Security Engineer III
Position Summary
This role owns the firewall estate, security architecture, and standards for all six properties, the documentation library behind them, and the posture roadmap that sequences the work, and personally implements the hardest parts of it.
This is a senior individual contributor role, not a management position.
Expect to be writing a standard in the morning, converting a property to it that night, and presenting the result to the Risk Committee the following week.
Position Title: Security Engineer III
Location: Remote (within driving distance of a Schurz property, see locations below)
Rate: $108,000 - $138,000 annually
Reports to: VP, Business Technology
Position Type: Full-time
Essential Responsibilities
Firewall Estate Ownership — Primary Responsibility
* Own the firewall estate for all six properties: the standard, the platform strategy, the refresh roadmap, and the vendor relationship.
This is the accountability that does not move.
* Define the firewall reference architecture — platform selection, high-availability model, management topology, zone model, and the policy standard every property implements.
* Decide whether the estate consolidates onto one vendor and drive that conversion, or document why a mixed estate is the right answer and how it will be managed consistently.
* Own the multi-year refresh and capacity plan as a budget line, and defend it.
* Personally execute the high-risk conversions, migrations, and cutovers rather than delegating them.
* Hold final approval on every firewall change that deviates from standard and on every exception that stays open.
Architecture and Standards
* Define the access-control and segmentation reference architecture for all six properties, replacing six locally grown conventions with one standard plus a documented deviation list.
* Author the hardening baselines platform by platform, and the method for measuring drift against them.
* Own the standards library itself: versioning, review cadence, ownership, approval path, and retirement of standards that no longer hold.
* Own the rule lifecycle governance model — naming, ownership, review cadence, expiration, exception register.
* Lead the conversion of each property onto the standard.
* Review and approve designs produced by Tier II; approve or reject deviations.
Internal Network Understanding
* Hold the authoritative picture of how all six networks actually work — edge, core, plant, subscriber, and management planes — including where they differ and why.
* Maintain the trust-boundary and data-flow model that segmentation decisions are made against, and keep it accurate as platform consolidation moves things.
* Be the person who can answer, without research, what is exposed where and what would happen if a given control failed.
Documentation as a Deliverable
* Own the documentation standard: what must exist for every property, in wha...
- Rate: Not Specified
- Location: Hagerstown, US-MD
- Type: Permanent
- Industry: IT
- Recruiter: Schurz Broadband Group, Inc.
- Contact: Katherine Thompson
- Email: to view click here
- Reference: SECUR002264-00001
- Posted: 2026-10-02 09:06:15 -
- View all Jobs from Schurz Broadband Group, Inc.
More Jobs from Schurz Broadband Group, Inc.
- Softwareentwickler Steuerungstechnik (m/w/d)
- Facharzt für Arbeitsmedizin Düsseldorf (m/w/d)
- QA Specialist
- Postbote für Pakete und Briefe – Aushilfe / Abruf in Bad Oeynhausen (m/w/d)
- Mitarbeiter in der Datenerfassung und im Lager (m/w/d)
- Electrical Trainee
- Mechanical Maintenance Planner- Dudley, NC Plywood
- Machine Operator (Coater/Rewinder)
- Kilns Taylor Forklift Operator - Talladega, AL
- Sr. Strategic Account Manager
- AI Data Analytics Engineer
- Senior or Principal Firmware Engineer - Optical Transceivers
- Signal Integrity Systems Engineer
- Senior Hardware Engineer
- Senior Optical Engineer
- Director, New Product Development
- Georgia Pacific Safety ELP - Sweetwater, TX
- Mold Process Engineer, Automotive Division
- SDET III/Senior Software Development Engineer in Test III
- EI&C Project Associate