Cyber Engineer III

Hard Rock Hotel and Casino
United States
28 days ago
Apply on www.jobmonkeyjobs.com
Prepare application

Role details

Contract type
Franchise
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Access Network Application Programming Interfaces (APIs) Agile Methodology Artificial Intelligence Amazon Web Services Data Analysis Proxy Servers Application Firewall Software Applications Microsoft Azure Border Gateway Protocol Cloud Computing
+48 more
Cyber Security Computer Networks Data Centers Dynamic Host Configuration Protocol DDoS Mitigation Network Address Translation Domain Name System (DNS) Data-Flow Analysis Identity and Access Management IPv6 Intrusion Detection and Prevention Virtual Private Networks (VPN) Information Systems Security Architecture Professional Python (Programming Language) Kerberos (Protocol) Network Security Network Control Networking Basics Routing Packet Analyzer Network Virtualization Open Shortest Path First (OSPF) NT LAN Manager PCI Data Security Standards Public Key Infrastructure Windows PowerShell Remote Access Technology Zero Trust Network Access Runbook Web Application Security Security Information and Event Management Systems Integration TCP/IP Data Logging Cloud-native Network Functions (CNF) Computer Networking Systems Transport Layer Security Google Cloud Load Balancing Delivery Pipeline Large Language Models Software Security Firewalls (Computer Science) Palo Alto Networks Cloudflare Open Network Automation Platform Cisco Golang

Job description

Reporting to the Manager of Cybersecurity Engineering, this role requires a hands-on, security-minded engineer who bridges the worlds of network engineering, cloud operations, and cybersecurity. You will configure and tune the enterprise network security stack - secure access service edge, perimeter and edge defenses, network detection and response, and zero-trust segmentation - and build the integrations and automations that connect it together across on-premises environments and Microsoft Azure (primary), Amazon Web Services, and Google Cloud.

This is a builder’s role, not an architecture role. You do not define standards from the sidelines; you take reference architectures and network security requirements and make them real: deploying and tuning controls, writing production-grade automation, and instrumenting the telemetry that turns raw network events into actionable insight. Your networking depth lets you treat traffic as evidence, and your fluency with AI and large language models lets you accelerate detection, triage, and analysis of network data far beyond manual effort.

You will work across campus, data center, edge, remote access, and cloud network domains, partnering with architecture, IAM, infrastructure, application, and SOC teams to ensure network controls are deployed consistently, operate reliably, and improve continuously across all Seminole Hard Rock business units. You measure your impact in risks reduced, incidents prevented, and manual effort eliminated through automation.

Responsibilities

Secure Access & Edge (SASE)

  • Deploy, configure, and tune secure-access service edge controls - secure web gateway, cloud firewall, CASB, and DLP policy - keeping coverage complete and policies current (Zscaler ZIA/ZPA)
  • Operate zero-trust network access for workforce and third parties, replacing legacy VPN patterns with identity-aware, least-privilege application access (Zscaler ZPA, GlobalProtect)
  • Operate the enterprise browser to enforce least-privilege, isolated access to sensitive applications from managed and unmanaged endpoints (Island)
  • Tune SSL/TLS inspection, tenant restrictions, and egress policy to balance security, privacy, and application compatibility - including protocols sensitive to interception such as NTLM, Kerberos, and certificate-pinned traffic
  • Manage traffic steering, forwarding, and PAC configurations so users land on the right control path from any location worldwide

Perimeter, WAF & Application Edge

  • Manage edge and perimeter defenses: web application firewall rules, DDoS mitigation, bot management, CDN and DNS policy for internet-facing properties (Cloudflare)
  • Operate API security posture and runtime protection, discovering shadow APIs and closing authentication and data-exposure gaps (Salt)
  • Administer next-generation firewall policy, NAT, and rule lifecycle across data center and property perimeters, driving rule hygiene and least-privilege access (Palo Alto Networks)
  • Harden DNS, certificate, and TLS posture at the edge in partnership with the PKI and infrastructure teams (Cloudflare, DigiCert, Keyfactor)
  • Coordinate perimeter changes with franchise, property, and vendor networks so remote sites integrate securely without breaking authentication or application flows

Network Detection, Response & Visibility

  • Deploy and tune network detection and response, triaging anomalous east-west and north-south activity and feeding high-fidelity findings to the SOC (Vectra)
  • Engineer network telemetry pipelines - flow data, DNS logs, proxy logs, firewall logs, packet metadata - that route, shape, and enrich data for cost-effective analysis (Cribl)
  • Develop and tune network-focused detections and SIEM content, mapping coverage to attacker techniques (Trellix Helix, Rapid7)
  • Investigate network-layer incidents end-to-end - from packet capture and flow analysis to proxy and firewall log correlation - isolating root cause under time pressure
  • Maintain authoritative visibility of network assets and attack surface, continuously reconciling what is connected against what is inventoried

