Compliance and cybersecurity assessments for regulated industries
RSI Security delivers compliance assessments, penetration testing, and advisory services to private and public sector organizations in regulated industries. The tech stack is heavy on specialized security tools (Burp Suite, Nmap, Nessus, Metasploit, Wireshark) paired with compliance frameworks (PCI DSS, CMMC, NIST, HITRUST, SOC 2, ISO 27001), and they're actively adopting NIST and ISO 27001 — signaling expansion into broader compliance advisory beyond their core CMMC expertise. The hiring mix reflects a security-first organization: 9 of 21 open roles are in security, with recent additions of a CMMC Lead and Chief Information Security Officer.
Notable leadership hires: CMMC Lead, Chief Information Security Officer
RSI Security, founded in 2008 and headquartered in Southlake, Texas, is a cybersecurity and compliance services firm serving mid-market and enterprise clients in healthcare, finance, and defense contracting. The company offers cyber engineering, penetration testing, compliance assessments (PCI DSS, CMMC, HITRUST, HIPAA/HITECH, GDPR, CCPA), and managed security services. Active projects include CMMC readiness assessments (levels 1–3), PCI DSS assessment lifecycles, ROC/AOC development, and ongoing penetration testing engagements. The organization operates across 51–200 employees with a distributed hiring footprint spanning the US, Mexico, and Syria.
Burp Suite, Nmap, Nessus, Metasploit, and Wireshark for penetration testing and vulnerability assessment; Vanta for SOC 2 compliance automation; HITRUST CSF and NIST frameworks for standards-based assessments.
PCI DSS, CMMC (levels 1–3), HITRUST, HIPAA/HITECH, SOC 2, ISO 27001, NIST, GDPR, and CCPA. They actively deliver readiness assessments, gap analysis, and remediation planning across these frameworks.
Other companies in the same industry, closest in size