Cyber Engineer III

    Highlights

    You will work across campus, data center, edge, remote access, and cloud network domains, partnering with architecture, IAM, infrastructure, application, and SOC teams to ensure network controls are deployed consistently, operate reliably, and improve continuously across all Seminole Hard Rock business units. As the Cybersecurity Network Engineer, you will implement, operate, and continuously improve the network security controls that defend traffic in, out, and across the enterprise - from the campus and data center edge to SASE, cloud networks, and the applications they carry - turning architecture and policy into running, automated, measurable defenses.

    Numbers & Facts

    LocationDavie, FL

    Description

    Skip to main content

    You may choose to display a cookie banner on the external site. You must specify the message in the cookie banner and may add a link to a relevant policy. If you are unfamiliar with these requirements, please seek the advice of legal counsel.

    What are cookies?

    Cookies are simple text files that are stored on your computer or mobile device by a website's server. Each cookie is unique to your web browser. Some information that we collect about you is collected passively through the use of "cookies." Cookies are small files of information, which save and retrieve information about your visit to the Website - for example, how you entered and navigated our Website, and what information was of interest to you. We use this information to remember you when you return and to customize our Website to your preferences. It will contain some anonymous information such as a unique identifier, website's domain name, and some digits and numbers. We may use two types of cookies: (i) Session cookies; and (ii) Persistent Cookies. Session Cookies and Persistent Cookies are categorized as: (a) Strictly Necessary Cookies; (b) Performance and Functional Cookies; (c) Targeting Cookies and (d) Social Media Cookies.

    What types of cookies do we use?

    Necessary cookies

    Necessary cookies allow us to offer you the best possible experience when accessing and navigating through our website and using its features. These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information. For example, these cookies let us recognize that you have created an account and have logged into that account. Strictly Necessary Cookies do not store any Personal Information.

    Performance & Functional cookies

    These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site, and will not be able to monitor its performance. If you do not allow Performance Cookies we will not know when you have visited our site, and we will not be able to monitor its performance. (Examples: monitor website performance and collect anonymous data on how visitors use a website).

    Targeting cookies

    These cookies enable us and third-party services to collect aggregated data for statistical purposes on how our visitors use the website. These cookies do not contain personal information such as names and email addresses and are used to help us improve your user experience of the website. These cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising. Examples include: Criteo, Google.

    Social Media Cookies

    These cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools. Examples include: Facebook, Instagram, Twitter).

    How to delete cookies?

    If you want to restrict or block the cookies that are set by our website, you can do so through your browser setting. Alternatively, you can visit www.internetcookies.com, which contains comprehensive information on how to do this on a wide variety of browsers and devices. You will find general information about cookies and details on how to delete cookies from your device.

    Do not track signals

    Currently, our systems do not recognize browser "do-not-track" requests. You may, however, disable certain tracking as discussed in the Cookies section (e.g., by disabling cookies). Please note that Hard Rock does not collect, and is not aware of third parties that collect, from users of the Website personal information about users' online activities across third party websites.

    Clear GIFS, Pixel Tags and other technologies

    Clear GIFs are tiny graphics with a unique identifier, similar in function to cookies. In contrast to cookies, which are stored on your computer's hard drive, clear GIFs are embedded invisibly on web pages. We may use clear GIFs (a.k.a. web beacons, web bugs or pixel tags), in connection with our Website to, among other things, track the activities of Website visitors, help us manage content, and compile statistics about Website usage. You may view and change your preferences at any time by using the 'Privacy Settings' link found in the footer of our website. We and our third party service providers also use clear GIFs in HTML e-mails to our customers, to help us track e-mail response rates, identify when our e-mails are viewed, and track whether our e-mails are forwarded.

    Third party analytics and tracking

    We use automated devices and applications, such as Google Analytics, to evaluate usage of our Site. We also may use other analytic means to evaluate our services. We use these tools to help us improve our services, performance and user experiences. These entities may use cookies, tracking pixels and other tracking technologies to perform their services. We do not share your personal information with these third parties.

    Contacting us

    If you have any questions about this policy or our use of cookies, please contact us at dataprotection@shrss.com.

