealth of opportunities for personal and professional development, supported by comprehensive training programs and a commitment to promoting from within.

Explore

Discover how Royal Caribbean Group is leading the way in employee satisfaction and guest service, setting new standards in the cruise industry.

The Royal Caribbean Group Advantage

With a focus on diversity, leadership, and professional growth, Royal Caribbean Group helps team members navigate their careers in an ever-evolving industry. The company's global scale and commitment to innovation offer unmatched opportunities for career advancement.

Stay Connected

Join the Team

Search open positions that match your skills and interests. Royal Caribbean Group looks for passionate, curious, creative, and solution-driven team players. SEARCH ROYAL CARIBBEAN JOBS

Keep Up to Date

Stay ahead with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the professionals who work at Royal Caribbean Group.

READ CAREERS BLOG

Job Alert Emails

Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Explore the exciting and rewarding opportunities that await at Royal Caribbean Group.
Learn more about Royal Caribbean Group
Size
10,001 employees
Industry

Similar Jobs

More Jobs at Royal Caribbean Group

More Information Technology Jobs

Find similar Lead, Information Risk and GRC jobs: