1,111,561open jobs
64,263companies
187,723added this week
Browse all
Salary
$108k – $138k per year
Location
In office (United States)
Seniority
Middle · 8+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 2, 2026. First seen by Alion on Oct 1, 2026.

Overview
Company
Impact
Profile match
Otava is a Michigan company that delivers secure hybrid cloud and data protection services. Its offering covers private cloud, backup, disaster recovery and compliance support. The company works largely through channel partners.

Position Summary

This role owns the firewall estate, security architecture, and standards for all six properties, the documentation library behind them, and the posture roadmap that sequences the work, and personally implements the hardest parts of it. This is a senior individual contributor role, not a management position. Expect to be writing a standard in the morning, converting a property to it that night, and presenting the result to the Risk Committee the following week.

Position Title: Security Engineer III

Location: Remote (within driving distance of a Schurz property, see locations below)

Rate: $108,000 - $138,000 annually

Reports to: VP, Business Technology

Position Type: Full-time

Essential Responsibilities

Firewall Estate Ownership - Primary Responsibility

  • Own the firewall estate for all six properties: the standard, the platform strategy, the refresh roadmap, and the vendor relationship. This is the accountability that does not move.
  • Define the firewall reference architecture - platform selection, high-availability model, management topology, zone model, and the policy standard every property implements.
  • Decide whether the estate consolidates onto one vendor and drive that conversion, or document why a mixed estate is the right answer and how it will be managed consistently.
  • Own the multi-year refresh and capacity plan as a budget line, and defend it.
  • Personally execute the high-risk conversions, migrations, and cutovers rather than delegating them.
  • Hold final approval on every firewall change that deviates from standard and on every exception that stays open.

Architecture and Standards

  • Define the access-control and segmentation reference architecture for all six properties, replacing six locally grown conventions with one standard plus a documented deviation list.
  • Author the hardening baselines platform by platform, and the method for measuring drift against them.
  • Own the standards library itself: versioning, review cadence, ownership, approval path, and retirement of standards that no longer hold.
  • Own the rule lifecycle governance model - naming, ownership, review cadence, expiration, exception register.
  • Lead the conversion of each property onto the standard.
  • Review and approve designs produced by Tier II; approve or reject deviations.

Internal Network Understanding

  • Hold the authoritative picture of how all six networks actually work - edge, core, plant, subscriber, and management planes - including where they differ and why.
  • Maintain the trust-boundary and data-flow model that segmentation decisions are made against, and keep it accurate as platform consolidation moves things.
  • Be the person who can answer, without research, what is exposed where and what would happen if a given control failed.

Documentation as a Deliverable

  • Own the documentation standard: what must exist for every property, in what form, reviewed how often, and who is accountable when it drifts.
  • Ensure current security architecture documentation, diagrams, standards, runbooks, and decision records exist for all six properties, and enforce that they stay current rather than decaying between audits.
  • Write the decision records that explain why a standard is what it is, so the next engineer does not relitigate settled questions.

Posture, Compliance, and Evidence

  • Maintain a security posture roadmap mapped to NIST CSF and CIS Controls, with a defensible current-state assessment behind it, and sequence the work against it.
  • Own the cybersecurity and supply chain risk management plans required for broadband grant programs. BEAD subgrantees must attest to a cybersecurity risk management plan reflecting the NIST framework and Executive Order 14028, plus a separate supply chain plan based on NISTIR 8276 and NIST SP 800-161, reevaluated periodically and resubmitted within 30 days of any substantive change.
  • Support FCC CPNI obligations, lawful-process handling, and breach notification analysis across a multi-state footprint where notification clocks differ by state.
  • Produce the evidence pack that satisfies auditors and cyber insurance underwriters without a fire drill each renewal.
  • Define and report the metrics that go to the Risk Committee and executive leadership.

Internal Program Leadership and Vendors

  • Lead major internal security initiatives end to end - zero-trust network access, privileged access management, out-of-band access resilience, internal endpoint protection consolidation, internal log platform decisions - including the implementation, not only the selection. Initiatives belonging to the managed services line are out of scope.
  • Run vendor evaluations with real cost modeling sized to a mid-tier budget. The enterprise answer is frequently the wrong answer; knowing when to buy the smaller product is part of the job.
  • Scope and govern third-party security engagements the company commissions, and own remediation of their findings.
  • Support contract and renewal negotiation with technical justification; provide budget input and multi-year capital planning.
  • Participate in threat-sharing appropriate to a smaller provider, including the small broadband provider ISAC community.

