Manager - Information Security - Vulnerability - Containers

2 weeks ago


Indianapolis, United States Marriott Full time

Job Number 24103262

Job Category Information Technology

Location Marriott International HQ, 7750 Wisconsin Avenue, Bethesda, Maryland, United States

Schedule Full-Time

Located Remotely? Y

Relocation? N

Position Type Management

JOB SUMMARY

The Manager, Vulnerability Management functions as a technical expert in the areas of vulnerability scanning and remediation tracking focused on vulnerabilities within containers and containerized applications. The role will be responsible for identifying vulnerabilities through vulnerability scanning, and ensuring remediation through assessment and reporting. The role will also design, roll out and maintain the evaluation process, identify areas for process improvement to assure the inclusion of appropriate elements of quality and compliance with security policy and regulations. The role will provide assistance with enterprise vulnerability scanning and will be able to create and manage integrated assessments. This role is for a individual contributor who can monitor and assess vulnerability scanning data, prioritize and address vulnerabilities within containers involving collaboration among development, operations and security teams. It requires the ability to communicate with technical and non-technical stakeholders, relay the importance of the vulnerability management activities, the risks presented by findings, and potential remediation actions. This role requires a working knowledge of security and network protocols, system and network administration, and configuration management.

CANDIDATE PROFILE

Education and Experience

Required:

Bachelors degree in Computer Sciences or related field or equivalent experience/certification

5+ years of information security experience that also includes background and knowledge of general security concepts such as defense in-depth, least privilege, etc.

2+ years experience with:

Vulnerability scanning and assessment using Tenable.io.

Containerization technologies in cloud environments with a focus on vulnerability management and remediation.

Vulnerability assessment and reporting including comprehensive understanding of Vulnerability Management methodologies and procedures, threat assessment, and remediation management.

Managing or using enterprise vulnerability assessment technologies, including Tenable.io, Tenable Security Center, or similar vulnerability solutions, is required.

Preferred:

Experience with using and configuring Aqua Security

Working knowledge of container security concepts, threats, and mitigations

Current information security certification, including Certified Information Systems Security Professional (CISSP), GIAC certification, or Certified Information Security Manager (CISM).

Technical leadership experience in both, sourced and contractor, environments.

Experience managing or operating enterprise vulnerability management in a large commercial enterprise.

Experience working in a multi-cloud enterprise environment.

Ability to understand and manipulate large data sets to provide analysis and reporting.

Experience working on medium to large projects involving multiple teams in a technical lead role within an enterprise environment.

Experience with managing technical aspects of various controls frameworks, such as NIST Security and Privacy Controls and PCI-DSS.

Experience managing or operating enterprise vulnerability management in a large commercial enterprise.

Familiarity with attack and exploitation techniques involving operating systems, applications, and devices commonly seen in an enterprise environment.

Excellent communication skills and problem solving ability.

Demonstrated ability to work independently and with others.

Technical infrastructure operations, administration, or engineering background.

CORE WORK ACTIVITIES

Identify, prioritize, and drive remediate of vulnerabilities across our containerized infrastructure

Provide technical expertise to vulnerability scanning and assessment on containers and containerized applications.

Develop and implement strategies for remediating vulnerabilities in containerized assets

Collaborate with DevOps and IT teams to drive vulnerability remediation

Support the development and implementation of strategies to enhance and mature the Vulnerability Management processes in containers and containerized applications.

Provide technical leadership to the information vulnerability management process, including developing and managing remediation activities.

Identify, triage, and prioritize vulnerabilities and associated remediation and mitigation activity using multiple sources of vulnerability, threat, and asset data.

Develop remediation and mitigation guidance to include vendor-supplied remediations, mitigating actions to reduce risk, and actions to address vulnerabilities within containers for which complete remediation does not exist, on both individual assets and on multi-asset solutions and environments.

Use internal solutions to report on open vulnerabilities, remediation progress, remediation compliance, and vulnerability metrics for use by technical, management, and executive stakeholders.

Perform planned and ad-hoc vulnerability scanning, determine remediation options and track remediation to completion.

Evaluate and test hardware, firmware and software for possible impact on system security, and the investigation and resolution of security risk and incidents.

Assist in the direction of third-party vendors activities to include prioritizing work, developing processes to govern such activities, and reporting on the status, type, and effectiveness of those activities.

Create, maintain, and mature vulnerability management processes and associated documentation.

Maintain documentation repositories related to vulnerability management for use by internal staff and technical stakeholders

Work proactively with IT Infrastructure partners with respect to strategic and tactical plans for information security.

Educates internal and external users of security technologies to continually improve the knowledge and skill-base of the organization on how best to manage security configuration, patch management and vulnerability management within the infrastructure services.

Participates in the evaluation and selection of security services products.

