> Markdown version of [/jobs/ext/2522499-senior-information-security-engineer](https://www.wearedevelopers.com/jobs/ext/2522499-senior-information-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Security Engineer - **Company:** The University of Tulsa - **Location:** Tulsa, OK, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Systems Engineering, Cloud Computing, Cyber Security, Identity and Access Management, Microsoft Security Essentials, PCI Data Security Standards, Windows PowerShell, Azure Active Directory, Scripting, Enterprise Software Applications, Software Security, Microsoft InTune, Information Technology, CIS Benchmarks - **Published:** August 10, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=854c45e0a4073ab6 ## About the Role * Bachelor's degree in information technology, Cybersecurity, or related field (or equivalent combination of education and experience) * 5-7 years of progressive experience in information security, systems engineering, or related field * Hands-on experience with Microsoft 365 security technologies (Defender, Purview, Intune) * Experience securing enterprise systems and applications * Knowledge of identity and access management, endpoint security, and data protection principles * Demonstrated experience leading technical projects or implementations, * Experience in higher education or similarly complex environments * Familiarity with Ellucian Colleague, Informer, or comparable ERP systems * Experience with scripting/automation (PowerShell) * Knowledge of security frameworks (NIST, CIS Controls, ISO 27001) * Relevant certifications: + Microsoft (SC-200, SC-300, SC-400) + CISSP, CISM, or equivalent, * Advanced technical troubleshooting and analytical skills * Ability to lead initiatives without formal supervisory authority * Strong collaboration and communication skills across technical and non-technical teams * Ability to translate security risks into actionable recommendations Reporting Relationship * Reports to: Chief Information Security Officer (CISO) * Supervisory Responsibility: None, * Primarily office or hybrid work environment * May require occasional after-hours support for incidents or system changes ## Description The Senior Information Security Engineer serves as an advanced technical resource responsible for the implementation, administration, and continuous improvement of enterprise security technologies. This role leads technical security initiatives with a primary focus on Microsoft 365 security platforms, while also supporting the security and configuration of on-premises enterprise applications. The position operates with a high degree of independence, providing technical leadership, mentoring peers, and partnering across IT and business units to ensure secure, complaint, and resilient systems., 1. Security Engineering (Cloud - Primary Responsibility) * Administer and optimize Microsoft security platforms, including Defender, Purview, and Intune * Configure and maintain security controls within Microsoft 365 and Entra ID (Azure AD) * Lead implementation of security tools, policies, and automation * Strengthening endpoint security, identity protection, and data-loss prevention capabilities * Partner with Security Operations to support monitoring, detection, and incident response 2. Enterprise Application & On-Prem Security * Secure and support enterprise applications (e.g., Ellucian Colleague, Informer) * Perform secure installation, configuration, patching, and upgrades * Implement role-based access controls and least privilege models * Conduct application security reviews and system hardening 3. Technical Leadership * Lead security-related projects and major system implementations * Provide guidance on secure design and architecture decisions * Develop and maintain security standards, procedures, and baselines * Mentor junior staff and provide subject matter expertise 4. Risk, Compliance, and Governance * Support institutional compliance efforts (FERPA, GLBA, PCI-DSS as applicable) * Conduct risk assessments and recommend remediation strategies * Identify control gaps and drive continuous improvement * Participate in incident response as a senior technical contributor ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)