Security Engineer III
$108k - $138kSchurz Communications
Position Summary
This role owns the firewall estate, security architecture, and standards for all six properties, the documentation library behind them, and the posture roadmap that sequences the work, and personally implements the hardest parts of it. This is a senior individual contributor role, not a management position. Expect to be writing a standard in the morning, converting a property to it that night, and presenting the result to the Risk Committee the following week.
Position Title : Security Engineer III
Location : Remote (within driving distance of a Schurz property, see locations below)
Rate: $108,000 - $138,000 annually
Reports to : VP, Business Technology
Position Type : Full-time
Essential Responsibilities
Firewall Estate Ownership — Primary Responsibility
- Own the firewall estate for all six properties: the standard, the platform strategy, the refresh roadmap, and the vendor relationship. This is the accountability that does not move.
- Define the firewall reference architecture — platform selection, high-availability model, management topology, zone model, and the policy standard every property implements.
- Decide whether the estate consolidates onto one vendor and drive that conversion, or document why a mixed estate is the right answer and how it will be managed consistently.
- Own the multi-year refresh and capacity plan as a budget line, and defend it.
- Personally execute the high-risk conversions, migrations, and cutovers rather than delegating them.
- Hold final approval on every firewall change that deviates from standard and on every exception that stays open.
Architecture and Standards
- Define the access-control and segmentation reference architecture for all six properties, replacing six locally grown conventions with one standard plus a documented deviation list.
- Author the hardening baselines platform by platform, and the method for measuring drift against them.
- Own the standards library itself: versioning, review cadence, ownership, approval path, and retirement of standards that no longer hold.
- Own the rule lifecycle governance model — naming, ownership, review cadence, expiration, exception register.
- Lead the conversion of each property onto the standard.
- Review and approve designs produced by Tier II; approve or reject deviations.
Internal Network Understanding
- Hold the authoritative picture of how all six networks actually work — edge, core, plant, subscriber, and management planes — including where they differ and why.
- Maintain the trust-boundary and data-flow model that segmentation decisions are made against, and keep it accurate as platform consolidation moves things.
- Be the person who can answer, without research, what is exposed where and what would happen if a given control failed.
Documentation as a Deliverable
- Own the documentation standard: what must exist for every property, in what form, reviewed how often, and who is accountable when it drifts.
- Ensure current security architecture documentation, diagrams, standards, runbooks, and decision records exist for all six properties, and enforce that they stay current rather than decaying between audits.
- Write the decision records that explain why a standard is what it is, so the next engineer does not relitigate settled questions.
Posture, Compliance, and Evidence
- Maintain a security posture roadmap mapped to NIST CSF and CIS Controls, with a defensible current-state assessment behind it, and sequence the work against it.
- Own the cybersecurity and supply chain risk management plans required for broadband grant programs. BEAD subgrantees must attest to a cybersecurity risk management plan reflecting the NIST framework and Executive Order 14028, plus a separate supply chain plan based on NISTIR 8276 and NIST SP 800-161, reevaluated periodically and resubmitted within 30 days of any substantive change.
- Support FCC CPNI obligations, lawful-process handling, and breach notification analysis across a multi-state footprint where notification clocks differ by state.
- Produce the evidence pack that satisfies auditors and cyber insurance underwriters without a fire drill each renewal.
- Define and report the metrics that go to the Risk Committee and executive leadership.
Internal Program Leadership and Vendors
- Lead major internal security initiatives end to end — zero-trust network access, privileged access management, out-of-band access resilience, internal endpoint protection consolidation, internal log platform decisions — including the implementation, not only the selection. Initiatives belonging to the managed services line are out of scope.
- Run vendor evaluations with real cost modeling sized to a mid-tier budget. The enterprise answer is frequently the wrong answer; knowing when to buy the smaller product is part of the job.
- Scope and govern third-party security engagements the company commissions, and own remediation of their findings.
- Support contract and renewal negotiation with technical justification; provide budget input and multi-year capital planning.
- Participate in threat-sharing appropriate to a smaller provider, including the small broadband provider ISAC community.
Incident Command and Readiness
- Serve as technical incident commander for major security incidents across properties, and as the hands during containment when nobody else can do it.
- Maintain forensic readiness: log retention, evidence handling, and the break-glass access path.
- Run tabletop exercises; coordinate with legal and compliance on notification thresholds and regulatory exposure.
