Security Engineer, MFA and Web Access Management
Marriott InternationalAbout the role
JOB SUMMARY
Leads the Identity & Access Management (IAM) function in Global Information Security organization through subject matter expertise (L3) on Multi-factor authentication (MFA), Web Access Management (WAM) technologies. Functions as the Security Engineer in the team providing engineering support for MFA and SSO service offerings, daily operations, and continuous improvements. Hands-on MFA implementation experience with PingOne SaaS products (DaVinci, Protect, Verify, Directory) including integrations with Ping Federate for SSO services. Analyzes and implements changes to the MFA and SSO infrastructure including configurations and customizations to address application, security, and performance requirements. Works with stakeholders to integrate and onboard new applications and helps troubleshoot integrations with existing applications and systems. Responsible for directing L2/L1 technical staff to address application security issues.
CANDIDATE PROFILE
Required Education and Experience
- Undergraduate degree in Computer Sciences or related field or equivalent work experience and certifications
- Minimum 4+ years of information security or infrastructure engineering experience including -
- 4+ years of experience in managing MFA offerings
- Passkeys, Biometrics, FIDO tokens, various authenticators
- Implementation exprience of PingOne products like DaVinci, Verify, Protect, Neo
- 4+ years’ experience of Federation/SSO services, protocols, and technologies
a. OAuth/OIDC, SAML, WS-FED
b. Browsers, MDM/MAM, X509 cert-based authentication (user & device) - 2+ years’ experience with Ping Access and Ping Federate architecture, design, and implementation
a. Policy design and implementation
b. Ping Fed custom adapter development
c. Integration of custom applications - 2+ years of experience in Development
a. JAVA, HTML/JavaScript/JSON, scripting (Ansible, Shell, Perl, Expect)
- 2+ years of experience translating business requirements to technical requirements with strong written and verbal communication skills
- 2+ years of experience with LDAP and directory Services using Radiantlogic or Ping Directory
Preferred:
- 5+ years of experience with integrating IAM solutions with infrastructure and applications
- 2+ years of experience in designing & implementing API services and data transformation layers
- 2+ years of experience on containerized deployment environments
- Current information security certification, including Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified SCADA Security Architect (CSSA) or Certified Secure Software Lifecycle Professional (CSSLP)
- Technical knowledge of industry best practices pertaining to MFA/WAM services
- Experience with defining & fulfilling Key Performance Indicators for MFA infrastructure
- Experience in the IAM domain with user lifecycle management, authentication, authorization, federation, and privileged access management
- Experience in implementing the capabilities such as Passwordless or adaptive authentication
- Experience with cloud/SaaS IAM/WAM services
- Experience with Zero-Trust Framework
- Experience with CASB and WAF technologies.
- Experience doing business analysis and requirements gathering for complex business systems
- Responsible for identifying, evaluating, and participating in decision making around new and emerging IAM/MFA technologies and should be able to support other areas of Information Security as needed
- Strong understanding of PKI, certificate management, security, and provisioning of identity data.
CORE WORK ACTIVITIES
- Functions as an MFA and WAM point of contact for IT system administrators, Service Desk, service providers and application owners.
- Works closely with senior engineers and other team members for MFA and SSO services and operational needs.
- Routinely collaborates with different security team members including, but not limited to architecture, infrastructure, network, compliance, and incident response
- Manages the MFA and WAM services including requirements gathering, design, building, testing, deployment, and operationalization.
- Collaborates with multiple stakeholders to support implementation of new applications and services.
- Defines and documents MFA an d WAM policies and procedures
- Creates test cases to ensure cross platform interoperability.
- Implemen
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s