Jobs and Careers
MA

Associate Architect - Global Information Security

Marriott International
United Statesfull_timeVerifiedPosted 11 Apr 2024
💰 $209,169/yr($96,038/yr$209,169/yr)

About the role

JOB SUMMARY

 

Contributes to and refines security strategies, requirements, and standards for applications and platforms. Supports in-depth technical security guidance as a Security Subject Matter Expert (SME) for various technologies and project areas. Ensures company security policies, standards and industry standards are communicated to program teams during the Software Development Life Cycle (SDLC) process. Able to identify gaps and work with project teams to improve security while retaining time to market, functionality, and scalability. Reviews and approves Security Accreditation tasks during each phase of SDLC. Serves as point of escalation for security issues and risks that may arise. Has a broad knowledge in areas of Security such as Cloud Computing, Application, IAM, Cryptography, Infrastructure, DevSecOps and Risk.

 

CANDIDATE PROFILE 

 

Education and Experience 

Required:

  • Bachelor's or master's degree in computer science, information systems, cybersecurity or a related field or equivalent experience/certification.
  • 7+ years’ progressive experience in technology/security engineering that included work in three or more of the following areas:
    • Conducting security reviews and identifying risks and gaps
    • Performing security accreditations
    • Developing security architectures and strategies
    • Developing Enterprise security patterns
    • Working with development teams and vendor teams for implementing compensating controls
  • 2+ years’ experience in contributing to the security architectures and identifying security risks/gaps as well as mitigation strategies.
  • 3+ years combined experience in some or all of the following:
    • Full-stack knowledge of IT infrastructure:
      • Applications
      • Databases
      • Operating systems — Windows, Unix, and Linux
      • IP networks — WAN and LAN
      • Knowledge of DevSecOps
      • Knowledge of API Architectures
    • Cryptography and current cryptographic standards, including PKI
    • Working knowledge of the OWASP Top 10

 

Preferred:

  • Strong working knowledge of Agile Methodologies with a focus on SAFe.
  • Strong working knowledge of IT service management (e.g., ITIL-related disciplines):
    • Change management
    • Configuration management
    • Asset management
    • Incident management
    • Problem management
  • Ability to provide security requirements for areas including but not limited to; Cloud Computing, Application Development, IAM, Cryptography, DevSecOps and Infrastructure design.
  • Ability to understand large complex integrated solutions and provide the security needed between systems.
  • Experience in developing Enterprise Security Strategies. 
  • Experience and a strong working knowledge of the methodologies to conduct threat-modeling exercises on new applications and services.
  • Experience designing the deployment of applications and infrastructure into hybrid, and public cloud services.
  • Ability to conduct independent research.
  • Strong abilities and experience in documentation and written communication for diverse audiences.
  • Experience working with diverse and distributed global teams. 
  • Current information security certification(s), such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), ISC2 Certified Cloud Security Professional (CCSP), GIAC certifications, ITIL.
  • Knowledge of Industry Standards such as NIST Cybersecurity Framework (CSF), PCI-DSS, COBIT, CSA, MITRE ATT&CK & CAPAC, STRIDE, NIST 800-53, CIS Benchmarks, etc.
  • Knowledge of securing technologies such as, but not limited to; SaaS services (i.e., O365, Salesforce), Application Design, Container Platforms (i.e., Docker, Kubernetes), APIs, Serverless, Network Infrastructure, Operating Systems, Identity and Access Management.
  • Knowledge of SDLC (Waterfall/Agile), DevSecOps, and good understanding of the ITIL Framework.
  • Knowledge of SAFe Agile Methodologies.
  • Strong negotiating, influencing and problem resolution skills.
  • Ability to effectively prioritize and execute tasks in a high-pressure environment.
  • Ability to assess customer/client needs, creatively approach solutions, decide, and influence appropriate courses of action.

 

CORE WORK ACTIVITIES 

 

Standards & Business Partnership

  • Contributes to, evaluates, and supports the documentation, and validation processes necessary to assure that associates, information technology systems and business processes meet the organization’s information assurance, security,

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Marriott International

View company profile →