Description
ABOUT ASPIRION
At Aspirion, our mission is simple and meaningful: to help healthcare providers get paid accurately, quickly, and transparently for the care they deliver. By combining deep human expertise with advanced technology and AI, we are helping make healthcare more affordable and accessible for everyone.
For more than two decades, Aspirion has been a market leader in revenue cycle services, specializing in some of the most complex and high-impact areas of reimbursement. From challenging denials and zero-balance reviews to aged accounts receivable, motor vehicle accident claims, workers' compensation, Veterans Affairs, and out-of-state Medicaid, we take on the work that others cannot solve and deliver real results for our clients. At the heart of that success is our team. Our teammates are the foundation of everything we do. With more than 1,400 individuals across the organization, we are united by a shared commitment to delivering exceptional outcomes and creating meaningful impact for the hospitals and health systems we serve.
We are building a results-driven environment where high performance, collaboration, and continuous growth are expected and supported. The people who thrive here bring a growth mindset, stay open to new technology, and collaborate across teams to solve problems. You will have the opportunity to work alongside a talented and driven team, engage with innovative technology, and play a direct role in solving complex challenges that matter.
Joining Aspirion means more than taking a job. It means being part of a team that is shaping the future of healthcare operations while making a measurable difference for providers and patients alike.
POSITION SUMMARY
The Security Engineer III reports to the Principal Security Engineer and serves as a senior, hands-on individual contributor supporting security controls across Aspirion's Microsoft Azure, Microsoft 365, identity, data, application, endpoint, and security-platform environments.
Working closely with the Principal Security Engineer, this role helps implement and operate the security strategy for Azure security posture, identity security, Microsoft Purview and data-protection controls, vulnerability and asset-management capabilities, and security automation. The engineer also partners with Security Operations, Infrastructure, Network, Application Development, Data, Privacy, Compliance, and business teams to turn security and regulatory requirements into practical, measurable controls.
Success in this role requires sound judgment, collaborative execution, and the ability to improve security without creating unnecessary friction. In coordination with the Principal Security Engineer, the engineer will take assigned work from assessment and design through implementation, documentation, and steady-state operation.
KEY RESPONSIBILITIES
Azure, Identity and Data Protection
· Design and maintain Azure security guardrails and configuration baselines across subscriptions, management groups, workloads, and platform services. Core areas include logging, encryption, secrets management, workload protection, network exposure, and configuration compliance.
· Operate and improve Microsoft Defender for Cloud, Azure Policy, Azure Monitor, and related security capabilities. Prioritize findings, coordinate remediation, validate fixes, and maintain documented risk exceptions.
· Implement and improve Microsoft Entra ID controls, including Conditional Access, Privileged Identity Management, role-based access control, access reviews, identity governance, managed identities, service principals, workload identities, and least-privilege access patterns.
· Partner with IT Operations, Endpoints, Servers, and DevOps teams, along with application owners, to strengthen joiner, mover, and leaver processes; privileged-access governance; periodic access certification; and monitoring of human and non-human identities.
· Configure, test, deploy, and tune Microsoft Purview capabilities, including data discovery and classification, sensitivity labels, automatic labeling, data-loss-prevention policies, retention and lifecycle controls, and monitoring of sensitive-data use and movement.
· Work with Data, Privacy, Legal, Compliance, and business owners to translate approved data-handling requirements into enforceable controls across Microsoft 365, Azure, endpoints, applications, and relevant SaaS platforms.
Vulnerability Management, Security Operations and Response
· Administer and improve vulnerability-management capabilities across cloud resources, endpoints, servers, network devices, applications, dependencies, containers, and infrastructure as code. Establish risk-based priorities, remediation targets, validation processes, reporting, and exception workflows.
· Improve the completeness and accuracy of security asset inventories by reconciling cloud, endpoint, network, application, and vulnerability-management sources. Identify unmanaged, unscanned, stale, duplicate, or unsupported assets and coordinate corrective action.
· Define security-telemetry and logging requirements, onboard relevant data sources, and develop or tune actionable detections with SOC and SIEM owners. Improve alert quality, investigation context, response automation, and coverage of Azure, identity, data, application, and endpoint threats.
· Support technical investigation, containment, recovery, and root-cause analysis for security incidents. Convert incident findings into durable engineering improvements, detections, preventive controls, and updated runbooks.
Cloud, Network and Application Security
· Partner with Infrastructure and Network teams to assess and improve segmentation, firewalls, web application protections, private connectivity, ingress and egress controls, DNS security, remote access, encryption in transit, and connectivity between cloud, on-premises, and third-party environments.
