Royal Caribbean Cruises Ltd logo
Engineer, Vulnerability Management
full-timePasay

Summary

Location

Pasay

Type

full-time

Explore Jobs

About this role

KEY RESPONSIBILITIES

Position Summary: The Threat & Vulnerability Management Engineer is responsible for the deployment, configuration, and management of vulnerability management tools and delivery of related services. The role of Threat & Vulnerability Management Engineer is to detect security vulnerabilities in information systems and drive resolution in compliance with corporate security policy. You will work with system owners to evaluate vulnerability findings, identify false-positives, and prepare & deploy patches. 

 

Essential Duties and Responsibilities:  

• Collaborate with key stakeholders including senior leadership to research, develop and implement an efficient architecture to discover vulnerabilities in both shoreside and maritime systems.  

• Manage the entire vulnerability lifecycle from discovery, triage, remediation, and validation.  

• Create and evolve a risk prioritization framework that accounts for multiple factors including vulnerability severity, system function, and network accessibility.  

• Help asset owners create effective solutions to safely patch infrastructure at scale, including assisting with automated deployment of common patches  

• Promote effective remediation while preserving stakeholder happiness.  

• Manage day-to-day workflow to ensure vulnerabilities are remediated within proper timelines.  

• Create process automation including scripting and API integrations 

 

 

 

 

 

 

 

QUALIFICATIONS AND EDUCATION

• Bachelor's degree in information security or equivalent. Advanced degree preferred 

• 4+ years of information technology experience, including 2+ years of specialization in vulnerability management 

• Vulnerability Management experience, especially with vulnerability scanners (e.g. Rapid7 IVM, Tenable, etc.) and experience remediating issues with system owners  

• Experience hardening system images according to industry baselines, such as CIS Benchmarks  

• Experience with cloud security posture management tools (e.g.  Orca Security, Prisma,  Wiz, etc.) and remediating vulnerabilities and misconfigurations in cloud environments  

• Nexpose Certified Administrator certification strongly preferred  

• Vulnerability exploitation certifications including GEVA, GPEN, OSCP, or similar preferred  

• Application Security experience using SAST/DAST/SCA tools preferred  

• Scripting experience in Python, PowerShell, or similar tools preferred 

 

 

 

 

FINANCIAL/QUANTITIVE RESPONSIBILITIES

N/A

 

 

 

 

 

 

COMPARABLE POSITIONS/PEERS

 

 

 

HOW HAS THE JOB CHANGED/GROWN

(Only needed if we need to re-evaluate and grade the job. Please explain what’s different with the scope from before.)

 

 

 

 

 

 

 

INTERNAL/ EXTERNAL RELATIONSHIPS

The role will collaborate closely with Business Application owners, and partner with key GIS teams—including Business Information Security Officers,  to remediate vulnerability findings.

 

 

 

PHYSICAL REQUIREMENTS

 

 

  • Ability to remain in a stationary position (e.g., seated at a desk) for extended periods.
  • Constant use of computer, keyboard, mouse, and other office technology.
  • Ability to communicate effectively via email, messaging tools, and virtual meetings.
  • Occasional need to move about the office, attend meetings, or access equipment.
  • May require lifting or transporting lightweight items (typically under 20 lbs), such as laptops or documents.

 

 

 

WORKING CONDITIONS

  • Standard office environment with the majority of work performed at a desk using a computer.
  • Role requires frequent interaction through virtual collaboration tools (e.g., email, chat, video conferencing).
  • May involve occasional meetings outside standard business hours to support global teams or address time‑sensitive security issues.
  • Work may include periodic on‑call responsibilities during critical vulnerability management cycles or incident response activities.
  • Minimal travel may be required for training, team meetings, or cross‑functional collaboration.
  • Noise level is generally low to moderate, consistent with standard office settings.

 

 

 

 

Other facts

Tech stack
Vulnerability Management,Information Security,Cloud Security,Scripting,Automation,Risk Prioritization,System Hardening,Patch Management,Stakeholder Collaboration,Vulnerability Scanners,Application Security,API Integrations,Incident Response,CIS Benchmarks,SAST,DAST

About Royal Caribbean Cruises Ltd

At Royal Caribbean Group, we deliver unforgettable vacations to guests who trust us with life’s greatest moments. We build the best ships, and even better careers, all while doing the right thing. We are passionate. We are innovative. We are unstoppable. We open the world to our employees. Your journey is our journey — chart your own course. Journey with us!

Our culture: 

What sets the Group apart is the multicultural environment we create with employees from over 126 countries. We cultivate a workplace where employees feel they can be themselves, are appreciated because of their differences and are empowered to become part of the fabric of the Group. We have been repeatedly recognized by the Ethisphere Institute as one of the World’s Most Ethical Companies. For us, it’s a simple three-word phrase: Make good choices. Our employees have a commitment to compliance, doing the right thing and integrity.

Our brands: 

Royal Caribbean Group (NYSE: RCL) is a cruise vacation company comprised of three award-winning global brands: Royal Caribbean, Celebrity Cruises, and Silversea. Royal Caribbean Group is also a 50% owner of a joint venture that operates TUI Cruises and Hapag-Lloyd Cruises. Together, our brands operate a global fleet traveling to more than 800 destinations worldwide.

Our promise: 

We deliver the best vacation experiences, responsibly. Every one of our values and actions flows from this promise. To operate the safest ships on the seas. To protect the oceans we sail. To put people and communities first in everything we do.

Link to the careers page: https://careers.royalcaribbeangroup.com/

Team size: 10,001+ employees
LinkedIn: Visit
Industry: Travel Arrangements

What you'll do

  • The Threat & Vulnerability Management Engineer is responsible for deploying, configuring, and managing vulnerability management tools. This role involves detecting security vulnerabilities in information systems and driving resolution in compliance with corporate security policy.

Ready to join Royal Caribbean Cruises Ltd?

Take the next step in your career journey

Frequently Asked Questions

What does a Engineer, Vulnerability Management do at Royal Caribbean Cruises Ltd?

As a Engineer, Vulnerability Management at Royal Caribbean Cruises Ltd, you will: the Threat & Vulnerability Management Engineer is responsible for deploying, configuring, and managing vulnerability management tools. This role involves detecting security vulnerabilities in information systems and driving resolution in compliance with corporate security policy..

Why join Royal Caribbean Cruises Ltd as a Engineer, Vulnerability Management?

Royal Caribbean Cruises Ltd is a leading Travel Arrangements company.

Is the Engineer, Vulnerability Management position at Royal Caribbean Cruises Ltd remote?

The Engineer, Vulnerability Management position at Royal Caribbean Cruises Ltd is based in Pasay, Metro Manila, Philippines. Contact the company through Clera for specific work arrangement details.

How do I apply for the Engineer, Vulnerability Management position at Royal Caribbean Cruises Ltd?

You can apply for the Engineer, Vulnerability Management position at Royal Caribbean Cruises Ltd directly through Clera. Click the "Apply Now" button above to start your application. Clera's AI-powered platform will help match your profile with this opportunity and guide you through the application process. You can also learn more about Royal Caribbean Cruises Ltd on their website.