Incident Command and Readiness

  • Serve as technical incident commander for major security incidents across properties, and as the hands during containment when nobody else can do it.
  • Maintain forensic readiness: log retention, evidence handling, and the break-glass access path.
  • Run tabletop exercises; coordinate with legal and compliance on notification thresholds and regulatory exposure.

Automation and People

  • Drive policy-as-code, drift detection, rollback capability, and tamper-evident audit evidence in the automation pipeline - and write the code.
  • Keep AI tooling in an advisory layer, out of the control path, with documented data-handling standards.
  • Mentor Tier I and II engineers and build the bench that makes this role survivable when the incumbent is unavailable.

Required Qualifications

  • Eight or more years in network and security engineering, with at least three in a senior or lead capacity setting standards rather than following them, while remaining hands-on.
  • Proven multi-site security architecture experience where the candidate both designed and implemented the result.
  • Expert-level firewall platform command, including centralized management at scale and migration leadership.
  • Service-provider security depth: BGP security controls, DDoS mitigation strategy, subscriber-network separation, and an understanding of how carrier plant differs from enterprise infrastructure.
  • Demonstrated ownership of a vulnerability and hardening program, including reporting to executives or a risk committee.
  • A body of written standards and documentation they can point to and discuss. This is a screening requirement, not a preference.
  • Self-directed at the roadmap level: able to enter an environment with no backlog and produce a defensible 12-month plan.
  • Able to write and present a recommendation a non-technical executive can act on.

Preferred Qualifications

  • CISSP or CISM; expert-level platform certification (PCNSE, NSE 8, CCIE Security).
  • Prior experience at a regional operator, cooperative, or municipal provider - someone who has done this with a small team and a real budget rather than an enterprise one.
  • Experience standardizing environments acquired or operated independently, where the starting point was six different ways of doing the same thing.
  • Regulated-data experience: CPNI, PCI DSS scope reduction, CALEA-adjacent handling.
  • Grant compliance exposure, particularly BEAD or state broadband program security requirements.
  • Prior ownership of a security budget or vendor portfolio.

Authority and Self-Direction

Sets the security roadmap and their own work against it. Approves architecture and cross-property standards; owns the exception register. Final technical escalation. Escalates to the Vice President for budget, contractual, or organizational decisions only. Accountable for outcomes on a quarterly cadence rather than for task-level activity.

First-Year Success Measures

  • Full ownership of the firewall estate established: one inventory of record, no firewall out of support, high-availability pairs tested, and a published refresh plan.
  • A single firewall, access-control, and segmentation standard published and adopted at all six properties, with a documented deviation list rather than six local conventions.
  • Complete, current security documentation for all six properties, with a review cadence that holds after the initial push.
  • A 12-month posture roadmap in place, sequenced and defensible, with the first two initiatives delivered rather than planned.
  • Grant, audit, and insurance evidence current and maintained on a calendar rather than a scramble.
  • Sustained reduction in critical findings and in the age of open findings.
  • Two engineers capable of leading a migration independently.

Conduct and Data Handling

  • Handles customer proprietary network information and subscriber data. Strict adherence to CPNI, lawful-process, and internal data-classification standards is a condition of the role.
  • Security tooling and administrative access are used only for authorized purposes; all privileged activity is logged and reviewable.
  • AI tooling is used within the published data-handling standard - advisory only, never in the control path for production changes.

Working Conditions

  • Remote, but must reside within driving distance of one of our property locations: Winona, MN; Sergeant Bluff, IA; Maricopa, AZ; Hagerstown, MD; Burlington, VT; or New Knoxville, OH
  • Office, data center, headend, and hub site environments; occasional work in equipment rooms and outside-plant facilities.
  • Ability to lift and position equipment up to 50 pounds and to rack and cable hardware.
  • After-hours and weekend maintenance windows; participation in an on-call rotation with defined response expectations.
  • Extended periods at a workstation; travel by vehicle between properties in multiple states.

Why Join Schurz Broadband Group?

When you join Schurz Broadband Group, you’ll be part of an award-winning company and team. We offer a comprehensive benefits package, including:

  • Group health & dental insurance
  • 401(k) program with company match
  • Generous PTO program
  • Company wellness program
  • Employer-paid short- and long-term disability
  • And much more!

We are committed to providing an environment that gives each employee the opportunity to nurture their gifts and achieve their potential. Our mission is to pass on to future generations-customers, employees, communities, and owners-an organization that is even stronger and better than it is today.

