Join our growing team and discover why Summit Utilities, Inc. continues to earn national and regional recognition as an employer of choice. Our recognitions include Best Places to Work in Maine (2019–2025); Best Places to Work in Arkansas (2020, 2023, 2025); Best Places to Work in Oklahoma (2022–2025); Best Places to Work in Missouri (2023 and 2026); Best Places to Work in Colorado (2025); Forbes America’s Best Small Employers (2023); and, most recently, Proud and Purposeful Employer (2026).
Summit is a growing natural gas utility providing safe, reliable, and clean burning natural gas service to homes and businesses in Arkansas, Colorado, Maine, Missouri, Oklahoma, and Texas. Being part of the Summit team means embracing excellence and innovation, committing to safety each and every day, and doing all that we can to serve each other, our customers, and the communities where we live. We aim to bring warmth and energy to everything we do.
We have an exciting opportunity for an Information Security Engineer (SGL18). This role may be hybrid-based in Fort Smith or Little Rock, Arkansas.
POSITION SUMMARY
The Information Security Engineer is a hands-on technical specialist responsible for designing, building, and maintaining the security platforms, tooling, and automation that protect Summit Utilities' digital assets, operational technology, and data. This role owns the architecture and day-to-day engineering of core security capabilities — including SIEM, EDR, IAM, and cloud security posture management (CSPM) and builds the integrations and automation that let the broader security organization operate efficiently.
The Information Security Engineer partners closely with the Information Security Architect, security operations, IT, and engineering teams to translate architecture standards and compliance requirements into working, production-grade security infrastructure. This role requires strong hands-on technical depth, coding and automation ability, and sound judgment in evaluating tooling and design trade-offs at scale.
This position requires broad technical proficiency across security domains, strong engineering fundamentals, and the ability to communicate complex technical designs to both technical and non-technical audiences.
PRIMARY DUTIES AND RESPONSIBILITIES
- Demonstrated experience designing, building, and operating security platforms (SIEM, EDR, IAM, CSPM) in production environments.
- Proven track record of building automation, integrations, or tooling that measurably reduced manual security work.
- Design, build, and maintain core security platforms — SIEM, EDR, IAM, and CSPM — including data pipelines, ingestion design, and platform integrations.
- Own the SIEM logging and detection data pipeline; design ingestion, parsing, and enrichment to support detection engineering and incident response.
- Build incident response tooling, forensic capabilities, and response automation to accelerate detection and response.
- Design and implement vulnerability scanning architecture and integrate vulnerability management into CI/CD pipelines.
- Build cloud security guardrails, infrastructure-as-code (IaC) security controls, and CSPM integrations across AWS, Azure, and/or GCP.
- Engineer the enterprise IAM platform, including identity federation, SSO, and automated provisioning/de-provisioning workflows.
- Architect and harden network and endpoint security controls (NGFW, EDR, segmentation) and evaluate emerging technologies.
- Build threat intelligence platform integrations and enrichment pipelines to support detection and response teams.
- Implement technical controls that satisfy compliance framework requirements (C2M2, NIST CSF, TSA Security Directives) in partnership with GRC.
- Provide technical evidence and configuration exports to support C2M2, NIST CSF, and TSA Security Directive audits and assessments.
- Support control testing by producing log samples, access reports, and system configuration artifacts requested by GRC/auditors.
- Document technical risk exceptions and compensating controls when a system can't fully meet a framework requirement.
- Maintain a mapping between deployed security tooling/controls and the specific framework requirements they satisfy.
- Design and deliver security platforms and integrations in alignment with enterprise reference architectures set by the Information Security Architect.
- Partner with engineering, platform, and product teams to embed secure design practices into the software delivery lifecycle.
- Serve as a technical mentor across the security organization; set and document engineering standards and best practices.
- Evaluate new security tools and technologies; drive build-vs-buy recommendations and proof-of-concept efforts.
- Participate in a shared on-call rotation to support critical security infrastructure and respond to platform-impacting issues.
Â
POSITION QUALIFICATIONS
EDUCATION AND WORK EXPERIENCE
- Bachelor’s degree in computer science, Engineering, Information Security, or a related field is required. Master's degree is preferred.
- 5–10+ years of progressive experience in security engineering or systems engineering.
- Professional certifications preferred: CISSP, GCIH, OSCP, AWS Certified Security – Specialty, Microsoft Certified: Azure Security Engineer, or Certified Kubernetes Security Specialist (CKS).
KNOWLEDGE, SKILLS, ABILITIESÂ
- Hands-on expertise in operating and tuning SIEM platforms (e.g., Splunk, Microsoft Sentinel), including correlation rule and detection content development.
- Working knowledge of cloud security engineering across AWS, Azure, and/or GCP, including IaC security controls and CSPM tooling.
- Experience engineering identity and access management (IAM) platforms, federation/SSO, and privileged access management (PAM).
- Solid understanding of network and endpoint security technologies, including NGFW, EDR, and network segmentation.
- Experience integrating vulnerability management and security testing into CI/CD pipelines.
- Familiarity with threat intelligence platforms and enrichment pipeline design.
- Working knowledge of compliance frameworks (C2M2, NIST CSF, TSA Security Directives) and the ability to translate requirements into technical controls.
- Ability to evaluate tooling trade-offs, design integrations, and reason about scale, reliability, and operational impact.
- Strong communication skills; able to explain complex technical designs to both technical and non-technical audiences.
- Self-directed; able to drive multi-quarter engineering road maps with minimal supervision.
- Meticulous attention to detail when building, testing, and documenting security platforms and automation.
The above statements are intended to describe the general nature and level of work being performed by employees assigned to this classification. They are not intended to be construed as an exhaustive list of all responsibilities, duties and/or skills required of all personnel so classified.
Summit offers competitive pay and medical/dental/vision and other benefits that provide flexibility, choice, and support to our employees when they need it most. We understand that home and family are essential pieces of your life, and our benefits are designed to support you both at work and at home.Â
Summit Utilities, Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or protected veteran status and will not be discriminated against on the basis of disability or veteran status.
Learn more about this Employer on their Career Site
