Lead, Information Risk and GRC
Listed on 2026-07-01
-
IT/Tech
Information Security, Cybersecurity, IT Business Analyst, IT Consultant
Journey with us! Combine your career goals and sense of team of employees. Royal Caribbean Group offers a competitive compensation and benefits package and excellent career development opportunities.
Royal Caribbean Group’s IT‑Global Information Security Team has an exciting career opportunity for a full‑time Lead, IS Third Party Risk Management reporting to the Sr Mgr, Cyber Security Risk Management.
Location: The position is onsite and based in Miramar, Florida.
Responsibilities- Lead and mature the organization’s Third‑Party Risk Management (TPRM) program, ensuring alignment with business objectives, vendor strategies, and regulatory requirements.
- Oversee end‑to‑end third‑party risk lifecycle, including vendor onboarding and inherent risk tiering; security due diligence (cyber risk assessments); continuous monitoring and reassessment; offboarding and risk closure.
- Define and enhance third‑party risk methodologies, including risk scoring models; standardized assessment templates; control validation and evidence review processes; prioritize and assess vendor‑related cyber risks, ensuring appropriate mitigation strategies, compensating controls, and risk acceptance processes are implemented.
- Provide executive‑level reporting on third‑party risk posture, including critical vendor risk exposure; concentration risk insights; remediation progress and SLA adherence.
- Partner with Sr. Director and Sr. Manager to define the strategic roadmap for GRC and TPRM platforms, ensuring scalability and alignment to enterprise risk management needs.
- Lead configuration and optimization of TPRM workflows within platforms such as Service Now GRC / Archer / Metric Stream; intake workflows; automated risk scoring; evidence tracking; issue remediation workflows.
- Identify automation opportunities to improve vendor onboarding cycle time; assessment throughput; reporting and dashboards.
- Oversee ongoing platform maintenance, enhancements, and user adoption across business units.
- Develop and maintain third‑party risk policies, standards, and procedures.
- Ensure cyclical policy reviews with CISO, CIO, and senior leadership, with updates reflecting evolving supply chain threats.
- Act as SME for third‑party risk during audits, regulatory reviews, and internal risk councils.
- Partner with Procurement, Legal, Privacy, and Business Owners to embed security requirements in vendor selection and contracting.
- Provide guidance and training to stakeholders on third‑party risk processes and expectations.
- Support escalation management for high‑risk or non‑compliant vendors.
- Bachelor’s in information technology/security or Computer Science (non‑technical degrees acceptable if combined with technology experience).
- At least one Information Security certification (CISSP, CCSP, CEH, CRISC, GIAC, CISM, etc.).
- 5‑7 years of experience in Information Security, Information Technology, Risk, Audit or a combination.
- 5‑7 years of managing projects and/or teams.
- 2‑5 years of experience in GRC platform development.
- Proficiency with GRC platforms (RSA Archer, Service Now GRC, Metric Stream) and risk assessment tools; strong understanding of information security frameworks (NIST CSF, ISO 27001).
- Deep understanding of cyber risk management principles, threat modeling, and risk mitigation strategies.
- Strong analytical and problem‑solving skills, ability to assess risks, identify solutions, and make data‑driven decisions.
- Previous experience in a lead or managerial role.
- Executive level written and verbal communication skills; ability to explain complex security concepts to technical and non‑technical audiences.
- Initiative, foresight, attention to detail, and big‑picture perspective.
- Team player who contributes to a positive team culture.
- Thrives in a fast‑paced, dynamic environment.
It is the policy of the Company to ensure equal employment and promotion opportunity to qualified candidates without discrimination or harassment on the basis of race, color, religion, sex, age, national origin, disability, sexual orientation, sexuality, gender identity or expression, marital status, or any other characteristic protected by law. Royal Caribbean Group and each of its subsidiaries prohibit and will not tolerate discrimination or harassment.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).