IT Security Manager

3 weeks ago


Las Vegas, United States Affinity Gaming Full time
Job DescriptionJob Description

SUMMARY:

The IT Security Manager is responsible for developing, managing, and maintaining all aspects of the company’s cybersecurity strategy. This includes protections for data and processes associated with industry regulations and protections such as but not limited to: PCI DSS, PII, HIPAA, GDPR, CCPA and Jurisdictional Gaming Regulations/Gaming Control Board Requirements. The IT Security Manager works directly with the Director, IT Engineering & Operations to build and refine strategies to protect the organization’s data, infrastructure, and employees against cyber threats and targeted attacks, throughout a multi-state, multi-property environment. The IT Security Manager will continually identify and monitor key risk factors and report regularly to the Director, IT Engineering & Operations on the effectiveness of the company’s cybersecurity program.

ESSENTIAL DUTIES AND RESPONSIBILITIES:

  • Defines and monitors Key Performance Indicators (KPIs) and uses the KPI information to develop baselines and trends related to the effectiveness of the company’s cybersecurity program.
  • Evaluates the effectiveness of the cybersecurity tools used by the company and makes recommendations on adding/changing/upgrading to keep the cybersecurity defenses current and effective.
  • Assumes a leadership position defining the company’s cybersecurity strategy.
  • Safeguards the availability, continuity, and security of the company’s data assets and infrastructure.
  • Schedules, procures, and acts as the primary liaison for all IT Security-related audits, penetration tests, and security assessments.
  • Performs regular vulnerability scanning; identifies, classifies, and research reported vulnerabilities, develops detailed and actionable remediation plans, and works with the technical teams to ensure the issues are remediated.
  • Acts as the primary point of contact between the company and the SIEM provider; responds to, evaluates, and escalates (as necessary) when threats are reported.
  • Develops and maintains appropriate documentation, including but not limited to: Policies, Standard Operating Procedures (SOPs), Configuration Management, and Knowledge Base (KB) articles related to but not limited to: all aspects of the company’s cybersecurity program, strategies, implemented cybersecurity products, network diagrams, 3rd party integrations and solutions present within the environment, risk assessment and mitigation, incident response and recovery, and security awareness and training.
  • Assists fellow IT staff in understanding and using cybersecurity-related technologies; conducts IT staff cybersecurity technology presentations and training as required or upon request.
  • Assumes a role as an approving member of the IT Change Advisory Board (CAB); responsible for ensuring changes meet the current cybersecurity requirements of the company.
  • Defines and maintains a strategy for sustaining reliable and actionable knowledge and awareness around both current and emerging IT Security vulnerabilities, exploits, threats, risks to the organization, and secure technologies.
  • Defines and maintains a strategy to regularly evaluate new cybersecurity technologies and methodologies which provide a more effective and/or efficient method to keep the company’s data and infrastructure safe.
  • Provides guidance, direction, and assistance to operations teams in the secure implementation of new technologies, upgrades, or security enhancements by being the company’s cybersecurity Subject Matter Expert (SME).
  • Analyzes current and emerging threats and vulnerabilities; reports to the IT and Executive stakeholders quarterly on the state of the company’s cybersecurity program and if/where improvements are necessary.
  • Monitors the company’s infrastructure and in-place cybersecurity tools for critical data mishandling; defines and maintains policies and procedures to prevent data loss; manages and coordinates response to any data loss incident.
  • Demonstrates a high level of analytical and problem-solving skills/activities relying on scientific methods to develop logical and repeatable problem-solving processes as well as efficient and documented defect/issue resolution.
  • Must be able to work in a 24X7 environment and be the on-call representative for IT Security.
  • Performs other duties as may be assigned.

QUALIFICATIONS:

To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill and/or ability required. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions of this job.

