It security engineer

1 week ago

Remote, United States Jobgether Full-time
This position is listed on behalf of a partner company, who manages all applications and next steps. The Security Engineer III is a senior individual contributor responsible for security architecture, firewall infrastructure, standards, and security posture across a multi-site broadband environment. You will own the firewall estate, establish consistent access-control and segmentation standards, and personally execute complex migrations and high-risk changes. You will work across network, security, infrastructure, compliance, vendors, and executive stakeholders to strengthen the organization’s overall security posture. The position also serves as a technical incident commander for major security events and drives automation, policy-as-code, and drift detection. This is a remote role with proximity to a designated property required, alongside occasional travel, maintenance windows, and on-call responsibilities. \Own the firewall estate across six properties, including platform strategy, reference architecture, vendor relationships, refresh planning, capacity planning, and high-risk migrations. Define and maintain security architecture standards covering firewalls, access control, network segmentation, hardening, rule lifecycle management, and documented exceptions. Establish an authoritative understanding of network environments across edge, core, plant, subscriber, and management planes, including trust boundaries and data flows. Lead the adoption of common security standards across properties while documenting and governing legitimate deviations. Develop and maintain a security posture roadmap aligned with NIST CSF and CIS Controls, including current-state assessments, remediation priorities, and executive-level metrics. Own cybersecurity and supply chain risk management plans supporting broadband grant requirements and relevant regulatory obligations. Support CPNI requirements, lawful-process handling, breach notification analysis, audit readiness, and cyber insurance evidence requirements. Lead major security initiatives such as zero-trust network access, privileged access management, endpoint protection consolidation, resilient out-of-band access, and security logging. Evaluate security vendors, support contract and renewal negotiations, manage technical engagements, and contribute to security budgets and multi-year capital planning. Serve as technical incident commander during major security incidents, leading containment, forensic readiness, evidence handling, and break-glass access procedures. Run tabletop exercises and coordinate with legal and compliance stakeholders regarding notification thresholds and regulatory exposure. Drive automation for policy-as-code, drift detection, rollback capabilities, and tamper-evident audit evidence while personally contributing to implementation. Establish responsible use of AI tooling within security workflows, keeping AI advisory and outside the production control path. 8+ years of experience in network and security engineering, including at least 3 years in a senior or lead role responsible for setting standards while remaining hands-on. ~ Proven experience designing and implementing multi-site security architectures. ~ Strong service-provider security knowledge, including BGP security controls, DDoS mitigation, subscriber-network separation, and the differences between carrier and enterprise infrastructure. ~ Demonstrated ownership of vulnerability management and security hardening programs, including reporting to executives or risk committees. ~ CISSP, CISM, or advanced platform certifications such as PCNSE, NSE 8, or CCIE Security are preferred. ~ Experience with regional operators, cooperatives, municipal providers, or other lean security teams is a plus. ~ Knowledge of regulated data requirements such as CPNI, PCI DSS scope reduction, or CALEA-related processes is advantageous. ~ Experience with BEAD or state broadband security requirements and grant compliance is a plus. ~ Ability to work remotely while collaborating across multiple locations and time zones. ~ Ability to work occasional after-hours and weekend maintenance windows and participate in an on-call rotation. ~ Ability to travel between properties and work in office, data center, headend, and outside-plant environments. ~ Ability to lift and position equipment weighing up to 50 pounds and rack and cable hardware. Remote work with proximity to a designated property. ~ Group health and dental insurance. ~Employer-paid short-term and long-term disability coverage. ~ Exposure to complex broadband, network security, compliance, incident response, and infrastructure environments. ~ We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Data Privacy Notice: By submitting your application, you ackn