Director, Security Architect

4 days ago


Singapore Marriott Full time

Job Number 24110313

Job Category Information Technology

Location Singapore Regional Office, 2 Harbourfront Place #06-08, Singapore, Singapore, Singapore

Schedule Full-Time

Located Remotely? N

Relocation? N

Position Type Management

JOB SUMMARY

Lead and manage security architecture and engineering in APEC. Performs security accreditation and evaluates the implementation of those controls in order to grant Approval to Operate for a release of new infrastructure, services, applications and processes into Marriott’s Production Environments in regional level.

Leverages existing Security Engagement processes and documentation, in conjunction with security compliance tools, to determine control implementation status. Will routinely process ITSM Release and Security Engagement Tasks to document justification for all approvals. Will routinely collaborate with multiple teams, including, but not limited to, Business Release Sponsors, Project Managers, Security Architects, Security Architecture Analysts, and Change Management teams to ensure the Security Processes are followed and completed in order to accredit the engagement or release.

Will routinely manage and communicate the status of the tasks assigned in ITSM to thoroughly document the accreditation resulting in granting of Approval to Operate. Understand, communicate, interpret and enforce MI Policies and Security Standards throughout the Certification and Accreditation process. Understand and communicate control objectives in terms of both MI Policy and Standards and Security Best Practice Frameworks, including, but not limited to, NIST RMF, NIST CSF, PCI DSS, GDPR, MPLS, EU Privacy, ISO, as referenced in Marriott’s Common Controls Framework. Will periodically provide status and metrics for the assigned C&A Engagements in order to provide visibility and transparency to GIS Senior Leadership

CANDIDATE PROFILE

Education and Experience

Required:

  • Bachelor’s degree in Information Systems, Computer Science or related field or equivalent experience/certification

  • 8+ years’ experience in Information Security with:

  • 3+ years in process-oriented Security Audit/Assurance/Technical Assessment role

  • 2+ years’ team management experience with security technical team members

  • 1-2 years’ experience/exposure to Common Controls Framework

  • Exposure/functional understanding of NIST RMF

  • Current and relevant information security certifications such as: CISSP (Certified Information Systems Security Professional), (ISC)2 CGRC certification, ISACA, PCI QSA/ISA, ITIL, IS Certification & Accreditation Professional - ISCAP, GIAC Information Security Professional (GISP),

Preferred Skills & Attributes

  • Strong oral and written communication skills and comfortable with speaking in large groups virtually and in person.

  • Ability to conduct independent security research.

  • Strong understanding of common OWASP flagship projects, Top 10, Cheat Sheets…etc.

  • Strong understanding of cryptography concepts: hashing, signing, encryption, decryption, tokenization

  • Strong understanding of SDLC and security integration points

  • Functional understanding of microservice application architecture

  • Functional understanding of common application security controls such as WAF, RASP, Intercepting Proxies

  • Comfortable with the following tools and technologies: GitHub Advanced Security, Postman, Fortify SCA, Jenkins, Artifactory, SonarQube, Docker, JIRA, Confluence, Aqua CSP, Nessus Pro or Tenable.io

  • Comfortable with technical report writing and crafting security requirements.

  • Basic understanding of network security concepts: DOS, DNS Spoofing, ARP Poisoning, Firewalls, Intrusion Detection, Segmentation

  • Basic understanding of Vulnerability and Patch Management practices

  • Basic understanding of endpoint security controls: EDR, Vulnerability Scanning Agents, HIDS, FIM

  • Basic understanding of Agile Software Development Practices & DevOps

  • Master’s degree in Computer Science or Software Engineering

  • Mid-level cloud computing certification, AWS Solutions Architect Associate, Azure Administrator Associate, Google Associate Cloud Engineer

  • Functional knowledge software engineering concepts: GOF software design patterns, SOLID design principles (SRP, OSP, LSP, ISP, and DIP) and design methods (Scrum, XP, Lean, Waterfall)

  • Functional understanding of common cryptographic algorithms and libraries

  • Functional foundational understanding of Cloud Computing

CORE WORK ACTIVITIES

Security Accreditation

  • Works with development teams to review application source code for security and operational risks.

  • Perform manual code reviews of applications that are not compatible with automated SAST tools.

  • Provide detailed security documentation to developers, software engineers and technical personnel when necessary.

  • Provide guidance and recommendation to software architects and engineers on how to correct code related security flaws.

Managing Work, Projects, and Policies

  • Manage security architecture and engineering team in Great China.

  • Participate in peer reviews of security assessments created by other team members.

  • Manage tickets and SLAs associated with security testing efforts.

  • Maintain and contribute to the enterprise SSDLC standard.

  • Coordinates and implements work and projects as assigned.

  • Generates and provides accurate and timely results in the form of reports, presentations, etc.

  • Analyzes information and evaluates results to choose the best solution and solve problems.

