I'm not an expert in server configuration, but I would be surprised to find that there's a "server type" where modx_security can't be disabled.
Anyway, back to the problem:
First, try disabling all plugins (or do them one-by-one if you prefer, starting with ones that might execute when a resource is saved). Delete all files in the core/cache directory after each change before testing.
If that's not it, do you have a copy of
SiteCheck? I'm not saying it will solve the problem, but since we're grasping at straws, it will tell you if there are any anomalies like a template or TV with an invalid category or a resource with an invalid parent field.