Associate Security Architect
- Hiring from
- United States
- Work type
- Hybrid
- Posted
524,705 remote jobs, straight from company career pages
100% free · New jobs every hour
Show job descriptionHide job description
Enterprise Security Architecture provides centralized security oversight, risk assessment, and pattern guidance across Caesars Entertainment. Importantly, ESA does not design business solutions — business units and solution teams own solution architecture. ESA reviews those solutions for security risk, develops reusable security patterns, and advises teams during design.
As an Associate Security Architect, you’ll be the engine behind that review-and-guidance function. You’ll support Security Architecture Reviews (SARs) and Business Impact Assessments (BIAs), help maintain the ESAF security pattern library, and grow into an advisory role under the mentorship of senior architects. This is a strong entry point into enterprise security architecture for someone with a security analyst, GRC, SOC, or solution-engineering background.
What success looks like in the first year:
Independently triages and drafts SAR review notes with minimal rework
Produces accurate BIAs and risk categorizations under light supervision
Meaningfully improves the currency and usability of the pattern library
Builds trusted working relationships with solution and infrastructure teams
Security Architecture Review (SAR) support
Intake and triage incoming review requests against SAR trigger criteria
Draft review notes: document proposed architectures, flag security gaps, and map recommended controls to ESAF patterns
Track that solution teams implement recommended controls and respond to review feedback
Sit in on threat-modeling sessions and consultations to build architectural judgment
Risk assessment support
Help conduct Business Impact Assessments (BIAs) and security risk categorization under senior review
Apply the risk-based BIA security checklists so control requirements scale appropriately to system risk
Prepare risk-assessment documentation as an input to decision-making
Governance boundary: In the ESA model, the team assesses risk but does not accept it. Risk acceptance and security exceptions are governed by the Exception Management Policy and decided by senior management / CIO. You’ll produce the assessment, not the acceptance decision.
Pattern & standards maintenance
Maintain and update ESAF security patterns, reference architectures, and control libraries across domains (AI, application, cloud, data, endpoint, GRC, IAM, infrastructure, network)
Keep documentation accurate, usable, and current — pattern quality and adoption are measured outcomes for the team
Collaboration & governance
Participate in weekly architecture reviews, monthly pattern updates, and knowledge-sharing sessions
Communicate security requirements clearly to solution teams the ESA function influences but does not control
Required
1–3 years in a security-adjacent role (security analyst, GRC, SOC, IT audit, or solution/security engineering)
Working knowledge of core security domains: IAM, network, cloud, application, and data security — breadth valued over deep single-stack specialization
Familiarity with at least one threat-modeling approach (e.g., STRIDE) or the MITRE ATT&CK framework
Awareness of regulatory frameworks relevant to gaming/hospitality: PCI-DSS, SOX, gaming commission requirements, and privacy laws (GDPR/CCPA)
Strong written communication — the role’s output is reviews, assessments, and documentation others must act on
Collaborative, diplomatic working style; comfortable influencing teams you don’t have authority over
Nice to have
Cloud security fundamentals, with AWS emphasis — the platform’s agentic/AI stack is built on Amazon Bedrock, so AWS IAM, VPC endpoints (PrivateLink), and KMS familiarity are especially valuable
Exposure to AWS Bedrock and agentic AI security — Bedrock Guardrails, Knowledge Base / RAG security, Bedrock Agents, and Bedrock AgentCore (Gateway/Runtime/Identity) with MCP servers. This is where the team’s AI security work actually lives (Bedrock-based, not Copilot-based), and it’s a currently high-demand area.
Understanding of MCP (Model Context Protocol) security concepts — agent-to-tool authentication (JWT/OAuth 2.0), tool-level access control, and centralized audit logging
GitLab CI/CD security — GitLab is the primary platform for code and pipelines across the enterprise. Familiarity with pipeline hardening, protected branches/environments and merge-request approvals, masked/protected CI/CD variables, GitLab Secret Detection and Dependency Scanning, and secrets management (HashiCorp Vault / AWS Secrets Manager) is directly applicable to the reviews this role supports.
Infrastructure-as-Code security exposure (Terraform with tfsec/checkov, encrypted/locked state) — IaC pipelines are in scope for ESA review
Security certifications (Security+, AWS/Azure security associate, or progress toward CISSP/CCSP)
Experience with SDLC/DevOps and CI/CD security integration