FLEX Associate Security Architect
Marriott International
- Location
- Bethesda, MD, United States
- Work model
- On-Site
- Level
- Entry
- H-1B history
- 40 approvals (FY2023)
- Posted
- 21h ago
Skills
About this role
This is a temporary position. JOB SUMMARY Contributes to and maintains security strategies, requirements, and standards for applications and platforms. Provides in-depth Technical Security guidance as the Security Subject Matter Experts (SME) for various technologies and project areas, with a heavy focus on API integration and tokenization. Ensures company security policies, standards and industry standards are communicated to program teams during the Software Development Life Cycle (SDLC) process. Able to identify gaps and work with project teams to improve security while retaining time to market, functionality and scalability. Reviews and approves Security Accreditation tasks during each of phase of SDLC. Serves as point of escalation for security issues and risks that may arise. Has a broad knowledge in areas of Security such as Cloud Computing, Application, IAM, Cryptography, Infrastructure, and Risk. CANDIDATE PROFILE Education and Experience Required :
Bachelor's or master's degree in computer science, information systems, cybersecurity or a related field or equivalent experience/certification. 6+ years overall Information Technology experience with: 4+ years of Information Security experience in security engineering with experience in three or more of the following areas
Conducting security reviews and identifying risks and gaps Performing security accreditations Developing security architectures and strategies Developing Enterprise security patterns Working with development teams and vendor teams for implementing compensating controls
Experience in reviewing and developing Security Architectures and identifying security risks/gaps as well as mitigation strategies. Strong experience in APIs, integrations, and tokenization. This role requires SME level knowledge for these technologies. The security architect should have 3+ years combined experience in five or more of the following areas:
Full-stack knowledge of IT infrastructure
Applications Databases Operating systems — Windows, Unix, and Linux IP networks — WAN and LAN Backup networks and media Containers/Kubernetes and microservices
Cryptography and current cryptographic standards, including PKI Direct, hands-on experience or a strong working knowledge of vulnerability management tools Working knowledge of the OWASP Top 10
Preferred
Ability to provide Security Requirements for areas including but not limited to; Cloud Computing, Application Development, IAM, Cryptography, and Infrastructure design and standards Current information security certification(s), such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), ISC2 Certified Cloud Security Professional (CCSP), GIAC certifications, ITIL Knowledge of securing technologies such as, but not limited to; SaaS services (i.e., O365, Salesforce), Application Design, Container Platforms (ie. Docker, Kubernetes), APIs, Serverless, Network Infrastructure, Operating Systems, Identity and Access Management Knowledge of SAFe Agile Methodologie
CORE WORK ACTIVITIES Contributes to, evaluates, and supports the documentation, and validation processes necessary to assure that associates, information technology systems and business processes meet the organization’s information assurance, security, and privacy requirements. Ensures appropriate treatment of risk, compliance, and assurance of internal policies and external regulations.
Defines strategy and roadmap, provides guidance, creates standards and guidelines, and reviews architectural designs. Ensures standards and guidelines incorporate legal and regulatory requirements. Conducts security and privacy technology research, assessments, and integration processes; provides and supports a prototype capability and/or evaluates its utility Consults with customers to gather and evaluate functional requirements and provides security and privacy requirements,