Las Vegas, NV

Salary
Posted
Jul 13, 2026
Location
Las Vegas, NV
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A technical GRC role focused on building and maintaining the compliance control framework for a large hospitality and gaming organization. Day-to-day work involves designing and refining control testing procedures, managing GRC tooling (audit automation, asset management, vulnerability management), and serving as the technical point of contact for internal and external auditors across frameworks such as SOX, PCI-DSS, NIST, HIPAA, and gaming-specific MICS. Suits someone with a background in cybersecurity compliance or audit who can bridge technical and non-technical stakeholders.

Mid level · 4+ years · Las Vegas-Henderson-Paradise, NV · Full-time

Must have (6)
SOXPCI-DSSNISTHIPAAGRCvulnerability management
Nice to have (3)
SQLCISASplunk

Posted 2 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 45 people in NV plausibly meet what this posting asks for (information security analysts). range 15–70

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
vulnerability management55%NIST40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $105,950 (middle half $88,228–$146,083).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (8)

Location is inferred as Las Vegas, NV based on Wynn Resorts North America headquarters; the posting does not explicitly state a city.

The degree requirement states 'college diploma or university degree in computer science or related discipline AND/OR 4 years of equivalent work experience' — the 'or equivalent experience' clause means no formal degree is hard-gated.

The 4-year experience requirement is stated at the role level against cybersecurity programs broadly, not tied to any specific technology.

SOX, PCI-DSS, NIST, and HIPAA are listed in the responsibilities section as explicit regulatory frameworks the role must implement and enforce; MICS (gaming-specific Minimum Internal Control Standards) is also named but is a niche gaming-industry standard rather than a broadly searchable skill.

SQL/database querying appears in the qualifications section as 'general ability to pull data from database tables… for compliance reporting' — this is framed as a general ability rather than a named technology gate, so it is marked preferred.

CISA, PCI-ISA, and Splunk certifications/training are explicitly called out under 'Strong consideration given for' — i.e., preferred, not required. PCI-ISA is omitted as a separate skill since PCI-DSS is already captured as a hard gate; Splunk is retained as a preferred skill.

The alt SOC 15-1211 (Computer Systems Analysts) is noted because the role has a significant systems-analysis and compliance-process-design dimension alongside its security focus.

Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): patch management, audit automation.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