Marriott International - Baton Rouge, LA

posted 4 months ago

Full-time - Mid Level
Hybrid - Baton Rouge, LA
Accommodation

About the position

This position will be part of the Cloud Security Engineering Team within the Global Information Security organization at Marriott International. The security engineer will be responsible for designing and building security capabilities in a multi-cloud environment, as well as building automation for cloud security controls to enhance the cloud security posture. This role will serve as a key engineering and supporting resource for the cloud security engineering program, ensuring that security measures are integrated into the cloud infrastructure effectively and efficiently. The security engineer will provide Cloud Security Governance and Optimization services to technical teams, advising on security best practices and guiding the development and infrastructure teams in adopting and enforcing security and access policies that align with the business's security needs. This includes conducting vulnerability assessments of cloud assets, delivering remediation recommendations, and providing knowledgeable assistance in resolving identified vulnerabilities. The engineer will also be responsible for improving the accessibility of security through automation and continuous integration pipelines, which includes detecting and fixing vulnerabilities and identifying potential attacks. In addition, the role involves providing subject matter expertise to the Security Engineering and Operations teams, ensuring the safeguarding of design, build, deploy, and maintenance of products and services in the cloud environment. The engineer will participate in researching, designing, and implementing security components that are standards-based, high-performing, and secure, while also educating internal and external users on security technologies to enhance the organization's knowledge and skill base. The position requires collaboration with project teams and architecture teams to modify infrastructure and security services as necessary to accommodate project needs, as well as documenting all architecture design and analysis work.

Responsibilities

  • Provides Cloud Security Governance and Optimization services to technical teams.
  • Advises on security best practices and guides development and infrastructure teams in adopting and enforcing security and access policies.
  • Conducts vulnerability assessments of cloud assets and delivers remediation recommendations.
  • Provides subject matter expertise to Security Engineering and Operations teams.
  • Improves the accessibility of security through automation and continuous integration pipelines.
  • Participates in researching, designing, and implementing security components that are standards-based and secure.
  • Educates internal and external users on security technologies.
  • Participates in the evaluation and selection of security service products.
  • Supports governance based on best practices and facilitates alignment to projects and major initiatives.
  • Analyzes the current environment to detect deficiencies and recommends solutions for improvement.

Requirements

  • Bachelor's degree in Information Security or related field or equivalent experience/certification.
  • 7+ years progressive Information Technology engineering experience.
  • 5+ years of Information Security experience in security engineering.
  • 3+ years in public cloud security (e.g., AWS, Azure).
  • 1+ years' experience with scripting languages (e.g., Python, JavaScript).
  • 1+ years' experience with CI/CD pipelines or security tooling for cloud-native deployments.

Nice-to-haves

  • Current information security certification, including Certified Information Security Manager (CISM) or Certified Information Systems Security Professional (CISSP).
  • Experience working with Agile and Scrum methodologies.
  • Experience and knowledge working in DevSecOps, CI/CD, Infrastructure as Code concepts and technologies.
  • Knowledge of Cloud Security Posture Management (CSPM) tools.
  • Knowledge of securing technologies such as Cloud-Native Services, Container Platforms, APIs, Identity and Access Management, Serverless technologies.

Benefits

  • Medical, dental, and vision coverage.
  • Health care flexible spending account.
  • Dependent care flexible spending account.
  • Life insurance.
  • Disability insurance.
  • Accident insurance.
  • Adoption expense reimbursements.
  • Paid parental leave.
  • Educational assistance.
  • 401(k) plan.
  • Stock purchase plan.
  • Discounts at Marriott properties.
  • Commuter benefits.
  • Employee assistance plan.
  • Childcare discounts.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service