CrawlJobs Logo

Security Engineer, MFA and Web Access Management

https://www.marriott.com Logo

Marriott Bonvoy

Location Icon

Location:
United States , Bethesda

Category Icon

Job Type Icon

Contract Type:
Not provided

Salary Icon

Salary:

84900.00 - 148600.00 USD / Year
Save Job
Save Icon
Job offer has expired

Job Description:

Leads the Identity & Access Management (IAM) function in Global Information Security organization through subject matter expertise (L3) on Multi-factor authentication (MFA), Web Access Management (WAM) technologies. Functions as the Security Engineer in the team providing engineering support for MFA and SSO service offerings, daily operations, and continuous improvements.

Job Responsibility:

  • Functions as an MFA and WAM point of contact for IT system administrators, Service Desk, service providers and application owners
  • Works closely with senior engineers and other team members for MFA and SSO services and operational needs
  • Routinely collaborates with different security team members including, but not limited to architecture, infrastructure, network, compliance, and incident response
  • Manages the MFA and WAM services including requirements gathering, design, building, testing, deployment, and operationalization
  • Collaborates with multiple stakeholders to support implementation of new applications and services
  • Defines and documents MFA and WAM policies and procedures
  • Creates test cases to ensure cross platform interoperability
  • Implements and validates security controls for the MFA and WAM solution
  • Designs security solutions to address risks throughout the Marriott SDLC process and confirm that the level of risk is acceptable in accordance with Marriott’s policies
  • Provides guidance and oversight for L2/L1 troubleshooting of operational issues
  • Leads the identification and remediation of relative security events
  • Submits reports in a timely manner, ensuring delivery deadlines are met
  • Promotes the documenting of project progress accurately
  • Provides input and assistance to other teams regarding projects
  • Manages and implements work and projects as assigned
  • Generates and provides accurate and timely results in the form of reports, presentations, etc
  • Analyzes information and evaluates results to choose the best solution and solve problems
  • Provides timely, accurate, and detailed status reports as requested
  • Provides technical expertise and support to persons inside and outside of the department
  • Demonstrates knowledge of job-relevant issues, products, systems, and processes
  • Demonstrates knowledge of function-specific procedures
  • Keeps up-to-date technically and applies new knowledge to job
  • Uses computers and computer systems (including hardware and software) to enter data and/ or process information
  • Understands and meets the needs of key stakeholders
  • Develops specific goals and plans to prioritize, organize, and accomplish work
  • Determines priorities, schedules, plans and necessary resources to ensure completion of any projects on schedule
  • Collaborates with internal partners and stakeholders to support business/initiative strategies
  • Communicates concepts in a clear and persuasive manner that is easy to understand
  • Generates and provides accurate and timely results in the form of reports, presentations, etc
  • Demonstrates an understanding of business priorities
  • Provides information to supervisors and co-workers by telephone, in written form, e-mail, or in person in a timely manner
  • Demonstrates self-confidence, energy and enthusiasm
  • Informs and/or updates leaders on relevant information in a timely manner
  • Manages time effectively and conducts activities in an organized manner
  • Presents ideas, expectations and information in a concise, organized manner
  • Uses problem solving methodology for decision making and follow up
  • Performs other reasonable duties as assigned by manager

Requirements:

  • Undergraduate degree in Computer Sciences or related field or equivalent work experience and certifications
  • Minimum 4+ years of information security or infrastructure engineering experience
  • 4+ years of experience in managing MFA offerings
  • Passkeys, Biometrics, FIDO tokens, various authenticators
  • Implementation experience of PingOne products like DaVinci, Verify, Protect, Neo
  • 4+ years’ experience of Federation/SSO services, protocols, and technologies
  • OAuth/OIDC, SAML, WS-FED
  • Browsers, MDM/MAM, X509 cert-based authentication (user & device)
  • 2+ years’ experience with Ping Access and Ping Federate architecture, design, and implementation
  • Policy design and implementation
  • Ping Fed custom adapter development
  • Integration of custom applications
  • 2+ years of experience in Development
  • JAVA, HTML/JavaScript/JSON, scripting (Ansible, Shell, Perl, Expect)
  • 2+ years of experience translating business requirements to technical requirements with strong written and verbal communication skills
  • 2+ years of experience with LDAP and directory Services using Radiantlogic or Ping Directory

