Senior Security Engineer
Listed on 2026-07-26
-
IT/Tech
Cybersecurity
Explore our on-site and remote revenue cycle management jobs.
At RSi, your revenue cycle career can grow in a workplace where talented people collaborate, and thrive together.
We believe in a culture driven by sharp, committed, and enthusiastic employees, and giving high-growth individuals the autonomy to perform.
Our current open positions are linked below. Are you the next member of our team?
Did you know? At least 1/3 of all RSi new hires come from internal referrals.
Position:Senior Security Engineer
Location: Remote
Remote Status: Hybrid
Job :326
# of Openings:1
Senior Security Engineer
|
Schedule:
Monday–Friday, 8am–5pm EST |
Location:
Remote
Work Where Excellence is Recognized
At RSi, we've proudly served healthcare providers for over 20 years, earning recognition as a "Best in KLAS" revenue cycle management firm and a USA Today Top 100 Workplace. Our reputation is built on delivering exceptional financial results for healthcare providers—and an unbeatable work culture for our team. We seek high-performing individuals willing to join our sharp, committed, and enthusiastic team.
Here, your performance is valued, your growth is prioritized, and your contributions make a meaningful impact every day.
RSi is a healthcare revenue cycle management company. We handle PHI and payment data for hospitals and health systems across the country, which means security has to be right. We're looking for a Senior Security Engineer to run the technical side of the program day to day.
This is an individual contributor role reporting to the CIO. You'll have direct access to leadership and real influence over where the program goes. You'll also be accountable for the work — the toolset, the detections, the posture, the incident calls when something goes wrong.
The environment is hybrid cloud — Azure and AWS, a Microsoft-heavy identity stack, Latitude as the core RCM platform, Microsoft 365, and a growing footprint of automation and generative AI in the business. HIPAA, PCI-DSS, and SOC 2 are all in play.
- Run Ninja One for RMM, patching, and endpoint hygiene across the workforce.
- Administer EDR coverage on Windows, macOS, and server workloads.
- Work with Infrastructure on Entra — conditional access, PIM, MFA, Defender for Identity.
- Keep least-privilege honest across on-prem AD, Entra , and our federated SaaS.
- Own Rapid7 InsightVM and InsightIDR as our primary vulnerability and SIEM platform.
- Run vulnerability management end to end: scanning, prioritization, SLAs, exceptions, executive reporting.
- Tune detections, triage alerts, and lead investigations.
- Coordinate pen tests and chase the remediation through to close.
- Configure Microsoft Defender for Cloud and Sentinel; integrate signal with Rapid7 where it makes sense.
- Administer AWS-native tooling:
Guard Duty, Security Hub, IAM Access Analyzer, Cloud Trail, Config, KMS. - Partner with Dev Ops to pull security into CI/CD and IaC reviews rather than bolt it on after.
- Lead containment, eradication, and recovery when we have a security incident.
- Keep the IR plan current and run tabletops with IT and executive stakeholders.
- Maintain detection coverage mapped to MITRE ATT&CK.
- Handle forensic collection in a way that holds up in a HIPAA environment.
- Evidence controls for HIPAA, PCI-DSS, SOC 2, and client security questionnaires.
- Support our NIST CSF and NIST AI RMF alignment, including the GenAI program.
- Help with third-party risk reviews for vendors, clients, and acquired entities.
- Write the policies and runbooks. Keep them usable.
- 7+ years in security engineering, with at least 3 in a senior or lead role.
- Hands-on Ninja One experience, or a comparable enterprise RMM platform.
- Real operational time in Rapid7 InsightVM and InsightIDR — tuning, reporting, workflow.
- Solid Azure security skills:
Defender for Cloud, Sentinel, Entra , Key Vault, Azure Policy. - Working knowledge of AWS security:
Guard Duty, Security Hub, IAM, Cloud Trail, KMS. - Experience securing a Microsoft 365 tenant, including Defender for Office 365.
- Power Shell scripting. Python or KQL is a plus.
- HIPAA or similar regulated‑industry background.
- You can write clearly and hold your ground in front of…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).