Sr. Cybersecurity Analyst, Vendor Assessment

2 months ago


Atlantic City, United States BetMGM Full time

About Us

We are BetMGM. We are revolutionizing sports betting and online gaming in the United States. We are a partnership between two powerhouse organizations-MGM Resorts International and Entain Group. You know our name through our exciting portfolio of brands including BetMGM Sportsbook, Borgata online, Party Casino and Party Poker. We aim to bring our ideas into action and find ways to deliver the best quality in gaming platforms.

We understand that each card in the deck plays a unique role in any given hand, just as our employees each play a unique role in accomplishing our goals as a company. We strive to create a culture of empathy where our employees feel valued, heard, and comfortable bringing their authentic selves to work. We want to build a product and a workplace that reflect the communities we serve so we approach our work fearlessly, take responsibility when we get it wrong, and ante-up again. We play to win, and we are all-in together.

We were recognized as one of Glassdoor's "Best Places to Work".

About the Role

BetMGM is seeking a Senior Cybersecurity Analyst in Vendor Assessment to identify, quantify, and mitigate risks to the organization from 3rd party vendor relationships, collaborating with the Cybersecurity Manager and BetMGM InfoSec team. This position is under the supervision of the Sr. Director Cyber & IT Risk.


The Sr. Analyst will show strong analytical skills, a detailed mindset, and strong communication and interpersonal skills to articulate findings of each vendor assessment to internal and external parties. This role will partner with various teams within our parent organizations (MGM and Entain) to respond to evolving business requirements and stay on top of emerging threats as it relates to onboarding and continuous monitoring of 3rd party vendor relationships. The Sr. Analyst will also leverage their expert knowledge of today's ever-changing cybersecurity landscape, technical state regulations, and risk landscape to influence the Technology acquisition process across our business.

Responsibilities

  • Conduct vendor evaluations thorough assessments of potential vendors to determine their suitability for partnership.
  • Conduct comprehensive security risk assessments of third-party vendors, evaluating their security controls, policies, standards, and infrastructure.
  • Analyze vendor capabilities, financial stability, reputation, and compliance with relevant regulations and standards.
  • Aid in the development and maintenance of comprehensive third-party risk management procedures, trackers, and documentation, aligned with industry best practices.
  • Collaborate with procurement teams to develop selection criteria and assist in vendor selection processes.
  • Help to establish and maintain key performance indicators (KPIs) and service level agreements (SLAs) for vendors.
  • Monitor vendor performance against established metrics and SLAs.
  • Identify areas for improvement and work with vendors to implement corrective actions.
  • Develop risk mitigation strategies and protocols in collaboration with internal stakeholders.
  • Conduct regular risk assessments and implement measures to minimize risk exposure.
  • Ensure that vendors comply with contractual agreements, regulatory requirements, and company policies.
  • Stay informed on relevant regulations and industry standards impacting vendor relationships.
  • Conduct audits and re-assessments to verify vendor compliance with established standards, prioritizing those with highly sensitive data.
  • Carry out application security vulnerability scanning and supply remediation options, where applicable.
  • If and only when necessary, attend third-party onsite visits in support of any part of the vendor assessment process (willingness to travel to vendors up to 10% of the time).
  • Prepare comprehensive reports and presentations summarizing vendor assessments, performance evaluations, and risk analyses.
  • Provide insights and recommendations based on data-driven analysis to support decision-making processes.
  • Communicate findings and recommendations to relevant stakeholders, including senior management and cross-functional teams.
  • Contribute to Kanban boards and/or other tracking tools to increase visibility into assigned work and promote workload efficiencies. Stay on top of latest emerging technology trends and proactively update the vendor assessment processes where needed.

Qualifications

  • 5+ years of experience with third-party vendor security assessment methodologies and security monitoring tools.
  • Proven experience in vendor management, procurement, supply chain management, or related roles.
  • Proven experience in conducting risk assessments.
  • Strong analytical skills with the ability to interpret complex data and draw actionable insights.
  • Ability to articulate identified risks to management and key stakeholders in a clear, actionable manner.
  • Excellent communication and interpersonal skills, with the ability to collaborate effectively with internal and external stakeholders.
  • Detail-oriented mindset with a focus on accuracy and precision.
  • Ability to work independently, manage multiple priorities, and meet deadlines in a fast-paced environment.
  • Knowledge of compliance, conduct, and operational risk management frameworks and processes.
  • Expertise in common technology controls for industry best practices (e.g., from NIST, ISO, ISACA, GLI etc.) frameworks.
  • Ability to collaborate with high-performing teams and individuals throughout BetMGM and externally to accomplish common goals.
  • Bachelor's or advanced degree in technology or a related field or equivalent work experience.
  • Relevant certifications (e.g., CSCP, CPIM, CISA) are a plus.
The annual salary range for this position is $89,200 to $117,075. Factors which may affect starting pay within this range may include geography/market, skills, education, experience and other qualifications of the successful candidate. This position is also eligible for participation in a performance-based bonus plan.

