Sr. Engineer - Data Security
- Full-time
- FLSA Status: Exempt
- Division: 22700 - G&A
- Career Areas: Information Technology
- Status: Full-Time
Job Description
Role Summary
The Sr. Data Security Engineer is responsible for the technical design and maturity of the controls that enforce Wynn Resorts' data processing policies. The role reports into the Executive Director of GRC, Architecture, and Data Security, takes ownership of the tools that protect data, and operationalizes company policy for the storage, classification, movement, protection, retention, and destruction of sensitive data. The Data Security team is a specialized function within Wynn's established, global Information Security organization; it concentrates on where sensitive data resides, how it moves, how it can be accessed, and ensures it is classified, protected, retained, and defensibly deleted, while partner security teams carry broader responsibility for networks, endpoints, operations, incident response, identity, etc.
The Sr. Data Security Engineer is the senior-most hands-on technical role in the Data Security team, and is an accomplished engineer experienced in technical areas including systems engineering, development, or data management, focused on applying data protection principles using industry standards and frameworks. The ideal candidate brings experience with the platforms where enterprise data lives and grows, and will demonstrate the capability to problem-solve, operate as the top point of technical escalation, and serve as a mentor to the Data Security Engineer and Analyst.
Job Responsibilities
- Advance and mature the data security tools, developing expertise beyond vendor support across configuration, tuning, integration, and troubleshooting. As a customer to Wynn’s vendor partners, drive the vendor’s product roadmap to better serve Wynn’s security program.
- Operationalize company policy for the storage, transmission, classification, and destruction of data into working controls, procedures, guidelines, and tooling.
- Mature sensitivity labeling and DLP enforcement across unstructured and structured data, and restrict the movement of sensitive data within and outside the organization.
- Identify data repositories with excessive access, inappropriate exposure, or inadequate security controls.
- Work with data owners to remediate data-security risks.
- Implement, manage, and advance data protection, retention, and lifecycle controls, including encryption at rest and in transit, obfuscation and masking, and privileged-access restriction, in accordance with regulatory and internal standards.
- Drive and optimize technical remediation efforts to enforce compliance against company security standards (encryption, obfuscation, privileged access) for Wynn-hosted structured data. Identify patterns and root cause for non-compliance, implement technical controls to remove friction while working with other teams to achieve success.
- Restrict production data strictly to its intended environment, preventing unauthorized access to or replication in non-production areas.
- Advance the effectiveness and efficiency of the tools used to inventory structured and unstructured data sources for evaluation against Wynn's policies and standards. Improve operational efficiency of driving remediation of gaps in access, storage, encryption, obfuscation, retention, and deletion.
- Advance the effectiveness of the defensible deletion and data loss prevention (DLP) programs, supporting metrics and KPIs for evaluation by management.
- Effectively enforce minimal access to sensitive data (permissions, roles, groups, users, and NHI across applications, SaaS, file shares, NTFS, and databases) through technical controls and data-sensitivity lens.
- Build automations (scripting, workflow, and AI-enabled) that enhance the data security program, uplevel the GRC team's technical effectiveness where the two overlap on permissions, roles, and access, and fold more advanced data governance into the existing GRC program.
- Develop department metrics and improvement opportunities that feed the KPI model reported to the Executive Director and CISO, covering how much data exists, how it moves, how it is accessed, and how effectively risk is reduced.
- Support the Data Privacy team on labeling, disposition, and defensible deletion.
- Other duties as assigned.
Qualifications
- A minimum of seven (7) years of relevant work experience in systems, data, or security. A college diploma or university degree in computer or data science or IT management is preferred but is not a substitute for experience
- Strength in all of the program's technical areas (systems engineering, development and scripting, or data security) and the capability to focus on data protection, advancing the overall capabilities of the team. Hands-on experience with the platforms where enterprise data resides
- Demonstrated ability to take ownership of a tool, develop expertise specific to that tool's capabilities and Wynn's environment, and advance that tool’s effectiveness
- Hands-on experience with unstructured data storage such as NAS, SMB and CIFS shares, and cloud file-collaboration systems, including volume shadow copies, previous versions, and immutable backups, is a plus
- Hands-on experience with structured data storage and processing such as on-premises and cloud DBMS (MySQL, MSSQL, OracleDB, and similar), including table relationships and primary and foreign-key handling, is a plus
- Practical understanding of permissions, roles, groups, users, and Non-Human Identity (NHI) as they relate to authorized and unauthorized access to sensitive data across applications, SaaS, file shares, and databases
- Demonstrated capability to advance industry-standard tools for DLP, sensitivity labeling, and record identification
- Working knowledge of, or the ability to grow into, data minimization principles, supporting frameworks and control testing (SOX, Gaming Regulations, PCI-DSS), and data-residency requirements
- Ability to create, manage, and continuously improve high-quality, accurate documentation
- Understanding of project-management principles such as problem statements, use cases, and success criteria
- High level of personal integrity and the judgment and maturity to handle highly sensitive data appropriately
- A critical thinker and strong problem-solver who is detail-oriented, self-motivated, and disciplined, with excellent time-management skills. Ability to independently troubleshoot and solve technical issues and turn technical problems into proposed solutions
- Excellent written and oral communication and presentation skills for technical and business audiences
- Poise and the ability to act calmly and competently in high-pressure, high-stress situations
Additional Information
Wynn Resorts is an equal opportunity employer committed to hiring a diverse workforce and sustaining an inclusive culture. Wynn Resorts does not discriminate on the basis of disability, veteran status or any other basis protected under federal, state or local laws.
By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply