Security Engineer III
Quick Summary
the standard, the platform strategy, the refresh roadmap, and the vendor relationship. This is the accountability that does not move.
BGP security controls, DDoS mitigation strategy, subs
This role owns the firewall estate, security architecture, and standards for all six properties, the documentation library behind them, and the posture roadmap that sequences the work, and personally implements the hardest parts of it. This is a senior individual contributor role, not a management position. Expect to be writing a standard in the morning, converting a property to it that night, and presenting the result to the Risk Committee the following week.
Responsibilities
~1 min read- →Own the firewall estate for all six properties: the standard, the platform strategy, the refresh roadmap, and the vendor relationship. This is the accountability that does not move.
- →Define the firewall reference architecture — platform selection, high-availability model, management topology, zone model, and the policy standard every property implements.
- →Decide whether the estate consolidates onto one vendor and drive that conversion, or document why a mixed estate is the right answer and how it will be managed consistently.
- →Own the multi-year refresh and capacity plan as a budget line, and defend it.
- →Personally execute the high-risk conversions, migrations, and cutovers rather than delegating them.
- →Hold final approval on every firewall change that deviates from standard and on every exception that stays open.
- Define the access-control and segmentation reference architecture for all six properties, replacing six locally grown conventions with one standard plus a documented deviation list.
- Author the hardening baselines platform by platform, and the method for measuring drift against them.
- Own the standards library itself: versioning, review cadence, ownership, approval path, and retirement of standards that no longer hold.
- Own the rule lifecycle governance model — naming, ownership, review cadence, expiration, exception register.
- Lead the conversion of each property onto the standard.
- Review and approve designs produced by Tier II; approve or reject deviations.
- Hold the authoritative picture of how all six networks actually work — edge, core, plant, subscriber, and management planes — including where they differ and why.
- Maintain the trust-boundary and data-flow model that segmentation decisions are made against, and keep it accurate as platform consolidation moves things.
- Be the person who can answer, without research, what is exposed where and what would happen if a given control failed.
- Own the documentation standard: what must exist for every property, in what form, reviewed how often, and who is accountable when it drifts.
- Ensure current security architecture documentation, diagrams, standards, runbooks, and decision records exist for all six properties, and enforce that they stay current rather than decaying between audits.
- Write the decision records that explain why a standard is what it is, so the next engineer does not relitigate settled questions.
- Maintain a security posture roadmap mapped to NIST CSF and CIS Controls, with a defensible current-state assessment behind it, and sequence the work against it.
- Own the cybersecurity and supply chain risk management plans required for broadband grant programs. BEAD subgrantees must attest to a cybersecurity risk management plan reflecting the NIST framework and Executive Order 14028, plus a separate supply chain plan based on NISTIR 8276 and NIST SP 800-161, reevaluated periodically and resubmitted within 30 days of any substantive change.
- Support FCC CPNI obligations, lawful-process handling, and breach notification analysis across a multi-state footprint where notification clocks differ by state.
- Produce the evidence pack that satisfies auditors and cyber insurance underwriters without a fire drill each renewal.
- Define and report the metrics that go to the Risk Committee and executive leadership.
- Lead major internal security initiatives end to end — zero-trust network access, privileged access management, out-of-band access resilience, internal endpoint protection consolidation, internal log platform decisions — including the implementation, not only the selection. Initiatives belonging to the managed services line are out of scope.
- Run vendor evaluations with real cost modeling sized to a mid-tier budget. The enterprise answer is frequently the wrong answer; knowing when to buy the smaller product is part of the job.
- Scope and govern third-party security engagements the company commissions, and own remediation of their findings.
- Support contract and renewal negotiation with technical justification; provide budget input and multi-year capital planning.
- Participate in threat-sharing appropriate to a smaller provider, including the small broadband provider ISAC community.
- Serve as technical incident commander for major security incidents across properties, and as the hands during containment when nobody else can do it.
- Maintain forensic readiness: log retention, evidence handling, and the break-glass access path.
- Run tabletop exercises; coordinate with legal and compliance on notification thresholds and regulatory exposure.
