Back to Jobs
Marriott Hotels Resorts

Manager, Vulnerability Management at Marriott Hotels Resorts

Marriott Hotels Resorts Bethesda, MD

Job Description

DescriptionJOB SUMMARYThe Manager Vulnerability Management functions as a technical expert in the area of vulnerability scanning and remediation tracking. The role will be responsible for identifying vulnerabilities through vulnerability scanning and ensuring remediation through assessment and reporting. The role will also maintain the evaluation process identify areas for process improvement to assure the inclusion of appropriate elements of quality and compliance with security policy and regulations. The role will provide assistance with enterprise vulnerability scanning and will be able to create and manage integrated assessments. This role is for a technical expert who can monitor and assess vulnerability scanning data. It requires the ability to communicate with technical and non-technical stakeholders relay the importance of the vulnerability management activities the risks presented by findings and potential remediation actions. This role requires a working knowledge of security and network protocols system and network administration and configuration management.CANDIDATE PROFILEEducation and ExperienceRequired:Bachelors degree in Computer Sciences or related field or equivalent experience/certification.5 years of information security experience that also includes background and knowledge of general security concepts such as defense in-depth least privilege etc.2 years experience with:Vulnerability scanning and assessment using .Vulnerability assessment and reporting including comprehensive understanding of Vulnerability Management methodologies and procedures threat assessment and remediation management.Implementing managing or using enterprise vulnerability assessment technologies including Tenable Security Center or similar vulnerability solutions is required.Preferred:Current information security certification including Certified Information Systems Security Professional (CISSP) GIAC certification or Certified Information Security Manager (CISM).Technical leadership experience in both sourced and contractor environments.Experience managing or operating enterprise vulnerability management in a large commercial enterprise.Experience working in a multi-cloud enterprise environment.Ability to understand and manipulate large data sets to provide analysis and reporting.Experience working on medium to large projects involving multiple teams in a technical lead role within an enterprise environment.Experience with managing technical aspects of various controls frameworks such as NIST Security and Privacy Controls and PCI-DSS.Experience managing or operating enterprise vulnerability management in a large commercial enterprise.Familiarity with attack and exploitation techniques involving operating systems applications and devices commonly seen in an enterprise environment.Excellent communication skills and problem solving ability.Demonstrated ability to work independently and with others.Technical infrastructure operations administration or engineering background.CORE WORK ACTIVITIESProvide technical leadership to the information vulnerability management process including developing and managing remediation activities.Identify triage and prioritize vulnerabilities and associated remediation and mitigation activity using multiple sources of vulnerability threat and asset data.Develop remediation and mitigation guidance to include vendor-supplied remediations mitigating actions to reduce risk and actions to address vulnerabilities for which complete remediation does not exist on both individual assets and on multi-asset solutions and environments.Use internal solutions to report on open vulnerabilities remediation progress remediation compliance and vulnerability metrics for use by technical management and executive stakeholders.Perform planned and ad-hoc vulnerability scanning determine remediation options and track remediation to completion.Evaluate and test hardware firmware and software for possible impact on system security and the investigation and resolution of security risk and incidents.Assist in the direction of third-party vendors activities to include prioritizing work developing processes to govern such activities and reporting on the status type and effectiveness of those activities.Create maintain and mature vulnerability management processes and associated documentation.Maintain documentation repositories related to vulnerability management for use by internal staff and technical stakeholdersWork proactively with IT Infrastructure partners with respect to strategic and tactical plans for information security.Educates internal and external users of security technologies to continually improve the knowledge and skill-base of the organization on how best to manage security configuration patch management and vulnerability management within the infrastructure services.Participates in the evaluation and selection of security services products.Promotes the benefits of security services to the organization and educates the team on security concepts.Technical LeadershipTrains and/or mentors other team members and peers as appropriateProvides financial input on department or project budgets capital expenditures or other cost/resource estimates as requestedIdentifies opportunities to enhance the service delivery processesIT GovernanceFollows all defined IT standards and processes (i.e. IT Governance SM&G Architecture etc.) and provides input for improvements to the appropriate process owners as neededMaintains a proper balance between business and operational riskFollows the defined project management standards and processes At Marriott International we are dedicated to being an equal opportunity employer welcoming all and providing access to opportunity. We actively foster an environment where the unique backgrounds of our associates are valued and greatest strength lies in the rich blend of culture talent and experiences of our associates. We are committed to non-discrimination on any protected basis including disability veteran status or other basis protected by applicable law.Required Experience:Manager Key Skills Abinitio,Lifting Equipment,Customer Service,Apache Commons,Business Management Employment Type : Full-Time Experience: years Vacancy: 1

Resume Suggestions

Highlight relevant experience and skills that match the job requirements to demonstrate your qualifications.

Quantify your achievements with specific metrics and results whenever possible to show impact.

Emphasize your proficiency in relevant technologies and tools mentioned in the job description.

Showcase your communication and collaboration skills through examples of successful projects and teamwork.

Explore More Opportunities