Promotes the benefits of security services to the organization and educates the team on security concepts.

Technical Leadership

Trains and/or mentors other team members, and peers as appropriate

Provides financial input on department or project budgets, capital expenditures or other cost/resource estimates as requested

Identifies opportunities to enhance the service delivery processes

IT Governance

Follows all defined IT standards and processes (i.e. IT Governance, SM&G, Architecture, etc.), and provides input for improvements to the appropriate process owners as needed

Maintains a proper balance between business and operational risk

Follows the defined project management standards and processes

California Applicants Only: The salary range for this position is $83,550 to $178,603 annually.

Colorado Applicants Only: The salary range for this position is $83,550 to $162,366 annually.

Hawaii Applicants Only: The salary range for this position is $101,096 to $178,603 annually.

New York Applicants Only: The salary range for this position is $83,550 to $178,603 annually.

Washington, D.C. Applicants Only: The salary range for this position is $91,905 to $162,366 annually.

Washington Applicants Only: The salary range for this position is $83,550 to $178,603 annually. In addition to the annual salary, the position will be eligible to receive an annual bonus. Employees will accrue 0.04616 PTO balance for every hour worked and eligible to receive minimum of 7 holidays annually.

All locations offer coverage for medical, dental, vision, health care flexible spending account, dependent care flexible spending account, life insurance, disability insurance, accident insurance, adoption expense reimbursements, paid parental leave, educational assistance, 401(k) plan, stock purchase plan, discounts at Marriott properties, commuter benefits, employee assistance plan, and childcare discounts. Benefits are subject to terms and conditions, which may include rules regarding eligibility, enrollment, waiting period, contribution, benefit limits, election changes, benefit exclusions, and others.

Marriott HQ is committed to a hybrid work environment that enables associates to Be connected. Headquarters-based positions are considered hybrid, for candidates within a commuting distance to Bethesda, MD; candidates outside of commuting distance to Bethesda, MD will be considered for Remote positions.

The application deadline for this position is 43 days after the date of this posting, July 23, 2024.

Marriott International is an equal opportunity employer. We believe in hiring a diverse workforce and sustaining an inclusive, people-first culture. We are committed to non-discrimination on any protected basis, such as disability and veteran status, or any other basis covered under applicable law.

Marriott International is the worlds largest hotel company, with more brands, more hotels and more opportunities for associates to grow and succeed. Be where you can do your best work,? begin your purpose, belong to an amazing global? team, and become the best version of you.



  • Indianapolis, United States Global Pharma Tek Full time

    Job Title: Information Security Analyst - Code and Vulnerability Analysis Location: Indianapolis, IN (Remote) Duration: Months Complete Description: Information security analyst position that functions as primary security code auditor for the agency's primary application. Key Responsibilities: Analyze code scan output from Veracode and...


  • Indianapolis, United States Brooksource Full time

    *Information Security Manager* *Indianapolis, IN (hybrid work structure) * *Contract to Hire* *3+ years of experience*Position is responsible for collaborating with supported agencies and departments on Cybersecurity strategy, helping to ensure secure Enterprise and Department-level Configuration and Supply Chain Management for IT Services and solutioning....


  • Indianapolis, Indiana, United States ExpertHiring Full time

    Job SummaryWe are seeking a highly skilled Threat and Vulnerability Management Specialist to join our team at ExpertHiring. As a key member of our IT security team, you will be responsible for conducting regular vulnerability assessments, analyzing and prioritizing vulnerabilities, and collaborating with various teams to remediate identified...


  • Indianapolis, Indiana, United States ExpertHiring Full time

    Job SummaryWe are seeking a highly skilled Threat Vulnerability Management Specialist to join our team at ExpertHiring. As a key member of our IT security team, you will be responsible for conducting regular vulnerability assessments, analyzing and prioritizing vulnerabilities, and collaborating with various teams to remediate identified vulnerabilities.Key...


  • Indianapolis, Indiana, United States ExpertHiring Full time

    Job SummaryWe are seeking a highly skilled Threat and Vulnerability Management Specialist to join our team at ExpertHiring. As a key member of our IT security team, you will be responsible for conducting regular vulnerability assessments, analyzing and prioritizing vulnerabilities, and collaborating with various teams to remediate identified...


  • Indianapolis, Indiana, United States Global Pharma Tek Full time

    Job Title: Information Security Specialist - Code and Vulnerability AnalysisJob Summary:Global Pharma Tek is seeking an experienced Information Security Specialist to join our team as a primary security code auditor for our primary application. The successful candidate will be responsible for analyzing code scan output from Veracode and SonarQube, assessing...


  • Indianapolis, Indiana, United States Brooksource Full time

    Position Title: Vulnerability Management AnalystLocation: RemoteCompensation: $25-30/hr. based on experienceContract Duration: 12 months with potential for permanent placementOverview: Brooksource is seeking a dedicated Vulnerability Management Analyst to support a financial services organization. This role is designed for individuals eager to enhance their...


