Endpoint Compliance Hardening Security Engineer (REMOTE)

Post Date

Jun 30, 2025

Location

Woonsocket,
Rhode Island

ZIP/Postal Code

02895
US
Aug 31, 2025 Insight Global

Job Type

Contract,Perm Possible

Category

Security Engineering

Req #

BOS-791991

Pay Rate

$44 - $55 (hourly estimate)

Job Description

A large healthcare company is seeking an experienced Endpoint Compliance Hardening Security Engineer to join its enterprise security team. The client is over $370Bn in revenue and operates over 9,000 locations. They are dedicated to putting people first from their customers to their employees, engaging with customer feedback to further innovate to provide the best care possible, simplifying processes for care, creating a trusting environment, and to creating the safest and highest quality of care to keep patients protected. The client is dedicated to giving back to those around them. They have stared a Foundation to provide financial support to the communities to help with areas such as maternal health, mental health, scholarships, free health services/screenings, etc. This role is remote but EST time zone 8AM-5pm EST.

The Endpoint Compliance Hardening Staff Security Engineer (410_IC) plays a critical role in defining, implementing, and managing secure policy configuration policies across the organization's IT systems and infrastructure. This role ensures that security policy configurations are aligned with industry best practices and focuses on ensuring compliance with security standards, minimizing vulnerabilities through configuration management, and supporting organizational goals for a strong security posture. The Engineer will download the respective CIS benchmarks since they are updated every 6 months and then meet with the Asset Owners to harden their assets and be technical enought to push back when they say they cannot meet the specific requirements. For example, If they need to harden an OS image and they say they cannot configure 12 code password they must push back to understand where within the tech environment there is a true roadblock, if so it will go for CISO exception. This resource will configure Qualys to scan for these benchmarks. The Endpoint Compliance Hardening Staff Security Engineer works closely with IT, DevOps, and security teams to enforce secure baselines and automate policy compliance.

Key Responsibilities:
1.Secure Policy Configuration Management (Hardening):
-Develop, implement, and maintain secure configuration policy framework and baselines for operating systems, databases, applications, and network devices (e.g., firewalls, routers).
-Evaluate and ensure compliance with industry standards (e.g., CIS Benchmarks, NIST SP 800-53, ISO 27001) across the enterprise.
-Identify and mitigate risks associated with misconfigurations across the IT environment.
-Collaborate with stakeholders to align secure configuration policies with business and compliance requirements.
-Automate configuration validation and remediation processes using tools like Ansible, Chef, Puppet, or SCCM.
-Take a risk-based prioritization approach to define, enable and test Security Policy Configurations across all technology types to safeguard critical systems and data.
-This role ensures that secure hardening configurations are current and continuously scanned with approved technology to reduce risk of system outages and data loss from improper management of system configurations.
-Regularly review and update policies to reflect changes in the threat landscape or regulatory requirements.
-Stay informed of emerging security threats, compliance requirements, and best practices related to secure configurations.
-Implement tools and processes to continuously monitor, detect and enforce secure policy configurations (e.g., vulnerability scanners, configuration management tools).
-Conduct security audits and assessments to identify deviations and implement corrective actions.
-Act as a technical resource for teams resolving configuration-related issues.
-Generate compliance reports for internal stakeholders and regulatory bodies.
-Develop and deliver executive-level reports on compliance with configuration policies, including metrics on policy adherence and risk mitigation.
-Lead root cause analysis and remediation efforts for configuration-related security incidents.

2.Collaboration and Integration
-Work closely with IT, DevOps, and Security Operations teams to ensure secure configuration policies are integrated into system and application lifecycles.
-Partner with compliance and risk teams to ensure configurations meet regulatory standards (e.g., PCI DSS, HIPAA, SOX).
-Provide guidance and support during internal and external audits.

3.Continuous Improvement and Training
-Promote a culture of security awareness and best practices within the organization.
-Drive automation initiatives to streamline configuration management processes.
-Provide training and resources to ensure teams understand and adhere to secure configuration policies.


Compensation:
$50/hr to $55/hr.
Exact compensation may vary based on several factors, including location, skills, experience, and education.
Employees in this role will enjoy a comprehensive benefits package starting on day one of employment, including options for medical, dental, and vision insurance. Eligibility to enroll in the 401(k) retirement plan begins after 90 days of employment. Additionally, employees in this role will have access to paid sick leave and other paid time off benefits as required under the applicable law of the worksite location.

We are a company committed to creating inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity employer that believes everyone matters. Qualified candidates will receive consideration for employment opportunities without regard to race, religion, sex, age, marital status, national origin, sexual orientation, citizenship status, disability, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to Human Resources Request Form. The EEOC "Know Your Rights" Poster is available here.

To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/ .

Required Skills & Experience

- 5+ years of experience in information security, with a focus on secure configuration management or related areas.
- hands on with Qualys configuration
- background in infrastructure (networking, servers, OS, etc)
- 5+ years of experience with CIS Benchmarks and other related secure configuration frameworks (NIST SP 800-53)
- Experience with system hardening and secure configuration standards (e.g., CIS Benchmarks, DISA STIGs).
- background with configuration management tools (e.g., Ansible, Chef, Puppet, SaltStack, Microsoft Intune).
- Knowledge of security monitoring tools and platforms (e.g., Splunk, Qualys, Tenable).
- Bachelors degree in Computer Science, Information Security, or a related field (Masters degree preferred).

Nice to Have Skills & Experience

- automation (XML, Python, powershell, bash)
- AI
- Certified Information Systems Security Professional (CISSP).
- Certified Information Systems Auditor (CISA).
- CompTIA Security+ or Cybersecurity Analyst (CySA+).
- Qualys Security Configuration Assessment (SCA)

Benefit packages for this role will start on the 31st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.