Gaming Compliance & Licensing Requirements

As an online gaming company, BetMGM is required to comply with state gaming regulations which includes licensing obligations. Applicable employees must be licensed by at least one jurisdictional agency, although certain positions require licensing by multiple agencies. Failure to become licensed or maintain licensure with each agency as required for the role may result in termination of employment. Please note that the licensing process includes comprehensive background checks which may include a review of criminal records, financial history, and personal background verification.

In addition, candidates must comply with and support the company's responsible gambling policies, procedures and initiatives.

About Our Culture

Building BetMGM from the ground up takes effort, energy, and teamwork, but that's what will make leading this industry all the more satisfying. We stay focused on our main goal with the help of these four company pillars:

Believe in Your Game - Take your shot There's a freedom to explore ideas usually only start-ups are lucky enough to experience.

Backed by the Best - With our expertise-merged with that of our world-class investors-we have the opportunity to take this business, and ourselves, farther than anyone has ever imagined.

Do What's Right - We operate with clarity and simplicity, always doing the right thing by our customers and each other, standing shoulder to shoulder every day.

Hustle Hard - Our combined commitment and ambition is what drives us to create some of the most innovative products in the industry.

What We Offer

As a valued employee, we're committed to giving you the resources and support you need. We offer Medical, Dental, Vision, Life Insurance, Commuter Benefits, Paid Time Off, Holidays, Employee Resource Groups and more

Applicable salary ranges may differ across markets. Actual pay will be determined based on experience and other job-related factors permitted by law. The position is also eligible for an annual bonus.

BetMGM LLC is an Equal Opportunity Employer. We provide equal employment opportunities to all qualified individuals, regardless of race, religion, gender, gender identity, age, marital status, national origin, sexual orientation, citizenship status, veteran status, disability, or any other legally protected status. As an organization, we are unwavering in our commitment to maintaining a discrimination-free work environment, and fostering a culture of inclusivity, belonging and equal opportunity for all employees and applicants.

We understand that each card in the deck plays a unique role in any given hand, just as our employees each play a unique role in accomplishing our company goals. So, we are committed to an inclusive culture for all and empowering our employees to thrive in meaningful careers. At BetMGM, we play to win, and we are "all in" together. If your experience looks a little different from what we've identified and you think you've got what it takes, we'd love to learn more about you.

If you need assistance or accommodation with your application due to a disability, you may contact us at recruitment@betmgm.com.

This job description is not an exclusive or exhaustive list of duties a person in this position may be asked to perform from time to time.


  • Cybersecurity Analyst

    4 weeks ago


    Kansas City, Missouri, United States Peraton Full time

    Cybersecurity Analyst Job DescriptionWe are seeking a highly skilled Cybersecurity Analyst to join our team at Peraton. As a Cybersecurity Analyst, you will be responsible for supporting enterprise-level hybrid cloud data center operations and enabling US Marine Corps customers to execute critical missions.Key Responsibilities:Provide technical and...


  • Oklahoma City, Oklahoma, United States MidFirst Bank Full time

    Cybersecurity Operations Analyst Job DescriptionMidFirst Bank is seeking a highly skilled Cybersecurity Operations Analyst to join our Cybersecurity Operations Team. As a Cybersecurity Operations Analyst, you will be responsible for the day-to-day administration of Okta and related services, protocols, and technologies.Key Responsibilities:Design, implement,...


  • Kansas City, Missouri, United States Peraton Full time

    Cybersecurity Technical AnalystJob Summary:Peraton is seeking a highly skilled Cybersecurity Technical Analyst to support our US Marine Corps (USMC) enterprise-level hybrid cloud data center operations. As a key member of our cybersecurity team, you will be responsible for conducting vulnerability analysis and self-assessment technical analysis, monitoring...

  • Cybersecurity Analyst

    6 months ago


    Panama City, United States ICI Services Full time

    ICI Services is looking for a motivated individual to provide cybersecurity expertise as a Cybersecurity Analyst to our US Navy client in Panama City, FL. ICI Services is an Employee-Owned Company providing Engineering & Integration, Systems Acquisition, Information Warfare, and In-Service Sustainment to US government clients. Security Clearance: *...


  • Atlantic Highlands, United States Hackensack Meridian Health Full time

    Description: Our team members are the heart of what makes us better. At Hackensack Meridian Health we help our patients live better, healthier lives and we help one another to succeed. With a culture rooted in connection and collaboration, our employees are team members. Here, competitive benefits are just the beginning. Its also about how we support one...

  • Cybersecurity Analyst

    3 weeks ago


    jersey city, United States Bamboo Crowd Full time

    Our client plays a role in the US agriculture ecosystem by supporting the financing of the farm credit system.They are undergoing a digital transformation and are looking for a Cybersecurity Analyst, partnering with the VP on this initiative. The position is located in Jersey City with a hybrid model.Responsibilities include: ingest the data from their...

  • Cybersecurity Analyst

    3 weeks ago


    Jersey City, United States Bamboo Crowd Full time

    Our client plays a role in the US agriculture ecosystem by supporting the financing of the farm credit system.They are undergoing a digital transformation and are looking for a Cybersecurity Analyst, partnering with the VP on this initiative. The position is located in Jersey City with a hybrid model.Responsibilities include: ingest the data from their...

