Director of Information Security & Assurance
Seneca Gaming CorporationAbout the role
The Director will report directly to the CIO and provide guidance for all Information Technology Security and Assurance concerns. The Director will also have an indirect reporting relationship to the SGC Audit Committee for audit compliance services.
ESSENTIAL FUNCTIONS AND RESPONSIBILITIES:
1. Works in close partnership with VP of Information Technology / CIO to ensure coordinated and effective information security operations across all systems and platforms.
2. Works closely and collaborates with Technical Services, Systems, Network, Operations, Applications and Support teams to ensure alignment between the information security and the enterprise information technology architecture, thus coordinating the strategic planning implicit in these architectures.
3. Leads and oversees the daily operations of the information security & assurance department and develops programs and best practices on information security domains such as access control, telecommunications and network security, risk analysis and security governance, security architecture, cryptography, operational security, application security, and business continuity/disaster recovery.
4. Together with the CIO, develops, implements, and monitors, a strategic, comprehensive enterprise information security and risk management program to ensure the integrity, confidentiality and availability of information owned, controlled or processed by the organization.
5. Manages the enterprise's security organization, consisting of direct reports and indirect reports and leads all hiring, training, staff development, performance management and annual compensation reviews.
6. Identifies legal, regulatory, organizational and other requirements and provides recommendations for managing the risk of non-compliance. Identifies gaps between current and desired risk levels.
7. Develops and communicates organizational information security policies and standards.
8. Leads the development of and provides management oversight for the information security operating and capital budgets and monitors for variances.
9. Creates and manages information assurance and risk management awareness training programs for all employees and approved system users.
10. Acts as the liaison between Internal Audit, Legal, Human Resources and Compliance Departments providing leadership and oversight for audit and information assurance activities.
11. Works directly with the business units to analyze information security risks and recommends appropriate risk treatment options to manage risk to acceptable levels.
12. Provides subject matter expertise to executive management on a broad range of information security standards and best practices, such as CIS, NIST, NIGC MICS, PCI DSS, COBIT, ITIL.
13. Provides strategic and tactical security guidance for all IT projects, including the evaluation and recommendation of technical controls.
14. Creates and facilitates the information assurance risk assessment process, including reporting and oversight of remediation efforts to address negative findings.
15. Collaborates on the development of a secure information technology infrastructure that provides reliable, resilient, responsive and secure enterprise information technology services.
16. Manages security incidents and events to protect corporate IT assets, including intellectual property, fixed assets and the company's reputation.
17. Coordinates the use of external resources involved in the information assurance program, including, but not limited to, interviewing, negotiating contracts and fees, and managing externa
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s