Manager, Security Architecture and IAM at Hard Rock Hotel & Casino Ottawa | Alfred, NY, US | Rezi

Manager, Security Architecture and IAM at Hard Rock Hotel & Casino Ottawa

Manager, Security Architecture and IAM

Hard Rock Hotel & Casino Ottawa · Alfred, NY, US

2 weeks ago

Manager, Security Architecture and IAM

Hard Rock Hotel & Casino Ottawa · Alfred, NY, US

20 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Manager, Security Architecture and IAM role.

Rezi rewrites your resume against Hard Rock Hotel & Casino Ottawa's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Manager, Security Architecture and IAM posting at Hard Rock Hotel & Casino Ottawa — free, in seconds.

About the Role

We are seeking a Manager of Identity & Access Management (IAM) and Automation to lead two strategic and deeply interconnected functions within the Cybersecurity & IT Governance organization. This role carries dual accountability: ownership of the enterprise IAM program and leadership of a centralized automation engineering capability that designs, builds, and delivers automation and integration solutions across the entire cybersecurity organization.

Responsibilities

  • Own the end-to-end enterprise IAM program: vision, roadmap, governance structure, budget, and executive reporting
  • Define target-state IAM architecture and drive alignment across IT, HR, Legal, Compliance, and property leadership
  • Manage program-level risks, milestones, and escalations; present program health and posture to the Risk Committee and senior leadership
  • Ensure IAM controls and processes meet regulatory obligations including PCI-DSS, SOX, and gaming control board requirements
  • Oversee the full identity lifecycle, provisioning, modification, de-provisioning, across all enterprise systems and business lines
  • Establish and mature access governance frameworks: RBAC, segregation of duties (SoD), least privilege, and periodic access certification
  • Lead selection, implementation, and management of IAM platforms spanning identity governance and administration, enterprise directory and federation, and privileged access management
  • Drive PAM, SSO/federation, and MFA strategy across on-premise and cloud environments
  • Partner with Internal Audit and Compliance on access reviews, evidence collection, and audit readiness
  • Build and lead an automation engineering team that develops, maintains, and evolves automation solutions as production-grade software, with version control, peer review, testing, and documentation
  • Define the team's operating model: intake process, backlog prioritization, sprint cadence, release standards, and SLA commitments for solution uptime and maintenance
  • Establish a shared automation platform and toolchain, selecting technologies, setting coding standards, and ensuring reuse across projects rather than one-off scripts
  • Champion API-first design and event-driven architecture principles across all automation development work
  • Report on automation engineering output: solutions delivered, manual effort eliminated, integration coverage, and backlog health
  • Lead the design and development of integrations between security tools, enterprise platforms (ITSM, SIEM, identity systems, HR, cloud), and third-party services, using REST APIs, GraphQL, webhooks, message queues, and middleware
  • Architect bidirectional data flows and synchronization patterns across the security toolstack to eliminate silos and enable real-time data sharing
  • Develop and maintain an integration catalog, documenting all active integrations, dependencies, data contracts, and refresh schedules
  • Evaluate and manage integration platforms, middleware, and equivalent iPaaS solutions
  • Ensure integration solutions are built with resilience in mind: error handling, retry logic, alerting, and rollback procedures
  • Translate manual, repetitive cybersecurity processes into automated, testable, and auditable workflows, spanning orchestration, conditional logic, approvals, and notifications
  • Develop automation using a mix of low-code workflow platforms and code-first approaches (Python, PowerShell, Bash) based on complexity and maintainability requirements
  • Build event-driven automation that responds in real time to signals from security tools, identity systems, cloud environments, and ticketing platforms
  • Maintain a library of reusable automation components, connectors, and templates available to all cybersecurity teams
  • Define and enforce software development lifecycle (SDLC) standards for automation code: source control (Git), peer review, CI/CD pipelines, environment promotion (dev/test/prod), and change management
  • Ensure all automation is testable, documented, and transferable, no single points of failure or undocumented tribal knowledge
  • Establish a process for regular review and deprecation of outdated automation to prevent technical debt accumulation
  • Define and track engineering KPIs: deployment frequency, change failure rate, mean time to recovery, and automation coverage across cybersecurity processes

Requirements

  • 12+ years of experience in IT, cybersecurity, or software engineering
  • At least 5 years in a senior leadership or director-level role
  • Proven ownership of an enterprise IAM program including identity governance, PAM, SSO, and access lifecycle management
  • Hands-on experience with enterprise IAM platforms: identity governance and administration, enterprise directory and federation, and privileged access management, or equivalents
  • Demonstrated experience leading an automation engineering, integration engineering, or DevSecOps function, not just administering tools
  • Strong proficiency in integration development: REST APIs, webhooks, event-driven architecture, and middleware/iPaaS platforms
  • Coding proficiency in one or more languages used in automation engineering (Python, PowerShell, JavaScript/Node.js, or similar)
  • Experience applying SDLC disciplines to automation work: source control, CI/CD, peer review, environment promotion, and documentation standards
  • Ability to architect scalable, maintainable automation solutions, not just one-off scripts
  • Excellent executive communication skills; able to articulate technical strategy and program health to risk committees and C-suite
  • Familiarity with PCI-DSS, SOX, NIST CSF, and ISO 27001
  • Experience in hospitality, gaming, or entertainment with complex, multi-property IT environments
  • Background in platform engineering, shared services, or building internal developer/automation platforms
  • Relevant certifications: CISSP, CISM, CIAM, vendor certifications in identity governance platforms, or certifications in enterprise integration platforms
  • Experience with cloud-native automation and integration services (Azure Logic Apps, AWS Lambda/Step Functions, GCP Workflows)
  • Familiarity with gaming regulatory compliance requirements

Skills

  • Identity & Access Management (IAM)
  • Automation Engineering
  • Cybersecurity
  • IT Governance
  • API Development
  • System Integrations
  • Event-driven Workflows
  • Scalable Solutions
  • Modern Development Practices
  • Identity Governance
  • Privileged Access Management (PAM)
  • Single Sign-On (SSO)
  • Multi-Factor Authentication (MFA)
  • REST APIs
  • GraphQL
  • Webhooks
  • Message Queues
  • Middleware
  • iPaaS
  • Low-code workflow platforms
  • Python
  • PowerShell
  • Bash
  • Software Development Lifecycle (SDLC)
  • Source Control (Git)
  • CI/CD
  • Peer Review
  • Environment Promotion
  • Change Management
  • NIST CSF
  • ISO 27001
  • Cloud-native automation
  • Azure Logic Apps
  • AWS Lambda/Step Functions
  • GCP Workflows

Experience Level

  • Senior leadership
  • Director-level

Benefits

  • Comprehensive benefits package
  • Health and well-being support
  • Future planning resources
  • Work-life balance support

About the Company

  • At Seminole Hard Rock Support Services, we’re on a mission to protect our guests, team members, and enterprise assets through world-class cybersecurity practices.