SrManager - Information Security - Threat Management & Response
Marriott InternationalAbout the role
Seeking a seasoned cybersecurity professional to lead and coordinate red team exercises, external engagements, and ongoing purple team initiatives aimed at uncovering vulnerabilities and enhancing the organization’s security posture. Collaborate closely with cross-functional teams to conduct continuous purple team exercises, sharing insights and knowledge to strengthen defenses. Analyze and prioritize findigs from red and purple team activities, providing data-driven recommendations for security enhancements. Produce comprehensive reports detailing exercise results and proposed mitigations. Offer guidance and support for implementing security controls and enhancements, while staying abreast of emerging threats and trends to ensure proactive proactive dfense measures.
This role is part Marriott Global Cybersecurity organization with our primary offices in Bethesda, MD, and Singapore and with teams elsewhere in the US, Europe and Asia.
CANDIDATE PROFILE
Education and Experience
Required:
- Bachelor’s degree in Computer Sciences or related field or equivalent experience/certification
- 7+ years of progressive information technology leadership experience
- 4+ years’ information security experience that includes:
- Red teaming, threat emulation experience
- Creation of threat reports for executive (non technical) and technical stakeholders
- Experience in threat data analysis and response planning.
Preferred:
- Current information security certification, including Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA) or Certified Information Systems Security Professional (CISSP)
- Technical leadership experience in a sourced environment
- Project management skills
- Excellent communication skills and problem solving ability
- Demonstrated ability to work independently and with others
- Ability to manage the details and compliance with standards and expectations
- Technical infrastructure operations, administration, or engineering background
CORE WORK ACTIVITIES
- Lead and organize red team exercises, external red team engagements, and ongoing purple team exercises to identify vulnerabilities, control gaps, and potential attack vectors in the organization’s information systems.
- Collaborate closely with various teams to conduct continuous purple team exercises, sharing insights and knowledge to enhance overall security posture.
- Analyze and prioritize findings from red and purple team exercises, offering data-driven recommendations to improve the organization’s security measures.
- Produce high-quality reports detailing exercise results, including vulnerabilities, risks, proposed mitigations, and thematic improvement opportunities.
- Provide guidance and support for implementing recommended security controls and enhancements.
- Utilize threat intelligence to identify detection opportunities and develop, test, and tune detection content for both host and network-based log sources.
- Demonstrate expertise in scripting capabilities, utilizing languages such as PowerShell, Pythin, VBScript, and shell scripts for automation and troubleshooting tasks.
- Conduct deep investigations and forensic analysis to identify security incidents, utilizing tools like CrowdStrike and Splunk for threat hunting and incident response.
- Stay up-to-date with emerging security threats and trends, including APT Tactics, Techniques, and Procedures (TTPs), to ensure the organization’s defenses remain effective.
- Collaborate with IT Teams on escalations, tracking, configuration issues, etc. related to security validation findings.
- Develop new detection rules to enhance detection capabilities and improve overall threat resilience.
- Foster a culture of continuous learning and improvement within the cybersecurity team, staying current with new technologies and best practices in the cybersecurity landscape.
- Generate detailed threat intelligence, red teaming reports on monthly, quarterly, and ad-hoc bases.
- Produce and review executive-level briefings on current events, red teaming activities and strategic cyber intelligence.
- Communicate complex threat events or security incident details to a wide audience, including executives, legal, and technical staff, in both verbal and written forms.
- Advise internal stakeholders on threat intelligence best practices and strategies.
- Engage in external threat intelligence sharing with partners and platforms.
Maintaining Goals
- Submits reports in a timely manner, ensuring delivery deadlines are met.
- Promotes the documenting of project progress accurat
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s