{"id":1716730,"url":"https://alion.io/job/otava-security-engineer-iii","title":"Security Engineer III","company":{"id":179764,"name":"Otava","domain":"otava.com","url":"https://alion.io/company/otava","size_band":"11-50","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"UltiPro","truth_index":null},"role":"Security","role_family":"Security","seniority":"middle","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":108000,"max":138000,"currency":"USD","period":"year","gross":null,"usd_annual":138000},"salary_estimate":null,"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"BGP","optional":false},{"name":"Commander.js","optional":false},{"name":"NIST CSF","optional":false},{"name":"Zero Trust","optional":false},{"name":"JavaScript","optional":true},{"name":"Node JS","optional":true},{"name":"PCI DSS","optional":true}],"status":"live","first_seen_at":"2026-10-01T13:46:44Z","employer_posted_date":"2026-10-01","last_verified_at":"2026-10-06T01:33:44Z","board_verified":true,"closed_at":null,"days_open":4,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":4},"description":"Position Summary\nThis role owns the firewall estate, security architecture, and standards for all six properties, the documentation library behind them, and the posture roadmap that sequences the work, and personally implements the hardest parts of it. This is a senior individual contributor role, not a management position. Expect to be writing a standard in the morning, converting a property to it that night, and presenting the result to the Risk Committee the following week.\nPosition Title: Security Engineer III\nLocation: Remote (within driving distance of a Schurz property, see locations below)\nRate: $108,000 - $138,000 annually\nReports to: VP, Business Technology\nPosition Type: Full-time\nEssential Responsibilities\nFirewall Estate Ownership - Primary Responsibility\nOwn the firewall estate for all six properties: the standard, the platform strategy, the refresh roadmap, and the vendor relationship. This is the accountability that does not move.\nDefine the firewall reference architecture - platform selection, high-availability model, management topology, zone model, and the policy standard every property implements.\nDecide whether the estate consolidates onto one vendor and drive that conversion, or document why a mixed estate is the right answer and how it will be managed consistently.\nOwn the multi-year refresh and capacity plan as a budget line, and defend it.\nPersonally execute the high-risk conversions, migrations, and cutovers rather than delegating them.\nHold final approval on every firewall change that deviates from standard and on every exception that stays open.\nArchitecture and Standards\nDefine the access-control and segmentation reference architecture for all six properties, replacing six locally grown conventions with one standard plus a documented deviation list.\nAuthor the hardening baselines platform by platform, and the method for measuring drift against them.\nOwn the standards library itself: versioning, review cadence, ownership, approval path, and retirement of standards that no longer hold.\nOwn the rule lifecycle governance model - naming, ownership, review cadence, expiration, exception register.\nLead the conversion of each property onto the standard.\nReview and approve designs produced by Tier II; approve or reject deviations.\nInternal Network Understanding\nHold the authoritative picture of how all six networks actually work - edge, core, plant, subscriber, and management planes - including where they differ and why.\nMaintain the trust-boundary and data-flow model that segmentation decisions are made against, and keep it accurate as platform consolidation moves things.\nBe the person who can answer, without research, what is exposed where and what would happen if a given control failed.\nDocumentation as a Deliverable\nOwn the documentation standard: what must exist for every property, in what form, reviewed how often, and who is accountable when it drifts.\nEnsure current security architecture documentation, diagrams, standards, runbooks, and decision records exist for all six properties, and enforce that they stay current rather than decaying between audits.\nWrite the decision records that explain why a standard is what it is, so the next engineer does not relitigate settled questions.\nPosture, Compliance, and Evidence\nMaintain a security posture roadmap mapped to NIST CSF and CIS Controls, with a defensible current-state assessment behind it, and sequence the work against it.\nOwn the cybersecurity and supply chain risk management plans required for broadband grant programs. BEAD subgrantees must attest to a cybersecurity risk management plan reflecting the NIST framework and Executive Order 14028, plus a separate supply chain plan based on NISTIR 8276 and NIST SP 800-161, reevaluated periodically and resubmitted within 30 days of any substantive change.\nSupport FCC CPNI obligations, lawful-process handling, and breach notification analysis across a multi-state footprint where notification clocks differ by state.\nProduce the evidence pack that satisfies auditors and cyber insurance underwriters without a fire drill each renewal.\nDefine and report the metrics that go to the Risk Committee and executive leadership.\nInternal Program Leadership and Vendors\nLead major internal security initiatives end to end - zero-trust network access, privileged access management, out-of-band access resilience, internal endpoint protection consolidation, internal log platform decisions - including the implementation, not only the selection. Initiatives belonging to the managed services line are out of scope.\nRun vendor evaluations with real cost modeling sized to a mid-tier budget. The enterprise answer is frequently the wrong answer; knowing when to buy the smaller product is part of the job.\nScope and govern third-party security engagements the company commissions, and own remediation of their findings.\nSupport contract and renewal negotiation with technical justification; provide budget input and multi-year capital planning.\nParticipate in threat-sharing appropriate to a smaller provider, including the small broadband provider ISAC community.\nIncident Command and Readiness\nServe as technical incident commander for major security incidents across properties, and as the hands during containment when nobody else can do it.\nMaintain forensic readiness: log retention, evidence handling, and the break-glass access path.\nRun tabletop exercises; coordinate with legal and compliance on notification thresholds and regulatory exposure.\nAutomation and People\nDrive policy-as-code, drift detection, rollback capability, and tamper-evident audit evidence in the automation pipeline - and write the code.\nKeep AI tooling in an advisory layer, out of the control path, with documented data-handling standards.