  • Indianapolis, Indiana, United States Brooksource Full time

    Position Title: Vulnerability Management AssociateLocation: RemoteCompensation: $25-30/hr. based on experienceContract Duration: 12 months with potential for full-time employmentOverview: Brooksource is seeking a dedicated Vulnerability Management Associate to enhance our cybersecurity initiatives. This role is perfect for individuals eager to expand their...


  • Indianapolis, Indiana, United States Brooksource Full time

    Position Title: Vulnerability Management AssociateLocation: RemoteCompensation: $25-30/hr. based on qualificationsContract Duration: 12 months with potential for full-time employmentOverview: Brooksource is seeking a dedicated Vulnerability Management Associate to enhance our cybersecurity efforts. This role is tailored for individuals eager to develop their...


  • Indianapolis, Indiana, United States Brooksource Full time

    Position Title: Vulnerability Management AnalystLocation: RemoteCompensation: $25-30/hr. based on qualificationsContract Duration: 12 months with potential for permanent placementRole Overview: As a Vulnerability Management Analyst at Brooksource, you will engage in a dynamic program designed to enhance your technical and professional skills while...


  • Indianapolis, Indiana, United States Brooksource Full time

    Position Title: Vulnerability Management AnalystLocation: RemoteCompensation: $25-30/hr. based on experienceContract Duration: 12 months with potential for permanent placementRole Overview: As a Vulnerability Management Analyst, you will be part of Brooksource's Elevate Program, which focuses on professional growth and technical skill enhancement within a...


  • Indianapolis, Indiana, United States Brooksource Full time

    Position Title: Vulnerability Management AnalystLocation: RemoteCompensation: $25-30/hr. based on experienceContract Duration: 12 months with potential for permanent placementRole Overview: As a Vulnerability Management Analyst with Brooksource, you will engage in a dynamic program designed to enhance your technical and professional skills while...


  • Indianapolis, United States Marvel Technologies Inc Full time

    Job OverviewPosition Title: Cyber Security ArchitectOverview:Marvel Technologies Inc is in search of a skilled Cyber Security Architect to create, execute, and uphold our organization's cyber security framework. The ideal candidate will possess a robust understanding of cyber security concepts, technologies, and best practices, with a focus on designing...


  • Indianapolis, United States Marvel Technologies Inc Full time

    Job OverviewPosition Title: Cyber Security ArchitectRole Summary:Marvel Technologies Inc is looking for a seasoned Cyber Security Architect to develop, execute, and oversee our organization's cyber security framework. The ideal candidate will possess a robust understanding of cyber security methodologies, technologies, and industry best practices, with a...


  • Indianapolis, United States LanceSoft Full time

    Resource work as an Information Security Analyst within Information Technology Division responsible for auditing and monitoring systems containing confidential information. Resource works as a Security Analyst and performs all procedures necessary to ensure the safety of information systems assets and to protect systems from intentional or inadvertent access...


  • Indianapolis, Indiana, United States N. Harris Computer Corporation - USA Full time

    Cloud Security AnalystN. Harris Computer Corporation - USAN. Harris Computer Corporation is seeking a skilled Cloud Security Analyst to join their team. This role involves evaluating, developing, and implementing security tools, standards, and procedures for various platforms in private and commercial cloud environments. As a Cloud Security Analyst, you will...


  • Indianapolis, United States Vergence Full time

    Job DescriptionJob DescriptionHybrid position. Must live in the Indianapolis area.Pay: $30.00/hourIn this role you will:•Provide routine security administration•Professionally handle communications with internal and external stakeholders on compliance issues•Educate control and system owners on compliance workflows and processes•Gather and report on...


  • Indianapolis, United States Eateam Full time

    The Jr. Security Analyst in Security Operations will collaborate with the IT Security Operations department, as well as other Indiana Office of Technology Teams to help identify, and collaborate with IT Teams, and state agencies to reduce risk associated with the State of Indiana's security posture. In addition, role will be the point of contact for one or...


  • Indianapolis, United States Freedom Mortgage Full time

    The Manager, Information Security is a vital and multi-faceted role comprised of leading IT policy implementation, governance, risk monitoring, and executive reporting. This position requires a problem-solver who can scan across many areas of experti Manager, Security, Information, Monitoring, IT, Technology, Management


  • Indianapolis, United States EDB Full time

    **A Little About Us** EDB provides a data and AI platform that enables organizations to harness the full power of Postgres for transactional, analytical, and AI workloads across any cloud, anywhere. EDB empowers enterprises to control risk, manage costs and scale efficiently for a data and AI led world. Serving more than 1,500 customers globally and as the...