Architect Sr IT Security
Boyd GamingAbout the role
Company Description
Boyd Gaming Corporation has been successful in gaming jurisdiction in which we operate in the United States and is one of the premier casino entertainment companies in the United States. Never content to rest upon our successes, we will continue to evolve and retain a position of leadership in our industry.
Our past success, our current business philosophies and our sound business planning, combine to position Boyd Gaming Corporation to maximize value for our shareholders, our team members and our communities.
Job Description
Under the direction of the Director – Information Security Architecture and Operations, the Senior Information Security Architect is a talented and highly motivated individual. The security architect will lead the review and acquire an in-depth understanding of the current application landscape and technical architecture, the security issues, opportunities and value to the business. The senior architect will help drive and develop the future state enterprise architecture and application frameworks, based on the business needs of various lines of business while ensuring that the frameworks incorporate Boyd Gaming’s security goals and standards, along with any external security frameworks (such as NIST-800) as directed.
This will include documentation of principals, policies and standards, and governance process. The architect will support the various application teams in identifying the migration path from current state to the future state architecture.
- Demonstrates solid understanding of architectural considerations such as security, performance, scalability, reliability, etc.
- Utilizes deep conceptual and technological understanding of contemporary security and architecture concepts, industry trends, and best practices. Successfully leverages this knowledge to assess the organizational needs.
- Works on architecture frameworks in support of highly complex organizations with multiple business areas, geographic areas and a wide systems footprint with multiple technology
- Demonstrates ability to think objectively and outside of the box to come up with innovative solutions and simplify complexity.
- Determines and leads the implementation of security requirements by evaluating business strategies and requirements; researching information security standards; conducting system security and vulnerability analyses/risk assessment; studying architecture/platform; identifying integration issues
- Implements security systems by specifying attack vectors, methodologies and equipment; directing equipment and software installation and calibration; preparing preventive and reactive security reassures; providing technical support; completing documentation
- Will explain the reference architecture/model to various business and IT stakeholders to get buy-in as well as enable the adherence to the established security standards and policies, providing support during the migration to the reference model.
- Inform, advise and work with IT teams as well as business units on compliance with standard and policy, secure architecture, perform buy vs build analysis, evaluate new tools/applications.
- Evaluate the security and applicability of applications and technology and architecture of systems from entities acquired by Boyd Gaming and provide inputs to the secure integration of those entities.
- Enhances security team accomplishments and competence by planning delivery of solutions; answering technical and procedural questions for less experienced team members; teaching improved processes; mentoring team members.
- Coordinate third party architectural risk analyses that include threat modeling and reference the threat model to inform decisions about which controls to implement to effectively address risk.
- Perform requirements analysis and design of security features and functionality and advise product managers and software engineers during the build process.
- Collaborate with the IT Products and DevOps teams to perform requirements analysis and design security features and functionality.
- Perform manual code reviews of code that represents a material change to the way the solution performs authentication, authorization, and accounting (AAA) as well as how data is secured at rest and in transit across trust boundaries.
- Establish secure coding standards leveraging CERT Secure Coding Standards, OWASP Proactive Controls, SANS SWAT Checklist, and/or SAFECode Fundamental Practice for Secure Software Development and educate software engineers on how to securely develop code without introducing security vulnerabilities.
- Evaluate and implement tactics, technics, and procedures to programmatically evaluate code for security related bugs during the pre-commit, commit, and acceptance phases of the Continuous Integration/Continuous Delivery (CI/CD
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s