Point your AI agent at freehire and let it find you a job.

Get the CLI →

Morongo Casino Resort & Spa

NewBe an early applicant

Director - Cybersecurity

Posted Updated
Discussion

Summary

Leads the entire cybersecurity program for Morongo Casino Resort & Spa and affiliated Tribal enterprises — setting security strategy and policy, running operations like threat monitoring, incident response, and vulnerability management, and ensuring PCI DSS and Tribal Gaming compliance. A senior leadership role (8+ years security, 5+ managing teams) based on-site in Cabazon, CA.

The Director – Cybersecurity is responsible for developing, implementing, and overseeing the cybersecurity strategy for Morongo Casino Resort & Spa and affiliated Tribal enterprises. This position safeguards information systems, networks, applications, and sensitive data by establishing security standards, managing cyber risks, directing incident response activities, and ensuring compliance with applicable regulatory and organizational requirements. The Director provides leadership to the cybersecurity team and partners with executive leadership, Information Technology, Gaming, and other departments to maintain a secure and resilient technology environment.

ESSENTIAL DUTIES AND RESPONSIBILITIES:

  • Develops and maintains a comprehensive cybersecurity strategy aligned with organizational goals, operational needs, and recognized industry standards.
  • Directs cybersecurity operations, including threat monitoring, vulnerability management, security engineering, identity and access management, incident response, and data protection.
  • Establishes and maintains cybersecurity policies, standards, procedures, and controls to protect organizational systems, networks, applications, and information.
  • Identifies, evaluates, and prioritizes cybersecurity risks and recommends appropriate safeguards and corrective actions.
  • Oversees the continuous monitoring of security systems, alerts, logs, and threat intelligence to identify and address suspicious or unauthorized activity.
  • Leads the response to cybersecurity incidents, including investigation, containment, recovery, documentation, and post-incident review.
  • Develops, maintains, and regularly tests cybersecurity incident response, disaster recovery, and business continuity procedures in coordination with appropriate stakeholders.
  • Ensures compliance with applicable Tribal Gaming requirements, payment card industry standards, data privacy obligations, and internal policies.
  • Provides executive leadership with regular reports regarding cybersecurity risks, incidents, program performance, emerging threats, and recommended investments.
  • Partners with Information Technology leadership to incorporate appropriate security controls into infrastructure, systems, applications, and technology projects.
  • Reviews new technologies, system changes, and third-party solutions to identify cybersecurity risks before implementation.
  • Oversees third-party cybersecurity risk assessments and works with vendors to address identified security concerns.
  • Directs vulnerability assessments, penetration testing, security audits, and remediation activities.
  • Establishes cybersecurity awareness and training programs to promote responsible security practices throughout the organization.
  • Develops and manages the cybersecurity department budget, staffing plan, contracts, technology investments, and vendor relationships.
  • Recruits, develops, coaches, and evaluates cybersecurity team members while supporting professional growth and succession planning.
  • Maintains current knowledge of cybersecurity threats, technologies, regulations, and industry best practices.
  • Handles sensitive, confidential, and privileged information with the highest level of discretion and integrity.
  • Maintains dependable attendance and availability to respond to critical cybersecurity incidents outside regular business hours when required.
  • Performs other duties as assigned.

SUPERVISORY RESPONSIBILITIES:
This position has direct supervisory responsibilities and is accountable for the leadership, development, performance management, and daily direction of assigned cybersecurity team members.

