Caesars Entertainment logo
Hiring from
United States
Work type
Hybrid
Posted
Is this job info correct?

524,705 remote jobs, straight from company career pages

100% free · New jobs every hour

Show job description

Enterprise Security Architecture provides centralized security oversight, risk assessment, and pattern guidance across Caesars Entertainment. Importantly, ESA does not design business solutions — business units and solution teams own solution architecture. ESA reviews those solutions for security risk, develops reusable security patterns, and advises teams during design.

As an Associate Security Architect, you’ll be the engine behind that review-and-guidance function. You’ll support Security Architecture Reviews (SARs) and Business Impact Assessments (BIAs), help maintain the ESAF security pattern library, and grow into an advisory role under the mentorship of senior architects. This is a strong entry point into enterprise security architecture for someone with a security analyst, GRC, SOC, or solution-engineering background.

What success looks like in the first year:

  • Independently triages and drafts SAR review notes with minimal rework

  • Produces accurate BIAs and risk categorizations under light supervision

  • Meaningfully improves the currency and usability of the pattern library

  • Builds trusted working relationships with solution and infrastructure teams

Security Architecture Review (SAR) support

  • Intake and triage incoming review requests against SAR trigger criteria

  • Draft review notes: document proposed architectures, flag security gaps, and map recommended controls to ESAF patterns

  • Track that solution teams implement recommended controls and respond to review feedback

  • Sit in on threat-modeling sessions and consultations to build architectural judgment

Risk assessment support

  • Help conduct Business Impact Assessments (BIAs) and security risk categorization under senior review

  • Apply the risk-based BIA security checklists so control requirements scale appropriately to system risk

  • Prepare risk-assessment documentation as an input to decision-making

  • Governance boundary: In the ESA model, the team assesses risk but does not accept it. Risk acceptance and security exceptions are governed by the Exception Management Policy and decided by senior management / CIO. You’ll produce the assessment, not the acceptance decision.

Pattern & standards maintenance

  • Maintain and update ESAF security patterns, reference architectures, and control libraries across domains (AI, application, cloud, data, endpoint, GRC, IAM, infrastructure, network)

  • Keep documentation accurate, usable, and current — pattern quality and adoption are measured outcomes for the team

Collaboration & governance

  • Participate in weekly architecture reviews, monthly pattern updates, and knowledge-sharing sessions

  • Communicate security requirements clearly to solution teams the ESA function influences but does not control

Required

  • 1–3 years in a security-adjacent role (security analyst, GRC, SOC, IT audit, or solution/security engineering)

  • Working knowledge of core security domains: IAM, network, cloud, application, and data security — breadth valued over deep single-stack specialization

  • Familiarity with at least one threat-modeling approach (e.g., STRIDE) or the MITRE ATT&CK framework

  • Awareness of regulatory frameworks relevant to gaming/hospitality: PCI-DSS, SOX, gaming commission requirements, and privacy laws (GDPR/CCPA)

  • Strong written communication — the role’s output is reviews, assessments, and documentation others must act on

  • Collaborative, diplomatic working style; comfortable influencing teams you don’t have authority over

Nice to have

  • Cloud security fundamentals, with AWS emphasis — the platform’s agentic/AI stack is built on Amazon Bedrock, so AWS IAM, VPC endpoints (PrivateLink), and KMS familiarity are especially valuable

  • Exposure to AWS Bedrock and agentic AI security — Bedrock Guardrails, Knowledge Base / RAG security, Bedrock Agents, and Bedrock AgentCore (Gateway/Runtime/Identity) with MCP servers. This is where the team’s AI security work actually lives (Bedrock-based, not Copilot-based), and it’s a currently high-demand area.

  • Understanding of MCP (Model Context Protocol) security concepts — agent-to-tool authentication (JWT/OAuth 2.0), tool-level access control, and centralized audit logging

  • GitLab CI/CD security — GitLab is the primary platform for code and pipelines across the enterprise. Familiarity with pipeline hardening, protected branches/environments and merge-request approvals, masked/protected CI/CD variables, GitLab Secret Detection and Dependency Scanning, and secrets management (HashiCorp Vault / AWS Secrets Manager) is directly applicable to the reviews this role supports.

  • Infrastructure-as-Code security exposure (Terraform with tfsec/checkov, encrypted/locked state) — IaC pipelines are in scope for ESA review

  • Security certifications (Security+, AWS/Azure security associate, or progress toward CISSP/CCSP)

  • Experience with SDLC/DevOps and CI/CD security integration

Similar jobs

Apply for this job