HRTMS Job Description Management
| VP IT Cyber Security J o b D e s c r i p t i o n | | |
Job Profile Title: | VP IT Cyber Security | Job Code: | 11456 | Profile Title: | 11456 VP IT Cyber Security | Grade / Band: | L5 | FLSA Status: | Exempt | The Vice President of Cyber Security plays a key leadership role in designing, building, and operating the cybersecurity capabilities that protect business operations, digital platforms, and technology infrastructure across MGM Resorts International. Reporting directly to the Chief Information Security Officer, the incumbent leads three core functions: Security Operations, Threat Exposure Management, and Secure Software Delivery. In this role, the Vice President directs real-time threat detection, incident response, and defense against modern automated and AI-driven threats, while managing programs that continuously identify, prioritize, and reduce vulnerabilities across the enterprise attack surface. Additionally, this leader owns the operational security of software development pipelines, build environments, code scanning tools, and artifact repositories. The Vice President serves as a primary cybersecurity advisor to software engineering, architecture, risk, and IT teams, drives strategic technology roadmaps, leads critical incident response actions, and builds the operational resilience needed to protect the global enterprise. | | | | | |
Principal Duties & Responsibilities | Incident Command & Resilience: Lead enterprise crisis incident response and digital forensics across cloud, on-premises, and gaming environments, engineering automated containment to maximize operational resilience | Autonomous SecOps & AI Defense: Direct autonomous security operations, advanced detection engineering, and automated response orchestration to counter multi-vector and AI-driven threats at machine speed | Attack Surface Visibility: Drive continuous internal and external attack surface management, maintaining complete asset discovery and workload visibility across the global footprint | Exploitability & Threat Simulation: Prioritize vulnerability remediation based on active adversary exploitability and threat intelligence, continuously validating defenses through automated threat simulations | Pipeline & Build Infrastructure Hardening: Own the operational security and hardening of all CI/CD pipelines, GitHub environments, runner infrastructure, and artifact repositories such as JFrog Artifactory | Application & Code Security: Implement automated developer-aligned security testing, including SAST, DAST, SCA, centralized secrets scanning, and security guardrails for AI-assisted code generation | Software Supply Chain Integrity: Enforce artifact provenance, Software Bill of Materials validation, and strict third-party dependency governance across all software delivery pipelines | Cross-Functional Zero Trust Architecture: Partner with Security Engineering, Enterprise Architecture, GRC, and IT teams to implement technical standards, Zero Trust controls, and machine credential security across all shared platforms | Roadmaps, Efficacy & Partner Accountability: Own strategic technology roadmaps, optimize detection fidelity, and drive performance accountability across engineering teams and vendors via Quarterly Business Reviews (QBRs), KPIs, and SLAs | Leadership & Budget Governance: Build, mentor, and scale high-performing technical teams while managing multi-million-dollar capital and operational budgets, vendor negotiations, and tool consolidation |
Required for All Jobs | Performs other job-related duties as requested | Proof of eligibility to work in the United States |
Education | Education Level | Education Details | Required/ Preferred | Bachelor's Degree | Computer science, electronic engineering, business administration or related field | Required | Master's Degree | Computer science, electronic engineering, business administration or related field | Preferred | | | | | |
Work Experience | Experience | Experience Details | Required/ Preferred | 6+ Years of Prior Relevant Experience | Experience working in or with cyber security teams of similar size and mission to MGMRI | Required | 4+ Years of Prior Relevant Experience | Experience working in or with cyber teams in a hospitality field | Preferred | | | | | |
Additional Requirements | Details | Required/ Preferred | CISSP, GCIH, or SANs, GIAC, ISC2, or ISACA certification | Preferred | Demonstrable track-record of successfully handling Security Events, Alerts, Incidents and Threats | Preferred | Familiarity or direct experience in legal and/or compliance requirements related to MGMRI cyber security programs and postures | Preferred | | | |
