Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Engineer III

$108k - $138k
Full-time

Schurz Communications

Position Summary

This role owns the firewall estate, security architecture, and standards for all six properties, the documentation library behind them, and the posture roadmap that sequences the work, and personally implements the hardest parts of it. This is a senior individual contributor role, not a management position. Expect to be writing a standard in the morning, converting a property to it that night, and presenting the result to the Risk Committee the following week.

Position Title : Security Engineer III

Location : Remote (within driving distance of a Schurz property, see locations below)

Rate: $108,000 - $138,000 annually

Reports to : VP, Business Technology

Position Type : Full-time

Essential Responsibilities

Firewall Estate Ownership — Primary Responsibility

  • Own the firewall estate for all six properties: the standard, the platform strategy, the refresh roadmap, and the vendor relationship. This is the accountability that does not move.
  • Define the firewall reference architecture — platform selection, high-availability model, management topology, zone model, and the policy standard every property implements.
  • Decide whether the estate consolidates onto one vendor and drive that conversion, or document why a mixed estate is the right answer and how it will be managed consistently.
  • Own the multi-year refresh and capacity plan as a budget line, and defend it.
  • Personally execute the high-risk conversions, migrations, and cutovers rather than delegating them.
  • Hold final approval on every firewall change that deviates from standard and on every exception that stays open.

Architecture and Standards

  • Define the access-control and segmentation reference architecture for all six properties, replacing six locally grown conventions with one standard plus a documented deviation list.
  • Author the hardening baselines platform by platform, and the method for measuring drift against them.
  • Own the standards library itself: versioning, review cadence, ownership, approval path, and retirement of standards that no longer hold.
  • Own the rule lifecycle governance model — naming, ownership, review cadence, expiration, exception register.
  • Lead the conversion of each property onto the standard.
  • Review and approve designs produced by Tier II; approve or reject deviations.

Internal Network Understanding

  • Hold the authoritative picture of how all six networks actually work — edge, core, plant, subscriber, and management planes — including where they differ and why.
  • Maintain the trust-boundary and data-flow model that segmentation decisions are made against, and keep it accurate as platform consolidation moves things.
  • Be the person who can answer, without research, what is exposed where and what would happen if a given control failed.

Documentation as a Deliverable

  • Own the documentation standard: what must exist for every property, in what form, reviewed how often, and who is accountable when it drifts.
  • Ensure current security architecture documentation, diagrams, standards, runbooks, and decision records exist for all six properties, and enforce that they stay current rather than decaying between audits.
  • Write the decision records that explain why a standard is what it is, so the next engineer does not relitigate settled questions.

Posture, Compliance, and Evidence

  • Maintain a security posture roadmap mapped to NIST CSF and CIS Controls, with a defensible current-state assessment behind it, and sequence the work against it.
  • Own the cybersecurity and supply chain risk management plans required for broadband grant programs. BEAD subgrantees must attest to a cybersecurity risk management plan reflecting the NIST framework and Executive Order 14028, plus a separate supply chain plan based on NISTIR 8276 and NIST SP 800-161, reevaluated periodically and resubmitted within 30 days of any substantive change.
  • Support FCC CPNI obligations, lawful-process handling, and breach notification analysis across a multi-state footprint where notification clocks differ by state.
  • Produce the evidence pack that satisfies auditors and cyber insurance underwriters without a fire drill each renewal.
  • Define and report the metrics that go to the Risk Committee and executive leadership.

Internal Program Leadership and Vendors

  • Lead major internal security initiatives end to end — zero-trust network access, privileged access management, out-of-band access resilience, internal endpoint protection consolidation, internal log platform decisions — including the implementation, not only the selection. Initiatives belonging to the managed services line are out of scope.
  • Run vendor evaluations with real cost modeling sized to a mid-tier budget. The enterprise answer is frequently the wrong answer; knowing when to buy the smaller product is part of the job.
  • Scope and govern third-party security engagements the company commissions, and own remediation of their findings.
  • Support contract and renewal negotiation with technical justification; provide budget input and multi-year capital planning.
  • Participate in threat-sharing appropriate to a smaller provider, including the small broadband provider ISAC community.