Schurz Communications and its subsidiaries’ strategic objectives:

  • We will attract, invest in, communicate with, and retain top talent.
  • We will innovate, partner, experiment and create a better future together.
  • We strive to continuously improve operating performance to ensure sustained growth.
  • We will dynamically grow revenues by building and nurturing mutually beneficial and profitable customer relationships.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,111,561 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
United States
$80k – $90k per year • Equity • Remote (United States) • 7+ years exp • Seattle
Python
JavaScript
PowerShell
DevOps
Terraform
VMWare
CloudFormation
Nomad
AWS
Docker
Ubuntu
CentOS Stream
Amazon ECS
Linux
Windows
Cybersecurity
Crowdstrike
Nessus
CIS Benchmarks
NIST 800-171
Microsoft Entra ID
EnCase
Active Directory
SIEM
Apply
Security Engineer 1 day ago
$100k – $120k per year • Equity • Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Omaha
DevOps
Windows Server
Platform Engineering
Windows
Management
Confluence
Jira
Power Automate
ITIL
Apply
$110k – $135k per year • Equity • Hybrid • Full-Time • 2+ years exp • Omaha
Python
DevOps
Rest API
GitHub Actions
CI/CD
Git
Platform Engineering
GitHub
Cybersecurity
CodeQL
Threat Modeling
Fortify
OWASP
Management
Agile
Apply
$140k – $151k per year • Remote (United States) • Full-Time • 4+ years exp • United States
Python
JavaScript
TypeScript
DevOps
CI/CD
AWS
Cybersecurity
OWASP Top 10
SOC 2
Threat Modeling
Management
Agile
Apply
$146k – $234k per year • Equity • In office • Full-Time • 5+ years exp • Cambridge
AI/ML
Agentic Workflows
Cybersecurity
ISO 27001
NIST CSF
Analytics
Power BI
Management
Jira
ServiceNow
SharePoint
Apply
≈ $66k – $163k per year (Estimated) • In office • Full-Time • Birmingham
Python
DevOps
Azure
AWS
Amazon EC2
VPN
BGP
OSPF
Cybersecurity
FortiGate
Apply
Network Architect 6 hours ago
≈ $58k – $142k per year (Estimated) • Hybrid • Full-Time • 3+ years exp • Warsaw • Katowice
DevOps
Azure
AWS
VPN
Cybersecurity
FortiGate
Zscaler
Zero Trust
Apply
$94k – $225k per year • Hybrid • Full-Time • 12+ years exp • Associate's Degree • Boston • Milwaukee • Dallas • Columbus • Kirkland
Python
DevOps
Platform Engineering
Cybersecurity
Zero Trust
Robotics
Digital Twin
Apply
$133k – $271k per year • Hybrid • Full-Time • 12+ years exp • Associate's Degree • Boston • Milwaukee • Dallas • Columbus • Kirkland
Python
DevOps
Platform Engineering
Cybersecurity
Zero Trust
Robotics
Digital Twin
Apply
In office • Full-Time • Tokyo
JavaScript
Node JS
Node JS
Commander.js
DevOps
Windows
Apply
$42k – $46k per year • Remote (United States) • Full-Time • High School Diploma • Burlington
Apply
≈ $60k – $120k per year (Estimated) • In office • Full-Time • 5+ years exp • Maricopa
Apply
Service Technician 3 days ago
≈ $40k – $72k per year (Estimated) • In office • Full-Time • 1+ year exp • High School Diploma • Winona
Apply
$50k – $65k per year • In office • Full-Time • Winona
Marketing
Salesforce
Apply
$34k – $42k per year • In office • Full-Time • High School Diploma • Hagerstown
DevOps
AWS
Marketing
Salesforce
Apply
≈ $43k – $96k per year (Estimated) • Remote (United States) • Full-Time • 5+ years exp • Bachelor's Degree • United States
Apply
≈ $75k – $155k per year (Estimated) • Remote (United States) • Full-Time • Bachelor's Degree • United States
Apply
≈ $71k – $180k per year (Estimated) • In office • Bachelor's Degree • United States
Apply
≈ $71k – $180k per year (Estimated) • In office • Bachelor's Degree • United States
Apply
≈ $50k – $89k per year (Estimated) • In office • 4+ years exp • United States
Apply
See all jobs
This is one of many
1,111,561 more open roles from verified company boards, updated every day.