The Senior Information Security Engineer serves as an advanced technical resource responsible for the implementation, administration, and continuous improvement of enterprise security technologies. This role leads technical security initiatives with a primary focus on Microsoft 365 security platforms, while also supporting the security and configuration of on-premises enterprise applications.
The position operates with a high degree of independence, providing technical leadership, mentoring peers, and partnering across IT and business units to ensure secure, complaint, and resilient systems.
Essential Duties and Responsibilities1. Security Engineering (Cloud – Primary Responsibility)
- Administer and optimize Microsoft security platforms, including Defender, Purview, and Intune
- Configure and maintain security controls within Microsoft 365 and Entra ID (Azure AD)
- Lead implementation of security tools, policies, and automation
- Strengthening endpoint security, identity protection, and data-loss prevention capabilities
- Partner with Security Operations to support monitoring, detection, and incident response
2. Enterprise Application & On-Prem Security
- Secure and support enterprise applications (e.g., Ellucian Colleague, Informer)
- Perform secure installation, configuration, patching, and upgrades
- Implement role-based access controls and least privilege models
- Conduct application security reviews and system hardening
3. Technical Leadership
- Lead security-related projects and major system implementations
- Provide guidance on secure design and architecture decisions
- Develop and maintain security standards, procedures, and baselines
- Mentor junior staff and provide subject matter expertise
4. Risk, Compliance, and Governance
- Support institutional compliance efforts (FERPA, GLBA, PCI-DSS as applicable)
- Conduct risk assessments and recommend remediation strategies
- Identify control gaps and drive continuous improvement
- Participate in incident response as a senior technical contributor
- Bachelor’s degree in information technology, Cybersecurity, or related field (or equivalent combination of education and experience)
- 5–7 years of progressive experience in information security, systems engineering, or related field
- Hands-on experience with Microsoft 365 security technologies (Defender, Purview, Intune)
- Experience securing enterprise systems and applications
- Knowledge of identity and access management, endpoint security, and data protection principles
- Demonstrated experience leading technical projects or implementations
- Experience in higher education or similarly complex environments
- Familiarity with Ellucian Colleague, Informer, or comparable ERP systems
- Experience with scripting/automation (PowerShell)
- Knowledge of security frameworks (NIST, CIS Controls, ISO 27001)
- Relevant certifications:
- Microsoft (SC-200, SC-300, SC-400)
- CISSP, CISM, or equivalent
- Advanced technical troubleshooting and analytical skills
- Ability to lead initiatives without formal supervisory authority
- Strong collaboration and communication skills across technical and non-technical teams
- Ability to translate security risks into actionable recommendations
- Reports to: Chief Information Security Officer (CISO)
- Supervisory Responsibility: None
- Primarily office or hybrid work environment
- May require occasional after-hours support for incidents or system changes
The University endeavors to create and nurture an informed and inclusive environment in its workplace and educational programs. Affirmative action and equal employment opportunity are integral parts of the University not just because they are legally mandated, but because we recognize that the present and future strength of the university is based primarily on people and their skills, experience, and potential. The University does not discriminate in access to, or treatment or employment in, its programs and activities on the basis of race, color, age, religion, sex, sexual orientation, gender identity or expression, national or ethnic origin, veteran status, disability, genetic information, ancestry, or marital status. The University seeks to recruit, select, and promote students, faculty, and all other employees on the basis of individual merit.
Skills Required
- Bachelor’s degree in information technology, cybersecurity, or a related field, or equivalent education and experience
- 5–7 years of progressive experience in information security, systems engineering, or a related field
- Hands-on experience with Microsoft 365 security technologies, including Defender, Purview, and Intune
- Experience securing enterprise systems and applications
- Knowledge of identity and access management, endpoint security, and data protection principles
- Demonstrated experience leading technical projects or implementations
- Experience in higher education or similarly complex environments
- Familiarity with Ellucian Colleague, Informer, or comparable ERP systems
- Experience with scripting or automation using PowerShell
- Knowledge of NIST, CIS Controls, or ISO 27001 security frameworks
- Microsoft SC-200, SC-300, or SC-400 certification
- CISSP, CISM, or equivalent certification
What We Do
The University of Tulsa (TU) is a private, STEM-focused research university located in Tulsa, Oklahoma, United States.