    Read Full Privacy Message

    Decline

    Accept Cookies

    Sign In

    Search for JobsStay Connected

    Cyber Engineer III page is loaded

    Cyber Engineer III

    Apply

    locationsSupport Services Headquarters Building

    time typeFull time

    posted onPosted 2 Days Ago

    job requisition idR10797

    Our team members are the key to our company's success, and their health and well-being, as well as that of their families, is very important to us. We offer a comprehensive benefits package that allows our team members stay healthy, plan for their future and maintain a healthy work-life balance. Benefits may vary with employment status. To see our fill list of Team Member Benefits please visit our career site: www.gotoworkhappy.com/benefits

    Job Description:

    Overview

    At Seminole Hard Rock Support Services, we are on a mission to protect our guests, team members, and enterprise assets through world-class cybersecurity practices. As the Cybersecurity Network Engineer, you will implement, operate, and continuously improve the network security controls that defend traffic in, out, and across the enterprise - from the campus and data center edge to SASE, cloud networks, and the applications they carry - turning architecture and policy into running, automated, measurable defenses.

    Reporting to the Manager of Cybersecurity Engineering, this role requires a hands-on, security-minded engineer who bridges the worlds of network engineering, cloud operations, and cybersecurity. You will configure and tune the enterprise network security stack - secure access service edge, perimeter and edge defenses, network detection and response, and zero-trust segmentation - and build the integrations and automations that connect it together across on-premises environments and Microsoft Azure (primary), Amazon Web Services, and Google Cloud.

    This is a builder's role, not an architecture role. You do not define standards from the sidelines; you take reference architectures and network security requirements and make them real: deploying and tuning controls, writing production-grade automation, and instrumenting the telemetry that turns raw network events into actionable insight. Your networking depth lets you treat traffic as evidence, and your fluency with AI and large language models lets you accelerate detection, triage, and analysis of network data far beyond manual effort.

    You will work across campus, data center, edge, remote access, and cloud network domains, partnering with architecture, IAM, infrastructure, application, and SOC teams to ensure network controls are deployed consistently, operate reliably, and improve continuously across all Seminole Hard Rock business units. You measure your impact in risks reduced, incidents prevented, and manual effort eliminated through automation.

    Responsibilities

    Secure Access & Edge (SASE)

    • Deploy, configure, and tune secure-access service edge controls - secure web gateway, cloud firewall, CASB, and DLP policy - keeping coverage complete and policies current (Zscaler ZIA/ZPA)
    • Operate zero-trust network access for workforce and third parties, replacing legacy VPN patterns with identity-aware, least-privilege application access (Zscaler ZPA, GlobalProtect)
    • Operate the enterprise browser to enforce least-privilege, isolated access to sensitive applications from managed and unmanaged endpoints (Island)
    • Tune SSL/TLS inspection, tenant restrictions, and egress policy to balance security, privacy, and application compatibility - including protocols sensitive to interception such as NTLM, Kerberos, and certificate-pinned traffic
    • Manage traffic steering, forwarding, and PAC configurations so users land on the right control path from any location worldwide

    Perimeter, WAF & Application Edge

    • Manage edge and perimeter defenses: web application firewall rules, DDoS mitigation, bot management, CDN and DNS policy for internet-facing properties (Cloudflare)
    • Operate API security posture and runtime protection, discovering shadow APIs and closing authentication and data-exposure gaps (Salt)
    • Administer next-generation firewall policy, NAT, and rule lifecycle across data center and property perimeters, driving rule hygiene and least-privilege access (Palo Alto Networks)
    • Harden DNS, certificate, and TLS posture at the edge in partnership with the PKI and infrastructure teams (Cloudflare, DigiCert, Keyfactor)
    • Coordinate perimeter changes with franchise, property, and vendor networks so remote sites integrate securely without breaking authentication or application flows

    Network Detection, Response & Visibility

    • Deploy and tune network detection and response, triaging anomalous east-west and north-south activity and feeding high-fidelity findings to the SOC (Vectra)
    • Engineer network telemetry pipelines - flow data, DNS logs, proxy logs, firewall logs, packet metadata - that route, shape, and enrich data for cost-effective analysis (Cribl)
    • Develop and tune network-focused detections and SIEM content, mapping coverage to attacker techniques (Trellix Helix, Rapid7)
    • Investigate network-layer incidents end-to-end - from packet capture and flow analysis to proxy and firewall log correlation - isolating root cause under time pressure
    • Maintain authoritative visibility of network assets and attack surface, continuously reconciling what is connected against what is inventoried

    Segmentation, Zero Trust & Cloud Networking

    • Apply zero-trust segmentation and least-privilege access principles consistently across campus, data center, gaming, and hospitality network estates
    • Design and enforce microsegmentation and network policy for sensitive zones - payment, gaming, surveillance, and OT/IoT environments - in partnership with infrastructure and compliance teams
    • Implement cloud network security guardrails across Azure (primary), AWS, and Google Cloud: virtual network design, firewalling, private connectivity, and logging baselines (Azure Firewall, NSGs, Private Link)
    • Remediate cloud network misconfigurations and exposure paths surfaced by posture management, preventing drift over time (Wiz, Microsoft Defender for Cloud)
    • Integrate network security checks into infrastructure-as-code and deployment workflows so network changes are secure by default

