Marriott International  Logo

Marriott International 

Senior Manager, Vulnerability Management

Posted Yesterday
Be an Early Applicant
In-Office or Remote
Hiring Remotely in United States
Senior level
In-Office or Remote
Hiring Remotely in United States
Senior level
Leads vulnerability management processes, assesses risks, manages remediation activities, and collaborates with teams to enhance security compliance and reduce threats.
The summary above was generated by AI

JOB SUMMARY

Leads workgroups and/or functions as a technical expert. Assesses and reports on vulnerabilities and remediation efforts across the enterprise. Guides, reviews and documents internal systems review activities. Designs and rolls out evaluation and improvement processes to assure the inclusion of appropriate elements of quality and compliance with security policy and regulations. Define, implement and manage the Information Vulnerability Management (IVM) Program through the identification and analysis of known and newly found vulnerabilities to determine their operational and security impact. Address vulnerabilities found through remediation recommendations, Information Vulnerability Alerts and Information Vulnerability Bulletins. This task area requires technical knowledge in computer network theory, IT standards and protocols, as well as an understanding of the lifecycle of cyberspace threats, attack vectors, and methods of exploitation.


CANDIDATE PROFILE

Education and Experience

Required:

  • Bachelor’s degree in Computer Sciences or related field or equivalent experience/certification
  • 7+ years of information security experience that also includes background and knowledge of general security concepts such as defense in-depth, least privilege, etc.
  • 3+ years’ experience with:
    • Vulnerability assessment and reporting including comprehensive understanding of Vulnerability Management methodologies and procedures, threat assessment, and remediation management 
    • Implementing, managing or using enterprise vulnerability assessment technologies, including Tenable.io, Tenable Security Center, or similar vulnerability solutions, is required

Preferred:

  • Current information security certification, including Certified Information Systems Security Professional (CISSP), GIAC certification, or Certified Information Security Manager (CISM)
  • Technical leadership experience in a sourced environment
  • Experience managing or operating enterprise vulnerability management in a large commercial enterprise
  • Experience with triaging vulnerabilities using open source and proprietary information and prioritizing remediation based on asset and threat data
  • Experience managing medium to large projects involving multiple teams in a technical lead role within an enterprise environment 
  • Familiarity with attack and exploitation techniques involving operating systems, applications, and devices commonly seen in an enterprise environment
  • Ability to understand and manipulate large data sets to provide analysis and reporting
  • Experience with developing scripted solutions, preferably with Python
  • Experience with workflow solutions, including ServiceNow and Jira
  • Experience with managing technical aspects of various controls frameworks, such as NIST Security and Privacy Controls and PCI-DSS
  • Excellent communication skills and problem solving ability
  • Demonstrated ability to work independently and with others
  • Technical infrastructure operations, administration, or engineering background
  • Experience working with Agile workflow management, including sprints and Kanban

CORE WORK ACTIVITIES

  • Provides technical leadership to the information vulnerability management process, including developing and managing remediation activities  
  • Assist with the development and implementation of strategies to enhance and mature the vulnerability management program
  • Identify, triage, and prioritize vulnerabilities and associated remediation and mitigation activity using multiple sources of vulnerability, threat, and asset data
  • Develop remediation and mitigation guidance to include vendor-supplied remediations, mitigating actions to reduce risk, and actions to address vulnerabilities for which complete remediation does not exist, on both individual assets and on multi-asset solutions and environments
  • Use internal solutions to report on open vulnerabilities, remediation progress, remediation compliance, and vulnerability metrics for use by technical, management, and executive stakeholders
  • Coordinate external testing of assets and environments to include penetration testing and security assessments
  • Conduct research using open source and proprietary intelligence to identify and analyze existing and new vulnerabilities
  • Perform planned and ad-hoc vulnerability scanning, determine remediation options and track remediation to completion.
  • Evaluate and test hardware, firmware and software for possible impact on system security, and the investigation and resolution of security risk and incidents. 
  • Assist in the direction of third-party vendors activities to include prioritizing work, developing processes to govern such activities, and reporting on the status, type, and effectiveness of those activities
  • Create, maintain, and mature vulnerability management processes and related documentation.
  • Maintain documentation repositories related to vulnerability management for use by internal staff and technical stakeholders
  • Maintain documentation repositories related to vulnerability management for use by internal staff and technical stakeholders
  • Work proactively with IT Infrastructure partners with respect to strategic and tactical plans for information security
  • Educates internal and external users of security technologies to continually improve the knowledge and skill-base of the organization on how best to manage patch management and vulnerability management within the infrastructure services
  • Participates in the evaluation and selection of security services products
  • Promotes the benefits of security services to the organization and educates the team on security concepts

