Platzhalter Bild

Director of Information Security & Assurance at Senecacasinos

Senecacasinos · Niagara Falls, United States Of America · Onsite

Apply Now
The Director of Information Security & Assurance (ISA) is responsible for establishing and maintaining an enterprise-wide information security program to support the confidentiality, integrity and availability of Seneca Gaming Corporation’s information assets. The Director of ISA collaborates and consults with IT management and business units to develop appropriate security controls. The Director leads the development of information security policies, procedures, and best practices and works with internal and external teams to implement and promote compliance with those procedures, best practices and/or regulatory compliance requirements. The Director of ISA is responsible for the development of an information security & assurance strategy within the context of a risk-based approach. This position is responsible for identifying, evaluating and reporting on information security risks in a manner that meets compliance and regulatory requirements. This position requires a visionary leader with strong leadership skills, business acumen and technology. The Director of ISA will work proactively with business units to implement practices that meet defined policies and standards for information security lead IT risk management activities.
The Director will report directly to the CIO and provide guidance for all Information Technology Security and Assurance concerns. The Director will also have an indirect reporting relationship to the SGC Audit Committee for audit compliance services.

ESSENTIAL FUNCTIONS AND RESPONSIBILITIES:
1.    Works in close partnership with VP of Information Technology / CIO to ensure coordinated and effective information security operations across all systems and platforms. 
2.    Works closely and collaborates with Technical Services, Systems, Network, Operations, Applications and Support teams to ensure alignment between the information security and the enterprise information technology architecture, thus coordinating the strategic planning implicit in these architectures. 
3.    Leads and oversees the daily operations of   the information security & assurance department and develops programs and best practices on information security domains such as access control, telecommunications and network security, risk analysis and security governance, security architecture, cryptography, operational security, application security, and business continuity/disaster recovery. 
4.    Together with the CIO, develops, implements, and monitors, a strategic, comprehensive enterprise information security and risk management program to ensure the integrity, confidentiality and availability of information owned, controlled or processed by the organization.
5.    Manages the enterprise's security organization, consisting of direct reports and indirect reports and leads all hiring, training, staff development, performance management and annual compensation reviews.
6.    Identifies legal, regulatory, organizational and other requirements and provides recommendations for managing the risk of non-compliance.  Identifies gaps between current and desired risk levels.
7.    Develops and communicates organizational information security policies and standards.
8.    Leads the development of and provides management oversight for the information security operating and capital budgets and monitors for variances. 
9.    Creates and manages information assurance and risk management awareness training programs for all employees and approved system users. 
10.    Acts as the liaison between Internal Audit, Legal, Human Resources and Compliance Departments providing leadership and oversight for audit and information assurance activities.
11.    Works directly with the business units to analyze information security risks and recommends appropriate risk treatment options to manage risk to acceptable levels.
12.    Provides subject matter expertise to executive management on a broad range of information security standards and best practices, such as CIS, NIST, NIGC MICS, PCI DSS, COBIT, ITIL. 
13.    Provides strategic and tactical security guidance for all IT projects, including the evaluation and recommendation of technical controls. 
14.    Creates and facilitates the information assurance risk assessment process, including reporting and oversight of remediation efforts to address negative findings. 
15.    Collaborates on the development of a secure information technology infrastructure that provides reliable, resilient, responsive and secure enterprise information technology services.
16.    Manages security incidents and events to protect corporate IT assets, including intellectual property, fixed assets and the company's reputation. 
17.    Coordinates the use of external resources involved in the information assurance program, including, but not limited to, interviewing, negotiating contracts and fees, and managing external resources. 
18.    Assists in the development of effective disaster recovery policies and procedures. 
19.    Develops business-relevant metrics to measure the efficiency and effectiveness of the program, facilitate appropriate resource allocation and increase the maturity of the security program.  

QUALIFICATIONS/REQUIREMENTS: 

Education/Experience:
1.    Must be 18 years of age or older upon employment.
2.    Bachelor’s Degree in an Information Technology related field.
3.    Minimum of ten (10) years of experience in an Information Technology management role with a combination of information technology and demonstrable information security and assurance responsibilities.
4.    Minimum of five (5) years in Information Technology project management, systems design and integration and experience leading project teams using formal project management methodologies 
5.    A level of pertinent security/risk-focused certification, e.g. Security+, CISSP, CISM, CISA, CRISC.
6.    An equivalent combination of education and/or experience may be substituted for the above requirements.
7.    A deep understanding of and extensive experience with implementing network operating systems, systems design and enterprise architecture, systems development lifecycle (SDLC), project management methodology, asset management, access control systems, network communication protocols and topology, security engineering, public key infrastructure and identity and access management concepts.
8.    Experience with security/risk-specific program/program component development, e.g. information security governance & continuous improvement, security awareness, vulnerability management, data protection, endpoint protection, identity & access management, cryptography & key management, business continuity/disaster recovery, incident response.
9.    Direct experience with IT-based audit processes.
10.    Excellent written and verbal communication skills; interpersonal and collaborative skills; and the ability to communicate security and risk-related concepts to technical and nontechnical audiences.
11.    Must be a critical thinker with strong problem-solving skills.
12.    Knowledge of technological trends and developments in the area of information assurance and risk management.
13.    Ability to lead and motivate cross-functional, interdisciplinary teams to achieve tactical and strategic goals.
14.    Knowledge of security and control frameworks, such as CIS, NIST, NIGC MICS, PCI DSS, COBIT, and ITIL.
15.    Experience with contract and vendor negotiations. 
16.    High level of personal integrity and ethical standards and the ability to professionally handle confidential matters and exemplify the appropriate level of judgment and maturity.
17.    High degree of initiative, dependability and ability to work with little supervision.
18.    Must possess and maintain a valid driver’s license and be able to substantiate a safe driving record within the parameters acceptable to our liability insurance carrier.

Language Skills and Reasoning Ability:
1.    Must possess excellent communication skills: listening, writing, speaking, and interpersonal skills. 
2.    Must have the ability to speak effectively to the public, employees, customers and vendors.
3.    Must have the ability to deal effectively and interact well with the customers, vendors and employees.
4.    Must have the ability to resolve problems/conflicts in a diplomatic and tactful manner.

Physical Requirements and Work Environment:
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job.  Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.  The noise level in the work environment is usually moderately loud. When on the casino floor, the noise levels increase to loud.  Must be able to work in an environment where smoking is permitted.
1.    Must be able to stand, walk, and move through all areas of the casino.
2.    Maintain physical stamina and proper mental attitude to work under pressure in a fast-paced, casino environment and effectively deal with customers, management, employees, and members of the business community in all situations.
 

Salary Starting Rate:

$143,936.95

Compensation is negotiable based on experience and education.
 

Each position has varying minimum qualifications. In the absence of fully qualified candidates, some requirements may be waived.

Apply Now

Other home office and work from home jobs