Engineer – InfoSec GRC (Governance, Risk, and Compliance)
Wynn Resorts
- Location
- Las Vegas, NV, United States
- Employment
- Full Time
- Work model
- On-Site
- Level
- Mid
- H-1B history
- 1 approvals (FY2023)
- Posted
- 7h ago
Skills
About this role
Engineer – InfoSec GRC (Governance, Risk, and Compliance) Full-time FLSA Status: Exempt Division: 22700 - G&A Career Areas: Information Technology Status: Full-Time Job Description Wynn Resorts is seeking an Engineer – InfoSec GRC to help advance the technical maturity, automation, and audit readiness of the Information Security Governance, Risk, and Compliance function. This role is ideal for a technically minded GRC professional who can translate regulatory, audit, and control requirements into practical system procedures, automated workflows, scheduled reporting, dashboards, and audit-ready evidence. The Engineer – InfoSec GRC will serve as a technical resource for control automation, evidence collection, compliance reporting, and continuous improvement across the GRC program. This position partners closely with Information Security, IT, Internal Audit, Finance, Legal, Compliance, and business stakeholders to improve the reliability, consistency, and efficiency of audit and compliance processes. Ideal Candidate Detail-oriented, technically curious GRC professional who enjoys improving complex processes, building reliable reporting, and making audit and compliance activities easier for analysts and stakeholders to execute. Ability to work independently, collaborate across teams, and communicate technical concepts clearly in a practical, audit-ready manner. Essential Job Duties & Responsibilities Design, implement, and improve technical solutions that support repeatable, auditable compliance with applicable frameworks and requirements, including SOX ITGC, PCI DSS, Gaming MICS, NIST, ISO, and other relevant standards. Automate audit procedures, control testing steps, evidence collection routines, and analyst-ready workflows to reduce manual effort and improve consistency, accuracy, and timeliness. Build, maintain, and validate scheduled compliance reporting from authoritative systems, including databases, applications, identity platforms, asset repositories, change management systems, vulnerability management tools, SIEM/logging platforms, GRC platforms, and other enterprise data sources. Develop dashboards, metrics, exception reports, control status reporting, remediation tracking outputs, and evidence artifacts that communicate compliance posture, control effectiveness, audit readiness, and risk trends. Support systems and platforms where GRC is the business stakeholder, including tools used for audit automation, evidence management, control monitoring, asset management, application inventory, change management, and scheduled reporting. Identify and implement technical improvements, data integrations, automation opportunities, and control monitoring enhancements that reduce recurring audit issues and strengthen stakeholder accountability. Maintain technical details within the GRC control framework, including system and network scoping, technical control interpretations, control-to-system mappings, artifact descriptions, reporting logic, and validation steps. Partner with internal and external auditors, assessors, IT teams, engineers, architects, application owners, and business stakeholders to explain control design, evidence, system data, reporting logic, and remediation status. Support the continuous improvement of GRC processes through technology, documentation, workflow optimization, reporting automation, and responsible use of AI-enabled capabilities. Perform other duties as assigned. Qualifications Degree in computer science, cybersecurity, data analytics, or related field (or equivalent experience) Four (4+) years of experience in cybersecurity, audit, risk, compliance, or related programs Ability to translate regulations and controls into technical requirements, testing procedures, metrics, and reporting