The attack surface is enormous. Marriott International operates across 9,700+ properties in 143 countries and territories under more than 30 brands - from budget to ultra-luxury. That means securing a sprawling, heterogeneous environment of reservation systems, loyalty databases, payment infrastructure, IoT-connected hotel operations, and guest-facing Wi-Fi networks, all while maintaining frictionless experiences for millions of guests and associates.
The company's security posture carries real historical weight. In 2018, Marriott disclosed a breach affecting up to 500 million guest records from its Starwood reservation system - a breach that had gone undetected for four years. The UK's Information Commissioner's Office fined the company £18.4 million under GDPR. That incident reshaped the organization's approach to data protection, incident response, and third-party risk, and any security team operating here does so with that context as institutional memory.
Marriott's stated culture emphasizes integrity and putting people first, which in a security context translates to protecting guest data across loyalty programs like Bonvoy, payment card environments subject to PCI DSS, and a massive workforce spanning diverse regulatory jurisdictions. The company operates a sustainability and social impact platform called Serve 360, signaling broader corporate responsibility commitments. Security practitioners joining the organization would be working across domains including identity and access management, cloud security, threat detection, vulnerability management, and compliance - scaled to one of the most distributed operational footprints in any industry.