· Assist with conducting security architecture and design reviews, threat modeling, and technical risk assessments for new and materially changed applications, integrations, APIs, and data flows. Provide practical secure-design patterns and remediation guidance.
· Help implement and operate security controls for application code, third-party dependencies, secrets, infrastructure as code, and deployment pipelines. Support risk-based security gates, remediation workflows, and documented exceptions without unnecessarily blocking delivery.
· Assess legacy and acquired applications for identity, data protection, network exposure, vulnerability, logging, dependency, and supportability risks. Define compensating controls and work with application owners on remediation, modernization, isolation, or retirement plans.
Security Platforms, Automation and Operational Excellence
· Work closely with the Principal Security Engineer to support the security environment, execute the security-engineering roadmap, evaluate technical options, and align implementation decisions, priorities, and operational improvements.
· Administer and integrate enterprise security tools, including access controls, service accounts, connectors, APIs, scanning policies, detection rules, data quality, system health, upgrades, and lifecycle management. Tune controls to reduce false positives while maintaining appropriate coverage.
· Develop reusable automation using PowerShell, Python, Microsoft Graph, REST APIs, KQL, Terraform, Bicep, or similar technologies. Automate control validation, policy enforcement, evidence collection, ticket creation, reporting, and repetitive operational work.
· Translate HIPAA, HITRUST, NIST, Zero Trust, and internal policy requirements into measurable technical controls. Test control effectiveness and produce audit-ready evidence, implementation documentation, control narratives, and remediation records.
· Establish and report meaningful measures such as asset and scanning coverage, identity-control coverage, policy adoption, vulnerability-remediation performance, logging coverage, alert quality, data-protection events, tool health, and exception aging.
· Manage assigned security-engineering initiatives from intake through implementation and operational handoff in coordination with the Principal Security Engineer. Communicate status, dependencies, risks, and tradeoffs to technical and business stakeholders.
· Develop and maintain standards, procedures, runbooks, reference configurations, and support documentation. Serve as a technical resource through reviews, pairing, mentoring, and stakeholder education.
· Participate in incident-escalation processes, including after-hours incident response when needed, and perform other duties as assigned.
Requirements
CORE COMPETENCIES
· Azure Security Engineering: Strong knowledge of Azure identity, governance, networking, monitoring, encryption, secrets management, workload protection, and security-posture management.
· Identity and Zero Trust: Ability to implement least privilege, privileged-access controls, Conditional Access, identity governance, access certification, and secure workload identities.
· Data Protection: Experience turning data-classification and handling requirements into sensitivity labeling, DLP, retention, encryption, and access controls.
· Vulnerability and Asset Management: Ability to improve coverage, prioritize risk, coordinate remediation, validate results, and maintain defensible exception processes.
· Security Operations: Working knowledge of telemetry onboarding, detection engineering, alert tuning, investigation, containment, root-cause analysis, and corrective action.
· Security Architecture: Ability to identify practical risks in cloud, network, applications, APIs, integrations, data flows, deployment pipelines, and legacy systems.
· Automation and Security as Code: Ability to use scripting, APIs, query languages, and infrastructure as code to improve consistency, coverage, efficiency, and evidence quality.
· Risk and Compliance: Ability to recommend proportionate controls, document tradeoffs, test effectiveness, and support audit-ready operation in a regulated environment.
· Collaborative Delivery: Ability to take ambiguous technical problems from discovery through implementation and sustainable operation while aligning priorities, designs, and key decisions with the Principal Security Engineer.
· Collaboration and Communication: Ability to influence cross-functional teams and produce clear technical guidance, implementation records, and risk summaries for varied audiences.
EDUCATION AND EXPERIENCE
· Four or more years of experience in security engineering, cloud infrastructure, identity engineering, security operations, application security, or a related technical discipline.
· Significant hands-on experience securing production Microsoft Azure environments, including direct implementation and operation of security controls.
· Strong experience with Microsoft Entra ID security, including Conditional Access, privileged access, role-based access control, identity governance, and human and workload identities.
· Hands-on experience configuring data classification, sensitivity labeling, DLP, retention, or related data-protection policies using Microsoft Purview or a comparable enterprise platform. Direct Microsoft Purview experience is strongly preferred.
· Experience administering or integrating enterprise vulnerability-management, asset-management, SIEM/SOAR, cloud-security, endpoint-security, application-security, or data-protection platforms.
