Apply now »

Director, Cyber Security Counter Threat Management

Journey with us! Combine your career goals and sense of adventure by joining our exciting team of employees. Royal Caribbean Group is pleased to offer a competitive compensation and benefits package, and excellent career development opportunities, each offering unique ways to explore the world.

 

We are proud to be the vacation-industry leader with global brands — including Royal Caribbean International, Celebrity Cruises and Silversea Cruises — the most innovative fleet and private destinations, and the best people. Together, we are dedicated to turning the vacation of a lifetime into a lifetime of vacations for our guests.

 

The Royal Caribbean Group’s IT Global Information Security Team has an exciting career opportunity for a full time Director, Cyber Security Counter Threat Management reporting to the Senior Director, Cyber Security Engineering and Defense Operations.

 

This position is onsite and based in Miami, Florida.

 

This position is also not eligible for work authorization sponsorship.

 

Position Summary:

 

The Director of Cyber Security Counter Threat Management leads two core functions: Attack Surface Management and Vulnerability Management.

For Attack Surface Management, this role sets the enterprise strategy for identifying, prioritizing, and reducing cyber attack surface risk across the global environment, with the goal of protecting Royal Caribbean Group assets.

 

For Vulnerability Management, this role leads the team responsible for reducing vulnerability risk across enterprise, cloud, infrastructure, and shipboard environments. Success requires executive-level communication, cross-functional influence, strong people leadership, and the ability to balance security risk reduction with business operations and enablement.

 

Essential Duties and Responsibilities:

 

  • Lead Managers and highly technical subject matter experts responsible for attack surface discovery & hardening, infrastructure vulnerability governance, and configuration risk management.
  • Set enterprise strategy, direction, roadmap, and operating model for the Attack Surface Management & Vulnerability Management.
  • Serve as an executive escalation point for complex remediation challenges, high-risk vulnerabilities, policy exceptions, and business-impacting security decisions while balancing the needs of security and business operations.
  • Technical mentorship - Develop technical talent and professional skills within the team
  • Partner with BISOs, Digital, IT, product, engineering, cloud, shipboard technology, and business leaders to drive risk reduction while enabling business outcomes.
  • Establish risk-based prioritization models that account for exploitability, asset criticality, business impact, regulatory expectations, and operational constraints.
  • Produce and track key performance indicators and risk indicators to demonstrate improvements in infrastructure vulnerabilities, configuration issues, assessment coverage, remediation aging, and overall exposure reduction.
  • Drive automation of ASM workflows using scripting, orchestration, APIs, AI-enabled workflows, and agentic AI capabilities to improve scale, speed, consistency, and measurable risk reduction.
  • Define governance, guardrails, and control expectations for AI- and automation-enabled ASM processes in partnership with cybersecurity, legal, compliance, privacy, and risk stakeholders.
  • Influence without authority across distributed technology and business teams to improve remediation ownership, accountability, and execution speed.

 

Qualifications:

 

  • Bachelor’s degree in Computer Science, Cyber Security, Information Technology, Engineering, or a similar technical discipline; advanced degree preferred.
  • 10+ years of experience in information technology.
  • 6+ years of experience in attack surface management, vulnerability management, infrastructure security, security engineering, or cloud security roles.
  • Demonstrated experience leading Managers and highly technical security SMEs
  • A broad and deep understanding of cyber-security threats, vulnerabilities, exploitability, controls, remediation strategies, and exposure management practices.
  • Strong technical knowledge in information technology, including hardware, networking, architecture, protocols, file systems, operating systems, cloud services, application architecture, APIs, and common enterprise platforms.
  • An ability to communicate complex and technical issues to diverse audiences, including engineers, operators, business stakeholders, executives, auditors, and regulators.
  • Strong decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and the associated impact on the organization.

 

Agency and Third-Party Submissions: Please note this is a direct search by the Company, and applications through agencies and other third parties will not be accepted, nor will fees be paid for unsolicited resumes. Any unsolicited resumes will be considered the Company's property.

 

We know there's a lot to consider. As you go through the application process, our recruiters will be glad to provide guidance, and more relevant details to answer any additional questions. Thank you again for your interest in Royal Caribbean Group. We'll hope to see you onboard soon!

 

It is the policy of the Company to ensure equal employment and promotion opportunity to qualified candidates without discrimination or harassment on the basis of race, color, religion, sex, age, national origin, disability, sexual orientation, sexuality, gender identity or expression, marital status, or any other characteristic protected by law. Royal Caribbean Group and each of its subsidiaries prohibit and will not tolerate discrimination or harassment. 

 

#LI-MP1


Nearest Major Market: Miami

Apply now »