Nice to have:

  • 5+ years of experience with integrating IAM solutions with infrastructure and applications
  • 2+ years of experience in designing & implementing API services and data transformation layers
  • 2+ years of experience on containerized deployment environments
  • Current information security certification, including Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified SCADA Security Architect (CSSA) or Certified Secure Software Lifecycle Professional (CSSLP)
  • Technical knowledge of industry best practices pertaining to MFA/WAM services
  • Experience with defining & fulfilling Key Performance Indicators for MFA infrastructure
  • Experience in the IAM domain with user lifecycle management, authentication, authorization, federation, and privileged access management
  • Experience in implementing the capabilities such as Passwordless or adaptive authentication
  • Experience with cloud/SaaS IAM/WAM services
  • Experience with Zero-Trust Framework
  • Experience with CASB and WAF technologies
  • Experience doing business analysis and requirements gathering for complex business systems
  • Responsible for identifying, evaluating, and participating in decision making around new and emerging IAM/MFA technologies and should be able to support other areas of Information Security as needed
  • Strong understanding of PKI, certificate management, security, and provisioning of identity data
What we offer:
  • 401(k) plan
  • stock purchase plan
  • discounts at Marriott properties
  • commuter benefits
  • employee assistance plan
  • childcare discounts
  • medical coverage
  • dental coverage
  • vision coverage
  • health care flexible spending account
  • dependent care flexible spending account
  • life insurance
  • disability insurance
  • accident insurance
  • adoption expense reimbursements
  • paid parental leave
  • educational assistance
  • paid sick leave
  • PTO balance
  • holidays

Additional Information:

Job Posted:
January 03, 2026

Expiration:
January 16, 2026

Employment Type:
Fulltime
Work Type:
Hybrid work
Job Link Share:

Looking for more opportunities? Search for other job offers that match your skills and interests.

Briefcase Icon

Similar Jobs for Security Engineer, MFA and Web Access Management

Senior Security Engineer

The Senior Security Engineer will provide hands-on technical leadership within t...
Location
Location
United Kingdom , Leeds; Thame
Salary
Salary:
65000.00 - 75000.00 GBP / Year
pexa.co.uk Logo
PEXA UK
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Proactive, can-do attitude to get things done quickly and efficiently
  • Strong collaboration and communication skills
  • Willingness to contribute ideas to the security programme
  • Demonstratable first-hand experience in achieving organisational adherence to security best practices
  • Experience in the practical protection of a remote working laptop estate and SaaS cloud solutions
  • Experience in identity and access management solutions
  • Experience in device business automation and updates
  • Experience in the security aspects of cloud web application hosting and defence measures like WAF
Job Responsibility
Job Responsibility
  • Maintenance and Operational Security: Ensure all security solutions remain operationally effective
  • Ensure technical teams timely patch applications, systems, software, and hardware
  • Maintain and audit secure configurations for devices, applications, and cloud environments
  • Access Control and Identity Management: Conduct regular user and privileged account reviews
  • Manage and monitor Privileged Identity Management (PIM) profiles and elevated access accounts
  • Coordinate with IT and HR for onboarding/offboarding
  • Tool, Infrastructure, and Encryption Management: Maintain and optimise security infrastructure and tools
  • Oversee encryption key and certificate management
  • Work with vendors and internal teams to ensure tools remain current
  • VPN, Network & Firewall Security: Design, configure, and maintain secure VPN and Zero-Trust network solutions
What we offer
What we offer
  • Your growth: We encourage you to hit your personal and professional learning and development goals with our tailored programs and tools
  • Your wellness: We care about your holistic wellbeing
  • Your work/life blend: We want to help you create your ideal work/life blend
  • Fulltime
Read More
Arrow Right

