Jobs and Careers
MA

Senior Manager - Information Security - Applications Controls Assurance

Marriott International
United Statesfull_timeVerifiedPosted 11 Oct 2024
💰 $162,300/yr($120,500/yr$162,300/yr)

About the role

 JOB SUMMARY

The Sr. Manager, Security Assurance will lead a team responsible for ensuring that all security and compliance objectives are met before the release of software and systems into production. This role will oversee both the Certification and Accreditation (C&A) process and the security-focused aspects of software/system release management. The ideal candidate will ensure that security controls are properly implemented, risks are accurately quantified, and all required testing and documentation are completed before systems are authorized for production operation. The successful candidate will be pivotal in guiding risk-aware decision-making, enhancing the company’s overall security posture, and driving continuous improvement in secure systems development and risk management practices.

 

The ideal candidate will bring a deep understanding of data security principles and privacy regulations (e.g., GDPR, CCPA), with hands-on experience in implementing privacy-preserving security controls such as data encryption, anonymization, pseudonymization and differential privacy along with experience in risk quantification methodologies and security control testing technical. They will leverage their leadership experience mentor a team, foster collaboration and continuous professional development.

 

CANDIDATE PROFILE

Required Education and Experience

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related discipline/experience.
  • 7+ years of experience in information security, that includes:
    • a focus on Certification and Accreditation (C&A), Risk Management Framework (RMF), and/or security controls assessment.
    • a deep understanding of data security principles and privacy regulations (e.g., GDPR, CCPA), with hands-on experience in implementing privacy-preserving security controls such as data encryption, anonymization, pseudonymization and differential privacy.
    • experience with software release processes and security integration within the SDLC.
  • 2+ years as a team lead or manager in a security role response for managing security assessments, risk management, and compliance efforts for production systems.
  • 2+ years of experience in software/system release management, with a focus on security validation.

 

Preferred:

  • Master’s degree in Cybersecurity, Computer Science, or a related discipline.
  • 8+ years of experience in information security, focusing on Certification and Accreditation (C&A), Risk Management Framework (RMF), and security controls assessment.
  • Experience with risk quantification methodologies and security control testing techniques 
  • 4+ years of experience in software/system release management, with a focus on security validation.
  • Comprehensive knowledge of risk management frameworks including FAIR, NIST RMF, MITRE TARA, and OCTAVE.
  • Deep knowledge of security frameworks such as NIST SP 800-53, ISO/IEC 27001, and PCI DSS, with a strong focus on the Risk Management Framework (RMF).
  • Experience with auditing security controls in alignment with RMF processes, including evaluating the effectiveness of controls against NIST 800-53, conducting assessments for compliance, and supporting authorization and accreditation activities.
  • Familiarity with common documentation frameworks such as the 4+1 View Model, C4 Model, and ISO/IEC/IEEE 42010, as well as UML diagrams, Arc42 templates, and Architecture Decision Records (ADRs) for consuming and interpreting architectural decisions and system design.
  • Proven leadership experience in regulatory environments, with strong project management skills.
  • Open FAIR Certification (Factor Analysis of Information Risk).

 

CORE WORK ACTIVITIES

  • Lead Security Reviews for Production Deployment - Oversee security reviews and authorizations to ensure systems meet security controls, risk management requirements, and compliance with regulatory standards.
  • Manage the Certification and Accreditation Process - Ensure end-to-end completion of C&A activities, including system categorization, control selection, implementation, assessment, authorization, and continuous monitoring.
  • Oversee Security in Release Management - Ensure security validation is embedded in the software/system release process, ensuring all security controls, risk assessments, and compliance checks are complete before production release.
  • Ensure Security Controls Are Functioning - Manage the testing and assessment of security controls to ensure they address identified risks and are functioning as intended.
  • Oversee Documentation an

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Marriott International

View company profile →