More jobs:
Security Engineer III
Job in
Towson, Baltimore City, Maryland, 21204, USA
Listed on 2026-10-04
Listing for:
Schurz Broadband Group, Inc.
Full Time
position Listed on 2026-10-04
Job specializations:
-
IT/Tech
Cybersecurity
Job Description & How to Apply Below
This role owns the firewall estate, security architecture, and standards for all six properties, the documentation library behind them, and the posture roadmap that sequences the work, and personally implements the hardest parts of it. This is a senior individual contributor role, not a management position. Expect to be writing a standard in the morning, converting a property to it that night, and presenting the result to the Risk Committee the following week.
Position Title:Security Engineer III
Location:
Remote (within driving distance of a Schurz property, see locations below) Rate: $108,000 - $138,000 annually
Reports to:
VP, Business Technology Position Type:
Full-time Essential Responsibilities Firewall Estate Ownership — Primary Responsibility
- Own the firewall estate for all six properties: the standard, the platform strategy, the refresh roadmap, and the vendor relationship. This is the accountability that does not move.
- Define the firewall reference architecture — platform selection, high-availability model, management topology, zone model, and the policy standard every property implements.
- Decide whether the estate consolidates onto one vendor and drive that conversion, or document why a mixed estate is the right answer and how it will be managed consistently.
- Own the multi-year refresh and capacity plan as a budget line, and defend it.
- Personally execute the high-risk conversions, migrations, and cutovers rather than delegating them.
- Hold final approval on every firewall change that deviates from standard and on every exception that stays open.
- Define the access-control and segmentation reference architecture for all six properties, replacing six locally grown conventions with one standard plus a documented deviation list.
- Author the hardening baselines platform by platform, and the method for measuring drift against them.
- Own the standards library itself: versioning, review cadence, ownership, approval path, and retirement of standards that no longer hold.
- Own the rule lifecycle governance model — naming, ownership, review cadence, expiration, exception register.
- Lead the conversion of each property onto the standard.
- Review and approve designs produced by Tier II; approve or reject deviations.
- Hold the authoritative picture of how all six networks actually work — edge, core, plant, subscriber, and management planes — including where they differ and why.
- Maintain the trust-boundary and data-flow model that segmentation decisions are made against, and keep it accurate as platform consolidation moves things.
- Be the person who can answer, without research, what is exposed where and what would happen if a given control failed.
- Own the documentation standard: what must exist for every property, in what form, reviewed how often, and who is accountable when it drifts.
- Ensure current security architecture documentation, diagrams, standards, runbooks, and decision records exist for all six properties, and enforce that they stay current rather than decaying between audits.
- Write the decision records that explain why a standard is what it is, so the next engineer does not relitigate settled questions.
- Maintain a security posture roadmap mapped to NIST CSF and CIS Controls, with a defensible current-state assessment behind it, and sequence the work against it.
- Own the cybersecurity and supply chain risk management plans required for broadband grant programs. BEAD subgrantees must attest to a cybersecurity risk management plan reflecting the NIST framework and Executive Order 14028, plus a separate supply chain plan based on NISTIR 8276 and NIST SP 800-161, reevaluated…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×