Automation and People
- Drive policy-as-code, drift detection, rollback capability, and tamper-evident audit evidence in the automation pipeline — and write the code.
- Keep AI tooling in an advisory layer, out of the control path, with documented data-handling standards.
- Mentor Tier I and II engineers and build the bench that makes this role survivable when the incumbent is unavailable.
Required Qualifications
- Eight or more years in network and security engineering, with at least three in a senior or lead capacity setting standards rather than following them, while remaining hands-on.
- Proven multi-site security architecture experience where the candidate both designed and implemented the result.
- Expert-level firewall platform command, including centralized management at scale and migration leadership.
- Service-provider security depth: BGP security controls, DDoS mitigation strategy, subscriber-network separation, and an understanding of how carrier plant differs from enterprise infrastructure.
- Demonstrated ownership of a vulnerability and hardening program, including reporting to executives or a risk committee.
- A body of written standards and documentation they can point to and discuss. This is a screening requirement, not a preference.
- Self-directed at the roadmap level: able to enter an environment with no backlog and produce a defensible 12-month plan.
- Able to write and present a recommendation a non-technical executive can act on.
Preferred Qualifications
- CISSP or CISM; expert-level platform certification (PCNSE, NSE 8, CCIE Security).
- Prior experience at a regional operator, cooperative, or municipal provider — someone who has done this with a small team and a real budget rather than an enterprise one.
- Experience standardizing environments acquired or operated independently, where the starting point was six different ways of doing the same thing.
- Regulated-data experience: CPNI, PCI DSS scope reduction, CALEA-adjacent handling.
- Grant compliance exposure, particularly BEAD or state broadband program security requirements.
- Prior ownership of a security budget or vendor portfolio.
Authority and Self-Direction
Sets the security roadmap and their own work against it. Approves architecture and cross-property standards; owns the exception register. Final technical escalation. Escalates to the Vice President for budget, contractual, or organizational decisions only. Accountable for outcomes on a quarterly cadence rather than for task-level activity.
First-Year Success Measures
- Full ownership of the firewall estate established: one inventory of record, no firewall out of support, high-availability pairs tested, and a published refresh plan.
- A single firewall, access-control, and segmentation standard published and adopted at all six properties, with a documented deviation list rather than six local conventions.
- Complete, current security documentation for all six properties, with a review cadence that holds after the initial push.
- A 12-month posture roadmap in place, sequenced and defensible, with the first two initiatives delivered rather than planned.
- Grant, audit, and insurance evidence current and maintained on a calendar rather than a scramble.
- Sustained reduction in critical findings and in the age of open findings.
- Two engineers capable of leading a migration independently.
Conduct and Data Handling
- Handles customer proprietary network information and subscriber data. Strict adherence to CPNI, lawful-process, and internal data-classification standards is a condition of the role.
- Security tooling and administrative access are used only for authorized purposes; all privileged activity is logged and reviewable.
- AI tooling is used within the published data-handling standard — advisory only, never in the control path for production changes.
Working Conditions
- Remote, but must reside within driving distance of one of our property locations: Winona, MN; Sergeant Bluff, IA; Maricopa, AZ; Hagerstown, MD; Burlington, VT; or New Knoxville, OH
- Office, data center, headend, and hub site environments; occasional work in equipment rooms and outside-plant facilities.
- Ability to lift and position equipment up to 50 pounds and to rack and cable hardware.
- After-hours and weekend maintenance windows; participation in an on-call rotation with defined response expectations.
- Extended periods at a workstation; travel by vehicle between properties in multiple states.
Why Join Schurz Broadband Group?
When you join Schurz Broadband Group, you’ll be part of an award-winning company and team. We offer a comprehensive benefits package, including:
- Group health & dental insurance
- 401(k) program with company match
- Generous PTO program
- Company wellness program
- Employer-paid short- and long-term disability
- And much more!
We are committed to providing an environment that gives each employee the opportunity to nurture their gifts and achieve their potential. Our mission is to pass on to future generations—customers, employees, communities, and owners—an organization that is even stronger and better than it is today.
Schurz Communications and its subsidiaries’ strategic objectives:
- We will attract, invest in, communicate with, and retain top talent.
- We will innovate, partner, experiment and create a better future together.
- We strive to continuously improve operating performance to ensure sustained growth.
- We will dynamically grow revenues by building and nurturing mutually beneficial and profitable customer relationships.
