Sr. Infrastructure Security Engineer
Marriott InternationalAbout the role
The Sr. Infrastructure Security Engineer ensures the stability, integrity and efficient operation of information systems and technologies across the global enterprise. This role serves as a key technical resource designing, engineering, and delivering system hardening and image creation automation for Windows and Linux environments within the public cloud and private VMWare environments. This role will also assist the team in vulnerability management, patch and compliance activities, and public cloud remediation efforts. They will work with systems, application, and enterprise/solution architects to develop requirements and test cases, implement, monitor, report, and tune applications, infrastructure, and services for Marriott’s enterprise platforms.
CANDIDATE PROFILE
Education and Experience
Required:
- Undergraduate degree in an engineering or computer science discipline and/or equivalent experience/certification
- 7+ years' progressive experience in Information Technology including:
- Proven track record of engineering enterprise solutions for a large global company
- 5+ years’ experience in information technology application development or systems engineering
- 5+ years Linux/windows experience
- 5+ years Cloud technologies including IaaS/PaaS/SaaS deployments in Public Cloud
- 5+ years in OS scripting and automation
- 3+ years’ experience with design and implementation of CIS/NIST hardening standards applied at an enterprise level
- 3+ years’ experience with design and implementation of a patch management solution
- 3+ years professional experience in Infrastructure as a Service (IaaS) modeling including infrastructure as code development (Terraform or similar) or infrastructure engineering at enterprise scale
- 3+ years experience implementing AWS Well-Architected security framework
- 3+ years professional experience with cloud computing technology and its concepts (e.g. AWS, Azure, GCP) and virtualized (e.g. VMWare, OpenStack)
- 3+ years’ experience with server patch management systems (e.g. RedHat Satellite, BigFix)
- 3+ years’ experience in script development using automation and scripting languages such as python, ansible, packer, PowerShell, and/or bash
- 2+ years professional experience in container operations (Docker, OpenShift Enterprise, GKE, ECS) and orchestration (Docker Swarm, Kubernetes)
- Knowledge of security controls frameworks, such as NIST 800-53, NIST CSF, COBIT, or CIS
- Knowledge of vulnerability management, patching, and related management tools (e.g. BigFix, RedHat Satellite Server, Nessus)
Preferred:
- Graduate Degree in Computer Science or Computer Engineering
- DevOps Engineer developing pipelines, administering Kubernetes, and creating and hardening containers using Dockerfile
- Experience in the design, implementation, and operational support of mission critical solutions
- Embraces DevOps/SRE mentality of automation first
- Possesses base of experience within software development (programming)
- Very good understanding of network technologies (layer 2-3, IP stack, CIDR routing)
- Demonstrated experience delivering technology solutions in a fast-paced, deadline driven enterprise environment
- Demonstrated experience learning and applying new technologies to solve business needs
- Excellent problem-solving skills working both independently and within cross-functional teams in a complex organizational structure
- Excellent understanding of change management, testing requirements, techniques, and tools to ensure high system availability
- Strong attention to detail with an ability to operate effectively across multiple priorities
- Excellent written and verbal communication skills for a wide range of audiences including executives, business stakeholders and IT teams
- Experience in one or more of the following: C, C++, Java, Python, Go, Perl, or Ruby
- Experience across many of the following platforms:
- Container platforms (Examples: OpenShift, Docker, Kubernetes, GKE)
- Operating Systems: Red Hat Enterprise Linux, Oracle Linux, Windows, CentOS
- Storage: Block Storage, Object Storage, Lifecycle Management and Data Replication, Backup & Recovery Best Practices
- Network Virtualization: Akamai Global Traffic Management and Edge & Delivery Networks, Elastic Load Balancing Services,
- Domain Name Services and Registration
- Security: Compliance, Information Assurance, Data Protection using industry-best practices and tooling (Crowdstrike Falcon, Tenable.io, Splunk, HashiCorp Vault signers, PKI and Certificate Management)
- Applications Frameworks: Java Spring, node.js, NginX, JavaEE, HTML5
- Clo
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s