QUALIFICATIONS:

  • Comprehensive knowledge of cybersecurity principles, frameworks, technologies, controls, and risk-management practices.
  • Strong understanding of network security, cloud security, endpoint protection, identity and access management, vulnerability management, encryption, and security monitoring.
  • Knowledge of recognized cybersecurity frameworks and standards, such as NIST, CIS Controls, ISO 27001, and PCI DSS.
  • Demonstrated experience leading cybersecurity incident response and coordinating activities across technical, operational, legal, and executive teams.
  • Ability to evaluate complex cybersecurity risks and communicate findings clearly to both technical and nontechnical audiences.
  • Strong leadership, strategic planning, project management, analytical, and decision-making skills.
  • Ability to manage multiple priorities and respond effectively in high-pressure or time-sensitive situations.
  • Demonstrates sound judgment, professionalism, confidentiality, reliability, and integrity.
  • Must be able to obtain and maintain all required licenses, certifications, and clearances.

EDUCATION and/or EXPERIENCE:

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field required.
  • Master’s degree in Cybersecurity, Information Technology, Business Administration, or a related field preferred.
  • Minimum of eight years of progressively responsible cybersecurity or information security experience required, including at least five years in a leadership or management capacity.
  • Experience within gaming, hospitality, financial services, healthcare, government, or another highly regulated environment is preferred.
  • An equivalent combination of education, training, and relevant experience may be considered.
  • Relevant professional certification, such as CISSP, CISM, CRISC, CCSP, or GIAC, is strongly preferred.

LICENSES, CERTIFICATES, REGISTRATIONS:

Must have successfully completed a background check and obtained a gaming license issued by the Morongo Gaming Agency, as required.

LANGUAGE SKILLS:

Must be able to read and interpret documents in English, such as instructions, guidelines, policies, and procedures. Must also be able to communicate clearly and effectively with team members, management, and guests.

PHYSICAL DEMANDS:

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform these functions.

  • Communication Skills: Must be able to communicate clearly and professionally in person, by phone, and in writing with IT teams, department staff, vendors, and leadership; responsible for conveying technical findings, providing security recommendations, and participating in incident response coordination.
  • Lifting and Carrying: Occasionally lifts and transports laptops, documentation, or small IT equipment weighing up to 25 pounds; physical demands are minimal and typically associated with setup or system inspections.
  • Manual Dexterity: Frequently uses hands and fingers to operate computers, configure security tools, navigate monitoring systems, and manage security controls and administrative tasks.
  • Mobility: Occasionally moves throughout office and IT areas to collaborate with team members, inspect devices, or support on-site audits and assessments.
  • Stationary Work: Frequently remains seated at a desk or security operations center (SOC) workstation for extended periods while monitoring activity, analyzing logs, or responding to cybersecurity incidents.
  • Tool Operation: Regular use of computers, cybersecurity software, intrusion detection systems (IDS/IPS), vulnerability scanners, threat intelligence platforms, and standard office technology.
  • Visual Acuity: Requires strong near vision to monitor security dashboards, analyze code, review logs and alerts, and identify potential threats or vulnerabilities with precision.
  • Working Conditions: Primarily works in a secure office or IT environment; may occasionally work in data centers or sensitive operational areas; exposure to moderate noise levels and a smoking environment when near or within casino or operational zones.

WORK ENVIRONMENT:

This is a dynamic, fast-paced environment that requires the ability to adapt and perform under pressure. The casino operates with moderate to loud noise levels and is a smoking environment, requiring team members to work comfortably in these conditions.

WORKING HOURS:

Morongo Casino Resort & Spa operates 24 hours a day, 365 days a year; therefore, flexibility in scheduling is essential. Team members must be available to work shifts that may include evenings, weekends, holidays, and special events. Schedules are subject to change based on business needs and may include overtime, as well as work on both weekdays and weekends.

EQUAL EMPLOYMENT OPPORTUNITY (EEO) AND INDIAN PREFERENCE:

Morongo Casino Resort & Spa is an Equal Opportunity Employer and gives hiring preference to qualified Native Americans as allowed by law. We consider all applicants without regard to race, color, religion, sex, sexual orientation, gender identity, age, disability, veteran status, or national origin.

We provide reasonable accommodations to qualified individuals with disabilities as required by the ADA. If you need help or an accommodation during the hiring process, please contact Human Resources.

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available