- .... Our teams empower organizations across the globe to create, secure, and run applications that enhance how we experience our evolving... ...About the Role F5 Distributed Cloud is seeking a Security Engineer III to advance our monitoring, detection, and incident response...SuggestedWork at officeLocal areaRemote workWork from homeShift workWeekend work
$108k - $138k
...Security Engineer III The Security Engineer III is a senior individual contributor responsible for security architecture, firewall infrastructure, standards, and security posture across a multi-site broadband environment. You will own the firewall estate, establish...SuggestedContract workTemporary workWork at officeRemote work$146.4k - $250.2k
...GENERAL PURPOSE The Identity and Access Management (IAM) Engineer is responsible for envisioning and taking steps to implement IAM... ...diligence functions. Serves as a liaison to the other Information Security and IT functional groups, influencing outcomes as appropriate....SuggestedFull timeWork at officeLocal areaRemote work$175.1k - $236.9k
Come join Earth's most customer-centric company!Amazon is looking for a Security Engineering Manager with strong leadership skills and a passion for security to lead a team that ensures our AI applications are designed and built to the highest standards. Your mission is...SuggestedRemote workFlexible hours$102.5k - $188.9k
...our clients to operate with resilience, grow with confidence, and proactively manage to secure success. Deloitte's Cyber Defense and Resilience offering is seeking a SIEM Engineer to support security monitoring, detection engineering, and incident analysis across...SuggestedWork at officeRemote work- ...possible, with the ultimate goal of enabling human life on Mars.SECURITY ENGINEER (OT)SpaceX is looking for a Security Engineer (OT) to join... ...ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C....Permanent employmentRemote workWeekend work
$107.7k - $179.5k
...we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success. Work You'll Do As a Project Security Engineer III on the Cyber Identity Engineering team, you will... Designing, implementing, and supporting identity...Local area$50 - $52 per hour
CW-Cyber Security Analyst III Immediate need for a talented CW-Cyber Security Analyst III. This is a 18+ months contract opportunity with long-term potential and is located in Iselin/ Chicago/ Portland (Hybrid). Please review the job description below and contact me ASAP...Contract workLocal areaImmediate start- Cyber Security Analyst III Location US-SC-North Charleston ID 2026-11524 Category Cyber Security Position Type Regular Full-Time Application... ...compliance activities Coordinating with platform engineers, network engineers, system administrators, developers, mission...Full timeFor contractorsLocal area
$165k - $242k
...at What You'll Do: The Enterprise Security team at CoreWeave is responsible for securing... ...About the Role: As a Senior Security Engineer, Enterprise Security , you'll design and... ...permanent resident (green card holder), (iii) refugee under 8 U.S.C. § 1157, or (iv)...Permanent employmentFull timeTemporary workFor contractorsCasual workWork at officeRemote workFlexible hours$108k - $140k
...candidate possesses a strong understanding of building internal security tooling and data pipelines using public cloud infrastructure.... ...’s degree, or equivalent experience, in Math, Science, Engineering, or Business fields. - Self-directed with the ability to identify...Full timeTemporary workRemote workWorldwideFlexible hours- Cyber Network Forensic Analyst III, TS/SCI Raytheon Technologies provides remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based, network-based and cloud-based cybersecurity...Immediate startRemote work
$165k - $280k
...goal of enabling human life on Mars.SR. NETWORK SECURITY ENGINEERSpaceX is looking for a Sr. Network Security Engineer to design, implement, and operate security for SpaceX... ..., permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee...Permanent employmentTemporary workRemote workFlexible hoursWeekend work- OverviewThe Security Engineer II is a mid-level individual contributor responsible for implementing, administering, and maintaining the security... ..., to designs and standards set by the Security Engineer III and the IT Security Architect.Assess systems and security tooling...Temporary workWork at officeImmediate startFlexible hours
$69.4k - $158k
Undersea Systems Security EngineerThe Opportunity: Join our team as a Systems Security Engineer supporting cybersecurity and systems security analysis for U.S. Navy afloat... ...challengesMaster’s degree in a technical field DoD IAT Level III CertificationClearance:Applicants selected...Full timeContract workPart timeLocal areaRemote work- ...Solution IT Inc. is looking for Cloudflare / Edge Security Engineer for one of its clients in Remote Job Title: Cloudflare / Edge Security... ...the original message. Thank you. Under Bill s.1618 Title III passed by the 105th U.S. Congress this mail cannot be considered...Full timeImmediate startRemote work
