Sr Information Security Engineer – Remote or Hybrid in MN or DC

Requisition Number: 2344611
Job Category: Technology
Primary Location: Eden Prairie, MN, US
(Remote considered)

Man standing and writing on a white board while presenting to coworkers in a meeting room.

Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by diversity and inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health equity on a global scale. Join us to start Caring. Connecting. Growing together.

 

The Enterprise Information Security (EIS) team is responsible for cybersecurity across our organization. We support our business and members by reducing risk, rapidly responding to threats, focusing on business resiliency and securing new acquisitions.

 

This function independently drives vulnerability remediation by coordinating with application and technical owners, tracking remediation timelines, and assisting teams with remediation where necessary. This position will work directly with senior engineers and system owners, auditors and members of the risk and compliance team. Participate in, and occasionally lead, tabletop testing of the cyber security DR and IR policies, as well as be responsible for updating these documents, and others.

 

If you are located in XXX, you will have the flexibility to work remotely* as you take on some tough challenges.  This position follows a hybrid schedule with four in-office days per week.

 

Primary Responsibilities:

  • Perform risk and control analysis to identify security risks and remediation plans
  • Drive vulnerability remediation with application and technical owners to meet agreed timelines
  • Prioritize vulnerabilities by risk, exploitability, and known exploited threats
  • Track remediation progress and maintain accurate vulnerability and risk metrics
  • Provide guidance on compensating controls and secure remediation approaches
  • Maintain and update security risk records and remediation plans
  • Develop and execute incident response and disaster recovery tabletop exercises
  • Create, maintain, and operationalize incident response plans and procedures
  • Support real-time security incident investigations, containment, and recovery
  • Evaluate and implement security controls across on‑prem and cloud environments
  • Serve as escalation point for complex identity, network, and security issues
  • Demonstrate understanding of discovery technologies to identify system vulnerabilities (eg, scanning tools)
  • Document risks associated with approved exceptions, define mitigation controls and establish long-term remediation strategies
  • Create reports around findings, outstanding risk and advise on next steps of the remediation process
  • Define/implement security data management/reporting requirements
  • Demonstrate knowledge of applicable IT industry security standards (eg, PCI-DSS, SSAE16, NIST800-53)
  • Maintain current knowledge on information security topics and their applicability program requirements

 

You’ll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in. 

Required Qualifications:

  • Bachelor’s degree or 5+ years of Technology experience
  • 3+ years of experience building relationships across multiple technical teams, stakeholders, and leadership
  • 2+ years of hands-on experience in technology and security audit
  • 2+ years of working experience with one or more compliance frameworks including NIST (800-53, 800-171), FedRAMP, MARS-e, and HITRUST
  • 1+ years of experience with an industry recognized vulnerability management tool, resolving of findings and tracking of remediation plans  
  • 1+ years of experience interacting with an executive audience

 

Preferred Qualifications:

  • Holds an audit, networking or security certification (CISA, GIAC, ISC2)
  • Project Management / Project coordination experience
  • Experience with application and system security implementation and remediation
  • Broad knowledge of Optum Technology and UHG/Optum/UHC businesses
  • Proven excellent interpersonal, oral and written communication skills, including ability to deliver a clear overview of strategy, opportunity and risks
  • Proven analytical skills related to application and customer inquiries
  • Proven influence and motivate teams that are required to interact with auditors

 

*All employees working remotely will be required to adhere to UnitedHealth Group’s Telecommuter Policy

 

Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you’ll find a far-reaching choice of benefits and incentives. The salary for this role will range from $91,700 to $163,700 annually based on full-time employment. We comply with all minimum wage laws as applicable.

 

At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes – an enterprise priority reflected in our mission.  

 

 

UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations.

 

UnitedHealth Group is a drug – free workplace. Candidates are required to pass a drug test before beginning employment.  

Additional Job Detail Information

Requisition Number 2344611

Employee Status Regular

Job Level Individual Contributor

Travel No

Country: US

Overtime Status Exempt

Schedule Full-time

Shift Day Job

Telecommuter Position Yes

Similar Jobs:

Our Hiring Process

We want you to know what our hiring process looks like. Watch the video and find out what to expect along the way.

What It’s Like

Watch the video and hear how our employees describe what it’s like to work here in Customer Service.

Careers at Optum

If you want to use your abilities to help us challenge the status quo and achieve on our ambitious mission, this is the right place for you. We are creating and delivering quality health care solutions that deeply impact the health care system. And this means opportunities for people like you to grow and innovate with us.

Closing the GAP

Our team members help close the gap in health care. Take a closer look and see how Lisa helps members navigate a complex health care system.