Security Engineer III
This role offers a hybrid work arrangement, with an expectation of weekly on-campus presence.
About the Role
The Security Engineer III serves as a senior cybersecurity professional responsible for leading complex security initiatives that protect the university's information assets, institutional data, and technology infrastructure. This position plays a critical role in advancing RIT's cybersecurity strategy through the implementation of security controls, proactive risk management, and collaboration with stakeholders across the institution.
The successful candidate will combine deep technical expertise with strong communication and collaboration skills to drive security initiatives that reduce institutional risk, enable innovation, and support the university's strategic objectives.
Responsibilities
- Lead the university's Data Loss Prevention (DLP) and data classification program through Microsoft Purview to strengthen data governance and safeguard sensitive information.
- Partner with Data Hub stakeholders to embed security controls, enhance security processes, and support the secure use of institutional data.
- Manage third-party cybersecurity risk through vendor security reviews and assessments to ensure compliance with regulatory requirements and university security standards.
- Support the identification and mitigation of emerging risks associated with Artificial Intelligence (AI), cloud services, and evolving technology platforms.
- Advise technical and business stakeholders on security architecture, risk management, and security best practices while serving as a mentor and trusted resource to colleagues.
- Participate in cybersecurity incident response activities, including occasional after-hours or on-site support during active security incidents when necessary.
- Conduct vulnerability scanning and penetration testing.
- Investigate services and application security.
- Perform security comparative review, security risk assessment, and security validation.
- Perform operational duties during security incident responses, troubleshoot, and perform root cause analysis for security solutions.
- Analyze, design, and install complex enterprise security solutions and frameworks.
- Design security solutions architecture, select tools and partners, and configure and manage capacity, changes, documentation, and reporting.
- Contribute to the documentation of security processes and procedures.
- Other duties as assigned.
Requirements
- Bachelor's degree in a related field.
- 5 years of related experience.
- Equivalent combination of experience and education may be considered.
Skills
- Knowledge of security architecture principles and best practices for system and network protection.
- Knowledge of advanced cybersecurity tools, such as firewalls and intrusion prevention systems.
- Skill in deploying and configuring cybersecurity tools and technologies to mitigate risks.
- Skill in designing and implementing security measures to protect IT infrastructure and sensitive data.
- Ability to lead complex technical projects.
- Ability to analyze complex security threats and develop proactive solutions to prevent breaches.
- Ability to troubleshoot and resolve advanced security incidents with minimal supervision.
Preferred Qualifications
While not required, the ideal candidate will hold a Certified Information Systems Security Professional (CISSP) certification or an equivalent industry-recognized cybersecurity certification. Learn more about the CISSP credential on the ISC² website.
About the Team
The Information Security Office provides leadership to the RIT community in safeguarding the confidentiality, integrity, and availability of the university's information assets. The team is responsible for advancing cybersecurity programs and services that enable teaching, learning, research, and business operations while helping the university effectively manage technology and data-related risks.
The Information Security Office is a highly collaborative team of cybersecurity professionals dedicated to protecting the university while enabling innovation. Team members work closely with faculty, staff, students, researchers, and technology partners across the institution to develop practical, risk-based solutions that support RIT's mission.
The office fosters a culture of trust, continuous learning, shared expertise, and professional growth, where individuals are empowered to lead initiatives, contribute new ideas, and make meaningful impacts on the university's security posture. The team oversees a broad portfolio of cybersecurity functions, including security engineering, security governance, awareness and training, threat intelligence and incident response, vulnerability management, data protection, and private information management.
As RIT continues to expand its use of cloud technologies, advanced analytics, and Artificial Intelligence (AI), the Information Security Office plays a critical role in enabling secure innovation through strong security practices, effective risk management, and strategic partnerships across the university.
Pay
$81,600.00 - $130,600.00 Annual