- Company Name
- Royal Caribbean Group
- Job Title
- Lead, Information Risk Management
- Job Description
-
Job Title: Lead, Information Risk Management
Role Summary: Senior leader responsible for directing comprehensive information security risk assessments across IT systems, applications, and processes. Oversees risk identification, analysis, mitigation, and reporting; ensures compliance with regulatory frameworks (SOX, GDPR, HIPAA, PCI‑DSS) and industry standards (ISO 27001, NIST CSF). Drives continuous improvement of the organization’s Information Risk Management program and collaborates with business, IT, legal, compliance, and audit functions.
Expectations: • 5‑7 years of experience in information security, risk management, or audit with demonstrated project and team leadership.
• Proven track record conducting application and third‑party risk assessments and managing risk mitigation strategies.
• Strong command of GRC platforms (RSA Archer, ServiceNow GRC, MetricStream) and risk assessment tools.
• Ability to communicate complex security concepts to executive and non‑technical audiences.
• Proactive, detail‑oriented, and capable of thriving in a fast‑paced environment.
Key Responsibilities
- Lead end‑to‑end information security risk assessments for enterprise systems, applications, and vendors.
- Identify, document, and prioritize cyber risks, producing actionable recommendations and risk dashboards for senior leadership.
- Ensure adherence to regulatory requirements and frameworks; support compliance assessments and documentation.
- Collaborate with BISOs, IT, legal, procurement, HR, internal audit, and other stakeholders to embed risk‑aware practices.
- Review security contract language to align with corporate policy and risk appetite.
- Manage and mentor a team of risk analysts, developing their assessment capabilities.
- Drive automation of risk workflows and compliance processes within GRC platforms.
- Update security policies and standards in response to threat landscape changes and regulatory updates.
- Partner with the Senior Manager to design and deliver risk literacy training.
Required Skills
- Expertise in cyber risk management, threat modeling, and risk mitigation.
- Proficiency in GRC platforms (RSA Archer, ServiceNow GRC, MetricStream).
- Deep knowledge of information security frameworks (ISO 27001, NIST CSF, PCI‑DSS, SOX, GDPR, HIPAA).
- Strong analytical, problem‑solving, and data‑driven decision‑making abilities.
- Excellent written and verbal communication; ability to convey technical concepts to diverse audiences.
- Leadership, team management, and stakeholder collaboration.
Required Education & Certifications
- Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or related field (non‑technical degrees with IT fundamentals acceptable).
- Minimum one industry certification: CISSP, CCSP, CEH, CRISC, GIAC, CISM, or equivalent.
- 2‑5 years experience in GRC platform development.