Incident Command and Readiness

  • Serve as technical incident commander for major security incidents across properties, and as the hands during containment when nobody else can do it.
  • Maintain forensic readiness: log retention, evidence handling, and the break-glass access path.
  • Run tabletop exercises; coordinate with legal and compliance on notification thresholds and regulatory exposure.

Automation and People

  • Drive policy-as-code, drift detection, rollback capability, and tamper-evident audit evidence in the automation pipeline — and write the code.
  • Keep AI tooling in an advisory layer, out of the control path, with documented data-handling standards.
  • Mentor Tier I and II engineers and build the bench that makes this role survivable when the incumbent is unavailable.

Required Qualifications

  • Eight or more years in network and security engineering, with at least three in a senior or lead capacity setting standards rather than following them, while remaining hands-on.
  • Proven multi-site security architecture experience where the candidate both designed and implemented the result.
  • Expert-level firewall platform command, including centralized management at scale and migration leadership.
  • Service-provider security depth: BGP security controls, DDoS mitigation strategy, subscriber-network separation, and an understanding of how carrier plant differs from enterprise infrastructure.
  • Demonstrated ownership of a vulnerability and hardening program, including reporting to executives or a risk committee.
  • A body of written standards and documentation they can point to and discuss. This is a screening requirement, not a preference.
  • Self-directed at the roadmap level: able to enter an environment with no backlog and produce a defensible 12-month plan.
  • Able to write and present a recommendation a non-technical executive can act on.

Preferred Qualifications

  • CISSP or CISM; expert-level platform certification (PCNSE, NSE 8, CCIE Security).
  • Prior experience at a regional operator, cooperative, or municipal provider — someone who has done this with a small team and a real budget rather than an enterprise one.
  • Experience standardizing environments acquired or operated independently, where the starting point was six different ways of doing the same thing.
  • Regulated-data experience: CPNI, PCI DSS scope reduction, CALEA-adjacent handling.
  • Grant compliance exposure, particularly BEAD or state broadband program security requirements.
  • Prior ownership of a security budget or vendor portfolio.

Authority and Self-Direction

Sets the security roadmap and their own work against it. Approves architecture and cross-property standards; owns the exception register. Final technical escalation. Escalates to the Vice President for budget, contractual, or organizational decisions only. Accountable for outcomes on a quarterly cadence rather than for task-level activity.

First-Year Success Measures

  • Full ownership of the firewall estate established: one inventory of record, no firewall out of support, high-availability pairs tested, and a published refresh plan.
  • A single firewall, access-control, and segmentation standard published and adopted at all six properties, with a documented deviation list rather than six local conventions.
  • Complete, current security documentation for all six properties, with a review cadence that holds after the initial push.
  • A 12-month posture roadmap in place, sequenced and defensible, with the first two initiatives delivered rather than planned.
  • Grant, audit, and insurance evidence current and maintained on a calendar rather than a scramble.
  • Sustained reduction in critical findings and in the age of open findings.
  • Two engineers capable of leading a migration independently.

Conduct and Data Handling

  • Handles customer proprietary network information and subscriber data. Strict adherence to CPNI, lawful-process, and internal data-classification standards is a condition of the role.
  • Security tooling and administrative access are used only for authorized purposes; all privileged activity is logged and reviewable.
  • AI tooling is used within the published data-handling standard — advisory only, never in the control path for production changes.

Working Conditions

  • Remote, but must reside within driving distance of one of our property locations: Winona, MN; Sergeant Bluff, IA; Maricopa, AZ; Hagerstown, MD; Burlington, VT; or New Knoxville, OH
  • Office, data center, headend, and hub site environments; occasional work in equipment rooms and outside-plant facilities.
  • Ability to lift and position equipment up to 50 pounds and to rack and cable hardware.
  • After-hours and weekend maintenance windows; participation in an on-call rotation with defined response expectations.
  • Extended periods at a workstation; travel by vehicle between properties in multiple states.

Why Join Schurz Broadband Group?