  • Minimum 21 years of age
  • Must obtain a Gaming registration
  • Quick, accurate, able to handle several tasks at once, and effectively perform under pressure
  • Excellent oral and written communication skills
  • Must be certified by an agency whose certification standards are equivalent to or greater than those used by the International Association of Privacy Professionals

EDUCATION and/or EXPERIENCE:

  • Degree in Computer Science, Information Assurance, Cybersecurity, or equivalent experience in related field(s)
  • Minimum 10 years of demonstrated significant experience and knowledge in Information Technology (IT) with a minimum of 5 years specializing in/focused on Cybersecurity
  • Minimum 5 years of significant knowledge and experience in all the following areas as they relate to a company’s cybersecurity program: PCI DSS, HIPAA, ITIL, Cybersecurity Standards and Frameworks (i.e., NIST, ISO, CIS, SOC), IT Change Control, Security Awareness, Risk Management, Audits, Cyber Defense, Cyber Tools and Operation, Threat Analysis, Patch Management, Vulnerability Management and Mitigation, Penetration Testing, Assessments, Intrusion Detection, Incident Response, and Device/Application Hardening Techniques
  • Minimum 5 years of combined cybersecurity experience in all the following areas: Information Security Management, Risk Management, Compliance and Regulatory Requirements, Security Architecture and Design, Secure System Configuration and Implementation, Incident Response and Management, Security Operations, Vulnerability Management/Classification/Remediation, Identity and Access Management (IAM), Security Awareness and Training, Emerging Technologies and Threats, Vendor and Third-Party Risk Management, Business Continuity, Disaster Recovery, Critical Data Protection, Security Analysis, Data Forensics, Physical and Virtual Security Assessment, and Secure Network Engineering

  • Minimum 5 years of combined technical experience with hands-on use and administration of all the following technologies/tools: Windows Servers and Workstations, Firewalls, Web Proxies/Filtering Engines, SIEMs, Endpoint Protection/EDR, IDS/IPS, Vulnerability Scanners, Vendor Access Management, Patch Management, XDR/MDR/NDR, VPNs, IPSEC, Email Security, Data Loss Prevention (DLP), Virtualization Hypervisors
  • Minimum 5 years of experience in and fundamental understanding of the following: Active Directory (AD), DNS, DHCP, IP Addressing & Subnet Masks, TCP/UDP, HTTP/HTTPS, SSL/TLS, SSH, VPN, LDAP, SMTP, SNMP, NTP, AAA (RADIUS and/or TACACS+), IDS/IPS, Cryptography (Encryption Algorithms and Hash Algorithms)
  • Experience managing multiple projects with competing priorities
  • Minimum 3 years of experience with the following vendor-specific technologies/tools/applications: Tenable Nessus
  • Experience with the following vendor-specific technologies/hardware/tools/applications/suite of products is a plus but not required: Forcepoint, Cylance, CrowdStrike, Sophos, Vectra, Darktrace, ManageEngine, Fortinet, Cisco, Cisco Meraki, Dell, VMware, Nutanix, Citrix, AWS, Azure, Microsoft 365, Linux distros (Red Hat Enterprise, CentOS, Ubuntu)

CERTIFICATES, LICENSES, REGISTRATIONS:

  • CISSP, CEH, CISM, CISA, CompTIA Security+, GSEC, CCSP, CIPP, OSCP, GCIH, CISMS, PCIP, Nevada Gaming License/Registration, and other IT and Cybersecurity certifications are a plus

LANGUAGE SKILLS:

  • Must have proficient communication skills in English, both verbally and in written form, including electronic communication, including the ability to articulate ideas clearly and effectively, as well as to convey information accurately through written documents, emails, and other electronic means.

MATHEMATICAL SKILLS:

  • Ability to add, subtract, multiply, and divide in all units of measure, using whole numbers, common fractions, and decimals.

DISCLAIMER:

This job posting is intended to describe the general nature of this position. It is not intended to be an exhaustive list of all responsibilities, duties and skills required. Employee benefits may vary by location, position, length of service and employment status. Final candidates will be required to complete a drug test and background check. Many positions will require a state gaming license. Affinity Gaming is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, national origin, gender, age, religion, disability, sexual orientation, veteran status, or marital status.