Network and Security Architect - SASE

We are seeking a highly skilled and experienced Network and Security Architect w...
Location
Location
Poland , Łódź
Salary
Salary:
Not provided
https://www.bosch.pl/ Logo
Robert Bosch Sp. z o.o.
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 10+ years of progressive experience in network and security architecture, with a strong focus on cloud security
  • 5+ years of hands-on experience designing, deploying, and managing large-scale ZTNA and SASE solutions in enterprise environments
  • Deep understanding and practical experience with leading SASE vendor platforms (e.g., Zscaler, Palo Alto Networks Prisma Access, Fortinet FortiSASE, Netskope, etc.)
  • Proven expertise in Zero Trust principles and their practical implementation across various layers (identity, device, application, data)
  • Strong knowledge of networking protocols (TCP/IP, BGP, OSPF, DNS, HTTP/S), VPN technologies (IPsec, SSL VPN), and network security concepts (firewalls, IDS/IPS, WAF)
  • Experience with cloud platforms (Azure, AWS, GCP) and their security services
  • Proficiency in identity and access management (IAM) concepts and technologies (SAML, OAuth, OpenID Connect, MFA)
  • Excellent analytical, problem-solving, and decision-making skills
  • Strong communication, presentation, and interpersonal skills with the ability to influence and persuade stakeholders at all levels
  • Ability to work independently and as part of a global, cross-functional team
Job Responsibility
Job Responsibility
  • Lead the design, development, and evolution of Bosch's global ZTNA and SASE architecture, ensuring alignment with industry best practices, regulatory requirements, and Bosch's security policies
  • Define architectural patterns, standards, and blueprints for ZTNA and SASE components, including Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), Firewall-as-a-Service (FWaaS), Zero Trust Network Access (ZTNA), Data Loss Prevention (DLP), and advanced threat protection
  • Evaluate and recommend new technologies, vendors, and solutions within the ZTNA/SASE ecosystem to enhance Bosch's security capabilities and optimize performance
  • Develop and maintain the architectural roadmap for ZTNA and SASE, forecasting future needs and anticipating technological shifts
  • Oversee the end-to-end deployment of ZTNA and SASE solutions, including planning, design, implementation, testing, and go-live
  • Collaborate with network engineering, security operations, application development, and business units to ensure seamless integration of ZTNA/SASE with existing IT infrastructure and applications
  • Define integration strategies for identity providers (e.g., Azure AD), endpoint security solutions, and other security tools
  • Provide expert guidance and technical leadership to implementation teams and external vendors
  • Translate high-level security requirements into detailed ZTNA and SASE policies, rules, and configurations
  • Develop and enforce security standards and guidelines for secure access, data protection, and threat prevention within the SASE framework
What we offer
What we offer
  • Competitive salary + annual bonus
  • Hybrid work with flexible working hours
  • Referral Bonus Program
  • Copyright costs for IT employees
  • Complex environment of working, professional support and possibility to share knowledge and best practices
  • Ongoing development opportunities in a multinational environment
  • Broad access to professional trainings (incl. language courses), conferences and webinars
  • Private medical care and life insurance
  • Cafeteria System with multiple benefits (incl. MultiSport, shopping vouchers, cinema tickets, etc.)
  • Prepaid Lunch Card
  • Fulltime
Read More
Arrow Right

