Journey with us!ย Combine your career goals and sense of adventure by joining our exciting team of employees. Royal Caribbean Group is pleased to offer a competitive compensation and benefits package, and excellent career development opportunities, each offering unique ways to explore the world.
The Royal Caribbean Group's IT-Global Information Security Team has an exciting career opportunity for a full-time Lead, IS Third Party Risk Management reporting to the Sr Mgr, CyberSecurity Risk Management
The position is onsite and based in Miramar , Florida.
- Essential Duties and Responsibilities:ย
We areย seekingย a highly skilled and experienced Lead, Information Risk and GRC with a strong emphasis on Third-Party Risk Management (TPRM) to join the Global Information Security (GIS) team. The ideal candidate will bring deepย expertiseย in managing third-party cyber risk across the vendor lifecycle and enhancing GRC and TPRM programs and platforms.ย - ย
- Lead and mature the organization's Third-Party Risk Management (TPRM) program, ensuring alignment with businessย objectives, vendor strategies, and regulatory requirements.ย
- Oversee end-to-end third-party risk lifecycle, including;ย Vendor onboarding and inherent risk tiering;ย Security due diligence (cyber risk assessments);ย Continuous monitoring and reassessment;ย Offboarding and risk closureย
- Define and enhance third-party risk methodologies, including;ย Risk scoring models;ย Standardized assessment templates;ย Control validation and evidence reviewย processes;ย Prioritizeย and assess vendor-related cyber risks, ensuringย appropriate mitigationย strategies, compensating controls, and risk acceptance processes are implemented.ย
- Provide executive-level reporting on third-party risk posture, including;ย Critical vendor risk exposure;ย Concentration risk insights;ย Remediation progress and SLA adherenceย
- Partner with Sr. Director and Sr. Manager to define the strategic roadmap for GRC and TPRM platforms, ensuring scalability and alignment to enterprise risk management needs.ย
- Lead configuration and optimization of TPRM workflows within platforms such as ServiceNow GRC / Archer / MetricStream; Intake workflows; Automated risk scoring; Evidence tracking; Issue remediation workflowsย
- Identifyย automation opportunities to improve; Vendor onboarding cycle time;ย Assessment throughput;ย Reporting and dashboardsย
- Oversee ongoing platform maintenance, enhancements, and user adoption across business units.ย
- Develop andย maintainย third-party risk policies, standards, and procedures.ย ย
- Ensure cyclical policy reviews with CISO, CIO, and senior leadership, with updates reflecting evolving supply chain threats.ย
- Act as SME for third-party risk during audits, regulatory reviews, and internal risk councils.ย
- Partner with Procurement, Legal, Privacy, and Business Owners to embed security requirements in vendor selection and contracting.ย
- Provide guidance and training to stakeholders on third-party risk processes and expectations.ย
- Support escalation management for high-risk or non-compliant vendors.
ย
- Qualifications, Knowledge and Skills:
Bachelor'sย in information technology/security, Computer Science isย preferred,ย non-technical degrees with Computer Science fundamentals will beย consideredย combined with technology experience.ย ย - At least one Information Security certification such as CISSP, CCSP, CEH, CRISC, GIAC, CISM, etc.ย required.ย
- 5-7ย years of Information Security, Information Technology, Risk,ย Auditย and/or a combination of experience.ย
- 5-7ย years of managing projects and/or teams.ย ย ย
- 2-5 years of experience in GRC platform development.ย ย
- Proficiencyย in GRC platforms (e.g., RSA Archer, ServiceNow GRC, MetricStream) and risk assessment tools. Strong understanding of information security frameworks (e.g., NISTย CSF, ISO 27001).ย
- Deep understanding of cyber risk management principles, threat modeling, and risk mitigation strategies.ย
- Strong analytical and problem-solving skills. Ability to assess risks,ย identifyย solutions, and make data-driven decisions.ย
- Previousย experience in a lead or managerial role is highly desirable.ย
- Executive level written and verbal communicationsย required.ย Ability to effectively communicate complex security concepts to both technical and non-technical audiences.ย
- Takesย initiative andย anticipatesย needs before they arise.ย
- Paysย close attention to detail whileย maintainingย aย big-pictureย perspective.ย
- Works well with others and contributes to a positive team culture.ย
- Thrives in a fast-paced, dynamic environment.ย
We know there's a lot to consider. As you go through the application process, our recruiters will be glad to provide guidance, and more relevant details to answer any additional questions. Thank you again for your interest in Royal Caribbean Group. We'll hope to see you onboard soon!
It is the policy of the Company to ensure equal employment and promotion opportunity to qualified candidates without discrimination or harassment on the basis of race, color, religion, sex, age, national origin, disability, sexual orientation, sexuality, gender identity or expression, marital status, or any other characteristic protected by law. Royal Caribbean Groupย and each of its subsidiaries prohibit and will not tolerate discrimination or harassment.