· Demonstrated experience improving vulnerability and asset-management coverage, prioritizing findings based on business risk, tracking remediation, and validating closure.
· Experience supporting security investigations and incident response, including log analysis, containment support, root-cause analysis, and preventive engineering changes.
· Working knowledge of cloud and network-security concepts, application-security reviews, APIs, third-party integrations, and legacy-technology risks.
· Automation experience using one or more of PowerShell, Python, Microsoft Graph, REST APIs, KQL, Terraform, or Bicep.
· Experience implementing and evidencing controls in a regulated environment. Healthcare and HIPAA experience are strongly preferred; familiarity with HITRUST and NIST is preferred.
· Candidates should hold a bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related discipline, or have equivalent practical experience.
PREFERRED CERTIFICATIONS
One or more of the following certifications, or equivalent practical expertise, is preferred:
· Microsoft Certified: Azure Security Engineer Associate or Cybersecurity Architect Expert.
· Microsoft identity, security-operations, or information-protection certification.
· CISSP, CCSP, GIAC, or another relevant cloud, incident-response, application-security, or security-engineering certification.
Benefits
At Aspirion we invest in our employees by offering a full benefits package, including:
- Health
- Dental
- Vision
- Life insurance
- Matching 401k
- Paid Time Off
- Wellness Program
- Competitive Salaries
- Advancement Opportunities
AAP/EEO Statement
Equal Opportunity Employer/Drug-Free Workplace: Aspirion is an Equal Employment Opportunity employer. We adhere to a policy of making employment decisions without regard to race, color, age, sex, pregnancy, religion, national origin, ancestry, medical condition, marital status, gender identity citizenship status, veteran status, disability, or veteran status. Aspirion has a Drug-Free Workplace Policy in effect that is strictly adhered to.
Skills Required
- 5+ years of experience in security engineering, cloud infrastructure, DevOps, or related technical roles
- Hands-on experience securing production AWS environments
- Strong AWS IAM skills, including roles, policies, least privilege, identity federation, and service roles
- Experience implementing cloud security posture management, guardrails, continuous compliance, and vulnerability remediation
- Hands-on Kubernetes and container security experience in production environments
- Experience with Kubernetes RBAC, network policies, pod security standards, image governance, secrets, and runtime protections
- Experience implementing and evidencing security controls in HIPAA-regulated environments
- Experience with encryption, key management, logging retention, and change or audit trails
- Experience supporting incident response for cloud or workload security events
- Automation and Infrastructure as Code experience using tools such as Python, Bash, or Terraform
- Experience implementing policy-as-code and continuous compliance checks
- Experience assessing and improving application code and Infrastructure as Code security
- Experience managing container security vulnerabilities, image scanning, OS package patching, image rebuilds, and remediation validation
- Experience implementing secure SDLC controls in CI/CD pipelines, including SAST, SCA, container image scanning, secrets scanning, and policy gates
- Experience operating in regulated environments; HIPAA experience is required
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent practical experience
- Familiarity with NIST or HITRUST
- AWS Certified Security Specialty or AWS Solutions Architect certification
- Certified Kubernetes Security Specialist or equivalent certification
- CISSP or CCSP certification, or ability to obtain certification
Aspirion Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Aspirion and has not been reviewed or approved by Aspirion.
-
Flexible Benefits — Remote and flexible schedules are widely offered in many roles. This flexibility can meaningfully enhance perceived total compensation.
-
Healthcare Strength — Medical, dental, and vision coverage begin on the first day of employment. Immediate access to core health plans is positioned as a standout element of the package.
-
Retirement Support — A 401(k) plan with an employer match is part of the offering. Employer-supported retirement savings are highlighted as a core benefit.
Aspirion Insights
What We Do
Aspirion’s mission is to be providers’ trusted partner to optimize otherwise challenging reimbursements Aspirion is a full-service revenue cycle management (RCM) company founded in 2006 that specializes exclusively in complex claims and denials. Our complex claims consist of Motor Vehicle Accident (MVA), third-party liability (TPL), Workers’ Compensation, Veterans Administration, Out-of-State Medicaid, and Medicaid Eligibility & Enrollment claims. Our denials service lines include premium denials and lower-value denials. While our clients traditionally categorize all of these claims as complex, to us they are simply claims—and they are all we do. Aspirion has one of the largest and most highly trained teams of investigators, specialists, clinicians, coders and attorneys. We work together to make our clients better.







