Skip to content

Open nowPosted 15 hours ago

Security Engineer III

Jobgether4,394 open roles

Where
US
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity Engineer IIIJobgether · US
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Jobgether's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Jobgether postings stay open a median of 4 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 15 hours ago

Jobgether median: 4 days open

The posting

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Engineer III based in United States.

The Security Engineer III is a senior individual contributor responsible for security architecture, firewall infrastructure, standards, and security posture across a multi-site broadband environment. You will own the firewall estate, establish consistent access-control and segmentation standards, and personally execute complex migrations and high-risk changes. The role combines hands-on engineering with long-term roadmap ownership, compliance readiness, documentation, and technical program leadership. You will work across network, security, infrastructure, compliance, vendors, and executive stakeholders to strengthen the organization’s overall security posture. The position also serves as a technical incident commander for major security events and drives automation, policy-as-code, and drift detection. Success requires someone who can operate independently, make architecture decisions, communicate with senior leadership, and remain deeply hands-on. This is a remote role with proximity to a designated property required, alongside occasional travel, maintenance windows, and on-call responsibilities.

Accountabilities:

  • Own the firewall estate across six properties, including platform strategy, reference architecture, vendor relationships, refresh planning, capacity planning, and high-risk migrations.
  • Define and maintain security architecture standards covering firewalls, access control, network segmentation, hardening, rule lifecycle management, and documented exceptions.
  • Establish an authoritative understanding of network environments across edge, core, plant, subscriber, and management planes, including trust boundaries and data flows.
  • Lead the adoption of common security standards across properties while documenting and governing legitimate deviations.
  • Maintain comprehensive security documentation, including architecture diagrams, standards, runbooks, decision records, and review processes.
  • Develop and maintain a security posture roadmap aligned with NIST CSF and CIS Controls, including current-state assessments, remediation priorities, and executive-level metrics.
  • Own cybersecurity and supply chain risk management plans supporting broadband grant requirements and relevant regulatory obligations.
  • Support CPNI requirements, lawful-process handling, breach notification analysis, audit readiness, and cyber insurance evidence requirements.
  • Lead major security initiatives such as zero-trust network access, privileged access management, endpoint protection consolidation, resilient out-of-band access, and security logging.
  • Evaluate security vendors, support contract and renewal negotiations, manage technical engagements, and contribute to security budgets and multi-year capital planning.
  • Serve as technical incident commander during major security incidents, leading containment, forensic readiness, evidence handling, and break-glass access procedures.
  • Run tabletop exercises and coordinate with legal and compliance stakeholders regarding notification thresholds and regulatory exposure.
  • Drive automation for policy-as-code, drift detection, rollback capabilities, and tamper-evident audit evidence while personally contributing to implementation.
  • Establish responsible use of AI tooling within security workflows, keeping AI advisory and outside the production control path.
  • Mentor Tier I and Tier II engineers and develop the internal capability to independently execute security migrations and initiatives.
  • Define and manage first-year outcomes, including firewall estate modernization, standardized security controls, complete documentation, posture improvements, current compliance evidence, and reduced critical findings.
  • 8+ years of experience in network and security engineering, including at least 3 years in a senior or lead role responsible for setting standards while remaining hands-on.
  • Proven experience designing and implementing multi-site security architectures.
  • Expert-level firewall expertise, including centralized management at scale and leadership of firewall migrations.
  • Strong service-provider security knowledge, including BGP security controls, DDoS mitigation, subscriber-network separation, and the differences between carrier and enterprise infrastructure.
  • Demonstrated ownership of vulnerability management and security hardening programs, including reporting to executives or risk committees.
  • A strong portfolio of written security standards, architecture documentation, and technical decision records.
  • Ability to independently assess an environment, establish priorities, and develop a defensible 12-month security roadmap.
  • Strong written and verbal communication skills, with the ability to present technical recommendations in a way that senior non-technical stakeholders can act on.
  • Experience managing security exceptions, standards, architecture approvals, vendor relationships, and technical escalations.
  • CISSP, CISM, or advanced platform certifications such as PCNSE, NSE 8, or CCIE Security are preferred.
  • Experience with regional operators, cooperatives, municipal providers, or other lean security teams is a plus.
  • Experience standardizing independently operated or acquired environments is preferred.
  • Knowledge of regulated data requirements such as CPNI, PCI DSS scope reduction, or CALEA-related processes is advantageous.
  • Experience with BEAD or state broadband security requirements and grant compliance is a plus.
  • Prior ownership of security budgets or vendor portfolios is preferred.
  • Ability to work remotely while collaborating across multiple locations and time zones.
  • Must be able to reside within driving distance of a designated property in Winona, MN; Sergeant Bluff, IA; Maricopa, AZ; Hagerstown, MD; Burlington, VT; or New Knoxville, OH.
  • Ability to work occasional after-hours and weekend maintenance windows and participate in an on-call rotation.
  • Ability to travel between properties and work in office, data center, headend, and outside-plant environments.
  • Ability to lift and position equipment weighing up to 50 pounds and rack and cable hardware.
  • Annual compensation of $108,000–$138,000.
  • Remote work with proximity to a designated property.
  • Group health and dental insurance.
  • 401(k) program with company match.
  • Generous paid time off program.
  • Company wellness program.
  • Employer-paid short-term and long-term disability coverage.
  • Opportunity to own enterprise-wide security architecture and a multi-year security roadmap.
  • Senior individual contributor role with significant technical authority and autonomy.
  • Exposure to complex broadband, network security, compliance, incident response, and infrastructure environments.
  • Opportunity to mentor engineers and shape security standards across multiple properties.

How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Jobgether's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Jobgether's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Jobgether's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.