Senior/Staff Enterprise Security Engineer

We're looking for a very experienced and highly motivated Senior or Staff Enterp...
Location
Location
United States , San Francisco; New York
Salary
Salary:
214200.00 - 252000.00 USD / Year
abridge.com Logo
Abridge
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 5 to 7+ years of progressive experience in an Enterprise/Corporate Security Engineering role
  • Proven hands-on experience developing security automation solutions with Python or similar high-level languages
  • Expert-level knowledge of IAM concepts, protocols (SAML, OAuth), and hands-on experience with at least IAM in Google Workspace
  • Strong experience deploying and managing modern Endpoint Protection (EDR) and MDM solutions in a large corporate environment
  • Deep understanding of networking and security protocols (TCP/IP, DNS, TLS/SSL, VPN, Firewalls) and how to secure hybrid environments
  • Demonstrated ability to lead complex projects, mentor junior staff, and communicate security risks and solutions effectively to both technical and non-technical stakeholders
Job Responsibility
Job Responsibility
  • Architect and implement enterprise-wide Identity and Access Management (IAM) and Privileged Access Management (PAM) solutions
  • Own the implementation and maintenance of authentication standards, including Single Sign-On (SSO), phishing resistant Multi-Factor Authentication (MFA), and identity federation protocols (SAML, OIDC, OAuth2)
  • Design and enforce security policies for critical SaaS applications using tools like SSPM (SaaS Security Posture Management)
  • Develop and automate the full identity lifecycle (joiner, mover, leaver) process
  • Lead the development of the security automation roadmap for Enterprise Security
  • Design and build custom automation scripts and integrations using languages like Python to connect security tools (SIEM, EDR, IAM, Ticketing)
  • Utilize Infrastructure as Code (IaC) tools (e.g., Terraform) to manage the secure configuration of enterprise tools and enforce security policies at scale
  • Engineer, deploy, and manage our Endpoint Detection and Response (EDR) and Mobile Device Management (MDM) platforms
  • Design, configure, and maintain enterprise network security controls, including next-generation firewalls, secure web gateways, VPNs, and micro-segmentation strategies
  • Own and optimize the email security stack, DMARC/DKIM/SPF enforcement, and anti-phishing controls
What we offer
What we offer
  • Generous Time Off: 14 paid holidays, flexible PTO for salaried employees, and accrued time off for hourly employees
  • Comprehensive Health Plans: Medical, Dental, and Vision coverage for all full-time employees and their families
  • Generous HSA Contribution: If you choose a High Deductible Health Plan, Abridge makes monthly contributions to your HSA
  • Paid Parental Leave: Generous paid parental leave for all full-time employees
  • Family Forming Benefits: Resources and financial support to help you build your family
  • 401(k) Matching: Contribution matching to help invest in your future
  • Personal Device Allowance: Tax free funds for personal device usage
  • Pre-tax Benefits: Access to Flexible Spending Accounts (FSA) and Commuter Benefits
  • Lifestyle Wallet: Monthly contributions for fitness, professional development, coworking, and more
  • Mental Health Support: Dedicated access to therapy and coaching to help you reach your goals
  • Fulltime
Read More
Arrow Right

Principal IAM Engineer

The IAM Principal Engineer is responsible for driving the development, maintenan...
Location
Location
United States , Mount Laurel
Salary
Salary:
142361.11 - 213541.67 USD / Year
comcastcorporation.com Logo
Comcast
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Over 10 years of experience implementing SailPoint IdentityIQ
  • More than 5 years of experience designing, architecting, implementing, operating, and maintaining Radiant Logic Virtual Directory Service (VDS), including Federated Identity Management (FIM) and Identity Correlation and Synchronization (ICS)
  • Skilled in integrating data sources and applications into VDS, configuring data access views and permissions, and performing identity correlation and synchronization
  • Strong knowledge of LDAP, Active Directory services, Multi-Factor Authentication (MFA), risk-based authentication, and privileged access management
  • Deep understanding of Identity and Access Management (IAM) across authentication, authorization, endpoint security, network security, and policy engines
  • Technical expertise with Microsoft MFA, SailPoint, CyberArk, ForgeRock, Okta, Ping Identity, Active Directory, Azure Active Directory, AWS, Google Cloud Platform, Microsoft Azure, and cross-domain IDM integrations
  • Solid grasp of cloud identity concepts and hands-on experience with Azure AD and other cloud environments
  • 3–5+ years of experience developing workflows, forms, connector configurations, provisioning policies, and rules within SailPoint IdentityIQ
  • Quick learner with the ability to adopt new technologies and collaborate effectively to capture and implement business system requirements
  • Proficient in source control and development tools such as GitHub and Eclipse
Job Responsibility
Job Responsibility
  • Apply your expertise in SailPoint IdentityIQ and Radiant One FID / Global Sync to enhance and expand the capabilities of the enterprise IAM platform
  • Collaborate with Agile teams to design, build, test, and support scalable IAM solutions that meet foundational enterprise needs, including identity federation, directory virtualization, and multi-source synchronization
  • Contribute innovative and efficient configuration and coding solutions in SailPoint IdentityIQ and Radiant One FID environments that differentiate the IAM platform
  • Engineer cost-effective technical solutions leveraging Radiant One FID and Global Sync to address business challenges and streamline identity and access processes
  • Develop both tactical and strategic IAM solutions aligned with evolving business requirements, including federated identity management and synchronized directory services
  • Partner with key stakeholders to gather and validate requirements, ensuring delivered solutions meet expectations across SailPoint IdentityIQ and Radiant One FID systems
  • Participate in project teams to design new system capabilities, including proof-of-concept (POC) implementations for both Radiant One FID and SailPoint IdentityIQ, and presentations that highlight their functionality
  • Deploy and manage Radiant One FID in Kubernetes environments using Helm charts, ensuring scalable, reproducible, and reliable containerized deployments
  • Support the end-to-end testing lifecycle for system changes, including integrations with Radiant One FID / Global Sync, from design through execution
  • Create proactive capacity forecasts to prevent outages and ensure system reliability for SailPoint IdentityIQ and Radiant One FID services
What we offer
What we offer
  • Paid Time off
  • Physical Wellbeing benefits
  • Financial Wellbeing benefits
  • Emotional Wellbeing benefits
  • Life Events + Family Support benefits
  • Fulltime
Read More
Arrow Right

