- Location
- San Manuel Commons - 674 Brier, United States of America
- Type
- Full-time
- Department
- Security
- Seniority
- VP
- Education
- Master
- Source
- Workday
Description
This position also oversees security and privacy operations, monitoring, reporting, and program performance to ensure alignment with organizational objectives and enterprise risk posture.
ESSENTIAL DUTIES AND RESPONSIBILITIES
1. Lead the implementation and continuous improvement of the enterprise information security and privacy programs, ensuring alignment with organizational objectives, risk management strategies, and regulatory requirements.
2. Direct and oversee information security operations, security engineering, governance, risk management, privacy, vulnerability management, incident response, threat intelligence, and data protection functions to ensure the confidentiality, integrity, and availability of enterprise information assets.
3. Develop, implement, and maintain security and privacy policies, standards, procedures, and control frameworks based on industry-recognized practices, regulatory requirements, and organizational risk tolerance.
4. Provide leadership and direction to security and privacy leaders and team members, ensuring the development of technical, regulatory, and business competencies while planning for future organizational capabilities and resource needs.
5. Partner with business, technology, legal, compliance, human resources, internal audit, and operational leaders to integrate security and privacy requirements into enterprise initiatives, projects, systems, and business processes.
6. Establish and maintain security and privacy governance processes, including risk identification, assessment, treatment, and reporting, to support informed decision-making and risk-based prioritization across the enterprise.
7. Oversee the enterprise privacy program, including privacy impact and risk assessments, data protection requirements, regulatory compliance activities, privacy-by-design practices, and the management of privacy incidents and inquiries.
8. Create, communicate, and implement risk-based processes for third-party and vendor risk management, including the assessment and treatment of risks associated with partners, consultants, service providers, and other external parties.
9. Oversee security and privacy monitoring, incident response, investigations, and threat intelligence activities, ensuring timely escalation, response, and remediation of identified risks and events.
10. Monitor the evolving threat, regulatory, and privacy landscape, advising executive leadership on emerging risks, compliance obligations, and appropriate mitigation strategies.
11. Develop and maintain program metrics, key performance indicators, dashboards, and executive reporting to measure program effectiveness, support resource allocation decisions, and communicate risk posture to senior leadership.
12. Collaborate with enterprise leaders to support business continuity, disaster recovery, data governance, artificial intelligence governance, and other risk-related initiatives that impact information security and privacy.
13. Prepare and deliver presentations, strategic updates, and recommendations to executive leadership, enterprise risk committees, and other governance bodies as required.
14. Perform other duties as assigned to support the efficient operation of the department.
SUPERVISORY RESPONSIBILITIES
Carries out supervisory responsibilities in accordance with the organization’s policies and applicable laws. Responsibilities include interviewing, hiring and training employees; planning, assigning reviewing and directing work; evaluating and appraising performance; rewarding and disciplining employees; addressing complaints and resolving problems. Make hiring decisions and designs individual development plans with succession planning in mind for all key roles.
EDUCATION, EXPERIENCE AND QUALIFICATIONS
Bachelor’s Degree in Business Administration or an Information Technology-related field required. Master’s Degree a strong plus (MBA, Information Technology or Legal/Compliance related degree preferred).
Minimum twelve (12) years of experience in a combination of information security, risk management, and IT related jobs required.
Minimum ten (10) years of supervisory experience required. Employment history must demonstrate increasing levels of responsibility.
Related, relevant, and/or direct experience may be considered in lieu of minimum educational requirements indicated above.
KNOWLEDGE, SKILLS AND ABILITIES (KSA)
Proven experience leading enterprise information security and privacy programs, including the development and implementation of policies, standards, and procedures that support organizational objectives.
Knowledge of applicable legal, regulatory, and industry requirements, including Sarbanes-Oxley Act (SOX), Health Insurance Portability and Accountability Act (HIPAA), Payment Card Industry Data Security Standard (PCI DSS), and privacy regulations.
Knowledge of information security and privacy frameworks, standards, and leading practices, including NIST, ISO/IEC 27001, COBIT, and related governance and risk management frameworks.
Demonstrated ability to develop, implement, and mature security and privacy governance programs.
Excellent written and verbal communication, interpersonal, and collaboration skills, with the ability to effectively communicate security, privacy, and risk concepts to technical and non-technical audiences.
Ability to build trusted relationships and influence stakeholders across all levels of the organization to achieve strategic and operational objectives.
Poise and ability to act calmly, decisively, and effectively in high-pressure and high-visibility situations.
Strong analytical, critical thinking, and problem-solving skills, with the ability to assess complex risks and develop practical solutions.
Demonstrated ability to manage multiple priorities, initiatives, and projects in a fast-paced environment while meeting established objectives and deadlines.
Strong leadership, organizational, and team development skills, including the ability to lead, motivate, and develop cross-functional and interdisciplinary teams.
Experience with strategic planning, financial management, budgeting, resource allocation, and project management.
Experience managing vendor relationships, contract negotiations, and third-party risk management activities.
High level of personal integrity and professionalism, with the ability to exercise sound judgment and appropriately handle sensitive and confidential information.
High degree of initiative, accountability, dependability, and ability to operate effectively with limited supervision.
LICENSES, CERTIFICATIONS AND REGISTRATIONS
At the discretion of the San Manuel Tribal Gaming Commission, you may be required to obtain and maintain a gaming license.
Professional security management certification, such as a Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA) or other similar credentials, is desired.
Driving Responsibilities: Role requires regular commuting between locations. A valid driver's license and vehicle insurance with minimum liability limits is required. Role will not operate or drive Tribe-owned vehicles or patron vehicles.
PHYSICAL REQUIREMENTS/ WORKING CONDITIONS – ENVIRONMENT
The physical demands and working environment described here are representative of those that an employee encounters and must be met by an employee to successfully perform the essential functions of this job.
Primary work environment is in a climate-controlled office setting.
Work requires travel to attend meetings, trade shows, and conferences.
Incumbents may be required to work evening, weekend and holiday shifts.
Must be able to work in a fast-paced, high-demand environment.
Strength sufficient to exert up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects and/or move up to 40 pounds occasionally.
Sedentary work: involves sitting most of the time. Constantly operates a computer and other office productivity machinery, such as a calculator, copy machine, and computer printer.
Physical activities that apply to the essential functions of the position are balancing, stooping, kneeling, crouching, reaching, pushing, pulling, lifting, grasping, talking, hearing, and repetitive motions.
Hearing sufficient to hear conversational levels in person, via videoconference and over the telephone.
Speech sufficient to make oneself heard and understood in person, in front of groups, in meetings, via videoconference and over the telephone.
Visual acuity that meets the requirements of the position: The worker is required to have close visual acuity to perform an activity such as preparing and analyzing data and figures; transcribing; viewing a computer terminal; expansive reading and visual inspection of employees, visitors or facility.
Mobility sufficient to safely move in an office environment, walk, stoop, bend and kneel, and enter, exit and operate a motor vehicle in the course of travel to promotional events, meetings, conferences, trade shows and San Manuel properties.
Endurance sufficient to sit, walk and stand for extended periods, and maintain efficiency throughout the entire work shift and during extended work hours.
The employee may be exposed to fumes or airborne particles including secondhand smoke.
Reasonable accommodation will be made in compliance with all applicable law.
As one of the largest private employers in the Inland Empire, San Manuel deeply cares about the future, growth and well-being of its employees. Join our team today!