$155k - $175k
...is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Red Team Security Engineer III based in United States. This role focuses on advanced offensive security operations supporting critical cybersecurity...Full timeApprenticeshipRemote work- ...the warfighter, designing, building, and securing modern digital capabilities across cloud,... ...Operational Architecture (NOA), working alongside engineers and operators to deliver resilient,... ...experienced Systems Network Engineer II/III to support critical and urgent program...Remote work
$100.46k - $161.38k
...position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Cyber Security Analyst III - Digital Forensics and Incident Response based in United States. This role supports enterprise cybersecurity operations...Full timeRemote work$96k - $120k
...• Trust Position Purpose Summary: The Network Infrastructure Engineer III provides expert-level implementation, configuration, support,... ...enterprise network environments, including LAN, WAN, wireless, and security infrastructure. This role operates across corporate and active...Work experience placementWork at officeLocal areaRemote work$107.9k - $195.05k
...an exciting opening for you as our next TS/SCI cleared Cyber Security Engineer supporting a long-term DIA-NDOC DOMEX Technology Platform (DTP... ...), configuring Nessus, Splunk Multiple IAT/IAM II or III advanced certifications such as, CISSP-ISSAP/ISSEP, CISM, CCSP...Contract workInterim roleLocal areaImmediate startRemote workFlexible hours$184k - $208k
...Muon seeks a Senior Network Security Engineer to join our team. The ideal candidate is a seasoned network security professional who will design... ..., (ii) U.S. lawful, permanent resident (green card holder), (iii) refugee under 8 U.S.C. § 1157, or (iv) asylee under 8 U.S.C....Permanent employmentFull timeTemporary workWork at officeRemote workFlexible hours$116k - $162.5k
..., evolve, and shape what comes next on our mission to make better food accessible to everyone. THE OPPORTUNITYAs the Senior Engineer, IT Security Engineering, under minimal supervision, you will participate in the efforts to implement and mature security capabilities that...Work at officeLocal areaRemote workWork from homeShift work- ...Job Description Job Description Title: Network Engineer III (L3) Department: Service Delivery Employment Type: Part-Time Contractor... ...strategic guidance on network architecture, modernization, security, scalability, and operational efficiency. Lead technical...Contract workPart timeFor contractorsRemote work
$78.71k - $126.59k
...Electric Association as a Systems & Network Engineer in the beautiful city of Fairbanks, where you'll help design, implement, secure, and maintain the technology infrastructure... ...opportunities from Engineer I through Engineer III, based on experience, technical expertise,...Temporary workFor contractors$132k - $198k
...obstructive urinary retention, and much more.The Senior Product Security Engineer - Embedded IoT is responsible for cybersecurity architecture... ...degree that satisfies the requirements of 8 C.F.R. § 214.2(h)(4)(iii)(A) is required.Physical Job RequirementsThe above statements...Full timeH1bWork at officeLocal areaImmediate startRemote workFlexible hours$164k - $242k
...What You'll Do: CoreWeave's Network Security team ensures network infrastructure is secure... ...and compliant. Our team partners with engineering, product teams, and partners to build... ...permanent resident (green card holder), (iii) refugee under 8 U.S.C. § 1157, or (iv)...Permanent employmentFull timeTemporary workCasual workWork at officeRemote workFlexible hours- ...Job Description Job Description Security Engineer – Splunk Location: Fayetteville, NC... ...Required Skills DoD 8570 Certification in the IAT Level III and/or CNDSP tier or obtain within six months. Splunk Enterprise...Work experience placementLocal areaRemote work
$200k - $255k
...Instead of accepting the status quo, we decided to fix it. National security professionals, journalists, parents, and everyone in between... ...a member of our team, you will collaborate with world-class engineers, architects, and visionaries, and work across organizational...Odd jobImmediate startRemote work- ...Description Job Description We are seeking an Information Systems Security Engineer (ISSE) to design, build, and integrate security into all... ...• DoW 8570/8140 IASAE Level II compliance required (Level III preferred) Nice to have • Experience securing AI/ML systems...Full timeRemote workHome officeRelocation packageFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer III. Be the first to apply!
- dlp security engineer Remote
- application security engineer Remote
- principal security engineer Remote
- security software engineer Remote
- aws cloud security engineer Remote
- sr security engineer Remote
- endpoint security engineer Remote
- offensive security engineer Remote
- sr information security engineer Remote
- security infrastructure engineer Remote