When you join Schurz Broadband Group, you’ll be part of an award-winning company and team. We offer a comprehensive benefits package, including:

  • Group health & dental insurance
  • 401(k) program with company match
  • Generous PTO program
  • Company wellness program
  • Employer-paid short- and long-term disability
  • And much more!

We are committed to providing an environment that gives each employee the opportunity to nurture their gifts and achieve their potential. Our mission is to pass on to future generations—customers, employees, communities, and owners—an organization that is even stronger and better than it is today.

Schurz Communications and its subsidiaries’ strategic objectives:

  • We will attract, invest in, communicate with, and retain top talent.
  • We will innovate, partner, experiment and create a better future together.
  • We strive to continuously improve operating performance to ensure sustained growth.
  • We will dynamically grow revenues by building and nurturing mutually beneficial and profitable customer relationships.
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Security Engineer III in Remote vacancy
  •  .... Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving...  ...About the Role F5 Distributed Cloud is seeking a Security Engineer III to advance our monitoring, detection, and incident response... 
    Suggested
    Work at office
    Local area
    Remote work
    Work from home
    Shift work
    Weekend work

    F5 Networks

    Reston, VA
    5 days ago
  • $108k - $138k

     ...Security Engineer III The Security Engineer III is a senior individual contributor responsible for security architecture, firewall infrastructure, standards, and security posture across a multi-site broadband environment. You will own the firewall estate, establish... 
    Suggested
    Contract work
    Temporary work
    Work at office
    Remote work

    Jobgether

    United States
    1 day ago
  • $146.4k - $250.2k

     ...GENERAL PURPOSE The Identity and Access Management (IAM) Engineer is responsible for envisioning and taking steps to implement IAM...  ...diligence functions. Serves as a liaison to the other Information Security and IT functional groups, influencing outcomes as appropriate.... 
    Suggested
    Full time
    Work at office
    Local area
    Remote work

    Ross Stores

    Dublin, CA
    17 days ago
  • $175.1k - $236.9k

    Come join Earth's most customer-centric company!Amazon is looking for a Security Engineering Manager with strong leadership skills and a passion for security to lead a team that ensures our AI applications are designed and built to the highest standards. Your mission is... 
    Suggested
    Remote work
    Flexible hours

    Amazon

    Seattle, WA
    1 day ago
  • $102.5k - $188.9k

     ...our clients to operate with resilience, grow with confidence, and proactively manage to secure success. Deloitte's Cyber Defense and Resilience offering is seeking a SIEM Engineer to support security monitoring, detection engineering, and incident analysis across... 
    Suggested
    Work at office
    Remote work

    Deloitte LLP

    Maryland, MD
    9 days ago
  •  ...possible, with the ultimate goal of enabling human life on Mars.SECURITY ENGINEER (OT)SpaceX is looking for a Security Engineer (OT) to join...  ...ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C.... 
    Permanent employment
    Remote work
    Weekend work

    SpaceX

    Cape Canaveral, FL
    3 days ago
  • $107.7k - $179.5k

     ...we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success. Work You'll Do As a Project Security Engineer III on the Cyber Identity Engineering team, you will... Designing, implementing, and supporting identity... 
    Local area

    Deloitte LLP

    Virginia
    14 hours ago
  • $50 - $52 per hour

    CW-Cyber Security Analyst III Immediate need for a talented CW-Cyber Security Analyst III. This is a 18+ months contract opportunity with long-term potential and is located in Iselin/ Chicago/ Portland (Hybrid). Please review the job description below and contact me ASAP... 
    Contract work
    Local area
    Immediate start

    Pyramid Corporation

    Iselin, NJ
    3 days ago
  • Cyber Security Analyst III Location US-SC-North Charleston ID 2026-11524 Category Cyber Security Position Type Regular Full-Time Application...  ...compliance activities Coordinating with platform engineers, network engineers, system administrators, developers, mission... 
    Full time
    For contractors
    Local area

