Wynn Resorts

Engineer - InfoSec GRC (Governance, Risk, and Compliance)

Wynn Resorts$90K — $120K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3-5 years of experience in cybersecurity programs, audits, and compliance management
  • Strong understanding of industry regulations like SOX, PCI-DSS, and NIST
  • Skilled in translating technical jargon for diverse audiences
  • Proficient in IT systems and architecture across multiple layers
  • Critical thinker with problem-solving abilities
  • Compliance certifications like CISA or PCI-ISA highly regarded
  • Experience in audit automation and support tools for governance processes

Responsibilities

  • Implement and enhance technical solutions for compliance with industry standards
  • Review and improve compliance audit procedures across teams
  • Maintain systems where GRC is the business stakeholder
  • Identify and recommend technical improvements to mitigate risks
  • Manage the Wynn GRC control framework's technical details
  • Conduct periodic audit reviews to optimize procedures
  • Act as the technical expert for inquiries from auditors and assessors
  • Support patch management compliance reporting and remediation efforts
  • Lead validation efforts for production changes
  • Stay updated on best practices for regulatory compliance and security
  • Train IT GRC staff across various business units
  • Develop security standards and procedures to manage risks

Benefits

  • Opportunity to work with a leading name in the gaming and hospitality industry
  • Collaborative environment with a chance to influence the GRC program
  • Access to professional development and training opportunities
  • Engagement with cross-functional teams
  • Exposure to cutting-edge security practices and compliance strategies
Full Job Description
The Engineer - InfoSec GRC (Governance, Risk, and Compliance) is the primary technical resource supporting the objectives of the GRC team for Wynn Resorts North America. This role owns and optimizes control testing procedures to be executed either by the InfoSec GRC team of analysts or various automation tools, and organizes supporting documentation including architecture diagrams, data flow diagrams, vendor documentation, etc. to demonstrate effectiveness to internal and external auditors. This role will be key in growing the technical maturity of the GRC program, reporting to the Manager - IT GRC, with general direction from the VP of Information Security and CISO and Executive Director of Information Security Engineering. The GRC team supports one of the four pillars of Information Security under the Chief Information Security Officer; the others are Architecture & Engineering, Incident Response, and Identity & Access Management. Qualifications 3 College diploma or university degree in computer science or related discipline and/or 4 years of equivalent work experience. Four(4) Years of applied work experience in cyber security programs, audits, assessments, risk, remediation, or cyber security compliance management. Job Responsibilities 3 Implements, operationalizes, and improves technical solutions to support effective and auditable compliance to applicable industry standard and regulations (SOX, PCI, MICS, NIST, HIPAA, etc.) 3 Review and continuously improve written compliance audit and due diligence procedures for execution by various technical and non-technical staff, including GRC analysts, internal auditors, and IT staff. 3 Support and maintain all systems where GRC is the business stakeholder, including tools used for audit automation, asset management, application inventory, change management, and vulnerability management. 3 Identify, evaluate, recommend, and implement technical improvements to mitigate control failures and gaps for stakeholders. 3 Own and maintain the technical details within the Wynn GRC control framework, including accurate scoping of systems and networks, technical interpretations of controls, descriptions of artifacts, etc. 3 Conducts periodic reviews of audits to optimize audit procedures and technical artifacts. 3 Operate as the technical subject matter expert to respond to inquiries from third-party assessors and auditors. 3 Collaborate with peers and management in various teams to ensure enterprise technical compliance requirements are effectively operationalized. 3 Support corporate compliance for the patch management process through reporting and technical interpretation of system vulnerabilities. Track operational remediation efforts against defined Service Level Agreements (SLAs). 3 Lead efforts to validate production changes to improve quality and accountability of system changes. 3 Remain current on best practices and technological advancements and act as a technical resource for security assessment and regulatory compliance. 3 Oversee all training for IT GRC across IT and various business units. 3 Evaluates risks and develops security standards, procedures, and controls to manage risks. Improves security positioning through process improvement, policy, automation, and the continuous evolution of capabilities. 3 Understand and enforce all applicable regulatory requirements and artifacts for control requirements, including but not limited to SOX, PCI-DSS, NIST, and jurisdictional specific Minimum Internal Control Standards (MICS). 3 Other duties as assigned. Qualifications 3 Effectively translate industry regulations, standards, and internal controls to all audience types, including non-technical stakeholders and highly technical IT engineers and architects. 3 Excellent ability to collaborate with other teams with alternative or conflicting areas of focus. 3 Working knowledge of Information technology systems at the application, data, operating system, virtualization, storage, and networking layers. 3 Knowledge of applicable information security management, governance, and compliance principles, practices, laws, rules, and regulations. 3 Researching and locating information related to internal and external organizations using online and other sources. 3 Troubleshooting and operating a computer and various software packages. 3 Defining problems, collecting, and analyzing data, establishing facts, and drawing valid conclusions. 3 Using judgment and ingenuity in maintaining objectives and technical standards. 3 Ability to apply a risk-based approach to planning, executing, and reporting on audit engagements and auditing process. 3 Comprehend technical language and to confer, analyze and write in an objective, lucid manner. 3 Work independently and prioritize multiple tasks and adapt to needed changes. 3 General ability to pull data from database tables, database views, application sources, and other data stores for the purpose of compliance reporting. 3 Poise and ability to act calmly and competently in high-pressure, high-stress situations. 3 Familiarity with state, local, federal, and gaming laws & regulations, as well as risk assessment and management methodology. 3 Must be a critical thinker with strong problem-solving skills. 3 Remain calm under high pressure/difficult situations. 3 Maintaining confidentiality. 3 Strong consideration given for compliance related certification or trainings, specifically with one or more of the following certifications or training: CISA, PCI-ISA, Splunk Searching and Reporting.

About Wynn Resorts

Wynn Resorts, Limited is a developer, owner and operator of destination casino resorts. The Company operates through two segments: Wynn Palace and Wynn Macau. Its Wynn Palace segment includes Encore at Wynn Macau resort. The Company's Wynn Macau segment includes Wynn Macau and Encore at Wynn Macau. It operates approximately two luxury hotel towers with a total of over 1,010 guest rooms, suites and villas, approximately 140 table games and over 710 slots in Wynn Palace and over 970 table games and approximately 860 slots in Wynn Macau. Its integrated resorts include accommodations, gaming, dining, entertainment and retail. The Company's Macau operations feature approximately 273,000 square feet of casino space with over 500 table games and approximately 840 slot machines. The Company also includes the Wynn Las Vegas resort, with approximately 410 table games and over 1,570 slot machines.
Learn more about Wynn Resorts
Size
26,950 employees
Market Cap
$9.6 billion
Industry
Net Income
-$2 billion
Founded
2002
5 Year Trend
-2.8%
Revenue
$2 billion
NASDAQ

Similar Jobs

More Jobs at Wynn Resorts

More Information Technology Jobs

Find similar Engineer - InfoSec GRC (Governance, Risk, and Compliance) jobs: