Summary
Hard Rock International is dedicated to protecting its guests, team members, and enterprise assets through world-class cybersecurity practices. The Cyber Engineer III will implement and improve network security controls across various environments, ensuring reliable and automated defenses while collaborating with multiple teams to enhance security measures.
Responsibilities
- Deploy, configure, and tune secure-access service edge controls — secure web gateway, cloud firewall, CASB, and DLP policy — keeping coverage complete and policies current (Zscaler ZIA/ZPA)
- Operate zero-trust network access for workforce and third parties, replacing legacy VPN patterns with identity-aware, least-privilege application access (Zscaler ZPA, GlobalProtect)
- Operate the enterprise browser to enforce least-privilege, isolated access to sensitive applications from managed and unmanaged endpoints (Island)
- Tune SSL/TLS inspection, tenant restrictions, and egress policy to balance security, privacy, and application compatibility — including protocols sensitive to interception such as NTLM, Kerberos, and certificate-pinned traffic
- Manage traffic steering, forwarding, and PAC configurations so users land on the right control path from any location worldwide
- Manage edge and perimeter defenses: web application firewall rules, DDoS mitigation, bot management, CDN and DNS policy for internet-facing properties (Cloudflare)
- Operate API security posture and runtime protection, discovering shadow APIs and closing authentication and data-exposure gaps (Salt)
- Administer next-generation firewall policy, NAT, and rule lifecycle across data center and property perimeters, driving rule hygiene and least-privilege access (Palo Alto Networks)
- Harden DNS, certificate, and TLS posture at the edge in partnership with the PKI and infrastructure teams (Cloudflare, DigiCert, Keyfactor)
- Coordinate perimeter changes with franchise, property, and vendor networks so remote sites integrate securely without breaking authentication or application flows
- Deploy and tune network detection and response, triaging anomalous east-west and north-south activity and feeding high-fidelity findings to the SOC (Vectra)
- Engineer network telemetry pipelines — flow data, DNS logs, proxy logs, firewall logs, packet metadata — that route, shape, and enrich data for cost-effective analysis (Cribl)
- Develop and tune network-focused detections and SIEM content, mapping coverage to attacker techniques (Trellix Helix, Rapid7)
- Investigate network-layer incidents end-to-end — from packet capture and flow analysis to proxy and firewall log correlation — isolating root cause under time pressure
- Maintain authoritative visibility of network assets and attack surface, continuously reconciling what is connected against what is inventoried
- Apply zero-trust segmentation and least-privilege access principles consistently across campus, data center, gaming, and hospitality network estates
- Design and enforce microsegmentation and network policy for sensitive zones — payment, gaming, surveillance, and OT/IoT environments — in partnership with infrastructure and compliance teams
- Implement cloud network security guardrails across Azure (primary), AWS, and Google Cloud: virtual network design, firewalling, private connectivity, and logging baselines (Azure Firewall, NSGs, Private Link)
- Remediate cloud network misconfigurations and exposure paths surfaced by posture management, preventing drift over time (Wiz, Microsoft Defender for Cloud)
- Integrate network security checks into infrastructure-as-code and deployment workflows so network changes are secure by default
- Build and maintain network security automations, integrations, and response playbooks across the stack using APIs and SOAR (Torq)
- Leverage AI/ML and large language models to analyze large volumes of network telemetry, accelerate alert triage and enrichment, surface anomalies, and automate reporting and documentation
- Develop and maintain production-grade scripts, services, and tooling (e.g., Python, PowerShell, Go) that operationalize network controls and eliminate repetitive manual work
- Automate firewall rule reviews, policy validation, and configuration compliance checks so drift is caught by pipelines, not people
- Instrument metrics and dashboards that make network control coverage, detection efficacy, and remediation timeliness measurable
- Partner with Cybersecurity Architecture, IAM, infrastructure, application, and SOC/MSSP teams to deploy network controls consistently and resolve issues quickly
- Support Cybersecurity Strategy & Governance, audit, and privacy programs by automating evidence collection and continuous control monitoring for network controls (Onspring, TrustArc, Microsoft Purview)
- Document standards, runbooks, integration designs, and operating procedures so network controls are repeatable and supportable
- Research, prototype, and pilot emerging network security tools and AI-driven capabilities that improve detection, automation, and analyst efficiency
- Participate in an on-call rotation and incident response for a 24/7 gaming and hospitality environment
Skills
- 4–7+ years of combined experience in network engineering, network security engineering, or cloud networking, with at least 3+ years focused on hands-on network security engineering in enterprise environments
- Deep network engineering expertise, with hands-on experience designing, operating, and troubleshooting enterprise networks: routing and switching, firewalls, proxies, VPN/ZTNA, load balancing, DNS, and TLS/PKI
- Strong automation and software proficiency, with hands-on experience in Python, PowerShell, Go, or similar languages, and the ability to build custom network security tooling, integrations, and automation from scratch
- Practical experience applying AI/ML or large language models to network data analysis, detection, triage, or automation
- Strong working knowledge of SASE / SSE platforms (secure web gateway, ZTNA, CASB, DLP), WAF and DDoS mitigation, NDR, and API security
- Hands-on experience securing cloud networks on Microsoft Azure (required), with working experience in AWS and/or Google Cloud: virtual network design, cloud firewalls, private connectivity, and network security posture management
- Deep networking fundamentals: TCP/IP, BGP/OSPF, DNS, DHCP, TLS/PKI, NAT, IPv6, packet analysis, segmentation, and zero-trust access models
- Experience integrating network security tools and data sources via API, with familiarity in SOAR playbook development and SIEM content engineering
- Familiarity with regulatory and compliance frameworks relevant to gaming and hospitality (PCI-DSS, SOX, tribal gaming regulations, GLBA), preferred but not required
- Relevant certifications preferred: Cisco CCNP Security, Palo Alto PCNSE, Zscaler certifications (ZDTA/ZCCP), Microsoft AZ-700 or AZ-500, AWS Advanced Networking Specialty, GIAC (GCIA, GDSA, GCLD), or equivalent; CISSP a plus
Qualifications
Must Haves
- 4–7+ years of combined experience in network engineering, network security engineering, or cloud networking, with at least 3+ years focused on hands-on network security engineering in enterprise environments
- Deep network engineering expertise, with hands-on experience designing, operating, and troubleshooting enterprise networks: routing and switching, firewalls, proxies, VPN/ZTNA, load balancing, DNS, and TLS/PKI
- Strong automation and software proficiency, with hands-on experience in Python, PowerShell, Go, or similar languages, and the ability to build custom network security tooling, integrations, and automation from scratch
- Practical experience applying AI/ML or large language models to network data analysis, detection, triage, or automation
- Strong working knowledge of SASE / SSE platforms (secure web gateway, ZTNA, CASB, DLP), WAF and DDoS mitigation, NDR, and API security
- Hands-on experience securing cloud networks on Microsoft Azure (required), with working experience in AWS and/or Google Cloud: virtual network design, cloud firewalls, private connectivity, and network security posture management
- Deep networking fundamentals: TCP/IP, BGP/OSPF, DNS, DHCP, TLS/PKI, NAT, IPv6, packet analysis, segmentation, and zero-trust access models
- Experience integrating network security tools and data sources via API, with familiarity in SOAR playbook development and SIEM content engineering
Nice to Haves
- Familiarity with regulatory and compliance frameworks relevant to gaming and hospitality (PCI-DSS, SOX, tribal gaming regulations, GLBA), preferred but not required
- Relevant certifications preferred: Cisco CCNP Security, Palo Alto PCNSE, Zscaler certifications (ZDTA/ZCCP), Microsoft AZ-700 or AZ-500, AWS Advanced Networking Specialty, GIAC (GCIA, GDSA, GCLD), or equivalent; CISSP a plus
Benefits
- Comprehensive benefits package
- Health and well-being support for team members and their families
- Work-life balance