  • Develops specific goals and plans to prioritize, organize, and accomplish work.

  • Sets and tracks goal progress for self and others.

  • Monitors the work of others to ensure it is completed on time and meets expectations.

  • Provides direction and assistance to other organizational units’ policies and procedures, and efficient control and utilization of resources.

Leading Team

  • Creates a team environment that encourages accountability, high standards, and innovation.

  • Leads specific team while assisting with meeting or exceeding department goals.

  • Makes sure others understand performance expectations.

  • Ensures that goals are being translated to the team as they relate to tracking and productivity.

  • Creates and nurtures an environment that emphasizes motivation, empowerment, teamwork, continuous improvement and a passion for providing service.

  • Understands employee and develops plans to address need areas and expand on the strengths.

  • Provides the team with the capabilities needed to meet or exceed expectations.

  • Leads by example demonstrating self-confidence, energy and enthusiasm.

Conducting Human Resources Activities

  • Acts proactively when dealing with employee concerns.

  • Extends professionalism and courtesy to employees at all times.

  • Communicates/updates all goals and results with employees.

  • Meets semiannually with staff on a one-to-one basis.

  • Establishes and maintains open, collaborative relationships with employees.

  • Solicits employee feedback.

  • Interviews job candidates and assists in making hiring decisions.

  • Receives hiring recommendations from team supervisors.

  • Ensures orientations for new team members are thorough and completed in a timely fashion.

  • Observes behaviors of employees and provides feedback to individuals.

Additional Responsibilities

  • Provides information to supervisors, co-workers, and subordinates by telephone, in written form, e-mail, or in person in a timely manner.

  • Manages group or interpersonal conflict.

  • Informs and/or updates executives, peers, and subordinates on relevant information in a timely manner.

  • Manages time effectively and conducts activities in an organized manner.

  • Presents ideas, expectations and information in a concise, organized manner.

  • Uses problem solving methodology for decision making and follow up.

  • Performs other reasonable duties as assigned by manager.

Marriott International is an equal opportunity employer. We believe in hiring a diverse workforce and sustaining an inclusive, people-first culture. We are committed to non-discrimination on any protected basis, such as disability and veteran status, or any other basis covered under applicable law.

Marriott International is the world’s largest hotel company, with more brands, more hotels and more opportunities for associates to grow and succeed. Be where you can do your best work,​ begin your purpose, belong to an amazing global​ team, and become the best version of you.


  • Cloud Architect

    1 week ago


    Singapore PCS Security Full time

    As there is an increased demand for cloud adoption and technologies, we are on the lookout for experienced Cloud Architects to drive and manage the design and development of complex cloud solutions.Responsibilities: Architect solutions to meet business and IT needs, ensuring technical viability of new projects and successful deployments, while orchestrating...


  • Singapore Marriott Full time

    Job Number Job Category Information TechnologyLocation Singapore Regional Office, 2 Harbourfront Place #06-08, Singapore, Singapore, SingaporeSchedule Full-TimeLocated Remotely? NRelocation? NPosition Type ManagementJOB SUMMARYLead and manage security architecture and engineering in APEC. Performs security accreditation and evaluates the implementation of...


  • Singapore AMBITION GROUP SINGAPORE PTE. LTD. Full time

    Roles & ResponsibilitiesVP, Security Architect for a leading Payment Solutions ProviderLeading Payment Solutions Provider Dynamic and collaborative work environment Opportunity to design secure system architectures and implement security solutionsOur client is a leading payment company in Singapore, overseeing the national clearing and payment...

  • Security Architect

    2 months ago


    Singapore TRINITY CONSULTING SERVICES PTE. LTD. Full time

    Roles & Responsibilities• Years of experience: 8-14 years• Well versed with security guidelines as OWASP and NIST frameworks• Done Security plan for major BFSI program• Worked with stakeholders on end to end VAPT• Experience of designing layered Security Architecture• Aware of ensuring security of data in transit and at restTell employers what...


  • Singapore LICO RESOURCES PTE. LTD. Full time

    Roles & ResponsibilitiesAre you enthusiastic about cybersecurity and eager to make a substantial impact in a top-tier multinational corporation? Lico Resources is partnering this leading MNC, and is on the lookout for a skilled and proactive Cyber Security Architect to enhance their existing team in Singapore. In this crucial role, you will be tasked with...

  • Solutions Architect

    1 week ago


    Singapore SSH Communications Security Full time

    We are looking for a highly skilled and passionate individual to join our team in Singapore as a Solutions Architect.As a Solutions Architect, you will work closely with clients to understand their unique requirements, as well as design and implement solutions that address their specific pain points. You will play a crucial role in ensuring that the...

