Senior Manager – Information Security Incident Command
Bethesda, MD, United States
Full Time Senior-level / Expert USD 98K - 166K
Marriott International
Book Directly & Save at any of our 9000+ Marriott Bonvoy Hotels. Choose from Luxury Hotels, Resorts, Extended Stay Hotels, Pet-Friendly Hotels & More.JOB SUMMARY
The Senior Manager supports and manages Red and Red/Blue Team (“Red Team”) testing as a part of the Global Information Security (GIS) PMO Incident Command team. Triages coordination and updates of issues and backlog of strategic recommendations and roadmap items based on the Red Team assessments. Collaborates across the Global Technology organization and with key business stakeholders to deliver results.
EDUCATION & EXPERIENCE
Required:
• Bachelor’s degree in Computer Science or related field or equivalent experience/certification
• 7+ years working with information security processes, issue management and Red Team support
• Several years’ experience with an expertise in Microsoft Office 365 products, particularly Word, Excel and PowerPoint
• Ability to work occasionally outside of normal business hours to support global efforts
Attributes:
• Strong verbal and written communication skills with the ability to articulate complex technical ideas in easy-to-understand business terms.
• Ability to independently and effectively prioritize and execute tasks in a fast-paced high-pressure environment.
• Very high level of interpersonal skills to work effectively with others, motivate employees, and elicit work output in a team environment.
• Extremely high level of analytical ability to resolve complex and difficult issues.
• Ability to provide and clearly communicate status, actions, risks and put forth recommendations and solutions.
• Ability to coordinate a team and drive towards project delivery.
Preferred:
• Graduate/post graduate degree
• Current information security certification, including Certified Information Systems Security Professional (CISSP), PCI Internal Security Assessor (ISA), Certified Information Security Manager (CISM), or Certified Information Systems Auditor (CISA).
• Expert level understanding of key network and system security controls. Expertise in various security technologies, such as firewalls and network segmentation, IDS, vulnerability/application scanning, and penetration testing.
• Capability in interpreting and understanding vulnerability scan and penetration testing results.
• Experience managing tasks within Jira.
• Demonstrated proficiency in project management methodology and program management.
• Demonstrated record of managing internal and external projects from inception to successful implementation.
• Solid understanding of current technologies with the ability to develop and deliver projects using leading edge technologies.
• Skilled in conceptualizing creative solutions, documenting them, and presenting/selling them to senior management.
• Working knowledge of business environment, service requirements, and/or hospitality culture.
CORE WORK ACTIVITIES
Lead Triage of Remediation Efforts
• Manage Red Team exercise program, leading quarterly testing, triage and tracking of Red Team issues, strategic recommendations and roadmap items.
• Lead quarterly planning, including working with team to develop a roadmap, determine testing scope, alignment on rules of engagement and coordinate system access.
• Manage Red Team exercise execution, managing 3rd party activities and follow up on results and actions.
• Drives the remediation governance process by holding stakeholders accountable for deadlines, completion of remediation plans and remediation efforts.
• Provides consistent and clear communication to remediation owners to understand their role.
• Coordinates the correct technical teams to drive the remediation plan, including subject matter experts and remediation owners.
• Facilitates and documents Marriott requirements with the technical teams.
• Confers understanding of the issues management process for remediations in alignment with the GlS standards and Red Team standard operating procedures (SOPs) and processes.
• Leads Remediation Review Group working sessions and remediation governance sessions.
• Leads Red Team status reporting, including development of quarterly status reports and facilitation of status meetings for Red Team executive sponsors.
• Drives and participates in the incremental improvements to the issues management process through process creation, tool building, report development and leading/participating in post-incident reviews.
• Manages the triage coordination and updates of multiple simultaneous remediation efforts.
• Ensures long term remediations are properly dispositioned as action, risks, projects or programs.
• Serve as a liaison with GIS, and other departments such as IT, Digital, Legal and Privacy, various business functions, etc.
• Ensures accountability for Red Team responsibilities through the development and maintenance of Red Team processes and SOPs.
• Follows PMO processes and procedures where applicable.
Supporting Major Security Incidents
• Supports major information security incidents, including coordination among multiple groups.
Maintaining Goals
• Submits reports in a timely manner, ensuring delivery deadlines are met.
• Promotes the documenting of remediation progress accurately.
• Provides input and assistance to other teams regarding remediation efforts.
Demonstrating and Applying Discipline Knowledge
• Provides technical expertise and support to persons inside and outside of the department.
• Demonstrates knowledge of job-relevant issues, products, systems, and processes.
• Demonstrates knowledge of function-specific procedures.
• Keeps up-to-date technically and applies new knowledge to job.
• Uses computers and computer systems (including hardware and software) to enter data and/ or process information.
Delivering on the Needs of Key Stakeholders
• Understands and meets the needs of key stakeholders.
• Develops specific goals and plans to prioritize, organize, and accomplish work.
• Determines priorities, schedules, plans and necessary resources to ensure completion of any projects on schedule.
• Collaborates with internal partners and stakeholders to support business/initiative strategies.
• Communicates concepts in a clear and persuasive manner that is easy to understand.
• Generates and provides accurate and timely results in the form of reports, meeting notes, presentations, etc.
• Demonstrates an understanding of business priorities.
Manages Information Security Projects
• Provides project management of information security projects.
• Provides effective reporting to stakeholders.
• Monitors projects for alignment with defined PMO governance processes.
• Participates in PMO portfolio and demand management processes.
The salary range for this position is $98,500 to $166,900 annually. In addition to the annual salary, the position will be eligible to receive an annual bonus.
Washington Applicants Only: Employees will accrue 0.04616 PTO balance for every hour worked and eligible to receive minimum of 7 holidays annually.
All locations offer coverage for medical, dental, vision, health care flexible spending account, dependent care flexible spending account, life insurance, disability insurance, accident insurance, adoption expense reimbursements, paid parental leave, educational assistance, 401(k) plan, stock purchase plan, discounts at Marriott properties, commuter benefits, employee assistance plan, and childcare discounts. Benefits are subject to terms and conditions, which may include rules regarding eligibility, enrollment, waiting period, contribution, benefit limits, election changes, benefit exclusions, and others.
Marriott HQ is committed to a hybrid work environment that enables associates to Be connected. Headquarters-based positions are considered hybrid, for candidates within a commuting distance to Bethesda, MD; candidates outside of commuting distance to Bethesda, MD will be considered for Remote positions.
The application deadline for this position is 28 days after the date of this posting, June 17, 2025.
Marriott International is an equal opportunity employer. We believe in hiring a diverse workforce and sustaining an inclusive, people-first culture. We are committed to non-discrimination on any protected basis, such as disability and veteran status, or any other basis covered under applicable law.
Tags: Blue team CISA CISM CISSP Computer Science Firewalls Governance IDS Jira Pentesting Privacy Red team
Perks/benefits: Career development Equity / stock options Flex hours Flexible spending account Flex vacation Health care Insurance Medical leave Parental leave Salary bonus Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.