Knowledge, Skills and Abilities | KSAs | Technical Depth in Software & Systems: Strong foundational background in software engineering principles, distributed systems architecture, cloud infrastructure, and modern developer ecosystems | Threat Mechanics & Adversary Tradecraft: In-depth knowledge of attacker tactics, techniques, and procedures (TTPs), automated attack chains, and emerging AI-enabled threat models | Analytical Problem Solving & Root Cause Analysis: Exceptional analytical and forensic mindset with the ability to dissect complex security events, evaluate technical failures, and determine root causes under high pressure | Security Architecture & Zero Trust Principles: Solid conceptual grasp of Zero Trust frameworks, workload identity controls, defense-in-depth design, and secure systems architecture | Operational Rigor & Metrics Management: Demonstrated ability to establish quantitative performance benchmarks to measure control efficacy and implement continuous process improvements | Strategic & Financial Acumen: Working knowledge of technology financial management, including capital and operating budget planning, vendor contract negotiations, and technology return on investment (ROI) optimization | Stakeholder Influence & Executive Presence: Superior verbal and written communication skills with the ability to influence cross-functional peers, build consensus across disparate teams, and translate deep technical risks into concise business decisions | Engineering Leadership & Talent Development: Proven capacity to attract, inspire, and develop top-tier technical talent while building a culture centered on engineering excellence, accountability, and psychological safety | Decisive Crisis Judgement: Exercises sound, risk-balanced judgement during critical incidents and fast-moving situations, prioritizing business continuity, customer trust, and operational resilience |
Physical Requirements | A thorough completion of this section is needed for compliance with legal standards such as the Americans with Disabilities Act. The physical requirements described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. | Physical Requirement | N/A | Rarely | Occasionally | Frequently | Constantly | Weight/ w.p.m. | Balancing | | | X | | | | Bending | | | X | | | | Carrying 10 pounds | | | X | | | | Clear speech - simple | | | | X | | | Clear speech - complex | | | | X | | | Climbing | X | | | | | | Distant vision | | | | X | | | Driving | X | | | | | | Flexibility - upper body | | | X | | | | Flexibility - lower body | | | X | | | | Hearing/Listening | | | | X | | | Kneeling | | | X | | | | Lifting 10 pounds | | | X | | | | Near vision | | | | X | | | Normal vision | | | | X | | | Pushing/Pulling | | | X | | | | Reaching | | | X | | | | Sitting | | | | X | | | Standing | | | X | | | | Typing | | | | X | | | Walking | | | | X | | | | | | | | | | | | | | | |
Work Environment | While performing the duties of this job, the associate is required to work within the selected work environments. | Work Environment | N/A | Rarely | Occasionally | Frequently | Constantly | Communication - verbal | | | | X | | Communication - written | | | | X | | Confined area | | | | X | | Contacts - works alone | | | | X | | Contacts - works around others | | | | X | | Contacts - works with others | | | | X | | Exposure to dust / dirt | | | X | | | Exposure to fumes / odors | | | X | | | Extreme cold | | X | | | | Extreme heat | | X | | | | Fast pace | | | | X | | Hazardous conditions - chemicals | X | | | | | Hazardous conditions - high structures | X | | | | | Hazardous conditions - high voltage | X | | | | | Indoors | | | | X | | Noise levels - low to moderate | | | | X | | Noise levels - high | | | X | | | Office conditions | | | | X | | Outdoors | | | X | | | Restricted area | | X | | | | Shifts | X | | | | | Smoke | | | X | | | Travel | | X | | | | Wet/Humid | | X | | | | | | | | | | | | | | |
Mental Requirements | While performing the duties of this job, the associate is required to work within the selected mental requirements. | Mental Requirement | N/A | Rarely | Occasionally | Frequently | Constantly | Analytical | | | | X | | Clerical | | | | X | | Comprehension | | | | X | | Crisis incidents | | X | | | | Customer service | | | | X | | Decision making | | | | X | | High pressure | | | | X | | Judgment | | | | X | | Long hours | | | X | | | Math skills - advance | | | X | | | Math skills - basic | | | | X | | Organization | | | | X | | Reading - simple | | | | X | | Reading - complex | | | | X | | Repetition | | | | X | | Tight deadlines | | | | X | | Writing - simple | | | | X | | Writing - complex | | | | X | | | | | | | | | | | | |
|