Our team members are the key to our company’s success, and their health and well-being, as well as that of their families, is very important to us. We offer a comprehensive benefits package that allows our team members stay healthy, plan for their future and maintain a healthy work-life balance. Benefits may vary with employment status. To see our fill list of Team Member Benefits please visit our career site: www.gotoworkhappy.com/benefits
Job Description:
At Seminole Hard Rock Support Services, we are on a mission to protect our guests, team members, and enterprise assets through world-class cybersecurity practices. As the Cybersecurity Engineer, you will implement, operate, and continuously improve the security controls that defend our systems, networks, and cloud environments across the enterprise, turning architecture and policy into running, automated, measurable defenses.
Reporting to the Manager of Cybersecurity Engineering, this role requires a hands-on, security-minded engineer who bridges the worlds of software development, cloud operations, and cybersecurity. You will configure and tune the enterprise security stack, build the integrations and automations that connect it together, and leverage AI to analyze security data at scale across Microsoft Azure (primary), Amazon Web Services, and Google Cloud.
This is a builder’s role, not an architecture role. You do not define standards from the sidelines, you take reference architectures and security requirements and make them real: deploying controls, writing production-grade automation, and instrumenting the telemetry that turns raw events into actionable insight. Your software development and architecture background lets you treat security operations as an engineering problem, and your fluency with AI and large language models lets you accelerate detection, triage, and analysis far beyond manual effort.
You will work across systems, network, and cloud security domains, partnering with architecture, IAM, infrastructure, application, and SOC teams to ensure controls are deployed consistently, operate reliably, and improve continuously across all Seminole Hard Rock business units. You measure your impact in risks reduced, incidents prevented, and manual effort eliminated through automation.
Responsibilities
Systems & Endpoint Security
- Deploy, configure, and tune endpoint and extended detection and response controls across Windows and Linux server and endpoint fleets, keeping coverage complete and policies current
- Operate identity threat detection and privileged-access protections, investigating and responding to identity-based threats
- Implement and automate certificate, PKI, secrets, and non-human / machine-identity lifecycles
- Maintain authoritative asset inventory and continuously reconcile attack-surface visibility across the environment
- Harden system configuration baselines and remediate drift in partnership with infrastructure and platform teams
Network Security
- Configure and operate secure-access service edge, secure web gateway, CASB, and DLP controls, and enterprise remote access
- Manage edge and perimeter defenses: web application firewall, DDoS mitigation, and CDN policy, and API security posture and runtime protection
- Deploy and tune network detection and response, triaging anomalous activity and feeding findings to the SOC
- Operate the enterprise browser to enforce least-privilege, isolated access to sensitive applications via an enterprise browser platform
- Apply zero-trust segmentation and least-privilege access principles consistently across the network estate
Cloud & SaaS Security
- Implement and maintain cloud-native application protection and posture management across Azure (primary), AWS, and Google Cloud, remediating misconfigurations and preventing drift
- Govern SaaS security posture and contain non-human identity sprawl across the SaaS estate
- Operate data security posture, data access governance, and data discovery and classification across cloud and on-premises stores
- Implement cloud-native guardrails, least-privilege IAM, encryption, and logging baselines in partnership with cloud engineering
- Integrate security checks into infrastructure-as-code and deployment workflows so cloud workloads are secure by default
Security Automation, AI & Detection Engineering
- Build and maintain security automations, integrations, and response playbooks across the stack using APIs and SOAR
- Engineer telemetry pipelines that route, shape, and enrich security data for cost-effective analysis, and develop and tune detections and SIEM content
- Leverage AI/ML and large language models to analyze large volumes of security data, accelerate alert triage and enrichment, surface anomalies, and automate reporting and documentation
- Develop and maintain production-grade scripts, services, and tooling (e.g., Python, PowerShell, Go) that operationalize security controls and eliminate repetitive manual work
- Instrument metrics and dashboards that make control coverage, detection efficacy, and remediation timeliness measurable
Vulnerability, Exposure & Human-Risk Defense
- Operate the vulnerability management lifecycle end-to-end: scanning, risk-based prioritization, tracking, and verification of remediation
- Coordinate penetration testing and manage findings through to closure
- Monitor external attack surface, threat exposure, and credential/brand leakage, and track third-party and vendor risk
- Operate email defenses, tuning detection and response for phishing and account-takeover threats
- Support security awareness and phishing-simulation programs with the data and integrations they need
Collaboration & Continuous Improvement
- Partner with Cybersecurity Architecture, IAM, infrastructure, application, and SOC/MSSP teams to deploy controls consistently and resolve issues quickly
- Support GRC, audit, and privacy programs by automating evidence collection and continuous control monitoring
- Document standards, runbooks, integration designs, and operating procedures so controls are repeatable and supportable