\nMentor Tier I and II engineers and build the bench that makes this role survivable when the incumbent is unavailable.\nRequired Qualifications\nEight or more years in network and security engineering, with at least three in a senior or lead capacity setting standards rather than following them, while remaining hands-on.\nProven multi-site security architecture experience where the candidate both designed and implemented the result.\nExpert-level firewall platform command, including centralized management at scale and migration leadership.\nService-provider security depth: BGP security controls, DDoS mitigation strategy, subscriber-network separation, and an understanding of how carrier plant differs from enterprise infrastructure.\nDemonstrated ownership of a vulnerability and hardening program, including reporting to executives or a risk committee.\nA body of written standards and documentation they can point to and discuss. This is a screening requirement, not a preference.\nSelf-directed at the roadmap level: able to enter an environment with no backlog and produce a defensible 12-month plan.\nAble to write and present a recommendation a non-technical executive can act on.\nPreferred Qualifications\nCISSP or CISM; expert-level platform certification (PCNSE, NSE 8, CCIE Security).\nPrior experience at a regional operator, cooperative, or municipal provider - someone who has done this with a small team and a real budget rather than an enterprise one.\nExperience standardizing environments acquired or operated independently, where the starting point was six different ways of doing the same thing.\nRegulated-data experience: CPNI, PCI DSS scope reduction, CALEA-adjacent handling.\nGrant compliance exposure, particularly BEAD or state broadband program security requirements.\nPrior ownership of a security budget or vendor portfolio.\nAuthority and Self-Direction\nSets the security roadmap and their own work against it. Approves architecture and cross-property standards; owns the exception register. Final technical escalation. Escalates to the Vice President for budget, contractual, or organizational decisions only. Accountable for outcomes on a quarterly cadence rather than for task-level activity.\nFirst-Year Success Measures\nFull ownership of the firewall estate established: one inventory of record, no firewall out of support, high-availability pairs tested, and a published refresh plan.\nA single firewall, access-control, and segmentation standard published and adopted at all six properties, with a documented deviation list rather than six local conventions.\nComplete, current security documentation for all six properties, with a review cadence that holds after the initial push.\nA 12-month posture roadmap in place, sequenced and defensible, with the first two initiatives delivered rather than planned.\nGrant, audit, and insurance evidence current and maintained on a calendar rather than a scramble.\nSustained reduction in critical findings and in the age of open findings.\nTwo engineers capable of leading a migration independently.\nConduct and Data Handling\nHandles customer proprietary network information and subscriber data. Strict adherence to CPNI, lawful-process, and internal data-classification standards is a condition of the role.\nSecurity tooling and administrative access are used only for authorized purposes; all privileged activity is logged and reviewable.\nAI tooling is used within the published data-handling standard - advisory only, never in the control path for production changes.\nWorking Conditions\nRemote, but must reside within driving distance of one of our property locations: Winona, MN; Sergeant Bluff, IA; Maricopa, AZ; Hagerstown, MD; Burlington, VT; or New Knoxville, OH\nOffice, data center, headend, and hub site environments; occasional work in equipment rooms and outside-plant facilities.\nAbility to lift and position equipment up to 50 pounds and to rack and cable hardware.\nAfter-hours and weekend maintenance windows; participation in an on-call rotation with defined response expectations.\nExtended periods at a workstation; travel by vehicle between properties in multiple states.\nWhy Join Schurz Broadband Group?\nWhen you join Schurz Broadband Group, you’ll be part of an award-winning company and team. We offer a comprehensive benefits package, including:\nGroup health & dental insurance\n401(k) program with company match\nGenerous PTO program\nCompany wellness program\nEmployer-paid short- and long-term disability\nAnd much more!\nWe are committed to providing an environment that gives each employee the opportunity to nurture their gifts and achieve their potential. Our mission is to pass on to future generations-customers, employees, communities, and owners-an organization that is even stronger and better than it is today.\nSchurz Communications and its subsidiaries’ strategic objectives:\nWe will attract, invest in, communicate with, and retain top talent. \nWe will innovate, partner, experiment and create a better future together. \nWe strive to continuously improve operating performance to ensure sustained growth. \nWe will dynamically grow revenues by building and nurturing mutually beneficial and profitable customer relationships.","description_format":"text","description_chars":11023,"description_truncated":false,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Dental insurance"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"},{"name":"Iowa","iso":null,"kind":"city"},{"name":"Maryland","iso":null,"kind":"city"},{"name":"Minnesota","iso":null,"kind":"city"},{"name":"Ohio","iso":null,"kind":"city"},{"name":"Vermont","iso":null,"kind":"city"},{"name":"Arizona","iso":null,"kind":"city"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Autonomous Driving","Information Security","Backup & Disaster Recovery"],"lifecycle":[{"event":"open","at":"2026-10-02T18:50:07Z"}],"visa":[],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":3,"expected_fill_days":27,"reasons":["conf:1","win:early"],"computed_at":"2026-10-05T05:45:15Z"},"pay":{"stated_usd_annual":138000,"is_top_pay":true},"html_url":"https://alion.io/job/otava-security-engineer-iii","json_url":"https://alion.io/job/otava-security-engineer-iii.json","meta":{"generated_at":"2026-10-06T02:38:29Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3973,"day_limit":5000,"remaining_today":1027,"minute_limit":60,"resets_at":"2026-10-07T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":179764},"rest":"https://alion.io/mcp/rest/get_company?id=179764"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fotava-security-engineer-iii"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fotava-security-engineer-iii"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fotava-security-engineer-iii"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/otava-security-engineer-iii\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fotava-security-engineer-iii"}]}