Lead iSeries Compliance Analyst
The Cybersecurity iSeries Lead Compliance Analyst for Caesars is responsible for reviewing and maintaining the Cybersecurity program and strategy at a tactical and operational level for the iSeries platform to ensure that security controls are functioning efficiently and effectively, more specifically in the realm of security logging, monitoring, alert management, incident handling, vulnerability, and configuration management. Furthermore, this position supports the Cybersecurity iSeries Team in doing security research and development, and any other security-related tasks needed to support the overall requirements of the program and strategy.
The Cybersecurity iSeries Lead Compliance Analyst provides security expertise to establish and implement security-related standards, procedures, and guidelines appropriate to securing the existing iSeries environment in partnership with various properties and Information Technology.
Operational Planning & Management
The Team member will work directly as a Lead Security Matter Expert to provide in person, written and conduct overviews with the following Teams:
Gaming Control Board Representatives (all jurisdictions)
External Auditors (i.e., Deloitte and Ernest & Young)
Internal Auditors
Internal Controls and Compliance
Property Internal Auditors
Minimize user productivity loss caused by security changes
Provide the necessary support for clients to meet their security business needs
Provide detailed and effective communication to both internal team and leadership
Support install, upgrade, configuration, deployment, and administration of all iSeries security applications
Monitor all high-level users and investigate any discrepancies.
Security Risk Management
Manage the iSeries aspect of various audits; SOX, PCI, Gaming Regulatory (MICS), assessments etc. to ensure that all outstanding findings and gaps are resolved by the various properties and IT
Develop, implement, and manage security policies, standards, procedures, and guidelines in the iSeries environment
Using the Cybersecurity risk management framework, ensure that all iSeries activities (e.g., penetration testing, vulnerability threat assessments, threat modeling, security reviews and assessments, code reviews) are conducted with the utmost quality
Incident Management
Perform as the iSeries security subject matter expert for the Incident Response team and investigating any possible incidents impacting the company
Research & Development
Provide R&D and consulting support to the Cybersecurity and Engineering teams, IT and business projects as needed
Documentation, Reporting & Analytics
Contribute to the design and implementation of an operational reporting framework as it relates to the iSeries security that will provide regular metrics and statistics about our business and IT environment; analyze trends in security events, activities, etc. to better understand risks, insufficiencies in our solutions, etc.; report security metrics and statistics to the Sr Architect, Director of Engineering, CISO and other key stakeholders
Document and follow-up on security exceptions relating to IT and property activities that could negatively impact security risks and/or not adhere to established policies, standards, or procedures
Manage all SOC requirements with regards to iSeries security metrics and ensure that metrics are gathered on a daily basis
Drives and challenges the business area on their current processes and assumptions to define the best solutions for the business need
Maintains documentation of recommended process flows and work instructions for processes
Performance and Training Management
Provide training and advice to less experienced security staff and/or other non-security professionals (IT, properties, e.g.)
Self-manage career in security by leveraging available courses in-house and courses offered externally; prepare a career plan for short-term and longer-term performance management
Organizational Planning and Management
Contribute to projects with the IT and property teams and for projects internal to Cybersecurity
Interact with key business partners to drive business initiatives
Assist in the preparation of project plans and associated documentation
Basic project management skills
Ability to work independently as well as to collaborate with others
Interact with key business partners to drive business initiatives
Proven ability to maintain and enterprise-grade iSeries infrastructure
Basic project management skills
Demonstrated ability to successfully participate in multiple initiatives simultaneously
Must be 21 years of age or older (required for regulated gaming environments)
Bachelor’s degree in information security, Computer Science, Information Systems, or equivalent professional experience in IT Security or Database Administration
Ability to pass background checks, obtain and maintain gaming licenses in required jurisdictions.
Strong verbal and written English communication skills
Hands-on experience with IBM i (OS 7.3 and higher) in 24x7 production environments
10+ years of experience administering IBM i platforms
5+ years of experience installing, maintaining, and supporting IBM i security applications
Proven experience identifying and remediating IBM i security vulnerabilities in a regulated environment
Working knowledge of PCI, SOX, HIPAA, MICS, and/or Gaming Regulatory requirements
General understanding of the Integrated File System (IFS) and its security implications
Working knowledge of IBM Access Client Solutions (ACS) and IBM Client Access
Support in a multi LPAR large scale production environment
ADDITIONAL REQUIREMENTS
Fortra - PowerTech security suite experience
Trinity Guard - TGSecure security tool
CrowdStrike or similar SIEM service