#ZR


  • Security Technician

    2 weeks ago


    Las Vegas, United States Security 101 Full time

    Job DescriptionJob DescriptionJob Title: Security TechnicianCompany: Security 101Location: Las Vegas, NVJob Summary:Security 101 – Las Vegas is now recruiting an experienced Security technician with the ability to install and service access control, intrusion, and video systems. Take advantage of the opportunity to learn, increase your value and industry...

  • IT Security Analyst

    3 days ago


    Las Vegas, United States IT Avalon Full time

    Job Title : Security Analyst Responsibilities: Conduct regular vulnerability assessments and security audits to identify and mitigate potential risks. Implement and maintain security protocols, policies, and procedures to safeguard company assets. Monitor and respond to security incidents, ensuring a swift resolution to minimize impact. ...

  • IT Security Analyst

    1 month ago


    Las Vegas, United States IT Avalon Full time

    Monday & Friday Remote, Tuesday, Wednesday, Thursday on-site.Contract to hireJob Title : Security Analyst Responsibilities: Conduct regular vulnerability assessments and security audits to identify and mitigate potential risks. Implement and maintain security protocols, policies, and procedures to safeguard company assets. Monitor and respond to security...

  • IT Security Analyst

    1 month ago


    Las Vegas, United States IT Avalon Full time

    Monday & Friday Remote, Tuesday, Wednesday, Thursday on-site.Contract to hireJob Title : Security Analyst Responsibilities: Conduct regular vulnerability assessments and security audits to identify and mitigate potential risks. Implement and maintain security protocols, policies, and procedures to safeguard company assets. Monitor and respond to security...


  • Las Vegas, United States Marksman Security Corporation Full time

    Job DescriptionJob DescriptionNow hiring an Armed Security Officer/Guard to join our growing team! The ideal candidate will be a self-motivated professional who prides themselves in delivering top notchcustomer service while ensuring a safe and secure environment! Ideal candidates will have previous experience in corrections, law enforcement, military...


  • Las Vegas, United States All Nation Security Services, Inc. Full time

    Job DescriptionJob DescriptionEmail resume for more information. Candidates can be contacted upon interview availability.We offer set schedules!We offer all three shifts upon availability!We offer a raise after 90 days and paid sick leaveWe promote from within!Must Possess:Valid Nevada ID or Driver's LicenseValid Social Security CardMUST HAVE VALID NV...

  • Security Technician

    13 hours ago


    Las Vegas, United States Orion Security Solutions Full time

    Job DescriptionJob DescriptionSalary: Position Title: Security TechnicianOSS Headquarters: Edmond, OKLocation: Las Vegas, NVDescription:   Orion Security Solutions is seeking a qualified technical security technician for a full-time position to be based in Edmond, OK. Orion Security Solutions (OSS) is an elite integration firm with expertise in advanced...

  • Security Technician

    3 days ago


    Las Vegas, United States Orion Security Solutions Full time

    Job DescriptionJob DescriptionSalary: Position Title: Security TechnicianOSS Headquarters: Edmond, OKLocation: Las Vegas, NVDescription:   Orion Security Solutions is seeking a qualified technical security technician for a full-time position to be based in Edmond, OK. Orion Security Solutions (OSS) is an elite integration firm with expertise in advanced...


  • Las Vegas, United States Orion Security Solutions Full time

    Job DescriptionJob DescriptionSalary: Position Title: Senior Technician/Team LeaderOSS Headquarters: Edmond, OKLocation: Las Vegas, NVDescription:                  Orion Security Solutions is seeking a qualified technical security technician for a full-time position to be based in Edmond, OK. Orion Security Solutions (OSS) is an elite integration...


