> Markdown version of [/jobs/ext/156341-senior-security-engineer](https://www.wearedevelopers.com/jobs/ext/156341-senior-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - **Company:** RSI Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Amazon Web Services, Apple Mac Systems, Microsoft Azure, Software as a Service, Cloud Computing, Continuous Integration, Information Leak Prevention, DevOps, Identity and Access Management, Python (Programming Language), Microsoft Office, Network Segmentation, PCI Data Security Standards, Performance Tuning, Windows PowerShell, Kusto Query Language, Security Information and Event Management, Systems Integration, Software Vulnerability Management, Large Language Models, Mitre Att&ck, Generative AI, HybridCloud, Key Vault - **Published:** May 30, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=f7a5f0ef0cfd0562 ## About the Role Do you have experience in macOS?, * 7+ years in security engineering, with at least 3 in a senior or lead role. * Hands-on NinjaOne experience, or a comparable enterprise RMM platform. * Real operational time in Rapid7 InsightVM and InsightIDR - tuning, reporting, workflow. * Solid Azure security skills: Defender for Cloud, Sentinel, Entra ID, Key Vault, Azure Policy. * Working knowledge of AWS security: GuardDuty, Security Hub, IAM, CloudTrail, KMS. * Experience securing a Microsoft 365 tenant, including Defender for Office 365. * PowerShell scripting. Python or KQL is a plus. * HIPAA or similar regulated-industry background. * You can write clearly and hold your ground in front of non-technical executives. * CISSP, CCSP, GCIH, AZ-500, SC-200, or AWS Certified Security - Specialty. * Healthcare RCM experience, or familiarity with Latitude by Genesis. * Time spent on GenAI or LLM security - data loss prevention, prompt and output governance. * M&A IT integration experience. * SOC 2 or HITRUST audit history. ## Description RSi is a healthcare revenue cycle management company. We handle PHI and payment data for hospitals and health systems across the country, which means security has to be right. We're looking for a Senior Security Engineer to run the technical side of the program day to day. This is an individual contributor role reporting to the CIO. You'll have direct access to leadership and real influence over where the program goes. You'll also be accountable for the work - the toolset, the detections, the posture, the incident calls when something goes wrong. The environment is hybrid cloud - Azure and AWS, a Microsoft-heavy identity stack, Latitude as the core RCM platform, Microsoft 365, and a growing footprint of automation and generative AI in the business. HIPAA, PCI-DSS, and SOC 2 are all in play. What You'll Do: * Run NinjaOne for RMM, patching, and endpoint hygiene across the workforce. * Administer EDR coverage on Windows, macOS, and server workloads. * Work with Infrastructure on Entra ID security - conditional access, PIM, MFA, Defender for Identity. * Keep least-privilege honest across on-prem AD, Entra ID, and our federated SaaS. * Own Rapid7 InsightVM and InsightIDR as our primary vulnerability and SIEM platform. * Run vulnerability management end to end: scanning, prioritization, SLAs, exceptions, executive reporting. * Tune detections, triage alerts, and lead investigations. * Coordinate pen tests and chase the remediation through to close. * Harden workloads across Azure and AWS - network segmentation, secrets, workload identity. * Configure Microsoft Defender for Cloud and Sentinel; integrate signal with Rapid7 where it makes sense. * Administer AWS-native tooling: GuardDuty, Security Hub, IAM Access Analyzer, CloudTrail, Config, KMS. * Partner with DevOps to pull security into CI/CD and IaC reviews rather than bolt it on after. * Lead containment, eradication, and recovery when we have a security incident. * Keep the IR plan current and run tabletops with IT and executive stakeholders. * Maintain detection coverage mapped to MITRE ATT&CK. * Handle forensic collection in a way that holds up in a HIPAA environment. * Evidence controls for HIPAA, PCI-DSS, SOC 2, and client security questionnaires. * Support our NIST CSF and NIST AI RMF alignment, including the GenAI program. * Help with third-party risk reviews for vendors, clients, and acquired entities. * Write the policies and runbooks. Keep them usable. ## Related Videos - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Best Practices for Using GitHub Secrets](https://www.wearedevelopers.com/videos/1214-best-practices-for-using-github-secrets) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)