FLEX Associate Security Architect

Marriott International, Inc.
Bethesda, MD, United States
about 1 month ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$100,381.0 - $166,982.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Application Programming Interfaces (APIs) Unix Software as a Service Cloud Computing Cloud Computing Security Cyber Security Information Systems Databases Linux Identity and Access Management Internet Protocol
+17 more
Information Systems Security Architecture Professional Network Architecture Open Web Application Security Public Key Infrastructure Systems Development Life Cycle Salesforce.Com Software Engineering Systems Integration Tokenization Software Vulnerability Management Office365 Containerization Kubernetes Information Technology Serverless Computing Docker Microservices

Job description

Contributes to and maintains security strategies, requirements, and standards for applications and platforms. Provides in-depth Technical Security guidance as the Security Subject Matter Experts (SME) for various technologies and project areas, with a heavy focus on API integration and tokenization. Ensures company security policies, standards and industry standards are communicated to program teams during the Software Development Life Cycle (SDLC) process. Able to identify gaps and work with project teams to improve security while retaining time to market, functionality and scalability. Reviews and approves Security Accreditation tasks during each of phase of SDLC. Serves as point of escalation for security issues and risks that may arise. Has a broad knowledge in areas of Security such as Cloud Computing, Application, IAM, Cryptography, Infrastructure, and Risk., Contributes to, evaluates, and supports the documentation, and validation processes necessary to assure that associates, information technology systems and business processes meet the organization’s information assurance, security, and privacy requirements. Ensures appropriate treatment of risk, compliance, and assurance of internal policies and external regulations.

  • Defines strategy and roadmap, provides guidance, creates standards and guidelines, and reviews architectural designs. Ensures standards and guidelines incorporate legal and regulatory requirements.
  • Conducts security and privacy technology research, assessments, and integration processes; provides and supports a prototype capability and/or evaluates its utility
  • Consults with customers to gather and evaluate functional requirements and provides security and privacy requirements, guidelines, and standards
  • Provides sound advice and recommendations to leadership and staff on a variety of relevant topics within the pertinent subject domain

Managing Projects and Priorities

  • Functions as a strategic senior technical expert within the department.
  • Develops specific goals and plans to prioritize, organize, and accomplish work.
  • Provides direction and assistance to other teams regarding projects.
  • Analyzes information and evaluates results to choose the best solution and solve problems.
  • Reviews vendor proposals and selects appropriate vendor for services/technologies/hardware.
  • Generates and provides accurate and timely results in the form of reports, presentations, etc.

Delivering on the Needs of Key Stakeholders

  • Understands and meets the needs of key stakeholders.
  • Communicates concepts in a clear and persuasive manner that is easy to understand.

Providing Technical Support and Consultation

  • Provides technical expertise and technical leadership within own and other teams.
  • Provides recommendations to improve the effectiveness of processes and programs.
  • Demonstrates advanced knowledge of job-relevant issues, products, systems, and processes.
  • Demonstrates advanced knowledge of function-specific procedures.

Requirements

  • Bachelor’s or master’s degree in computer science, information systems, cybersecurity or a related field or equivalent experience/certification.
  • 6+ years overall Information Technology experience with:
  • 4+ years of Information Security experience in security engineering with experience in three or more of the following areas
  • Conducting security reviews and identifying risks and gaps
  • Performing security accreditations
  • Developing security architectures and strategies
  • Developing Enterprise security patterns
  • Working with development teams and vendor teams for implementing compensating controls
  • Experience in reviewing and developing Security Architectures and identifying security risks/gaps as well as mitigation strategies.
  • Strong experience in APIs, integrations, and tokenization. This role requires SME level knowledge for these technologies.
  • The security architect should have 3+ years combined experience in five or more of the following areas:
  • Full-stack knowledge of IT infrastructure:
  • Applications
  • Databases
  • Operating systems - Windows, Unix, and Linux
  • IP networks - WAN and LAN
  • Backup networks and media
  • Containers/Kubernetes and microservices
  • Cryptography and current cryptographic standards, including PKI
  • Direct, hands-on experience or a strong working knowledge of vulnerability management tools
  • Working knowledge of the OWASP Top 10

Preferred :

  • Ability to provide Security Requirements for areas including but not limited to; Cloud Computing, Application Development, IAM, Cryptography, and Infrastructure design and standards
  • Current information security certification(s), such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), ISC2 Certified Cloud Security Professional (CCSP), GIAC certifications, ITIL
  • Knowledge of securing technologies such as, but not limited to; SaaS services (i.e., O365, Salesforce), Application Design, Container Platforms (ie. Docker, Kubernetes), APIs, Serverless, Network Infrastructure, Operating Systems, Identity and Access Management
  • Knowledge of SAFe Agile Methodologie

Benefits & conditions

All locations offer 401(k) plan, stock purchase plan, discounts at Marriott properties, commuter benefits, employee assistance plan, and childcare discounts. Benefits are subject to terms and conditions, which may include rules regarding eligibility, enrollment, waiting period, contribution, benefit limits, election changes, benefit exclusions, and others. Click here (https://life.marriott.com/wp-content/uploads/2025/09/benefitsoverviewf_2025edits_8.19.25.pdf) to learn more.

Full-time positions also offer coverage for medical, dental, vision, health care flexible spending account, dependent care flexible spending account, life insurance, disability insurance, accident insurance, adoption expense reimbursements, and paid parental leave.

Washington Applicants Only : Employees will accrue paid sick leave, 0.0384 PTO balance for every hour worked and be eligible to receive minimum of 9 holidays annually.

Marriott HQ is committed to a hybrid work environment that enables associates to Be connected. Headquarters-based positions are considered hybrid, for candidates within a commuting distance to Bethesda, MD; candidates outside of commuting distance to Bethesda, MD will be considered for Remote positions.

About the company

Marriott International is the world’s largest hotel company, with more brands, more hotels and more opportunities for associates to grow and succeed. Be where you can do your best work, begin your purpose, belong to an amazing global team, and become the best version of you.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:03 min

Microsoft integrating native Unix coreutils into Windows environments

Chris Heilmann +2 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:04 min

Defining timestamps and the international standard format

Denny Biasiolli Denny Biasiolli · Europe 2026 Virtual

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all