  • Las Vegas, United States Orion Security Solutions Full time

    Job DescriptionJob DescriptionSalary: Position Title: Senior Technician/Team LeaderOSS Headquarters: Edmond, OKLocation: Las Vegas, NVDescription:                  Orion Security Solutions is seeking a qualified technical security technician for a full-time position to be based in Edmond, OK. Orion Security Solutions (OSS) is an elite integration...


  • Las Vegas, Nevada, United States GardaWorld Security Services Full time

    Job Summary NOW HIRING GardaWorld Security is searching for bright and talented professionals who wish to share in the unique culture of our business - one where people feel inspired, encouraged, and rewarded. We are excited to announce an immediate opening in Las Vegas Now is your opportunity to join our world-class team as one of the fastest growing...


  • Las Vegas, United States Orion Security Solutions Full time

    Job DescriptionJob DescriptionSalary: Position Title: Security Sustainment TechnicianOSS Headquarters: Edmond, OKLocation:Las Vegas, NVDescription:                      Orion Security Solutions is seeking a qualified technical security technician for the role of Sustainment Technician. This is a full-time position to be based in Las...

  • Security Officer

    4 days ago


    Las Vegas, United States Allied Universal Security Full time

    Allied Universal, North America's leading security and facility services company, provides rewarding careers that give you a sense of purpose. While working in a dynamic, diverse and inclusive workplace, you will be part of a team that fuels a culture that will reflect in our communities and customers we serve. We offer medical, dental and vision coverage,...

  • Security Director

    4 days ago


    Las Vegas, Nevada, United States GardaWorld Security Services Full time

    Job Summary Job Title: Regional Director of SecurityLocation: Las Vegas, NevadaSalary: $ $110000 / yearMinimum of seven (7) years of crowd management and guest services experience at a sports/entertainment venue, with an emphasis in business management.Job Summary: Responsible for the leadership, development, and implementation of a successful guest services...


  • Las Vegas, United States St. Moritz Security Services Full time

    Essential Functions and Responsibilities The following are the duties that are necessary to satisfy the minimum requirements of the position. Other duties may be assigned on an as-needed basis. Responsible for executing security services as outlined in the Post Order Manual and accompanying policy and procedural guidelines and as directed by SMSSI...

  • Program Manager

    1 month ago


    Las Vegas, United States Transportation Security Administration Full time

    Summary Securing Travel, Protecting People - At the Transportation Security Administration, you will serve in a high-stakes environment to safeguard the American way of life. In cities across the country, you would secure airports, seaports, railroads, highways, and/or public transit systems, thus protecting America's transportation infrastructure...


  • Las Vegas, United States Redwood Private Security Full time

    On-call Security Officer Unarmed - SWING/GRAVE - OPEN AVAILABILITY ($17-$19)Description of DutiesProvide a high-visibility patrol of the assigned property/ building.Monitor access control and maintain general security of the community as described in Post Orders.Maintain a high-level of professionalism and customer service to residents/ commercial tenants/...


  • Las Vegas, United States Inter-Con Security Systems, Inc. Full time

    Job DescriptionJob DescriptionMeet with us in person and get hired on the spotInter-Con Security 9525 Hillwood Drive, Las Vegas NV9am to 4pm Various Posts in Las Vegas include working at transit stations or on a Bus.Minimum Requirements Armed OfficerEach Armed Security Officer to be assigned to the RTC account must meet or exceed, at least, oneof the...


  • North Las Vegas, United States Secured IT Solutions LLC Full time

    Our client, a large federal contractor , is seeking two (2) Cyber Security Engineer II . The first individual is required to have experience with testing of NIST SP 800-53v5 security controls. The second individual is required to have experience with installation of network switches and network taps required. Gigamon and Extreme experience...


  • Las Vegas, United States National Nuclear Security Administration Full time

    As the Manager, Nevada Field Office, you will have responsibility for: 1) the safe and secure operation of facilities under the purview of the field office; 2) support for NNSA programs to ensure their success in accordance with requirements; and 3) the long-term sustainability of the Nevada National Security Site (NNSS) to support NNSA, DOE and other...