What are the responsibilities and job description for the Director, Cloud and Digital Platform Security position at Churchill Downs Incorporated - Louisville, KY?
SUMMARY:
We are seeking a strategic and experienced Director of Cloud and Digital Platform Security to oversee and enhance our security posture across public cloud environments, applications, and digital platforms. This leadership role will be responsible for developing and implementing security strategies, policies, and practices that protect our organization from threats while ensuring compliance with industry standards.
The Director, Cloud and Digital Platform Security, is part of the Churchill Downs Incorporated (CDI) Cybersecurity leadership team working closely with IT, Development, and product teams
ESSENTIAL DUTIES AND RESPONSIBILITIES include the following:
- Cloud Security Management: Develop and maintain a comprehensive cloud security strategy to safeguard data and applications in AWS cloud environments. Design and implement best practices for identity and access management, encryption, landing zones and AMIs.
- Digital Platform Security: Oversee the security of digital platforms, including web applications, mobile apps, and APIs. Ensure compliance with relevant regulations and implement measures to safeguard corporate and customer data.
- AI Security Oversight: Establish security protocols for AI models and applications, ensuring the protection of data integrity and privacy. Assess and mitigate risks associated with AI development and deployment.
- Application Security Leadership: Lead efforts to integrate security into the software development lifecycle (SDLC). Collaborate with development teams to implement security testing (e.g., SAST, DAST) and conduct regular vulnerability assessments.
- Team Development and Leadership: Build and manage a high-performing security team. Foster a culture of security awareness across the organization through training and communication initiatives.
- Collaboration and Communication: Work closely with IT, DevOps, and product teams to ensure security is a core consideration in all technology initiatives
REQUIRED SKILLS:
- Security Architecture Design: Demonstrated skills in designing security architectures that support business needs while ensuring robust protection across cloud and application environments.
- Cloud Security Expertise: In-depth knowledge of AWS cloud security architectures, frameworks, and best practices.
- Application Security Knowledge: Strong understanding of secure coding practices, application vulnerabilities (e.g., OWASP Top Ten), and experience with security testing methodologies.
- DevSecOps Integration: Experience with integrating security practices into DevOps workflows, fostering collaboration between development, operations, and security teams.
- Application Development Knowledge: Understanding of modern application development methodologies (e.g., Agile, DevOps) and frameworks
EDUCATION and EXPERIENCE:
- Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or a combination of education and relevant experience required.
- 7 years of experience in information security, with a focus on cloud security, and application security.
- 5 years in a leadership or management role, demonstrating the ability to lead and develop a team effectively.
REGULATORY
- Ability to obtain racing and/or gaming licenses as required in any jurisdiction where CDI operates. The Gaming industry is highly regulated and as such demands an extensive background check to obtain a license.
PHYSICAL DEMANDS/ WORKING CONDITIONS:
- Extended periods of sitting at a desk and working on a computer.
- Regular use of a keyboard and mouse for typing and navigating software.
- Viewing a computer screen for prolonged periods.
- Ability to manipulate paperwork, including filing, sorting, and organizing.
- Moving within the office environment to attend meetings, use office equipment, or interact with colleagues.
- Occasional lifting of office supplies or paperwork (up to 20 pounds).
- Speaking and listening to colleagues and clients in person, over the phone, or via video conferencing.
- Working in a climate-controlled office environment with moderate noise levels.
- Performing repetitive tasks such as data entry or document preparation.
- Working under artificial lighting conditions typical of an office environment, which may include fluorescent or LED lighting.
Role is onsite five days a week at the Louisville, KY CDI headquarters office.