SrManager - Information Security - Threat Management & Response

3 weeks ago


Nashville, United States Marriott Full time

Job Number 24081559

Job Category Information Technology

Location Marriott International HQ, 7750 Wisconsin Avenue, Bethesda, Maryland, United States

Schedule Full-Time

Located Remotely? Y

Relocation? N

Position Type Management

JOB SUMMARY

Seeking a seasoned cybersecurity professional to lead and coordinate red team exercises, external engagements, and ongoing purple team initiatives aimed at uncovering vulnerabilities and enhancing the organization’s security posture. Collaborate closely with cross-functional teams to conduct continuous purple team exercises, sharing insights and knowledge to strengthen defenses. Analyze and prioritize findigs from red and purple team activities, providing data-driven recommendations for security enhancements. Produce comprehensive reports detailing exercise results and proposed mitigations. Offer guidance and support for implementing security controls and enhancements, while staying abreast of emerging threats and trends to ensure proactive proactive dfense measures.

This role is part Marriott Global Cybersecurity organization with our primary offices in Bethesda, MD, and Singapore and with teams elsewhere in the US, Europe and Asia.

CANDIDATE PROFILE

Education and Experience

Required:

  • Bachelor’s degree in Computer Sciences or related field or equivalent experience/certification

  • 7+ years of progressive information technology leadership experience

  • 4+ years’ information security experience that includes:

  • Red teaming, threat emulation experience

  • Creation of threat reports for executive (non technical) and technical stakeholders

  • Experience in threat data analysis and response planning.

Preferred:

  • Current information security certification, including Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA) or Certified Information Systems Security Professional (CISSP)

  • Technical leadership experience in a sourced environment

  • Project management skills

  • Excellent communication skills and problem solving ability

  • Demonstrated ability to work independently and with others

  • Ability to manage the details and compliance with standards and expectations

  • Technical infrastructure operations, administration, or engineering background

CORE WORK ACTIVITIES

  • Lead and organize red team exercises, external red team engagements, and ongoing purple team exercises to identify vulnerabilities, control gaps, and potential attack vectors in the organization’s information systems.

  • Collaborate closely with various teams to conduct continuous purple team exercises, sharing insights and knowledge to enhance overall security posture.

  • Analyze and prioritize findings from red and purple team exercises, offering data-driven recommendations to improve the organization’s security measures.

  • Produce high-quality reports detailing exercise results, including vulnerabilities, risks, proposed mitigations, and thematic improvement opportunities.

  • Provide guidance and support for implementing recommended security controls and enhancements.

  • Utilize threat intelligence to identify detection opportunities and develop, test, and tune detection content for both host and network-based log sources.

  • Demonstrate expertise in scripting capabilities, utilizing languages such as PowerShell, Pythin, VBScript, and shell scripts for automation and troubleshooting tasks.

  • Conduct deep investigations and forensic analysis to identify security incidents, utilizing tools like CrowdStrike and Splunk for threat hunting and incident response.

  • Stay up-to-date with emerging security threats and trends, including APT Tactics, Techniques, and Procedures (TTPs), to ensure the organization’s defenses remain effective.

  • Collaborate with IT Teams on escalations, tracking, configuration issues, etc. related to security validation findings.

  • Develop new detection rules to enhance detection capabilities and improve overall threat resilience.

  • Foster a culture of continuous learning and improvement within the cybersecurity team, staying current with new technologies and best practices in the cybersecurity landscape.

  • Generate detailed threat intelligence, red teaming reports on monthly, quarterly, and ad-hoc bases.

  • Produce and review executive-level briefings on current events, red teaming activities and strategic cyber intelligence.

  • Communicate complex threat events or security incident details to a wide audience, including executives, legal, and technical staff, in both verbal and written forms.

  • Advise internal stakeholders on threat intelligence best practices and strategies.

  • Engage in external threat intelligence sharing with partners and platforms.

Maintaining Goals

  • Submits reports in a timely manner, ensuring delivery deadlines are met.

  • Promotes the documenting of project progress accurately.

  • Provides input and assistance to other teams regarding projects.

Managing Work, Projects, and Policies

  • Manages and implements work and projects as assigned.

  • Generates and provides accurate and timely results in the form of reports, presentations, etc.

  • Analyzes information and evaluates results to choose the best solution and solve problems.

  • Provides timely, accurate, and detailed status reports as requested.

Demonstrating and Applying Discipline Knowledge

  • Provides technical expertise and support to persons inside and outside of the department.

  • Demonstrates knowledge of job-relevant issues, products, systems, and processes.

  • Demonstrates knowledge of function-specific procedures.

  • Keeps up-to-date technically and applies new knowledge to job.

  • Uses computers and computer systems (including hardware and software) to enter data and/ or process information.

Delivering on the Needs of Key Stakeholders

  • Understands and meets the needs of key stakeholders.

  • Develops specific goals and plans to prioritize, organize, and accomplish work.