    Scientific Research

    North Charleston, SC
    1 day ago
  • $165k - $242k

     ...at  What You'll Do: The Enterprise Security team at CoreWeave is responsible for securing...  ...About the Role: As a Senior Security Engineer, Enterprise Security , you'll design and...  ...permanent resident (green card holder), (iii) refugee under 8 U.S.C. § 1157, or (iv)... 
    Permanent employment
    Full time
    Temporary work
    For contractors
    Casual work
    Work at office
    Remote work
    Flexible hours

    CoreWeave

    Sunnyvale, CA
    18 days ago
  • $108k - $140k

     ...candidate possesses a strong understanding of building internal security tooling and data pipelines using public cloud infrastructure....  ...’s degree, or equivalent experience, in Math, Science, Engineering, or Business fields. - Self-directed with the ability to identify... 
    Full time
    Temporary work
    Remote work
    Worldwide
    Flexible hours

    Spycloud

    Remote
    24 days ago
  • Cyber Network Forensic Analyst III, TS/SCI Raytheon Technologies provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based, network-based and cloud-based cybersecurity... 
    Immediate start
    Remote work

    Raytheon Technologies

    Arlington, VA
    4 days ago
  • $165k - $280k

     ...goal of enabling human life on Mars.SR. NETWORK SECURITY ENGINEERSpaceX is looking for a Sr. Network Security Engineer to design, implement, and operate security for SpaceX...  ..., permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee... 
    Permanent employment
    Temporary work
    Remote work
    Flexible hours
    Weekend work

    SpaceX

    Palo Alto, CA
    4 days ago
  • OverviewThe Security Engineer II is a mid-level individual contributor responsible for implementing, administering, and maintaining the security...  ..., to designs and standards set by the Security Engineer III and the IT Security Architect.Assess systems and security tooling... 
    Temporary work
    Work at office
    Immediate start
    Flexible hours

    Sprouts Farmers Market

    Phoenix, AZ
    2 days ago
  • $69.4k - $158k

    Undersea Systems Security EngineerThe Opportunity: Join our team as a Systems Security Engineer supporting cybersecurity and systems security analysis for U.S. Navy afloat...  ...challengesMaster’s degree in a technical field DoD IAT Level III CertificationClearance:Applicants selected... 
    Full time
    Contract work
    Part time
    Local area
    Remote work

    Booz Allen Hamilton

    Washington DC
    14 hours ago
  •  ...Solution IT Inc. is looking for Cloudflare / Edge Security Engineer for one of its clients in Remote Job Title: Cloudflare / Edge Security...  ...the original message. Thank you. Under Bill s.1618 Title III passed by the 105th U.S. Congress this mail cannot be considered... 
    Full time
    Immediate start
    Remote work

    SolutionIT

    Remote
    2 days ago
  • $155k - $175k

     ...is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Red Team Security Engineer III based in United States. This role focuses on advanced offensive security operations supporting critical cybersecurity... 
    Full time
    Apprenticeship
    Remote work

    jobgether

    United States
    2 days ago
  •  ...the warfighter, designing, building, and securing modern digital capabilities across cloud,...  ...Operational Architecture (NOA), working alongside engineers and operators to deliver resilient,...  ...experienced Systems Network Engineer II/III to support critical and urgent program... 
    Remote work

    PMAT

    San Diego, CA
    24 days ago
  • $100.46k - $161.38k

     ...position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Cyber Security Analyst III - Digital Forensics and Incident Response based in United States. This role supports enterprise cybersecurity operations... 
    Full time
    Remote work

    jobgether

    United States
    8 days ago
  • $96k - $120k

     ...• Trust Position Purpose Summary: The Network Infrastructure Engineer III provides expert-level implementation, configuration, support,...  ...enterprise network environments, including LAN, WAN, wireless, and security infrastructure. This role operates across corporate and active... 
    Work experience placement
    Work at office
    Local area
    Remote work

