Chief Info Security Officer (CISO)
Bethesda, MD - USA
Job Summary
As the #1 leader in hospitality worldwide Marriott International has nearly 40 brands and over 9800 hotels in its portfolio across 145 countries and were still growing. By joining Marriott you can be a part of something bigger than yourself be inspired by whats possible and discover your own future as we continue to undertake the industrys largest digital and technology transformation that will allow us to maintain our position as the industry leader in travel and hospitality for years to come. The patent-pending platforms and architecture is built with secure by design trust by design principles. Come build whats next.
As a critical member of the senior technology leadership team the Chief Information Security Officer (CISO) defines leads and executes the enterprise-wide information security governance risk compliance and trust strategy to protect the companys digital assets technology platforms brand reputation and customer trust in an increasingly AI-enabled world. This executive establishes and operationalizes a Trust and Security by Design modelensuring security privacy resilience and ethical use of technology are embedded into every product platform and digital experience as well as the culture of how we work. They are also accountable for leading all Board-level engagement on information security with Marriotts BOD technology subcommittee instilling confidence in our current and continually evolving cybersecurity strategy.
The CISO is accountable for evolving the organizations cybersecurity posture through intelligent automation advanced analytics and AI driven security capabilities enabling proactive risk reduction faster threat detection and response and scalable governance across a global decentralized environment. The CISO will be accountable for a forward-thinking and resilient Information Security ProgramGovernance Risk and Compliance (GRC) Identity and Access Management (IAM) Security Architecture and Strategy and Security Operations Center (SOC).
Serving as the strategic leader for cyber risk regulatory compliance and digital trust the CISO partners closely with IT Legal HR Compliance Data Privacy and business leaders to align security outcomes with business priorities. This executive sets the tone for a culture of security consciousness responsible AI use and continuous improvementanticipating emerging threats and embedding modern automated defenses to protect the companys future. The role reports to the Chief Information Officer.
CANDIDATE PROFILE
Education and Experience
Required:
- Bachelors degree in information security Computer Science or related field.
- 15 years of progressive cybersecurity experience with at least 10 years in a senior leadership role that reflects significant people and financial management experiences and leading through a range of moments from crisis to driving change.
- Demonstrated success leading enterprise information security programs and teams.
- Demonstrated experience applying AI machine learning and automation to cybersecurity operations risk management or governance at enterprise scale.
- Proven leadership embedding security by design and privacy by design principles into digital transformation cloud adoption and product development lifecycles.
- Experience governing the secure and responsible use of AIenabled technologies including risk management controls and ethical considerations.
- Extensive knowledge of cybersecurity frameworks (NIST ISO 27001) risk management practices and IT governance.
- Experience managing complex security operations incident response and threat mitigation.
- Strong background in security technologies including firewalls SIEM intrusion detection encryption and identity & access management.
- Experience implementing DevSecOps secure software development and security engineering practices.
- Experience with cloud security and securing multicloud infrastructures.
- Experience with leading Identity & access management (IAM).
- Deep understanding of Network and endpoint protection technologies.
- Working knowledge of data privacy regulations (e.g. GDPR HIPAA) and compliance programs.
- Strong platform skills and proven track record in executive communication and influencing at the Csuite and Board levels.
- Strong analytical decisionmaking and problemsolving capabilities.
Preferred:
- Masters degree in Cybersecurity IT Business Administration or related field.
- Certifications such as CISSP CISM CISA or CRISC.
- Background in digital forensics vulnerability management and penetration testing.
- Experience deploying AIdriven threat detection security orchestration (SOAR) automated incident response and predictive risk analytics.
- Familiarity with emerging regulatory and industry expectations related to AI governance algorithmic risk and digital trust.
CORE FOCUS
Trust & Security by Design
The CISO is the executive owner of the enterprise Trust and Security by Design framework ensuring that cybersecurity data protection privacy resilience and ethical technology use are foundational design requirementsnot afterthefact controls. This includes embedding security and trust principles into:
- Digital products and guestfacing experiences
- Cloud AI and data platforms
- Workplace technologies and enduser computing
- Thirdparty and ecosystem integrations
Security decisions are riskbased automated where possible and aligned to customer trust regulatory expectations and longterm enterprise value.
Set the Information Security Strategy & Champion Change
- Develop and communicate a compelling enterprise security and trust vision that integrates AIenabled security capabilities and automation aligned to business outcomes.