  • Cybersecurity Analyst

    3 weeks ago


    jersey city, United States Bamboo Crowd Full time

    Our client plays a role in the US agriculture ecosystem by supporting the financing of the farm credit system.They are undergoing a digital transformation and are looking for a Cybersecurity Analyst, partnering with the VP on this initiative. The position is located in Jersey City with a hybrid model.Responsibilities include: ingest the data from their...

  • Cybersecurity Lead

    2 months ago


    new york city, United States PRI Technology Full time

    Lead Cybersecurity Analyst/PMNew York, NY (Hybrid: 3 days onsite per week)Full Time (No 3rd party resumes allowed)PRIMARY FUNCTION:The Lead Cybersecurity Analyst is responsible for leading implementation of the organization's cybersecurity controls, to implement and maintain reporting dashboards and metrics, to manage cybersecurity projects, will participate...

  • Cybersecurity Lead

    1 month ago


    new york city, United States PRI Technology Full time

    Lead Cybersecurity Analyst/PMNew York, NY (Hybrid: 3 days onsite per week)Full Time (No 3rd party resumes allowed)PRIMARY FUNCTION:The Lead Cybersecurity Analyst is responsible for leading implementation of the organization's cybersecurity controls, to implement and maintain reporting dashboards and metrics, to manage cybersecurity projects, will participate...


  • Long Island City, United States The Estee Lauder Companies Full time

    Job Title: Senior Cybersecurity AnalystDescriptionAs a Senior Cybersecurity Analyst, you will play a crucial role in driving innovation and helping the organization stay at the cutting edge of execution excellence.Cybersecurity thrives on standards, collaboration, and innovation, and you will help create the culture and environment rife for this...


  • new york city, United States Glocomms Full time

    Job Title: Senior Cyber Security Analyst (Hybrid)I am working with a leading national energy supplier seeking an experienced Senior Cyber Security Analyst to lead technical security efforts and protect sensitive data from emerging cyber threats. In this hands-on role, you'll design and implement data security measures, provide technical guidance, and improve...


  • new york city (norwood), United States Encore Technologies Full time

    Job Title: Cybersecurity Analyst IIHybridShift : 7AM – 8PM, Friday, Saturday, SundayPosition Overview:Encore Technologies is seeking a Cybersecurity Analyst II with a strong focus on security to help evolve our IT Operations Command Center (ITOCC) into a Security Operations Center (SOC). This role will be critical in maintaining our existing systems while...


  • Oklahoma City, United States Loves Travel Stops & Country Store Full time

    Req ID:446612 Benefits:* Fuel Your Growth with Love's - company funded tuition assistance program* Paid Time Off * 401(k) – 100% Match up to 5% * Medical/Dental/Vision Insurance after 30 days * Hiring Immediately * BASIC PURPOSE: The IT Contract Manager plays a key role in orchestrating and administering agreements between enterprises and technology...


  • Salt Lake City, United States USANA Health Sciences Full time

    Who We Are Looking For We are looking for an experienced individual to join the USANA’s security team as a cybersecurity GRC manager. In this position, you will be responsible for leading and managing the organization’s cybersecurity governance, risk, and compliance (GRC) programs. This role will focus on conducting cyber risk assessments,...


  • Grove City, United States Western Alliance Bank Full time

    Job Title: Senior ERM IT/IS Analyst Location: CityScape What you'll do: Western Alliance Bank Corporation is currently seeking a highly qualified and experienced Second Line of Defense Technology (IT) and Information Security (IS) Senior Analyst to join our IT/IS and TPRM risk management team in the second line of defense. The successful candidate will take...

  • ERM IT Senior Analyst

    15 hours ago


    Grove City, United States Western Alliance Bank Full time

    Job Title: ERM IT Senior Analyst Location: CityScape What you'll do: Western Alliance Bank Corporation is currently seeking a highly qualified and experienced Second Line of Defense Technology (IT) and Information Security (IS) Senior Analyst to join our IT/IS and TPRM risk management team in the second line of defense. The successful candidate will take on...


  • Culver City, United States Tucker Parker Smith Group (TPS Group) Full time

    Sr. Payroll System AnalystLocation: Culver City, CA5-Month Assignment (potential to extend / convert)Pay: $35-$44Our client, a leading multinational media and entertainment company, is seeking a Sr. Payroll System Analyst to join their team.You will manage the consistency of employee data between all related systems. In addition, this role will be...


  • culver city, United States Tucker Parker Smith Group (TPS Group) Full time

    Sr. Payroll System AnalystLocation: Culver City, CA5-Month Assignment (potential to extend / convert)Pay: $35-$44Our client, a leading multinational media and entertainment company, is seeking a Sr. Payroll System Analyst to join their team.You will manage the consistency of employee data between all related systems. In addition, this role will be...


  • Charles City, United States CFGI Full time

    About CFGI: CFGI is a unique and highly specialized financial consulting firm that is strategically positioned to assist the office of the CFO through a range of routine and complex business scenarios. As an extension of your corporate finance team, CFGI works alongside your internal staff, serving in a variety of roles from technical accounting advisor, M&A...