- Research, prototype, and pilot emerging tools and AI-driven capabilities that improve detection, automation, and analyst efficiency
- Participate in an on-call rotation and incident response for a 24/7 gaming and hospitality environment
Qualifications & Experience
• 5–7+ years of combined experience in cybersecurity engineering, systems / network / cloud administration, or software / platform engineering, with at least 4+ years focused on hands-on security engineering in enterprise environments
• Strong software development proficiency, with hands-on experience in Python, PowerShell, Go, or similar languages, and the ability to build custom security tooling, integrations, and automation from scratch
• Deep infrastructure and systems expertise, with hands-on experience securing and operating workloads across IaaS, PaaS, and containerized (Docker, Kubernetes) environments on Microsoft Azure (required), with working experience in AWS and/or Google Cloud, across Linux and Windows
• Practical experience applying AI/ML or large language models to security data analysis, detection, triage, or automation
• Strong working knowledge of endpoint / XDR, identity and privileged access, network security (proxies, VPN, WAF, NDR, API security), and cloud security posture management
• Solid grasp of the vulnerability management lifecycle end-to-end, plus exposure and third-party risk monitoring
• Deep networking and systems fundamentals: TCP/IP, DNS, TLS/PKI, firewalls, segmentation, and zero-trust access models
• Experience integrating security tools and data sources via API, with familiarity in SOAR and SIEM content development
• Familiarity with regulatory and compliance frameworks relevant to gaming and hospitality (PCI-DSS, SOX, tribal gaming regulations, GLBA), preferred but not required
• Relevant certifications preferred: CompTIA Security+, Microsoft SC-series or AZ-500, AWS Security Specialty, Google Professional Cloud Security Engineer, GIAC (GCIH, GCSA, GCLD), Certified Kubernetes Security Specialist (CKS), or equivalent; CISSP a plus
Professional Skills
• Translate security requirements and architecture into deployed, automated controls that operate reliably and integrate cleanly into existing systems and workflows, without creating friction
• Operate as a hands-on engineer who personally builds, configures, tests, and ships high-quality automation and integrations, measuring success in problems solved, not tickets closed
• Troubleshoot methodically across systems, network, and cloud layers, isolating root cause under time pressure during incidents
• Collaborate effectively across cross-functional teams: cybersecurity, software development, cloud and infrastructure engineering, IAM, compliance, and the SOC
• Communicate technical findings and recommendations clearly to both technical peers and non-technical stakeholders
• Thrive in an Agile, fast-paced environment that values automation, rapid iteration, and measurable security outcomes over manual process
• Demonstrate a builder’s mindset and a passion for using engineering and AI to make security faster, more consistent, and more scalable
Skills Required
- 5-7+ years of combined experience in cybersecurity engineering, systems, network, cloud administration, or software/platform engineering, including at least 4 years of hands-on security engineering
- Strong software development proficiency using Python, PowerShell, Go, or similar languages
- Hands-on experience securing IaaS, PaaS, and containerized Docker/Kubernetes environments on Microsoft Azure
- Working experience with Amazon Web Services and/or Google Cloud
- Experience operating across Linux and Windows environments
- Practical experience applying AI/ML or large language models to security analysis, detection, triage, or automation
- Strong knowledge of endpoint/XDR, identity and privileged access, network security, API security, and cloud security posture management
- Experience with vulnerability management, exposure monitoring, and third-party risk monitoring
- Knowledge of TCP/IP, DNS, TLS/PKI, firewalls, segmentation, and zero-trust access models
- Experience integrating security tools and data sources through APIs; familiarity with SOAR and SIEM content development
- Familiarity with PCI-DSS, SOX, tribal gaming regulations, and GLBA
- Relevant cybersecurity or cloud certifications, such as Security+, Microsoft SC-series or AZ-500, AWS Security Specialty, Google Professional Cloud Security Engineer, GIAC, CKS, or CISSP
Seminole Hard Rock Entertainment, Inc. Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Seminole Hard Rock Entertainment, Inc. and has not been reviewed or approved by Seminole Hard Rock Entertainment, Inc..
-
Pay Growth & Progression — The company implemented substantial wage increases across many job classifications and highlights periodic raises tied to evaluations. Feedback suggests these structural pay actions have lifted base rates for a broad segment of roles.
-
Healthcare Strength — Competitive medical, dental, and vision coverage is paired with wellness programs and tax-advantaged accounts to support team members and their families. These offerings indicate a focus on health and wellbeing beyond basic coverage.
-
Wellbeing & Lifestyle Benefits — Free shift meals, broad brand discounts, tuition reimbursement, and development programs expand total rewards beyond base pay. Weekly pay, recognition efforts, and commuter assistance at many sites further bolster everyday value.
Seminole Hard Rock Entertainment, Inc. Insights
What We Do
Seminole Hard Rock Entertainment, Inc. is a global leader in the gaming and hospitality industry, owning and operating a portfolio of luxury casino hotels and entertainment venues. The company provides a wide array of services, including world-class gambling, upscale lodging, fine dining, and premier convention spaces, focusing on delivering extraordinary guest experiences through its diverse locations and the iconic Hard Rock brand.
.png)