Partner Solution Architect - Security

The Global Channel Partner Sales (GCPS) team is a sales organization accountable...
Location
Location
France , Paris
Salary
Salary:
Not provided
https://www.microsoft.com/ Logo
Microsoft Corporation
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor's degree in computer science, Information Technology, Engineering, Business or related field AND extensive technical consulting, technical consultative selling, product development, or related technical/sales experience
  • OR Master's degree in computer science, Information Technology, Engineering, Business or related field AND technical consulting, technical consultative selling, product development, or related technical/sales experience
  • OR equivalent experience
  • Experience working in a customer-facing role (e.g., internal and/or external)
  • Experience working on technical projects
  • Technical Certification in Cloud Security (e.g., Azure, Amazon Web Services, Google, independent security certifications)
  • Previous related experience in technology IP solutions or services development, with a deep understanding of digital transformation business drivers, cloud platforms, and emerging cloud trends like generative AI (ARTIFICIAL INTELLIGENCE) and SaaS (Software as a Service) services
  • Strong working knowledge of Threat Protection, Data Security, NIS2, Identity, Sentinel, etc.
  • M365 and Azure Security platform value and multi-tenancy management
  • Security, governance, data access, and incident response best practices
Job Responsibility
Job Responsibility
  • Design Secure Cloud Architectures - Ensure robust, scalable, and secure cloud infrastructure tailored to partner needs
  • Lead Security Architectural Design Sessions - Facilitate the creation of effective and efficient cloud solutions through collaborative planning and design sessions
  • Develop Security Proof of Concepts and Pilots – Demonstrate the feasibility and benefits of proposed cloud solutions
  • Provide Security Technical Guidance and Support - Ensure successful implementation and optimization of cloud solutions
  • Transition Partner from Legacy Systems - Facilitate smooth transitions to modern and secure cloud environments
  • Partner Enablement and Business Acumen - Experience in offering guidance to the broader technical team to ensure that technical pre-sales, deployment, and consumption are part of solution development efforts and the ability to coach the partner on building resilience to technical issues and dealing with competition and and/or discuss Microsoft products and articulate the value proposition of Microsoft Cloud services to partners by understanding of business processes and the ability to identify opportunities where technology can drive business value
  • Ensure strong integration with wider channel ecosystem within Microsoft, work closely with the PSS and PDM sales roles to drive positive outcomes mapped to Microsoft strategy across the Netherlands and Belgium, Luxembourg, France Channel with potential across EMEA
  • Fulltime
Read More
Arrow Right
New

