Lead iSeries Compliance Analyst
About the Role
The Cybersecurity iSeries Lead Compliance Analyst is responsible for reviewing and maintaining the Cybersecurity program and strategy at a tactical and operational level for the iSeries platform. This role ensures security controls function efficiently and effectively, particularly in security logging, monitoring, alert management, incident handling, vulnerability, and configuration management. Additionally, the position supports the Cybersecurity iSeries Team in security research and development and other security-related tasks to meet program requirements. The analyst provides security expertise to establish and implement standards, procedures, and guidelines for securing the iSeries environment in partnership with various properties and Information Technology teams.
Responsibilities
- Operational Planning & Management
- Act as a Lead Security Matter Expert, providing in-person, written, and conducted overviews for:
- Gaming Control Board Representatives (all jurisdictions)
- External Auditors (e.g., Deloitte, Ernest & Young)
- Internal Auditors
- Internal Controls and Compliance teams
- Property Internal Auditors
- Minimize user productivity loss caused by security changes.
- Support clients in meeting their security business needs.
- Provide detailed and effective communication to internal teams and leadership.
- Support install, upgrade, configuration, deployment, and administration of all iSeries security applications.
- Monitor all high-level users and investigate discrepancies.
- Act as a Lead Security Matter Expert, providing in-person, written, and conducted overviews for:
- Security Risk Management
- Manage the iSeries aspect of various audits (SOX, PCI, Gaming Regulatory (MICS), assessments) to ensure resolution of findings and gaps.
- Develop, implement, and manage security policies, standards, procedures, and guidelines in the iSeries environment.
- Ensure all iSeries activities (e.g., penetration testing, vulnerability threat assessments, threat modeling, security reviews, code reviews) are conducted with high quality using the Cybersecurity risk management framework.
- Incident Management
- Serve as the iSeries security subject matter expert for the Incident Response team, investigating potential incidents impacting the company.
- Research & Development
- Provide R&D and consulting support to Cybersecurity, Engineering teams, IT, and business projects as needed.
- Documentation, Reporting & Analytics
- Contribute to designing and implementing an operational reporting framework for iSeries security, providing regular metrics and statistics about the business and IT environment.
- Analyze trends in security events to identify risks and insufficiencies in solutions.
- Report security metrics and statistics to senior stakeholders (Sr Architect, Director of Engineering, CISO).
- Document and follow up on security exceptions related to IT and property activities that may impact security risks or non-adherence to policies.
- Manage all SOC requirements regarding iSeries security metrics, ensuring daily metric collection.
- Drive and challenge business areas on current processes to define optimal solutions.
- Maintain documentation of recommended process flows and work instructions.
- Performance and Training Management
- Provide training and advice to less experienced security staff and non-security professionals (IT, properties).
- Self-manage career development in security by leveraging in-house and external courses; prepare a career plan for performance management.
- Organizational Planning and Management
- Contribute to projects with IT, property teams, and internal Cybersecurity initiatives.
- Interact with key business partners to drive business initiatives.
- Assist in preparing project plans and associated documentation.
- Demonstrate basic project management skills and the ability to work independently or collaboratively.
- Maintain an enterprise-grade iSeries infrastructure.
- Successfully participate in multiple initiatives simultaneously.
Requirements
- Must be 21 years of age or older (required for regulated gaming environments).
- Bachelor’s degree in Information Security, Computer Science, Information Systems, or equivalent professional experience in IT Security or Database Administration.
- Ability to pass background checks and obtain/maintain gaming licenses in required jurisdictions.
- Strong verbal and written English communication skills.
- Hands-on experience with IBM i (OS 7.3 and higher) in 24x7 production environments.
- 10+ years of experience administering IBM i platforms.
- 5+ years of experience installing, maintaining, and supporting IBM i security applications.
- Proven experience identifying and remediating IBM i security vulnerabilities in a regulated environment.
- Working knowledge of PCI, SOX, HIPAA, MICS, and/or Gaming Regulatory requirements.
- General understanding of the Integrated File System (IFS) and its security implications.
- Working knowledge of IBM Access Client Solutions (ACS) and IBM Client Access Support in a multi-LPAR, large-scale production environment.
Additional Requirements
- Fortra - PowerTech security suite experience.
- Trinity Guard - TGSecure security tool experience.
- CrowdStrike or similar SIEM service experience.
About Us
At Caesars Entertainment, Inc., our Team Members create the extraordinary. We are the largest casino-entertainment company in the U.S. and one of the world's most diversified casino-entertainment providers. Since our beginning in Reno, Nevada, in 1937, Caesars Entertainment has grown through development, expansions, and acquisitions. Our resorts operate primarily under the Caesars®, Harrah's®, Horseshoe®, and Eldorado® brand names. We focus on building loyalty and value with our guests through impeccable service, operational excellence, and technological leadership. The company is committed to its Team Members, suppliers, communities, and the environment through its PEOPLE PLANET PLAY framework.
Our Caesars family is driven by our Mission, Vision, and Values. We take pride in living these values – Together We Win, All In On Service, and Blaze the Trail – every day. Our mission is to Create the Extraordinary. Our vision is to Create spectacular worlds that immerse, inspire, and connect you. We don’t perform magic; we create it with excellence.