  • Determines priorities, schedules, plans and necessary resources to ensure completion of any projects on schedule.

  • Collaborates with internal partners and stakeholders to support business/initiative strategies

  • Communicates concepts in a clear and persuasive manner that is easy to understand.

  • Generates and provides accurate and timely results in the form of reports, presentations, etc.

  • Demonstrates an understanding of business priorities

Additional Responsibilities

  • Provides information to supervisors and co-workers by telephone, in written form, e-mail, or in person in a timely manner.

  • Demonstrates self-confidence, energy and enthusiasm.

  • Informs and/or updates leaders on relevant information in a timely manner.

  • Manages time effectively and conducts activities in an organized manner.

  • Presents ideas, expectations and information in a concise, organized manner.

  • Uses problem solving methodology for decision making and follow up.

  • Performs other reasonable duties as assigned by manager.

California Applicants Only: The salary range for this position is $96,038.00 to $209,169.00 annually.

Colorado Applicants Only: The salary range for this position is $96,038.00 to $190,154.00 annually.

Hawaii Applicants Only: The salary range for this position is $116,205.00 to $209,169.00 annually.

New York Applicants Only: The salary range for this position is $96,038.00 to $209,169.00 annually.

Washington Applicants Only: The salary range for this position is $96,038.00 to $209,169.00 annually. In addition to the annual salary, the position will be eligible to receive an annual bonus. Employees will accrue 0.04616 PTO balance for every hour worked and eligible to receive minimum of 7 holidays annually.

All locations offer coverage for medical, dental, vision, health care flexible spending account, dependent care flexible spending account, life insurance, disability insurance, accident insurance, adoption expense reimbursements, paid parental leave, educational assistance, 401(k) plan, stock purchase plan, discounts at Marriott properties, commuter benefits, employee assistance plan, and childcare discounts. Benefits are subject to terms and conditions, which may include rules regarding eligibility, enrollment, waiting period, contribution, benefit limits, election changes, benefit exclusions, and others.

Marriott HQ is committed to a hybrid work environment that enables associates to Be connected. Headquarters-based positions are considered hybrid, for candidates within a commuting distance to Bethesda, MD; candidates outside of commuting distance to Bethesda, MD will be considered for Remote positions.

The application deadline for this position is 28 days after the date of this posting, 5/9/2024.

Marriott International is an equal opportunity employer. We believe in hiring a diverse workforce and sustaining an inclusive, people-first culture. We are committed to non-discrimination on any protected basis, such as disability and veteran status, or any other basis covered under applicable law.

Marriott International is the world’s largest hotel company, with more brands, more hotels and more opportunities for associates to grow and succeed. Be where you can do your best work,​ begin your purpose, belong to an amazing global​ team, and become the best version of you.



  • Nashville, Tennessee, United States Marriott Full time

    Job Number Job Category Information TechnologyLocation Marriott International HQ, 7750 Wisconsin Avenue, Bethesda, Maryland, United StatesSchedule Full-TimeLocated Remotely? YRelocation? NPosition Type ManagementJOB SUMMARYSeeking a seasoned cybersecurity professional to lead and coordinate red team exercises, external engagements, and ongoing purple team...


  • Nashville, United States Honest Medical Group Full time

    Job DescriptionJob DescriptionWho You AreYou are devoted, compassionate, and enjoy being on the front lines in healthcare, changing the lives of your patients. You are passionate about getting to the root cause of a patient's conditions, removing social determinants of healthcare, and ensuring the highest possible quality of life for those in your care....


  • Nashville, United States AllianceBernstein Holding L.P. Full time

    Who We Are: As a leading global investment management firm, AB fosters diverse perspectives and embraces innovation to help our clients navigate the uncertainty of capital markets. Through high-quality research and diversified investment services, we serve institutions, individuals, and private wealth clients in major markets worldwide. Our ambition is...


  • Nashville, United States AllianceBernstein Full time

    Who We Are: As a leading global investment management firm, AB fosters diverse perspectives and embraces innovation to help our clients navigate the uncertainty of capital markets. Through high-quality research and diversified investment services, we serve institutions, individuals, and private wealth clients in major markets worldwide. Our ambition is...


  • Nashville, United States ClientSolv Full time

    Company Description ClientSolv Technologies is an IT solution firm with over a decade of experience serving Fortune 1000 companies, public sector and small to medium sized companies. ClientSolv Technologies is a woman-owned and operated company that is certified as a WMBE, 8a firm by the Federal government's Small Business Administration. Job Description We...


  • Nashville, United States ClientSolv Full time

    Company Description ClientSolv Technologies is an IT solution firm with over a decade of experience serving Fortune 1000 companies, public sector and small to medium sized companies. ClientSolv Technologies is a woman-owned and operated company that is certified as a WMBE, 8a firm by the Federal government's Small Business Administration. Job Description We...