  • Security Architect

    1 week ago


    Singapore NodeFlair Full time

    Job Summary:SalaryS$8,750 - S$17,500 / MonthlyJob TypeSeniorityLeadYears of ExperienceAt least 5 yearsTech StacksStrategy AWS Microsoft IAM Azure Java JavaScript PythonThe Role Responsibilities Deliver workable risk/threatdriven solutions with cost/benefit analysis. Communicate with both technical and nontechnical stakeholders, provide guidance on proper...


  • Singapore ILLUMINA SINGAPORE PTE. LTD. Full time

    Roles & ResponsibilitiesPosition Summary This role requires Product Security and software development experience, knowledge, and skills. You'll be responsible for leading pre-market and post-market security initiatives & solutions including Illumina medical instruments and connected software before they are released to customers. The Product Security...

  • Security Architect

    1 week ago


    Singapore Pinpoint Asia Full time

    Key Responsibilities: Develop and maintain a comprehensive security architecture strategy aligned with business objectives and regulatory requirements. Collaborate with stakeholders to understand current and future business needs, ensuring security measures are integrated seamlessly. Conduct risk assessments to identify potential security threats and...


  • Singapore Prestige Headhunters Full time

    N- Posted by Nevin Khoo Partner Technology & Quants Our clients are an international bank who are looking to scale up their cyber security function in Asia. This is a chance for a technical security architect to pivot into a more functional role working across various teams both business and technology.VP Cyber Security ArchitectThe role is focused on,...


  • Singapore Eames Consulting Full time

    Job Details:Sector: Cyber-Location: Singapore-Job Type: Permanent-Salary: 220,000 per year-Contact: Tricia LeeOur client, a renowned financial institution, is looking to hire a VP, Senior Security Architect to join their growing team in Singapore. As a VP, Senior Security Architect, you will be responsible for developing and implementing comprehensive...


  • Singapore Picus Full time

    About PicusPicus Security Inc is a place where exceptional people gather to do their best work. We convert new ideas to exceptional solutions and great customer experiences. Bring passion and dedication to your job and there's no telling what you could accomplish. Join Picus to become part of our talented teamPicus Security pioneered Breach and Attack...


  • Singapore TOPPAN NEXT TECH PTE. LTD. Full time

    TOPPAN Next Tech is expanding its Security Solutions and Services (SSS) division to enhance its business edge and pursue exciting opportunities in the market place for:Multi Modal Biometrics (face, fingerprint, iris) Key Installation Protection (military bases, protected buildings, secured facilities) Vehicle Access Control (2FA, biometric authentication,...


  • Singapore SINGAPORE SECURITY FORCE PTE. LTD. Full time

    Role Description:This position reports to the Director and is responsible for managing Security department. They oversee the day-to-day operations of their department, ensuring that everyone is working towards the same goal and objectives.Specific Responsbilities:Individual to be involved in:Developing and implementing security policies, protocols and...


  • Singapore Kerry Consulting Full time

    Description:We are currently partnering with a Global Financial Services Firm in hiring for Security Architects for an expanding team that aspires to be the best-in-class within the industry.Responsibilities: Partner with a global, diverse and talented team in performing security reviews, identifying gaps in security architecture, and developing a security...


  • Singapore ST ENGINEERING INFO-SECURITY PTE. LTD. Full time

    Job Description: Cybersecurity Solutions Architect at SecureTechResponsibilities:Serve as the primary contact point post-tender award, ensuring successful delivery of cybersecurity solutions.Design and implement comprehensive cybersecurity solutions for identification, protection, detection, response, and recovery from threats and vulnerabilities.Define...

  • Operations Director

    1 week ago


    Singapore ARDANT SECURITY MANAGEMENT PTE. LTD. Full time

    1. Report directly to the Managing DirectorAssist the Managing Director in the running of the company's Operations DepartmentEnsure that all staff adhere to all rules and regulations of the Company and customers.Responsible for ensuring that all operational matters at various levels are attended to.Monitor information relating to customer perception and...


  • Singapore Eames Consulting Full time

    Director, Cyber Security PolicyAre you an experienced Cyber Security Risk and Policy professional looking for a role focused in security policy writing? If you have strong experience in cyber security policy writing, our client, an established firm in the telecommunication sector, is looking for a Director, Cyber Security Policy, to join their team.As...


  • Singapore STAR CAREER CONSULTING PTE. LTD. Full time

    **Enterprise Architect (Cyber Security, Network)Our Esteemed and Reputable Client is looking for **Enterprise Architect (Cyber Security, Network)Requirements:- Strong involvement as Enterprise Architect/ Solution Architect:- Technically incline in Network Infrastructure and Cyber Security:- Good in Network and Security Design: Responsible in handling...


  • Singapore Singtel Group Full time

    NCS is the leading information, communications and technology (ICT) service provider in Singapore. We deliver end-to-end ICT solutions to help governments and enterprises realise business value through digital transformation and the innovative use of technology.     The Security Solutions Architect (SSA) will act in many ways as the Technology...