    Network Automation, AI & Detection Engineering

    • Build and maintain network security automations, integrations, and response playbooks across the stack using APIs and SOAR (Torq)
    • Leverage AI/ML and large language models to analyze large volumes of network telemetry, accelerate alert triage and enrichment, surface anomalies, and automate reporting and documentation
    • Develop and maintain production-grade scripts, services, and tooling (e.g., Python, PowerShell, Go) that operationalize network controls and eliminate repetitive manual work
    • Automate firewall rule reviews, policy validation, and configuration compliance checks so drift is caught by pipelines, not people
    • Instrument metrics and dashboards that make network control coverage, detection efficacy, and remediation timeliness measurable

    Collaboration & Continuous Improvement

    • Partner with Cybersecurity Architecture, IAM, infrastructure, application, and SOC/MSSP teams to deploy network controls consistently and resolve issues quickly
    • Support Cybersecurity Strategy & Governance, audit, and privacy programs by automating evidence collection and continuous control monitoring for network controls (Onspring, TrustArc, Microsoft Purview)
    • Document standards, runbooks, integration designs, and operating procedures so network controls are repeatable and supportable
    • Research, prototype, and pilot emerging network security tools and AI-driven capabilities that improve detection, automation, and analyst efficiency
    • Participate in an on-call rotation and incident response for a 24/7 gaming and hospitality environment

    Qualifications & Experience

    • 4-7+ years of combined experience in network engineering, network security engineering, or cloud networking, with at least 3+ years focused on hands-on network security engineering in enterprise environments
    • Deep network engineering expertise, with hands-on experience designing, operating, and troubleshooting enterprise networks: routing and switching, firewalls, proxies, VPN/ZTNA, load balancing, DNS, and TLS/PKI
    • Strong automation and software proficiency, with hands-on experience in Python, PowerShell, Go, or similar languages, and the ability to build custom network security tooling, integrations, and automation from scratch
    • Practical experience applying AI/ML or large language models to network data analysis, detection, triage, or automation
    • Strong working knowledge of SASE / SSE platforms (secure web gateway, ZTNA, CASB, DLP), WAF and DDoS mitigation, NDR, and API security
    • Hands-on experience securing cloud networks on Microsoft Azure (required), with working experience in AWS and/or Google Cloud: virtual network design, cloud firewalls, private connectivity, and network security posture management
    • Deep networking fundamentals: TCP/IP, BGP/OSPF, DNS, DHCP, TLS/PKI, NAT, IPv6, packet analysis, segmentation, and zero-trust access models
    • Experience integrating network security tools and data sources via API, with familiarity in SOAR playbook development and SIEM content engineering
    • Familiarity with regulatory and compliance frameworks relevant to gaming and hospitality (PCI-DSS, SOX, tribal gaming regulations, GLBA), preferred but not required
    • Relevant certifications preferred: Cisco CCNP Security, Palo Alto PCNSE, Zscaler certifications (ZDTA/ZCCP), Microsoft AZ-700 or AZ-500, AWS Advanced Networking Specialty, GIAC (GCIA, GDSA, GCLD), or equivalent; CISSP a plus

    Professional Skills

    • Translate network security requirements and architecture into deployed, automated controls that operate reliably and integrate cleanly into existing networks and workflows, without creating friction
    • Operate as a hands-on engineer who personally builds, configures, tests, and ships high-quality automation and integrations, measuring success in problems solved, not tickets closed
    • Troubleshoot methodically across physical, virtual, and cloud network layers - from packet captures to policy engines - isolating root cause under time pressure during incidents
    • Collaborate effectively across cross-functional teams: cybersecurity, network and infrastructure engineering, cloud, IAM, compliance, and the SOC
    • Communicate technical findings and recommendations clearly to both technical peers and non-technical stakeholders, including property and franchise contacts
    • Thrive in an Agile, fast-paced environment that values automation, rapid iteration, and measurable security outcomes over manual process
    • Demonstrate a builder's mindset and a passion for using engineering and AI to make network security faster, more consistent, and more scalable

    Loading

    Follow Us

    *

    Privacy Policy

    2026 Workday, Inc. All rights reserved.

    Similar Jobs