Support Worker

This specialist supported living service has been purpose-built for young adults...
Location
Location
United Kingdom , Church Stretton, Shrewsbury
Salary
Salary:
12.39 GBP / Hour
brookstreet.co.uk Logo
Brook-St Hiredonline
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Full UK manual driving licence held for at least 1 year
  • Access to your own vehicle (rural location)
  • Passionate about supporting people to live happy, fulfilled lives
  • Patient, caring, and a good listener
  • Confident communicator with individuals and families
  • Able to promote independence and daily living skills
  • Good IT skills and ability to use digital systems
  • Able to work independently and use initiative
Job Responsibility
Job Responsibility
  • Support individuals with daily living and independence skills
  • Promote inclusion and engagement in the wider community
  • Provide personal care where required
  • Build positive, trusting relationships with individuals and their families
  • Encourage participation in social and community activities
  • Work collaboratively within a supportive team environment
What we offer
What we offer
  • Competitive hourly pay
  • High-quality training provided
  • Comprehensive induction with shadow shifts
  • 28 days holiday in year one, increasing with service
  • Free and confidential counselling services
  • Health Cash Plan covering dental, optical, physio & more
  • Long service awards
  • Contributory pension scheme
  • Clear career development and progression opportunities
  • Regular supervision and team meetings
Read More
Arrow Right
New

Marketing designer

Fundraise Up is a modern fundraising platform built to make donating to nonprofi...
Location
Location
Serbia
Salary
Salary:
375000.00 - 445000.00 RSD / Month
fundraiseup.com Logo
Fundraise Up
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 5+ years of experience in communication or brand design
  • Strong understanding of how design solves business problems and communicates brand values
  • AI as a working tool: hands-on experience using neural networks to speed up workflows, generate assets, and optimize routine tasks (practical skills over theory)
  • Strong illustration skills: ability to draw by hand and advanced proficiency in Figma (working with complex gradients, shadows, and lighting)
  • Web & Marketing: experience designing websites, solid understanding of landing pages and marketing funnels
  • Multiformat experience: creating presentations, designing for offline events (booths, print materials), and basic motion design (building simple animations, tweaking easings)
  • Conversational English (B2)
Job Responsibility
Job Responsibility
  • Develop and evolve the brand’s visual ecosystem (website, blog, social media), owning storytelling and translating complex ideas into clear, accessible metaphors
  • Create graphic content and illustrations, actively leveraging AI tools to accelerate production workflows
  • Produce materials for conferences and events — from merchandise and booth design to motion videos
  • Collaborate closely with the team to ensure visual consistency across all channels
What we offer
What we offer
  • 31 days off
  • 100% paid telemedicine plan
  • Home Office Setup Assistance: the company offers assistance with purchasing furniture (office chair, office desk, monitor) and other items to create a comfortable workspace
  • English learning courses
  • Relevant professional education
  • Gym or swimming pool
  • Co-working
  • Remote working
  • Stock options
  • Fulltime
Read More
Arrow Right
New

Marketing designer

Fundraise Up is a modern fundraising platform built to make donating to nonprofi...
Location
Location
Georgia
Salary
Salary:
8000.00 - 10800.00 GEL / Month
fundraiseup.com Logo
Fundraise Up
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 5+ years of experience in communication or brand design
  • Strong understanding of how design solves business problems and communicates brand values
  • AI as a working tool: hands-on experience using neural networks to speed up workflows, generate assets, and optimize routine tasks (practical skills over theory)
  • Strong illustration skills: ability to draw by hand and advanced proficiency in Figma (working with complex gradients, shadows, and lighting)
  • Web & Marketing: experience designing websites, solid understanding of landing pages and marketing funnels
  • Multiformat experience: creating presentations, designing for offline events (booths, print materials), and basic motion design (building simple animations, tweaking easings)
  • Conversational English (B2)
Job Responsibility
Job Responsibility
  • Develop and evolve the brand’s visual ecosystem (website, blog, social media), owning storytelling and translating complex ideas into clear, accessible metaphors
  • Create graphic content and illustrations, actively leveraging AI tools to accelerate production workflows
  • Produce materials for conferences and events — from merchandise and booth design to motion videos
  • Collaborate closely with the team to ensure visual consistency across all channels
What we offer
What we offer
  • 31 days off
  • 100% paid telemedicine plan
  • Home Office Setup Assistance: the company offers assistance with purchasing furniture (office chair, office desk, monitor) and other items to create a comfortable workspace
  • English learning courses
  • Relevant professional education
  • Gym or swimming pool
  • Co-working
  • Remote working
  • Stock options
  • Fulltime
Read More
Arrow Right