Sr. Manager, Application Security

Marriott International, Inc.
Bethesda, MD, United States
26 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Compensation
$110,400.0 - $190,000.0
Working hours
Regular working hours
Job source

Tech stack

JIRA Cyber Security Github Open Source Technology Open Web Application Security Systems Development Life Cycle Release Management Software Engineering Software Security Information Technology Enterprise Integration Jenkins
+3 more
Servicenow Static Application Security Testing Dynamic Application Security Testing

Job description

The Senior Manager of Application Security will serve as the operational and programmatic leader for the AppSec organization, partnering closely with the Director of Application Security to scale delivery, strengthen integration with Security Architecture, and ensure consistent execution of AppSec priorities. This role leads cross-team coordination, drives prioritization, improves repeatable and automated processes, ensures alignment with risk and engineering teams, and elevates visibility of AppSec work across the organization., * Lead day-to-day operational execution of AppSec programs

  • Collaborate on Strategy formulation and execution.
  • Strengthen SER/AppSec integration
  • Drive prioritization frameworks and alignment with enterprise objectives
  • Establish repeatable, automated AppSec processes
  • Represent AppSec in cross-functional governance forums
  • Increased automation and repeatability. Shifting tooling integration left.
  • Clear metrics and reporting covering: operational, security and strategy perspectives
  • Implement initiatives for secure open-source consumption and artifact management

Technical Oversight

  • Monitor and assess application security risks
  • Develop and track security metrics
  • Recommend mitigation strategies
  • Provide technical leadership regarding tooling integration, process definition and execution

Stakeholder Alignment & Communication

  • Ensure AppSec work is well-communicated and visible
  • Deliver concise reporting to stakeholders
  • Mentor AppSec team members
  • Translate complex technical concepts for non-technical audiences

Managing Work, Projects, and Policies

  • Coordinates and implements work and projects as assigned.
  • Generates and provides accurate and timely results in the form of reports, presentations, etc.
  • Analyzes information and evaluates results to choose the best solution and solve problems.
  • Develops specific goals and plans to prioritize, organize, and accomplish work.
  • Sets and tracks goal progress for self and others.
  • Monitors the work of others to ensure it is completed on time and meets expectations.
  • Provides direction and assistance to other organizational units’ policies and procedures, and efficient control and utilization of resources.

Success Measures (First 12 Months)

  • Improved Security Architecture/AppSec workflow integration
  • Increased automation and repeatability.
  • Establishment of clear metrics for operational, security and strategic reporting
  • Clear work prioritization
  • Improved visibility and transparency of AppSec processes, execution and deliverables

Requirements

  • Bachelor’s degree in Information Technology, Cybersecurity, Computer Science or related field or equivalent experience/certification
  • 7+ years of experience in Information Technology/Security including:
  • 4+ years information security leadership
  • 2+ years as a team lead or manager in a security role response for managing security assessments, risk management, and compliance efforts for production systems.
  • 2+ years of experience in software/system release management, with a focus on security validation
  • Expertise across AppSec testing modalities (SAST, DAST, IAST etc)
  • Expertise with SCA SDLC tooling and repository integration
  • Proficiency in GitHub, JIRA, ServiceNow, Jenkins, Harness
  • Strong understanding of OWASP and MITRE CVE/CWE
  • Ability to drive cross-functional workflow integration and prioritization

Preferred Skills/Experience:

  • Master’s degree in Cybersecurity, Computer Science, or a related discipline
  • Relevant certifications (CISM, CISSP, CSSLP)
  • Application Development and Process expertise
  • Proven experience across AppSec tooling vendors
  • Excellent written and verbal communication / presentation skills
  • Proven leadership experience in highly regulated environments, with strong project management skills.

Benefits & conditions

All positions offer a 401(k) plan, stock purchase plan, discounts at Marriott properties, commuter benefits, employee assistance plan, and childcare discounts. Benefits are subject to terms and conditions, which may include rules regarding eligibility, enrollment, waiting period, contribution, benefit limits, election changes, benefit exclusions, and others. Click here (https://life.marriott.com/wp-content/uploads/2025/09/benefitsoverviewp_2025edits_8.19.25.pdf) to learn more.

Full-time positions also offer coverage for medical, dental, vision, health care flexible spending account, dependent care flexible spending account, life insurance, disability insurance, accident insurance, adoption expense reimbursements, paid parental leave and educational assistance.

Washington Applicants Only : Employees will accrue paid sick leave, 0.077 PTO balance for every hour worked and be eligible to receive a minimum of 9 holidays annually.

Marriott HQ is committed to a hybrid work environment that enables associates to Be connected. Headquarters-based positions are considered hybrid, for candidates within a commuting distance to Bethesda, MD; candidates outside of commuting distance to Bethesda, MD will be considered for Remote positions.

About the company

Marriott International is the world’s largest hotel company, with more brands, more hotels and more opportunities for associates to grow and succeed. Be where you can do your best work, begin your purpose, belong to an amazing global team, and become the best version of you.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · WWC 2023

1:02 min

Applying an ETL methodology to infrastructure configuration management

Axel Barbier · WWC 2023

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

5:47 min

Integrating user stories and test automation via Jira tools

Christoph Ruggenthaler · LIVE

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

Videos

See all

Related articles

See all