Pursue your passion and potential
Director Information Security Risk Management
Hyderabad, India
Caring. Connecting. Growing together.
With these values to guide us, our people are committed to making a meaningful difference in the lives of those we are honored to serve.
Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together.
The Director, XXX Technology and Cyber Governance is responsible for leading the GRC offshore teams for Technology, Cyber and AI Governance Risk and Control. The team drives the implementation, and continuous improvement of governance routines that ensure effective adherence to technology and cybersecurity standards. This role plays a critical part in shaping the enterprise technology risk profile and embedding sustainable, risk-based governance practices that drive accountability, transparency, and informed decision-making across technology organizations.
Success in this role requires not only deep audit and risk expertise but also the ability to architect governance operating models, integrate risk into business processes, and influence senior stakeholders to adopt consistent and scalable risk management practices.
Scope
The role requires ongoing engagement with policy and standard owners, executive leadership, and technology stakeholders to establish robust governance routines that translate policy requirements into measurable, enforceable, and sustainable practices.
The Director will lead the offshore (India, Ireland and Philippines) GRC Technology and Cybersecurity teams to define the governance pillars including risk assessments, metrics, and executive reporting, governance routines that ensure technology team alignment to enterprise risk appetite and regulatory expectations.
The role also partners with suppliers, business owners, control owners, and risk teams to identify gaps, validate remediation, and assess control effectiveness, while driving improvements in governance maturity and operational resilience.
Primary Responsibilities:
- Lead a team that supports the definition and implementation of a comprehensive technology and cybersecurity and AI governance framework, including oversight routines, risk reporting structures, and escalation pathways
- Design and collaborate with Technology and Cybersecurity teams to operationalize risk governance routines that integrate into day-to-day technology processes (e.g., SDLC, cloud deployments, third-party onboarding)
- As part of governance, collaborate with Technology and Cybersecurity teams to ensure they define Key Risk Indicators (KRIs), Key Control Indicators (KCIs), and performance metrics, including thresholds aligned to risk appetite that support the GRC metrics framework
- Lead risk profiling and aggregation activities, connecting control effectiveness, threat landscape, and business impact into a clear enterprise risk view
- Evaluate and challenge governance processes to ensure consistency, scalability, automation, and sustainability
- Drive standardization of governance practices across disparate technology teams and domains
- Assess effectiveness of preventive vs. detective controls, continuous monitoring capabilities, and automated controls
- Influence leadership to strengthen risk ownership, accountability, and decision-making discipline
- Ensure governance routines satisfy regulatory, audit, and industry framework expectations
- Comply with the terms and conditions of the employment contract, company policies and procedures, and any and all directives (such as, but not limited to, transfer and/or re-assignment to different work locations, change in teams and/or work shifts, policies in regards to flexibility of work benefits and/or work environment, alternative work arrangements, and other decisions that may arise due to the changing business environment). The Company may adopt, vary or rescind these policies and directives in its absolute discretion and without any limitation (implied or otherwise) on its ability to do so
Core Competencies
- Technology & Cybersecurity Expertise
- Advanced knowledge of enterprise architectures, cloud platforms, data ecosystems, and technology cybersecurity domains (IAM, network, endpoint, application security)
- Ability to evaluate how technology design decisions impact risk exposure and control effectiveness
- Risk Governance & Operating Model Design
- Ability to assess complex and ambiguous scenarios and define governance approaches where precedents do not exist
- Proven ability to design end-to-end governance operating models, including roles, responsibilities, workflows, and accountability structures
- Expertise in embedding risk governance into core technology lifecycle processes (including AI, SDLC, DevSecOps, infrastructure provisioning)
- Strong capability to define risk appetite statements, tolerance levels, and action-trigger thresholds
- Understanding of tiered governance models (operational, tactical, executive-level oversight)
- Ability to align governance routines to business strategy and digital transformation initiatives
- Analytical & Strategic Thinking
- Stakeholder Influence & Executive Communication (ENHANCED)
- Ability to communicate complex technical risks in clear, business-relevant terms
- Strong executive presence with experience influencing senior leaders and driving behavioral change
- Capability to challenge constructively while maintaining strong partnerships
- Skilled in delivering impactful reporting, including risk narratives, dashboards, and escalation briefings
- Regulatory & Industry Alignment
- Deep understanding of frameworks such as NIST CSF, ISO 27001, COBIT, SOX, FFIEC
- Ability to map governance routines to regulatory expectations and audit requirements
- Stakeholder Influence & Executive Communication (ENHANCED)
Awareness of evolving cybersecurity regulations and supervisory expectations.
Required Qualifications:
- Associate's degree (or higher) in Information Security, Risk Management, Business, or related field
- 10+ years in technology and information security with strong experience in risk governance, control assurance, and cybersecurity risk management
- 5+ years working across matrixed organizations with multiple stakeholders
- 5+ years managing and establishing a global team
- Demonstrated experience in:
- o Assessing Technology, AI and Cybersecurity Risk risks and controls
- o Designing or maturing risk governance routines and frameworks
- o Defining risk metrics, thresholds, and escalation processes
- o Assessing control effectiveness at scale
Preferred Qualifications:
- Certifications: CISA, CRISC, CISSP, CISM
- Experience in large-scale governance transformation or audit modernization initiatives
- Experience in technology engineering or technology development or technology infrastructure or cybersecurity management
- Exposure to cloud governance, AI risk frameworks, and DevSecOps environments
What Differentiates a High-Performing Director in This Role
- Designs governance - not just evaluates it
- Thinks in terms of systems, scalability, and sustainability rather than isolated controls
- Anticipates emerging risks and embeds them into governance early
- Uses data and automation to drive efficiency and insight
- Influences enterprise-wide behavior change and accountability
- Balances risk mitigation with business agility and innovation
- Inspires and motivates their team to think out of the box and drive innovation
At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission.
Benefits
Our mission of helping people live healthier lives extends to our team members. Learn more about our range of benefits designed to help you live well.
Life
Resources and support to focus on what matters most to you, in every facet of your life.
Emotional
Education, tools and resources to help you reduce and manage stress, build resilience and more.
Physical
Health plans and other coverage to support wellness for you and your loved ones.
Financial
Benefits for today and to help you plan for the future, including your retirement.
We’re honored to be recognized for our exceptional work culture
Connect with us