Segmentation, Zero Trust & Cloud Networking

  • Apply zero-trust segmentation and least-privilege access principles consistently across campus, data center, gaming, and hospitality network estates
  • Design and enforce microsegmentation and network policy for sensitive zones - payment, gaming, surveillance, and OT/IoT environments - in partnership with infrastructure and compliance teams
  • Implement cloud network security guardrails across Azure (primary), AWS, and Google Cloud: virtual network design, firewalling, private connectivity, and logging baselines (Azure Firewall, NSGs, Private Link)
  • Remediate cloud network misconfigurations and exposure paths surfaced by posture management, preventing drift over time (Wiz, Microsoft Defender for Cloud)
  • Integrate network security checks into infrastructure-as-code and deployment workflows so network changes are secure by default

Network Automation, AI & Detection Engineering

  • Build and maintain network security automations, integrations, and response playbooks across the stack using APIs and SOAR (Torq)
  • Leverage AI/ML and large language models to analyze large volumes of network telemetry, accelerate alert triage and enrichment, surface anomalies, and automate reporting and documentation
  • Develop and maintain production-grade scripts, services, and tooling (e.g., Python, PowerShell, Go) that operationalize network controls and eliminate repetitive manual work
  • Automate firewall rule reviews, policy validation, and configuration compliance checks so drift is caught by pipelines, not people
  • Instrument metrics and dashboards that make network control coverage, detection efficacy, and remediation timeliness measurable

Collaboration & Continuous Improvement

  • Partner with Cybersecurity Architecture, IAM, infrastructure, application, and SOC/MSSP teams to deploy network controls consistently and resolve issues quickly
  • Support Cybersecurity Strategy & Governance, audit, and privacy programs by automating evidence collection and continuous control monitoring for network controls (Onspring, TrustArc, Microsoft Purview)
  • Document standards, runbooks, integration designs, and operating procedures so network controls are repeatable and supportable
  • Research, prototype, and pilot emerging network security tools and AI-driven capabilities that improve detection, automation, and analyst efficiency
  • Participate in an on-call rotation and incident response for a 24/7 gaming and hospitality environment

Requirements

  • 4-7+ years of combined experience in network engineering, network security engineering, or cloud networking, with at least 3+ years focused on hands-on network security engineering in enterprise environments
  • Deep network engineering expertise, with hands-on experience designing, operating, and troubleshooting enterprise networks: routing and switching, firewalls, proxies, VPN/ZTNA, load balancing, DNS, and TLS/PKI
  • Strong automation and software proficiency, with hands-on experience in Python, PowerShell, Go, or similar languages, and the ability to build custom network security tooling, integrations, and automation from scratch
  • Practical experience applying AI/ML or large language models to network data analysis, detection, triage, or automation
  • Strong working knowledge of SASE / SSE platforms (secure web gateway, ZTNA, CASB, DLP), WAF and DDoS mitigation, NDR, and API security
  • Hands-on experience securing cloud networks on Microsoft Azure (required), with working experience in AWS and/or Google Cloud: virtual network design, cloud firewalls, private connectivity, and network security posture management
  • Deep networking fundamentals: TCP/IP, BGP/OSPF, DNS, DHCP, TLS/PKI, NAT, IPv6, packet analysis, segmentation, and zero-trust access models
  • Experience integrating network security tools and data sources via API, with familiarity in SOAR playbook development and SIEM content engineering
  • Familiarity with regulatory and compliance frameworks relevant to gaming and hospitality (PCI-DSS, SOX, tribal gaming regulations, GLBA), preferred but not required
  • Relevant certifications preferred: Cisco CCNP Security, Palo Alto PCNSE, Zscaler certifications (ZDTA/ZCCP), Microsoft AZ-700 or AZ-500, AWS Advanced Networking Specialty, GIAC (GCIA, GDSA, GCLD), or equivalent; CISSP a plus

Professional Skills

  • Translate network security requirements and architecture into deployed, automated controls that operate reliably and integrate cleanly into existing networks and workflows, without creating friction
  • Operate as a hands-on engineer who personally builds, configures, tests, and ships high-quality automation and integrations, measuring success in problems solved, not tickets closed
  • Troubleshoot methodically across physical, virtual, and cloud network layers - from packet captures to policy engines - isolating root cause under time pressure during incidents
  • Collaborate effectively across cross-functional teams: cybersecurity, network and infrastructure engineering, cloud, IAM, compliance, and the SOC
  • Communicate technical findings and recommendations clearly to both technical peers and non-technical stakeholders, including property and franchise contacts
  • Thrive in an Agile, fast-paced environment that values automation, rapid iteration, and measurable security outcomes over manual process
  • Demonstrate a builder’s mindset and a passion for using engineering and AI to make network security faster, more consistent, and more scalable

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.jobmonkeyjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:08 min

Building solutions with open source GoLang infrastructure tools

Jad Wahab · LIVE

1:34 min

The pros and cons of campus-wide IP authentication

Christoph Eicke Christoph Eicke · World Congress 2025

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

6:16 min

Event-driven Golang backend architecture and cloud deployment

Irina Branovic Irina Branovic · World Congress 2026 Europe

Videos

See all

Related articles

See all