Manager, Security Architecture and IAM

Hard Rock Hotel and Casino
United States
1 day ago
Apply on www.jobmonkeyjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

JavaScript (Programming Language) Microsoft Azure Bash Shell Cloud Computing Cloud Engineering Software Documentation Cyber Security Computer Programming Continuous Integration Middleware Identity and Access Management IT Management
+27 more
Python (Programming Language) Node.Js PCI Data Security Standards Windows PowerShell Systems Development Life Cycle Queueing Systems Role-Based Access Control Security Information and Event Management Software Engineering Data Streaming Systems Integration Enterprise Software Applications Cloud Platform System Technical Debt AWS Lambda Git Event Driven Architecture Customer Identity Access Management Low-code Enterprise Integration Real Time Data Graphql Api Design Restful APIs Webhooks Software Version Control Devsecops

Job description

At Seminole Hard Rock Support Services, we’re on a mission to protect our guests, team members, and enterprise assets through world-class cybersecurity practices. We are seeking a Manager of Identity & Access Management (IAM) and Automation to lead two strategic and deeply interconnected functions within the Cybersecurity & IT Governance organization. This role carries dual accountability: ownership of the enterprise IAM program and leadership of a centralized automation engineering capability that designs, builds, and delivers automation and integration solutions across the entire cybersecurity organization.

This is not a tool-administrator or playbook-configuration role. The Manager will lead engineers who develop production-grade automation, building APIs, engineering system integrations, designing event-driven workflows, and delivering scalable solutions that eliminate manual processes and accelerate security outcomes enterprise-wide. The ideal candidate is a technically deep leader who has architected automation at scale, understands modern development practices, and can credibly engage both engineers and executive stakeholders.

Scope of Leadership - Two Core Streams

STREAM 1 Identity & Access Management Program

Program Strategy & Ownership

  • Own the end-to-end enterprise IAM program: vision, roadmap, governance structure, budget, and executive reporting
  • Define target-state IAM architecture and drive alignment across IT, HR, Legal, Compliance, and property leadership
  • Manage program-level risks, milestones, and escalations; present program health and posture to the Risk Committee and senior leadership
  • Ensure IAM controls and processes meet regulatory obligations including PCI-DSS, SOX, and gaming control board requirements

Identity Governance & Access Management

  • Oversee the full identity lifecycle, provisioning, modification, de-provisioning, across all enterprise systems and business lines
  • Establish and mature access governance frameworks: RBAC, segregation of duties (SoD), least privilege, and periodic access certification
  • Lead selection, implementation, and management of IAM platforms spanning identity governance and administration, enterprise directory and federation, and privileged access management
  • Drive PAM, SSO/federation, and MFA strategy across on-premise and cloud environments
  • Partner with Internal Audit and Compliance on access reviews, evidence collection, and audit readiness
STREAM 2 Automation Engineering & Integration

This stream is an engineering discipline, not a support function. The Manager leads a team of automation engineers responsible for designing and developing the integrations, pipelines, and workflows that power the cybersecurity organization. The team operates as an internal engineering practice with defined delivery standards, a product-style backlog, and accountability for uptime and quality of the solutions they build.

Automation Engineering Practice

  • Build and lead an automation engineering team that develops, maintains, and evolves automation solutions as production-grade software, with version control, peer review, testing, and documentation
  • Define the team’s operating model: intake process, backlog prioritization, sprint cadence, release standards, and SLA commitments for solution uptime and maintenance
  • Establish a shared automation platform and toolchain, selecting technologies, setting coding standards, and ensuring reuse across projects rather than one-off scripts
  • Champion API-first design and event-driven architecture principles across all automation development work
  • Report on automation engineering output: solutions delivered, manual effort eliminated, integration coverage, and backlog health

Integration Development

  • Lead the design and development of integrations between security tools, enterprise platforms (ITSM, SIEM, identity systems, HR, cloud), and third-party services, using REST APIs, GraphQL, webhooks, message queues, and middleware
  • Architect bidirectional data flows and synchronization patterns across the security toolstack to eliminate silos and enable real-time data sharing
  • Develop and maintain an integration catalog, documenting all active integrations, dependencies, data contracts, and refresh schedules
  • Evaluate and manage integration platforms, middleware, and equivalent iPaaS solutions
  • Ensure integration solutions are built with resilience in mind: error handling, retry logic, alerting, and rollback procedures

Workflow & Process Automation Development

  • Translate manual, repetitive cybersecurity processes into automated, testable, and auditable workflows, spanning orchestration, conditional logic, approvals, and notifications
  • Develop automation using a mix of low-code workflow platforms and code-first approaches (Python, PowerShell, Bash) based on complexity and maintainability requirements
  • Build event-driven automation that responds in real time to signals from security tools, identity systems, cloud environments, and ticketing platforms
  • Maintain a library of reusable automation components, connectors, and templates available to all cybersecurity teams

Engineering Standards & Governance

  • Define and enforce software development lifecycle (SDLC) standards for automation code: source control (Git), peer review, CI/CD pipelines, environment promotion (dev/test/prod), and change management
  • Ensure all automation is testable, documented, and transferable, no single points of failure or undocumented tribal knowledge
  • Establish a process for regular review and deprecation of outdated automation to prevent technical debt accumulation
  • Define and track engineering KPIs: deployment frequency, change failure rate, mean time to recovery, and automation coverage across cybersecurity processes

Requirements

  • 12+ years of experience in IT, cybersecurity, or software engineering - with at least 5 years in a senior leadership or director-level role
  • Proven ownership of an enterprise IAM program including identity governance, PAM, SSO, and access lifecycle management
  • Hands-on experience with enterprise IAM platforms: identity governance and administration, enterprise directory and federation, and privileged access management, or equivalents
  • Demonstrated experience leading an automation engineering, integration engineering, or DevSecOps function, not just administering tools
  • Strong proficiency in integration development: REST APIs, webhooks, event-driven architecture, and middleware/iPaaS platforms
  • Coding proficiency in one or more languages used in automation engineering (Python, PowerShell, JavaScript/Node.js, or similar)
  • Experience applying SDLC disciplines to automation work: source control, CI/CD, peer review, environment promotion, and documentation standards
  • Ability to architect scalable, maintainable automation solutions, not just one-off scripts
  • Excellent executive communication skills; able to articulate technical strategy and program health to risk committees and C-suite
  • Familiarity with PCI-DSS, SOX, NIST CSF, and ISO 27001, * Experience in hospitality, gaming, or entertainment with complex, multi-property IT environments
  • Background in platform engineering, shared services, or building internal developer/automation platforms
  • Relevant certifications: CISSP, CISM, CIAM, vendor certifications in identity governance platforms, or certifications in enterprise integration platforms
  • Experience with cloud-native automation and integration services (Azure Logic Apps, AWS Lambda/Step Functions, GCP Workflows)
  • Familiarity with gaming regulatory compliance requirements

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.jobmonkeyjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

2:52 min

Generating APIs with the Neo4j GraphQL library

William Lyon · LIVE

45 sec

Working securely with Node.js path application programming interfaces

Sonya Moisset · World Congress 2023

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

56 sec

Favorite git commands and the importance of patch commits

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all