Lead iSeries Compliance Analyst
About Us
At Caesars Entertainment, Inc., our Team Members create the extraordinary. We are the largest casino-entertainment company in the U.S. and one of the world's most diversified casino-entertainment providers. Since beginning in Reno, Nevada, in 1937, Caesars Entertainment has grown through the development of new resorts, expansions and acquisitions. Our resorts operate primarily under the Caesars®, Harrah's®, Horseshoe® and Eldorado® brand names. We focus on building loyalty and value with our guests through a combination of impeccable service, operational excellence and technological leadership. The company is committed to its Team Members, suppliers, communities and the environment through its PEOPLE PLANET PLAY framework.
Our Caesars family is driven by our Mission, Vision and Values. We take great pride in living these values – Together We Win, All In On Service and Blaze the Trail – every day. Our mission is to “Create the Extraordinary”. Our vision is to “Create spectacular worlds that immerse, inspire and connect you. We don’t perform magic; we create it with excellence.”
Responsibilities
Operational Planning & Management
- Work directly as a Lead Security Matter Expert to provide in-person, written, and overview support to the following teams:
- Gaming Control Board Representatives (all jurisdictions)
- External Auditors (e.g., Deloitte and Ernest & Young)
- Internal Auditors
- Internal Controls and Compliance
- Property Internal Auditors
- Minimize user productivity loss caused by security changes.
- Provide necessary support for clients to meet their security business needs.
- Deliver detailed and effective communication to both internal team and leadership.
- Support install, upgrade, configuration, deployment, and administration of all iSeries security applications.
- Monitor all high-level users and investigate any discrepancies.
Security Risk Management
- Manage the iSeries aspect of various audits (SOX, PCI, Gaming Regulatory (MICS), assessments) to ensure all outstanding findings and gaps are resolved by properties and IT.
- Develop, implement, and manage security policies, standards, procedures, and guidelines in the iSeries environment.
- Using the Cybersecurity risk management framework, ensure all iSeries activities (e.g., penetration testing, vulnerability threat assessments, threat modeling, security reviews and assessments, code reviews) are conducted with the utmost quality.
Incident Management
- Serve as the iSeries security subject matter expert for the Incident Response team and investigate any possible incidents impacting the company.
Research & Development
- Provide R&D and consulting support to the Cybersecurity and Engineering teams, IT, and business projects as needed.
Documentation, Reporting & Analytics
- Contribute to the design and implementation of an operational reporting framework for iSeries security, providing regular metrics and statistics about the business and IT environment.
- Analyze trends in security events and activities to better understand risks and insufficiencies in solutions.
- Report security metrics and statistics to the Sr Architect, Director of Engineering, CISO, and other key stakeholders.
- Document and follow up on security exceptions relating to IT and property activities that could negatively impact security risks or non-adherence to policies, standards, or procedures.
- Manage all SOC requirements regarding iSeries security metrics and ensure metrics are gathered daily.
- Drive and challenge business areas on their current processes and assumptions to define the best solutions.
- Maintain documentation of recommended process flows and work instructions.
Performance and Training Management
- Provide training and advice to less experienced security staff and/or other non-security professionals (IT, properties).
- Self-manage career in security by leveraging available in-house and external courses; prepare a career plan for short-term and longer-term performance management.
Organizational Planning and Management
- Contribute to projects with IT, property teams, and internal Cybersecurity projects.
- Interact with key business partners to drive business initiatives.
- Assist in the preparation of project plans and associated documentation.
- Demonstrate basic project management skills and ability to work independently as well as collaborate with others.
- Proven ability to maintain an enterprise-grade iSeries infrastructure.
- Demonstrated ability to successfully participate in multiple initiatives simultaneously.
Requirements
- Must be 21 years of age or older (required for regulated gaming environments).
- Bachelor’s degree in Information Security, Computer Science, Information Systems, or equivalent professional experience in IT Security or Database Administration.
- Ability to pass background checks and obtain and maintain gaming licenses in required jurisdictions.
- Strong verbal and written English communication skills.
- Hands-on experience with IBM i (OS 7.3 and higher) in 24x7 production environments.
- 10+ years of experience administering IBM i platforms.
- 5+ years of experience installing, maintaining, and supporting IBM i security applications.
- Proven experience identifying and remediating IBM i security vulnerabilities in a regulated environment.
- Working knowledge of PCI, SOX, HIPAA, MICS, and/or Gaming Regulatory requirements.
- General understanding of the Integrated File System (IFS) and its security implications.
- Working knowledge of IBM Access Client Solutions (ACS) and IBM Client Access Support in a multi-LPAR large-scale production environment.
Additional Requirements
- Fortra - PowerTech security suite experience.
- Trinity Guard - TGSecure security tool experience.
- CrowdStrike or similar SIEM service experience.