The Manager – IT GRC (Governance, Risk, and Compliance) is responsible for managing and maturing the Information Technology governance, risk, and compliance operations of Wynn Resorts North America through management of direct reports and collaboration with staff from Information Technology, Compliance, Legal & Privacy, and Internal Audit. Reporting to the Executive Director of Information Security, this role will be key in growing the existing compliance team into the newly restructured GRC program. The GRC team supports one of the four pillars of Information Security under the Chief Information Security Officer; the others are Architecture & Engineering, Incident Response, and Identity & Access Management.
Job Responsibilities
- Understand and enforce all applicable regulatory requirements and artifacts for control requirements, including but not limited to SOX, PCI-DSS, and jurisdictional specific Minimum Internal Control Standards (MICS).
- Act as the liaison for regulatory third-party assessors including relevant Gaming Control Boards and PCI-DSS assessors.
- Improve and maintain custom frameworks for tracking regulatory compliance requirements to audit artifacts, including defined procedures for each artifact with an associated calendar of due dates.
- Collaborate with peers and leaders across the organization to ensure enterprise compliance requirements are maintained, enforced, and operationalized.
- Improve and maintain a comprehensive policy library, tying IT procedures, guidelines, and standards to approved company policy. Manage and socialize documentation of standard operating procedures for IT.
- Improve and maintain the application inventory system as the source of record for approved business applications. Define and govern application ownership and assignment of application-specific responsibilities through written guidelines such as a RACI matrix.
- Redefine the asset classification structure. Build procedures for assets and license inventory and coordinate the activities of the asset management team to execute.
- Manage the technical risk registry and related compensating controls under guidance from Information Security leadership.
- Manage and maintain corporate compliance for the patch management process through assessment and reporting of system vulnerabilities. Track operational remediation efforts against defined Service Level Agreements (SLAs).
- Lead and optimize the weekly Production Change Request (PCR) process to improve quality and accountability of system changes.
- Lead both manual and automation efforts to ensure systems for both employee and vendors adhere to the least privilege model of role-based access.
- Oversee all training for IT GRC across IT and various business units.
- Where necessary, supervise recruitment, development, retention, and organization of system staff in accordance with corporate budgetary objectives and personnel policies.
- Develop metrics for the department and opportunities for improvement.
- Other duties as assigned.