    Packaging Corporation of America

    Lake Forest, IL
    2 days ago
  • $107.9k - $195.05k

     ...an exciting opening for you as our next  TS/SCI cleared Cyber Security Engineer supporting a long-term DIA-NDOC DOMEX Technology Platform (DTP...  ...), configuring Nessus, Splunk Multiple IAT/IAM II or III advanced certifications such as, CISSP-ISSAP/ISSEP, CISM, CCSP... 
    Contract work
    Interim role
    Local area
    Immediate start
    Remote work
    Flexible hours

    Leidos

    Gaithersburg, MD
    2 days ago
  • $184k - $208k

     ...Muon seeks a Senior Network Security Engineer to join our team. The ideal candidate is a seasoned network security professional who will design...  ..., (ii) U.S. lawful, permanent resident (green card holder), (iii) refugee under 8 U.S.C. § 1157, or (iv) asylee under 8 U.S.C.... 
    Permanent employment
    Full time
    Temporary work
    Work at office
    Remote work
    Flexible hours

    Muon Space, Inc.

    San Jose, CA
    15 hours ago
  • $116k - $162.5k

     ..., evolve, and shape what comes next on our mission to make better food accessible to everyone. THE OPPORTUNITYAs the Senior Engineer, IT Security Engineering, under minimal supervision, you will participate in the efforts to implement and mature security capabilities that... 
    Work at office
    Local area
    Remote work
    Work from home
    Shift work

    Chipotle Mexican Grill

    Newport Beach, CA
    1 day ago
  •  ...Job Description Job Description Title:  Network Engineer III (L3) Department:  Service Delivery Employment Type:  Part-Time Contractor...  ...strategic guidance on network architecture, modernization, security, scalability, and operational efficiency. Lead technical... 
    Contract work
    Part time
    For contractors
    Remote work

    GMI

    Scottsdale, AZ
    17 days ago
  • $78.71k - $126.59k

     ...Electric Association as a Systems & Network Engineer in the beautiful city of Fairbanks, where you'll help design, implement, secure, and maintain the technology infrastructure...  ...opportunities from Engineer I through Engineer III, based on experience, technical expertise,... 
    Temporary work
    For contractors

    Golden Valley Electric Association

    Fairbanks, AK
    18 days ago
  • $132k - $198k

     ...obstructive urinary retention, and much more.The Senior Product Security Engineer - Embedded IoT is responsible for cybersecurity architecture...  ...degree that satisfies the requirements of 8 C.F.R. § 214.2(h)(4)(iii)(A) is required.Physical Job RequirementsThe above statements... 
    Full time
    H1b
    Work at office
    Local area
    Immediate start
    Remote work
    Flexible hours

    Medtronic

    Minneapolis, MN
    1 day ago
  • $164k - $242k

     ...What You'll Do: CoreWeave's Network Security team ensures network infrastructure is secure...  ...and compliant. Our team partners with engineering, product teams, and partners to build...  ...permanent resident (green card holder), (iii) refugee under 8 U.S.C. § 1157, or (iv)... 
    Permanent employment
    Full time
    Temporary work
    Casual work
    Work at office
    Remote work
    Flexible hours

    CoreWeave

    Livingston, NJ
    a month ago
  •  ...Job Description Job Description Security Engineer – Splunk                                                Location: Fayetteville, NC...  ...Required Skills DoD 8570 Certification in the IAT Level III and/or CNDSP tier or obtain within six months.  Splunk Enterprise... 
    Work experience placement
    Local area
    Remote work

    SOFtact Solutions

    Fayetteville, NC
    a month ago
  • $200k - $255k

     ...Instead of accepting the status quo, we decided to fix it. National security professionals, journalists, parents, and everyone in between...  ...a member of our team, you will collaborate with world-class engineers, architects, and visionaries, and work across organizational... 
    Odd job
    Immediate start
    Remote work

    Cape

    United States
    3 days ago
  •  ...Description Job Description We are seeking an Information Systems Security Engineer (ISSE) to design, build, and integrate security into all...  ...• DoW 8570/8140 IASAE Level II compliance required (Level III preferred) Nice to have • Experience securing AI/ML systems... 
    Full time
    Remote work
    Home office
    Relocation package
    Flexible hours

    Spear AI

    Washington DC
    a month ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Engineer III. Be the first to apply!