- Lead a multiyear cybersecurity and digital trust roadmap that embeds Trust and Security by Design into all technology initiatives.
- Proactively evaluate emerging threats AIdriven risks and technology trends adjusting strategy to ensure resilience and responsible innovation.
- Champion the adoption of automation to reduce manual controls improve decision quality and increase speed and consistency across security operations.
- Establish and oversee a global governance framework that integrates cybersecurity data protection privacy AI risk and digital trust.
- Leverage automation and analytics to continuously assess risk prioritize remediation and monitor control effectiveness.
- Ensure thirdparty vendor and ecosystem risk programs incorporate securitybydesign expectations and automated assurance mechanisms.
- Provide executive and Boardlevel reporting using datadriven forwardlooking risk indicators rather than static compliance metrics.
- Oversee modern AIenabled Security Operations capabilities that leverage advanced analytics automation and orchestration to detect and respond to threats in real time.
- Lead enterprise incident response with a focus on speed accuracy and automation including postincident learning and continuous improvement.
- Integrate threat intelligence digital forensics and predictive analytics to anticipate and mitigate emerging risks.
- Direct the design of secure resilient architectures across applications infrastructure cloud and AI platforms.
- Embed securitybydesign zerotrust and privacybydesign principles into all digital initiatives and product development lifecycles.
- Partner with IT and engineering teams to integrate security controls into CI/CD pipelines DevSecOps practices and AI development processes.
- Continuously modernize the security technology stack with a focus on automation scalability and reduced operational friction.
- Continuously improve the role based system access framework and provisioning.
- Build a highperforming security organization skilled in automation datadriven decisionmaking and AIenabled security practices.
- Lead enterprisewide security privacy and responsibleAI awareness programs that reinforce trust as a shared accountability.
- Foster a culture where innovation and security advance togetherbalancing speed safety and customer trust.
Information Security Governance Risk & Trust Management
- Establish and oversee a global governance framework that integrates cybersecurity data protection privacy AI risk and digital trust.
- Leverage automation and analytics to continuously assess risk prioritize remediation and monitor control effectiveness.
- Ensure thirdparty vendor and ecosystem risk programs incorporate securitybydesign expectations and automated assurance mechanisms.
- Provide executive and Boardlevel reporting using datadriven forwardlooking risk indicators rather than static compliance metrics.
Security Operations Automation & Incident Response
- Oversee modern AIenabled Security Operations capabilities that leverage advanced analytics automation and orchestration to detect and respond to threats in real time.
- Lead enterprise incident response with a focus on speed accuracy and automation including postincident learning and continuous improvement.
- Integrate threat intelligence digital forensics and predictive analytics to anticipate and mitigate emerging risks.
Security Architecture & AI Technology Enablement
- Direct the design of secure resilient architectures across applications infrastructure cloud and AI platforms.
- Embed securitybydesign zerotrust and privacybydesign principles into all digital initiatives and product development lifecycles.
- Partner with IT and engineering teams to integrate security controls into CI/CD pipelines DevSecOps practices and AI development processes.
- Continuously modernize the security technology stack with a focus on automation scalability and reduced operational friction.
- Continuously improve the role based system access framework and provisioning.
People Leadership & Organizational Development
- Build a highperforming security organization skilled in automation datadriven decisionmaking and AIenabled security practices.
- Lead enterprisewide security privacy and responsibleAI awareness programs that reinforce trust as a shared accountability.
- Foster a culture where innovation and security advance togetherbalancing speed safety and customer trust.
This role is not solely responsible for protecting systemsit is accountable for protecting trust enabling innovation and ensuring security is designed into how the enterprise operates scales and serves its customers.
At Marriott International we are dedicated to being an equal opportunity employer welcoming all and providing access to opportunity. We actively foster an environment where the unique backgrounds of our associates are valued and greatest strength lies in the rich blend of culture talent and experiences of our associates. We are committed to non-discrimination on any protected basis including disability veteran status or other basis protected by applicable law.
Required Experience:
Chief
About Company
At Le Méridien, we are inspired by the era of glamorous travel, celebrating each culture through the distinctly European spirit of savouring the good life. Our guests are curious and creative, cosmopolitan culture seekers that appreciate moments of connection and slowing down to savou ... View more