  • Security Officer

    1 month ago


    Nashville, United States Security Defense Association Full time

    Job DescriptionJob DescriptionThe Security Officer is responsible for securing the facility and maintaining constant surveillance on the property. Under the supervision of the HR Generalist, the Security Officer is responsible for ensuring the safety and security of the employees, documentation of activities, caring for clients, ensuring no outside...


  • Nashville, United States US Tech Solutions Full time

    Duration: 12 months contractJob Description:An Information Security Specialist interprets information security policies, standards, and other requirements as they relate to internal information system and coordinates the implementation of these and other information security requirements. The Information Security Specialist redesigns and reengineers internal...

  • Armed Security Officer

    2 months ago


    Nashville, United States First Class Security Full time

    Job DescriptionJob DescriptionSalary: **FOR IMMEDIATE HIRE for Part Time and Full Time Positions**We are looking for a professional to protect and serve our clientele throughout the Middle Tennessee area as an Armed Security Officer. You will maintain a high visibility presence and prevent all illegal or inappropriate actions. Your objective will be to...


  • Nashville, United States Aramark Uniform Services Full time

    ** District Manager- AMP- Nashville, TN** **Job Category****:** In Unit-Service-Mngmt **Requisition Number****:** DISTR014491 Showing 1 location **Job Details** **Description** Responsibilities/Essential Functions: Develops and maintains client relationships with Key Customers to grow base business and improve retention of account base. Engages with sales to...


  • Nashville, United States Aramark Uniform Services Full time

    ** District Manager- AMP- Nashville, TN** **Job Category****:** In Unit-Service-Mngmt **Requisition Number****:** DISTR014491 Showing 1 location **Job Details** **Description** Responsibilities/Essential Functions: Develops and maintains client relationships with Key Customers to grow base business and improve retention of account base. Engages with sales...


  • Nashville, United States Walden Security Full time

    Walden Security is currently recruiting experienced Court Security Officers. CSOs will provide armed security to courthouses under the USMS contract. Essential Duties and Responsibilities: Includes the following and other duties may be assigned: Perform entrance control: Enforce the District's entry and identification system which includes operating...


  • Nashville, United States Volunteer Corporate Credit Union Full time

    Job DescriptionJob DescriptionPOSITION SUMMARYJob Function: Sr. Network Security Engineer designs, plans, installs, and supports network and communications systems with an emphasis on Security Engineering to maintain the company's overall security posture and to defend against cyber-attacks.Involved in a wide range of issues including secure...


  • Nashville, United States Marksman Security Corporation Full time

    Job DescriptionJob Description  Marksman Security Corporation is seeking a Licensed Security Operations Manager! Nashville Area The Security Operations Manager will oversee security personnel, ensuring the site is properly staffed and officers are trained and motivated. The Security operations Manager will also work closely with the client contact to...

  • Office Security Guard

    1 month ago


    Nashville, United States Freeland Management Full time

    Job DescriptionJob DescriptionJob Title: Office Security Guard Location: Nashville, TN Position Type: Full-Time Reports To: Security Supervisor About Us: Freeland Realty is a local real estate firm. We prioritize developing positive business relationships that create the best outcome for both us and our partners. Our team works together to establish a...


  • Nashville, United States ASRC Federal Full time

    Summary: ASRC Federal Analytical Services, Inc is looking for a Cyber Security Engineer who has experience supporting system builds, implementing information security best practices, performing security analysis, integration of software installation and documentation of unique hardware and custom software in a multi-platform/multi-network environment during...


  • Nashville, United States ASRC Federal Full time

    Job Description Summary:  ASRC Federal Analytical Services, Inc is looking for a Cyber Security Engineer who has experience supporting system builds, implementing information security best practices, performing security analysis, integration of software installation and documentation of unique hardware and custom software in a...


  • Nashville, United States School Facility Management Full time

    Job DescriptionJob DescriptionSalary: $25 to $29 per hourServa Security is looking to meet and potentially hire experienced security professionals who wish to work in private school security. We are looking for hard-working, service oriented team-players with lady and gentlemen like manners, but who also have tactical skills.We have a variety of 10 and 12...

  • Stadium Security

    5 days ago


    Nashville, Tennessee, United States GardaWorld Security Services Full time

    Job Summary Job Title:Account ManagerDepartment:ManagementFLSA Status:ExemptReports To:Area Manager/Regional Director/Vice PresidentCompensation$ $65000 Job Summary:Event, crowd management, or stadium experience requiredAs an Account Manager, you'll work under the guidance of the Area Manager. Your responsibilities include directing and coordinating...

  • Jr. Security Analyst

    2 weeks ago


    Nashville, United States Medasource Full time

    Position: Junior Security AnalystDuration: 6-month contract to hireStart Date: June 10thLocation: Nashville, TN (Hybrid)• Onsite: 2 days per week• Remote: 3 days per weekCompany Overview:Our client is a leading enterprise healthcare system dedicated to delivering exceptional patient care and pioneering technical advancements in the healthcare industry....