Information Security Manager

FireKeepers Casino Hotel

$87K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in cybersecurity, information security, computer science, or related field preferred; equivalent experience acceptable.
  • 5-7 years of progressive information security or cybersecurity experience in a related field.
  • 3+ years of experience leading security initiatives or projects.
  • Strong knowledge of cybersecurity frameworks like NIST, ISO, PCI DSS, and gaming industry regulations.
  • Experience with security technologies, including SIEM and endpoint protection.

Responsibilities

  • Define and maintain the organization's Information Security strategy.
  • Generate and maintain an IT security risk register.
  • Establish and enforce security policies, standards, and frameworks.
  • Provide executive-level reporting on security posture and risk exposure.
  • Conduct regular risk assessments and oversee vulnerability management lifecycle.

Benefits

  • Health, dental, and vision insurance options available.
  • 401(k) retirement plan with employer contributions.
  • Generous paid time off and holiday leave policies.
  • Opportunities for professional development and training.
  • Collaborative work environment fostering teamwork and innovation.
Full Job Description
Description

This position is on-site and does not offer remote work options.

At this time, we do not sponsor employment visas for this position. Candidates must be authorized to work in the United States without sponsorship.

PAY: Starting at $87,464.00 per year, with opportunities for annual increases.

REPORTS TO:

Chief Information Officer

SCOPE OF POSITION:

Responsible for the governance, integration, and continual improvement of the Information Security Management practice within our ITIL-aligned environment.

ESSENTIAL DUTIES AND RESPONSIBILITIES:

The following is a list of the main duties and responsibilities. However, other duties may be assigned as deemed necessary by management. All duties must be performed in accordance with Tribal, Federal, and other applicable requirements, organizational specific policies, procedures and practices.
  • Define and maintain the Information Security strategy and ensure it is aligned to business objectives.
  • Generate and maintain the IT security risk register.
  • Establish and enforce policies, standards, and control frameworks.
  • Provide executive-level reporting on security posture and risk exposure.
  • Participate in Service Management governance forums.
  • Oversee enterprise vulnerability management lifecycle.
  • Ensure risk-based prioritization and remediation tracking via IT Service Management solution.
  • Conduct regular risk assessments, including third-party risk evaluations.
  • Align security controls to regulatory and contractual requirements.
  • Participate in Change Advisory Board (CAB) to assess security impact.
  • Oversee penetration testing scope and remediation validation.
  • Ensure logging, monitoring, and detection controls are validated before service go-live.
  • Drive EOL system identification and migration planning.
  • Integrate security incidents into Incident and Major Incident processes.
  • Lead tabletop exercises and response simulations.
  • Ensure full detection coverage and event source validation.
  • Track and report on remediation of security findings.
  • Lead vendor security assessments and questionnaire processes.
  • Ensure security requirements are embedded in contracts and renewals.
  • Oversee annual cyber liability documentation and compliance activities.
  • Develop and maintain SOPs aligned to ITIL practices.
  • Provide leadership and establish training plans and competency milestones for IT Security Analysts.
  • Conduct ongoing gap analysis and maturity assessments.
  • Define KPIs and measurable improvement objectives.
  • Responsible for developing, implementing, and maintaining information security policies, standards, procedures, and security awareness programs.
  • Conduct risk assessments, vulnerability management, incident response coordination, and security compliance activities.
  • Communicate complex technical and security concepts to executive leadership, business stakeholders, and technical personnel..
  • Manages multiple priorities while maintaining strict confidentiality regarding sensitive information.


SUPERVISORY RESPONSIBILITIES:Carries out supervisory responsibilities in accordance with the organization's policies and applicable laws. Responsibilities include maintaining sufficient staffing levels; interviewing, hiring, and training Team Members; planning, assigning, and directing work; appraising performance; rewarding and disciplining Team Members; addressing complaints and resolving problems.

MINIMUM REQUIRED QUALIFICATIONS

An applicant's education, training and experience must be sufficient to demonstrate that the applicant possesses the ability to successfully perform each of the essential duties and responsibilities satisfactorily. FireKeepers reserves the right to verify the sufficiency of a candidate's education, training and competencies through the interview process, testing and methods.The requirements listed below are generally representative of the education, experience, and skills and/or abilities required to enable one to successfully perform the essential duties and responsibilities:

Proficiency in both written and verbal English communication is required.

Bachelor's degree in cybersecurity, information security, computer science, information technology, information systems, or a related field preferred; equivalent professional experience will be considered. Minimum of five (5) years of progressive experience in information security, cybersecurity, risk management, compliance, or related information technology disciplines. Minimum of three (3) years of experience leading security initiatives, projects, teams, or programs. Strong knowledge of cybersecurity frameworks and standards such as NIST Cybersecurity Framework (CSF), NIST 800-53, CIS Controls, ISO 27001, PCI DSS, and applicable gaming industry regulatory requirements. Knowledge of security technologies including endpoint protection, SIEM, identity and access management, network security, cloud security, and data protection solutions.

GENERAL OR PREFERRED QUALIFICATIONS

Bachelor's degree or above in Cybersecurity, Information Security, Information Technology, Business Administration, or a related field. Seven (7) or more years of information security or cybersecurity experience, including experience within the gaming, casino, hospitality, healthcare, or other highly regulated industries. Experience supporting or leading compliance efforts related to PCI DSS, GLI standards, SOX, HIPAA, NIST, ISO 27001, or similar regulatory and security frameworks. Experience overseeing third-party risk management, security audits, penetration testing, vulnerability assessments, and incident response activities. Proven ability to develop cybersecurity strategy, security roadmaps, and risk mitigation plans aligned with organizational objectives. Professional certifications preferred, including one or more of the following: Certified Information Systems Security Professional (CISSP); Certified Information Security Manager (CISM); Certified Information Systems Auditor (CISA); GIAC certifications; CompTIA Security+, CySA+, or CASP+. Experience presenting cybersecurity risks, metrics, and strategic initiatives to executive leadership, audit committees, and regulatory bodies.

PHYSICAL & ENVIRONMENTAL DEMANDS:

The physical demands described here are representative of those that must be met by a Team Member to successfully perform the essential functions of this job.

Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

While performing the duties of this position, a Team Member is regularly required to talk or to hear. The Team Member is also regularly required to stand, walk, sit, and use hands to handle or feel objects, tools or controls. A Team Member is occasionally required to reach with hands and arms, and to sit; climb or balance; and stoop, kneel, crouch or crawl. Specific vision abilities required by this job include close vision, distance vision, color vision, peripheral vision, depth perception and the ability to adjust focus.

Work is performed throughout all areas of the facility where the noise level varies from quiet to loud depending upon business.

INDIAN PREFERENCE

Indian preference will be applied in the selection of qualified applicants in accordance with the NHBP Indian Preference in Employment Code, which affords employment preferences to NHBP Tribal citizens, parents or spouses of NHBP citizens and other Native Americans. For purposes of this preference, NHBP law defines "Native American" as: (a) an enrolled member of any other federally-recognized Indian tribes; (b) an enrolled member of a Canadian Indian tribe or First Nation; or (c) an enrolled member of the Grand River Band of Ottawa Indians or the Burt Lake Band of Ottawa/Chippewa Indians.

FireKeepers Casino Hotel reserves the right to make changes to the above job description as necessary.

Similar Jobs

More Information Technology Jobs

Find similar Information Security Manager jobs: