Senior Security Engineer at RxBenefits
Billings, MT
$120,000–$150,000from the description
Jul 13, 2026
Billings, MT
Jul 21, 2026
What this job asks for AI summary
A senior individual-contributor role responsible for owning a SIEM platform (Sumo Logic preferred) and the broader security operations function at a healthcare benefits company. Day-to-day work spans log source architecture, detection engineering mapped to MITRE ATT&CK, alert triage, threat hunting across AWS/cloud/endpoint/identity environments, and leading the full incident response lifecycle. Suits an experienced security engineer comfortable working independently in a HIPAA-regulated, compliance-driven setting.
Senior level · 7+ years · Remote · Full-time
“or” means any one of them counts — you don't need all of them.
Posted 7 times — it's one opening, so apply once.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 490 people nationally plausibly meet what this posting asks for (information security analysts). range 100–740
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (9)
The JD requires a Bachelor's degree 'or equivalent work experience,' so no formal degree is hard-gated.
A cyber-specific certification (GCIH, GCFA, CISSP, or a relevant SIEM/vendor cert) is listed as required; no single cert is named as the exclusive gate.
Sumo Logic is 'strongly preferred' within the required SIEM section — it is listed under Required Skills with that qualifier, so it is treated as a hard gate on SIEM expertise with Sumo Logic as the named platform.
CrowdStrike and Zscaler appear in the required section as parenthetical examples ('e.g.') of EDR and network security platforms respectively; they are captured as hard gates with the understanding that equivalent platforms in those categories would likely be accepted.
PowerShell, Python, and Bash are listed together as interchangeable scripting options in the required section; PowerShell is the primary name with Python and Bash as alternatives.
The role is fully remote ('Remote first work environment') with no stated geographic restriction.
The 7-year total IT experience minimum includes a sub-requirement of at least 4 years specifically in security engineering, SOC, or incident response.
Tabletop exercise experience and healthcare industry experience are listed under Preferred Skills/Experience.
This posting reads as a fully-remote role, so it was scored against the national candidate pool rather than a single metro.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.