Security Engineer III @Schurz Communications
All Others
Salary usd 108,000 - 1..
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted Today

[Hiring] Security Engineer III @Schurz Communications

Today - Schurz Communications is hiring a remote Security Engineer III. 💸 Salary: usd 108,000 - 138,000 per year 📍Location: USA

Role Description

This role owns the firewall estate, security architecture, and standards for all six properties, the documentation library behind them, and the posture roadmap that sequences the work, and personally implements the hardest parts of it. This is a senior individual contributor role, not a management position. Expect to be writing a standard in the morning, converting a property to it that night, and presenting the result to the Risk Committee the following week.

Qualifications

  • Eight or more years in network and security engineering, with at least three in a senior or lead capacity setting standards rather than following them, while remaining hands-on.
  • Proven multi-site security architecture experience where the candidate both designed and implemented the result.
  • Expert-level firewall platform command, including centralized management at scale and migration leadership.
  • Service-provider security depth: BGP security controls, DDoS mitigation strategy, subscriber-network separation, and an understanding of how carrier plant differs from enterprise infrastructure.
  • Demonstrated ownership of a vulnerability and hardening program, including reporting to executives or a risk committee.
  • A body of written standards and documentation they can point to and discuss. This is a screening requirement, not a preference.
  • Self-directed at the roadmap level: able to enter an environment with no backlog and produce a defensible 12-month plan.
  • Able to write and present a recommendation a non-technical executive can act on.

Requirements

  • Own the firewall estate for all six properties: the standard, the platform strategy, the refresh roadmap, and the vendor relationship.
  • Define the firewall reference architecture — platform selection, high-availability model, management topology, zone model, and the policy standard every property implements.
  • Decide whether the estate consolidates onto one vendor and drive that conversion, or document why a mixed estate is the right answer and how it will be managed consistently.
  • Own the multi-year refresh and capacity plan as a budget line, and defend it.
  • Personally execute the high-risk conversions, migrations, and cutovers rather than delegating them.
  • Hold final approval on every firewall change that deviates from standard and on every exception that stays open.
  • Define the access-control and segmentation reference architecture for all six properties, replacing six locally grown conventions with one standard plus a documented deviation list.
  • Author the hardening baselines platform by platform, and the method for measuring drift against them.
  • Own the standards library itself: versioning, review cadence, ownership, approval path, and retirement of standards that no longer hold.
  • Own the rule lifecycle governance model — naming, ownership, review cadence, expiration, exception register.
  • Lead the conversion of each property onto the standard.
  • Review and approve designs produced by Tier II; approve or reject deviations.
  • Hold the authoritative picture of how all six networks actually work — edge, core, plant, subscriber, and management planes — including where they differ and why.
  • Maintain the trust-boundary and data-flow model that segmentation decisions are made against, and keep it accurate as platform consolidation moves things.
  • Be the person who can answer, without research, what is exposed where and what would happen if a given control failed.
  • Own the documentation standard: what must exist for every property, in what form, reviewed how often, and who is accountable when it drifts.
  • Ensure current security architecture documentation, diagrams, standards, runbooks, and decision records exist for all six properties, and enforce that they stay current rather than decaying between audits.
  • Write the decision records that explain why a standard is what it is, so the next engineer does not relitigate settled questions.
  • Maintain a security posture roadmap mapped to NIST CSF and CIS Controls, with a defensible current-state assessment behind it, and sequence the work against it.
  • Own the cybersecurity and supply chain risk management plans required for broadband grant programs.
  • Support FCC CPNI obligations, lawful-process handling, and breach notification analysis across a multi-state footprint where notification clocks differ by state.
  • Produce the evidence pack that satisfies auditors and cyber insurance underwriters without a fire drill each renewal.
  • Define and report the metrics that go to the Risk Committee and executive leadership.
  • Lead major internal security initiatives end to end — zero-trust network access, privileged access management, out-of-band access resilience, internal endpoint protection consolidation, internal log platform decisions.
  • Run vendor evaluations with real cost modeling sized to a mid-tier budget.
  • Scope and govern third-party security engagements the company commissions, and own remediation of their findings.
  • Support contract and renewal negotiation with technical justification; provide budget input and multi-year capital planning.
  • Participate in threat-sharing appropriate to a smaller provider, including the small broadband provider ISAC community.
  • Serve as technical incident commander for major security incidents across properties, and as the hands during containment when nobody else can do it.
  • Maintain forensic readiness: log retention, evidence handling, and the break-glass access path.
  • Run tabletop exercises; coordinate with legal and compliance on notification thresholds and regulatory exposure.
  • Drive policy-as-code, drift detection, rollback capability, and tamper-evident audit evidence in the automation pipeline — and write the code.
  • Keep AI tooling in an advisory layer, out of the control path, with documented data-handling standards.
  • Mentor Tier I and II engineers and build the bench that makes this role survivable when the incumbent is unavailable.

Benefits

  • Group health & dental insurance
  • 401(k) program with company match
  • Generous PTO program
  • Company wellness program
  • Employer-paid short- and long-term disability
  • And much more!

Company Description

When you join Schurz Broadband Group, you’ll be part of an award-winning company and team. We are committed to providing an environment that gives each employee the opportunity to nurture their gifts and achieve their potential. Our mission is to pass on to future generations—customers, employees, communities, and owners—an organization that is even stronger and better than it is today.

Before You Apply
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Security Engineer III @Schurz Communications
All Others
Salary usd 108,000 - 1..
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted Today
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
×
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews

⚡ 129,097+ remote jobs, refreshed hourly

🔔 Real-time alerts: Apply first, direct to employer

🛡️ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later