> Markdown version of [/jobs/ext/2979994-information-security-manager](https://www.wearedevelopers.com/jobs/ext/2979994-information-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Manager - **Company:** FireKeepers Casino Hotel - **Location:** Battle Creek, MI, United States (Remote available) - **Experience:** Experienced - **Salary:** $87,464.0 - $107,141.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cloud Computing Security, CompTIA Security+, Cyber Security, Information Systems, Identity and Access Management, Information Systems Security Architecture Professional, Network Security, PCI Data Security Standards, Security Information and Event Management, Software Vulnerability Management, Data Logging, Information Technology, CIS Benchmarks, Vulnerability Analysis - **Published:** September 18, 2026 - **Apply:** https://jobs.mitalent.org/job-seeker/job-details/JobCode/409129376 ## About the Role An applicant's education, training and experience must be sufficient to demonstrate that the applicant possesses the ability to successfully perform each of the essential duties and responsibilities satisfactorily. FireKeepers reserves the right to verify the sufficiency of a candidate's education, training and competencies through the interview process, testing and methods.The requirements listed below are generally representative of the education, experience, and skills and/or abilities required to enable one to successfully perform the essential duties and responsibilities: Proficiency in both written and verbal English communication is required. Bachelor's degree in cybersecurity, information security, computer science, information technology, information systems, or a related field preferred; equivalent professional experience will be considered. Minimum of five (5) years of progressive experience in information security, cybersecurity, risk management, compliance, or related information technology disciplines. Minimum of three (3) years of experience leading security initiatives, projects, teams, or programs. Strong knowledge of cybersecurity frameworks and standards such as NIST Cybersecurity Framework (CSF), NIST 800-53, CIS Controls, ISO 27001, PCI DSS, and applicable gaming industry regulatory requirements. Knowledge of security technologies including endpoint protection, SIEM, identity and access management, network security, cloud security, and data protection solutions. GENERAL OR PREFERRED QUALIFICATIONS Bachelor's degree or above in Cybersecurity, Information Security, Information Technology, Business Administration, or a related field. Seven (7) or more years of information security or cybersecurity experience, including experience within the gaming, casino, hospitality, healthcare, or other highly regulated industries. Experience supporting or leading compliance efforts related to PCI DSS, GLI standards, SOX, HIPAA, NIST, ISO 27001, or similar regulatory and security frameworks. Experience overseeing third-party risk management, security audits, penetration testing, vulnerability assessments, and incident response activities. Proven ability to develop cybersecurity strategy, security roadmaps, and risk mitigation plans aligned with organizational objectives. Professional certifications preferred, including one or more of the following: Certified Information Systems Security Professional (CISSP); Certified Information Security Manager (CISM); Certified Information Systems Auditor (CISA); GIAC certifications; CompTIA Security+, CySA+, or CASP+. Experience presenting cybersecurity risks, metrics, and strategic initiatives to executive leadership, audit committees, and regulatory bodies. PHYSICAL & ENVIRONMENTAL DEMANDS, Bachelors Degree ## Description The following is a list of the main duties and responsibilities. However, other duties may be assigned as deemed necessary by management. All duties must be performed in accordance with Tribal, Federal, and other applicable requirements, organizational specific policies, procedures and practices. * Define and maintain the Information Security strategy and ensure it is aligned to business objectives. * Generate and maintain the IT security risk register. * Establish and enforce policies, standards, and control frameworks. * Provide executive-level reporting on security posture and risk exposure. * Participate in Service Management governance forums. * Oversee enterprise vulnerability management lifecycle. * Ensure risk-based prioritization and remediation tracking via IT Service Management solution. * Conduct regular risk assessments, including third-party risk evaluations. * Align security controls to regulatory and contractual requirements. * Participate in Change Advisory Board (CAB) to assess security impact. * Oversee penetration testing scope and remediation validation. * Ensure logging, monitoring, and detection controls are validated before service go-live. * Drive EOL system identification and migration planning. * Integrate security incidents into Incident and Major Incident processes. * Lead tabletop exercises and response simulations. * Ensure full detection coverage and event source validation. * Track and report on remediation of security findings. * Lead vendor security assessments and questionnaire processes. * Ensure security requirements are embedded in contracts and renewals. * Oversee annual cyber liability documentation and compliance activities. * Develop and maintain SOPs aligned to ITIL practices. * Provide leadership and establish training plans and competency milestones for IT Security Analysts. * Conduct ongoing gap analysis and maturity assessments. * Define KPIs and measurable improvement objectives. * Responsible for developing, implementing, and maintaining information security policies, standards, procedures, and security awareness programs. * Conduct risk assessments, vulnerability management, incident response coordination, and security compliance activities. * Communicate complex technical and security concepts to executive leadership, business stakeholders, and technical personnel.. * Manages multiple priorities while maintaining strict confidentiality regarding sensitive information. SUPERVISORY RESPONSIBILITIES:Carries out supervisory responsibilities in accordance with the organization's policies and applicable laws. Responsibilities include maintaining sufficient staffing levels; interviewing, hiring, and training Team Members; planning, assigning, and directing work; appraising performance; rewarding and disciplining Team Members; addressing complaints and resolving problems., The physical demands described here are representative of those that must be met by a Team Member to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. While performing the duties of this position, a Team Member is regularly required to talk or to ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)