- Drive policy-as-code, drift detection, rollback capability, and tamper-evident audit evidence in the automation pipeline — and write the code.
- Keep AI tooling in an advisory layer, out of the control path, with documented data-handling standards.
- Mentor Tier I and II engineers and build the bench that makes this role survivable when the incumbent is unavailable.
Requirements
~2 min read- Eight or more years in network and security engineering, with at least three in a senior or lead capacity setting standards rather than following them, while remaining hands-on.
- Proven multi-site security architecture experience where the candidate both designed and implemented the result.
- Expert-level firewall platform command, including centralized management at scale and migration leadership.
- Service-provider security depth: BGP security controls, DDoS mitigation strategy, subscriber-network separation, and an understanding of how carrier plant differs from enterprise infrastructure.
- Demonstrated ownership of a vulnerability and hardening program, including reporting to executives or a risk committee.
- A body of written standards and documentation they can point to and discuss. This is a screening requirement, not a preference.
- Self-directed at the roadmap level: able to enter an environment with no backlog and produce a defensible 12-month plan.
- Able to write and present a recommendation a non-technical executive can act on.
- CISSP or CISM; expert-level platform certification (PCNSE, NSE 8, CCIE Security).
- Prior experience at a regional operator, cooperative, or municipal provider — someone who has done this with a small team and a real budget rather than an enterprise one.
- Experience standardizing environments acquired or operated independently, where the starting point was six different ways of doing the same thing.
- Regulated-data experience: CPNI, PCI DSS scope reduction, CALEA-adjacent handling.
- Grant compliance exposure, particularly BEAD or state broadband program security requirements.
- Prior ownership of a security budget or vendor portfolio.
Sets the security roadmap and their own work against it. Approves architecture and cross-property standards; owns the exception register. Final technical escalation. Escalates to the Vice President for budget, contractual, or organizational decisions only. Accountable for outcomes on a quarterly cadence rather than for task-level activity.
- Full ownership of the firewall estate established: one inventory of record, no firewall out of support, high-availability pairs tested, and a published refresh plan.
- A single firewall, access-control, and segmentation standard published and adopted at all six properties, with a documented deviation list rather than six local conventions.
- Complete, current security documentation for all six properties, with a review cadence that holds after the initial push.
- A 12-month posture roadmap in place, sequenced and defensible, with the first two initiatives delivered rather than planned.
- Grant, audit, and insurance evidence current and maintained on a calendar rather than a scramble.
- Sustained reduction in critical findings and in the age of open findings.
- Two engineers capable of leading a migration independently.
- Handles customer proprietary network information and subscriber data. Strict adherence to CPNI, lawful-process, and internal data-classification standards is a condition of the role.
- Security tooling and administrative access are used only for authorized purposes; all privileged activity is logged and reviewable.
- AI tooling is used within the published data-handling standard — advisory only, never in the control path for production changes.
- Remote, but must reside within driving distance of one of our property locations: Winona, MN; Sergeant Bluff, IA; Maricopa, AZ; Hagerstown, MD; Burlington, VT; or New Knoxville, OH
- Office, data center, headend, and hub site environments; occasional work in equipment rooms and outside-plant facilities.
- Ability to lift and position equipment up to 50 pounds and to rack and cable hardware.
- After-hours and weekend maintenance windows; participation in an on-call rotation with defined response expectations.
- Extended periods at a workstation; travel by vehicle between properties in multiple states.
What We Offer
~1 min readWhen you join Schurz Broadband Group, you’ll be part of an award-winning company and team. We offer a comprehensive benefits package, including:
- We will attract, invest in, communicate with, and retain top talent.
- We will innovate, partner, experiment and create a better future together.
- We strive to continuously improve operating performance to ensure sustained growth.
- We will dynamically grow revenues by building and nurturing mutually beneficial and profitable customer relationships.
Location & Eligibility
Listing Details
- Posted
- October 1, 2026
- First seen
- October 1, 2026
- Last seen
- October 1, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 56%
- Scored at
- October 1, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.