> Markdown version of [/jobs/ext/2435790-flex-associate-security-architect](https://www.wearedevelopers.com/jobs/ext/2435790-flex-associate-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # FLEX Associate Security Architect - **Company:** Marriott International, Inc. - **Location:** Bethesda, MD, United States (Remote available) - **Experience:** Experienced - **Salary:** $100,381.0 - $166,982.0 - **Contract:** Temporary contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), Unix, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, Information Systems, Databases, Linux, Identity and Access Management, Internet Protocol, Information Systems Security Architecture Professional, Network Architecture, Open Web Application Security, Public Key Infrastructure, Systems Development Life Cycle, Salesforce.Com, Software Engineering, Systems Integration, Tokenization, Software Vulnerability Management, Office365, Containerization, Kubernetes, Information Technology, Serverless Computing, Docker, Microservices - **Published:** August 1, 2026 - **Apply:** https://dejobs.org/x/x/EDEE6F8F7DB8451188AFDF69CA95C6B5/job/ ## About the Role * Bachelor's or master's degree in computer science, information systems, cybersecurity or a related field or equivalent experience/certification. * 6+ years overall Information Technology experience with: * 4+ years of Information Security experience in security engineering with experience in three or more of the following areas * Conducting security reviews and identifying risks and gaps * Performing security accreditations * Developing security architectures and strategies * Developing Enterprise security patterns * Working with development teams and vendor teams for implementing compensating controls * Experience in reviewing and developing Security Architectures and identifying security risks/gaps as well as mitigation strategies. * Strong experience in APIs, integrations, and tokenization. This role requires SME level knowledge for these technologies. * The security architect should have 3+ years combined experience in five or more of the following areas: * Full-stack knowledge of IT infrastructure: * Applications * Databases * Operating systems - Windows, Unix, and Linux * IP networks - WAN and LAN * Backup networks and media * Containers/Kubernetes and microservices * Cryptography and current cryptographic standards, including PKI * Direct, hands-on experience or a strong working knowledge of vulnerability management tools * Working knowledge of the OWASP Top 10 Preferred : * Ability to provide Security Requirements for areas including but not limited to; Cloud Computing, Application Development, IAM, Cryptography, and Infrastructure design and standards * Current information security certification(s), such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), ISC2 Certified Cloud Security Professional (CCSP), GIAC certifications, ITIL * Knowledge of securing technologies such as, but not limited to; SaaS services (i.e., O365, Salesforce), Application Design, Container Platforms (ie. Docker, Kubernetes), APIs, Serverless, Network Infrastructure, Operating Systems, Identity and Access Management * Knowledge of SAFe Agile Methodologie ## Description Contributes to and maintains security strategies, requirements, and standards for applications and platforms. Provides in-depth Technical Security guidance as the Security Subject Matter Experts (SME) for various technologies and project areas, with a heavy focus on API integration and tokenization. Ensures company security policies, standards and industry standards are communicated to program teams during the Software Development Life Cycle (SDLC) process. Able to identify gaps and work with project teams to improve security while retaining time to market, functionality and scalability. Reviews and approves Security Accreditation tasks during each of phase of SDLC. Serves as point of escalation for security issues and risks that may arise. Has a broad knowledge in areas of Security such as Cloud Computing, Application, IAM, Cryptography, Infrastructure, and Risk., Contributes to, evaluates, and supports the documentation, and validation processes necessary to assure that associates, information technology systems and business processes meet the organization's information assurance, security, and privacy requirements. Ensures appropriate treatment of risk, compliance, and assurance of internal policies and external regulations. * Defines strategy and roadmap, provides guidance, creates standards and guidelines, and reviews architectural designs. Ensures standards and guidelines incorporate legal and regulatory requirements. * Conducts security and privacy technology research, assessments, and integration processes; provides and supports a prototype capability and/or evaluates its utility * Consults with customers to gather and evaluate functional requirements and provides security and privacy requirements, guidelines, and standards * Provides sound advice and recommendations to leadership and staff on a variety of relevant topics within the pertinent subject domain Managing Projects and Priorities * Functions as a strategic senior technical expert within the department. * Develops specific goals and plans to prioritize, organize, and accomplish work. * Provides direction and assistance to other teams regarding projects. * Analyzes information and evaluates results to choose the best solution and solve problems. * Reviews vendor proposals and selects appropriate vendor for services/technologies/hardware. * Generates and provides accurate and timely results in the form of reports, presentations, etc. Delivering on the Needs of Key Stakeholders * Understands and meets the needs of key stakeholders. * Communicates concepts in a clear and persuasive manner that is easy to understand. Providing Technical Support and Consultation * Provides technical expertise and technical leadership within own and other teams. * Provides recommendations to improve the effectiveness of processes and programs. * Demonstrates advanced knowledge of job-relevant issues, products, systems, and processes. * Demonstrates advanced knowledge of function-specific procedures. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Top Must-Visit Developer Conferences in the US in 2026](https://www.wearedevelopers.com/magazine/679-top-must-visit-developer-conferences-in-the-us-in-2026) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)