  Technical Leadership

  • Trains and/or mentors other team members, and peers as appropriate 
  • Provides financial input on department or project budgets, capital expenditure or other cost/resource estimates as requested
  • Identifies opportunities to enhance the service delivery processes

 IT Governance

  • Follows all defined IT standards and processes (i.e. IT Governance, SM&G, Architecture, etc.), and provides input for improvements to the appropriate process owners as needed
  • Maintains a proper balance between business and operational risk 
  • Follows the defined project management standards and processes

At Marriott International, we are dedicated to being an equal opportunity employer, welcoming all and providing access to opportunity. We actively foster an environment where the unique backgrounds of our associates are valued and celebrated. Our greatest strength lies in the rich blend of culture, talent, and experiences of our associates.  We are committed to non-discrimination on any protected basis, including disability, veteran status, or other basis protected by applicable law. 

About Us
All positions offer a 401(k) plan, stock purchase plan, discounts at Marriott properties, commuter benefits, employee assistance plan, and childcare discounts.  Benefits are subject to terms and conditions, which may include rules regarding eligibility, enrollment, waiting period, contribution, benefit limits, election changes, benefit exclusions, and others. Click here to learn more.

Full-time positions also offer coverage for medical, dental, vision, health care flexible spending account, dependent care flexible spending account, life insurance, disability insurance, accident insurance, adoption expense reimbursements, paid parental leave and educational assistance. 

Washington Applicants Only: Employees will accrue paid sick leave, 0.077 PTO balance for every hour worked and be eligible to receive a minimum of 9 holidays annually.

Marriott HQ is committed to a hybrid work environment that enables associates to Be connected.  Headquarters-based positions are considered hybrid, for candidates within a commuting distance to Bethesda, MD; candidates outside of commuting distance to Bethesda, MD will be considered for Remote positions.
About the TeamMarriott International is the world’s largest hotel company, with more brands, more hotels and more opportunities for associates to grow and succeed. Be where you can do your best work,​ begin your purpose, belong to an amazing global​ team, and become the best version of you.

Top Skills

JIRA
Nist Security And Privacy Controls
Pci-Dss
Python
Servicenow
Tenable Security Center
Tenable.Io

Similar Jobs

4 Minutes Ago
Remote
United States
230K-271K Annually
Senior level
230K-271K Annually
Senior level
Artificial Intelligence • Marketing Tech • Software • Generative AI • Automation
The Enterprise Solutions Engineer at Jasper acts as a technical partner to the sales team, guiding clients through their AI journey and aligning solutions to business goals. Responsibilities include leading demos, managing trials, and presenting to C-suite stakeholders, while leveraging expertise in MarTech and AI technology.
Top Skills: AIAPIsAutomation ToolsIpaas SolutionsMartech
9 Minutes Ago
Easy Apply
Remote
US
Easy Apply
103K-221K Annually
Mid level
103K-221K Annually
Mid level
Cloud • Security • Software • Cybersecurity • Automation
As a Public Sector Solutions Architect, you'll advise U.S. government customers on GitLab's solutions, lead technical evaluations, and engage with clients to drive adoption and success.
Top Skills: Ci/CdCloud ComputingDevsecopsGitlab
10 Minutes Ago
Easy Apply
Remote
United States
Easy Apply
208K-288K Annually
Senior level
208K-288K Annually
Senior level
Artificial Intelligence • Fintech • Machine Learning • Social Impact • Software
As Lead Commercial Counsel, support Lending Partnerships by negotiating complex B2B SaaS agreements, providing legal advice, and managing commercial transactions. Engage collaboratively to mitigate risks while driving business growth.
Top Skills: AIB2B SaasTechnology

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account