Skip to main content
Search JobsOpen search form

Explore remote jobs

Pursue your passion and potential

Principal Attack Surface Management - Remote or Hybrid in MN or DC

Eden Prairie, Minnesota

Caring. Connecting. Growing together.

With these values to guide us, our people are committed to making a meaningful difference in the lives of those we are honored to serve.

Principal Attack Surface Management - Remote or Hybrid in MN or DC

Requisition number: 2355877 Job category: Technology Primary location: Eden Prairie, MN Date posted: 05/28/2026 Overtime status: Exempt Travel: No

Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together.  

The Enterprise Information Security (EIS) team is responsible for cybersecurity across our organization. We support our business and members by reducing risk, rapidly responding to threats, focusing on business resiliency and securing new acquisitions.

You'll enjoy the flexibility to work remotely* from anywhere within the U.S. as you take on some tough challenges. For all hires in the Minneapolis or Washington, D.C. area, you will be required to work in the office a minimum of four days per week.

Primary Responsibilities:

Attack Surface Management & Exposure Reduction

  • Design, implement, and operate the organization's Attack Surface Management (ASM) program with a focus on continuous discovery, monitoring, and risk reduction
  • Identify and maintain an accurate inventory of external-facing assets, services, domains, IP ranges, cloud resources, and third party exposures
  • Configure and manage attack surface discovery and monitoring tools, including:
  • External scanning and exposure monitoring platforms (e.g., Shodan, Tenable, similar ASM tools)
  • Dark web monitoring solutions for credential leakage, data exposure, and brand risk
  • Network and application exposure analysis tools (e.g., AlgoSec or comparable platforms)
  • Analyze exposed services, misconfigurations, and vulnerabilities to determine true business risk and exploitation likelihood
  • Partner with infrastructure, network, cloud, application, and third party teams to drive remediation of identified exposures
  • Support secure email and messaging initiatives, including SMTP migrations and exposure reduction using platforms such as Proofpoint
  • Develop and maintain risk based prioritization models for attack surface findings
  • Track and report on attack surface reduction metrics, trends, and program maturity over time

Engineering & Automation

  • Automate asset discovery, exposure analysis, reporting, and validation workflows using scripting and APIs (PowerShell, Python, REST)
  • Build repeatable processes to improve visibility, accuracy, and operational efficiency of ASM tooling
  • Integrate ASM tools and findings with SIEM, SOAR, ticketing, and vulnerability management platforms
  • Evaluate new attack surface and exposure management capabilities, recommending tooling or process improvements based on risk and business impact
  • Leverage enterprise-approved AI tools to enhance productivity and innovation by streamlining workflows and automating repetitive tasks
  • Evaluate emerging trends to drive continuous improvement and strategic innovation

Collaboration & Guidance

  • Work closely with IT, infrastructure, network, cloud, application, and security teams to embed attack surface awareness into system design and change processes
  • Provide technical guidance on secure architecture, exposure reduction, and preventative controls
  • Clearly communicate attack surface risks, findings, and remediation strategies to both technical and non technical stakeholders
  • Contribute to security standards, policies, and architectural guidance related to external exposure management

You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in.

Required Qualifications: 

  • 7+ years of experience in cybersecurity, security engineering, or a related field
  • 3+ years of hands on experience in attack surface management, vulnerability management, external exposure monitoring, or a closely related discipline
  • Proven solid understanding of internet facing infrastructure, cloud services, networking, DNS, certificates, and common exposure patterns
  • Experience working cross functionally to drive remediation of security risks

Preferred Qualifications: 

  • 2+ years of scripting or automation experience (PowerShell, Python, REST APIs)
  • Experience with ASM, exposure management, or scanning tools such as Shodan, Tenable, or similar platforms
  • Demonstrated familiarity with dark web monitoring, credential exposure analysis, and brand protection tooling
  • Experience with network security policy analysis tools (e.g., AlgoSec) or similar technologies
  • Experience supporting secure email platforms or SMTP migrations (e.g., Proofpoint)
  • Experience integrating security tooling with SIEM, SOAR, or ticketing systems

Key Competencies:

  • Solid engineering mindset with hands on execution
  • Excellent analytical and problem solving skills
  • Ability to assess risk beyond raw vulnerability severity
  • Ability to balance security improvements with operational realities
  • Clear communicator with both technical and non technical audiences
  • Solid ownership mentality and attention to detail

*All employees working remotely will be required to adhere to UnitedHealth Group's Telecommuter Policy.

Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you'll find a far-reaching choice of benefits and incentives. The salary for this role will range from $112,700 to $193,200 annually based on full-time employment. We comply with all minimum wage laws as applicable.

Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants.

At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission.    

UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations.

UnitedHealth Group is a drug - free workplace. Candidates are required to pass a drug test before beginning employment.

Benefits

Our mission of helping people live healthier lives extends to our team members. Learn more about our range of benefits designed to help you live well.

Life

Resources and support to focus on what matters most to you, in every facet of your life.

Emotional

Education, tools and resources to help you reduce and manage stress, build resilience and more.

Physical

Health plans and other coverage to support wellness for you and your loved ones.

Financial

Benefits for today and to help you plan for the future, including your retirement.

Learn more
testimonial-img-1
testimonial-img-2
testimonial-img-3

We’re honored to be recognized for our exceptional work culture

AGWF recognition award
2025 Campus Forward Award badge from RippleMatch
LinkedIn Top Companies 2025 award badge
Forbes Best Large Employers in the United States 2024 award badge
America’s Greatest Workplaces 2024 award badge