Principal Network Detection & Response Engineer

Posted Yesterday
Be an Early Applicant
Eden Prairie, MN, USA
In-Office
113K-193K Annually
Senior level
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
The Role
Leads enterprise Network Detection and Response architecture, deployment, optimization, and threat detection engineering across hybrid cloud and on-premises environments. Analyzes packet captures, network flows, protocols, and encrypted telemetry to identify advanced threats and lateral movement. Integrates NDR with SIEM, SOAR, and EDR platforms to automate response and improve detection and response times. Partners with threat intelligence, hunting, and incident response teams, conducts security architecture reviews, and mentors security engineers.
Summary Generated by Built In
Requisition Number: 2362093
Optum Tech is a global leader in health care innovation. Our teams develop cutting-edge solutions that help people live healthier lives and help make the health system work better for everyone. From advanced data analytics and AI to cybersecurity, we use innovative approaches to solve some of health care's most complex challenges. Your contributions here have the potential to change lives. Ready to build the next breakthrough? Join us to start Caring. Connecting. Growing together.
As a Principal Network Detection & Response Engineer within our Cyber Operations Group team, you will lead the architecture, deployment, and continuous optimization of enterprise-wide Network Detection and Response (NDR) capabilities. In this role, you will be instrumental in protecting critical enterprise assets by analyzing network telemetry, developing advanced threat detection logic, and orchestrating rapid response strategies against sophisticated cyber threats. You will collaborate closely with threat intelligence, incident response, and infrastructure teams to design resilient, cutting-edge security monitoring solutions across hybrid-cloud and on-premises environments.
You'll enjoy the flexibility to work remotely * from anywhere within the U.S. as you take on some tough challenges. For all hires in the Minneapolis or Washington, D.C. area, you will be required to work in the office a minimum of four days per week.
Primary Responsibilities:
  • Lead the strategy, architectural design, and optimization of Network Detection & Response (NDR) and network security monitoring platforms across hybrid enterprise environments
  • Develop, test, and tune high-fidelity detection signatures, behavioral rules, and anomaly detection models to identify advanced persistent threats (APTs) and zero-day vulnerabilities
  • Analyze complex network traffic, packet captures (PCAP), flow data, and encrypted telemetry to uncover evasive malicious activity and lateral movement
  • Drive automated response workflows and integration between NDR tools, SIEM, SOAR, and Endpoint Detection & Response (EDR) platforms to minimize Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR)
  • Partner with Threat Hunting, Threat Intelligence, and Incident Response teams to translate emerging cyber threat tactics, techniques, and procedures (TTPs) into actionable detections
  • Conduct technical reviews, risk assessments, and architectural evaluations of proposed network infrastructure changes to ensure alignment with security detection objectives
  • Mentor senior and junior security engineers, providing technical guidance, rule reviews, and subject matter expertise in network defense and threat hunting

You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in.
Required Qualifications:
  • 5+ years of professional experience in cybersecurity engineering, network security, or intrusion detection/prevention
  • 3+ years of hands-on experience deploying, configuring, and tuning Network Detection & Response (NDR) or Network Traffic Analysis (NTA) platforms (e.g., Corelight, Darktrace, ExtraHop, Zeek/Bro, Suricata)
  • 3+ years of experience analyzing network protocols (e.g., TCP/IP, DNS, TLS, BGP) and conducting deep packet inspection using tools such as Wireshark, Zeek, or Suricata
  • 3+ years of experience integrating network telemetry and security alerts into enterprise SIEM (e.g., Splunk, Sentinel) and SOAR tools

Preferred Qualifications:
  • Industry certifications in information security or network security (e.g., CISSP, GCIA, GCIH, GNFA, CCNP Security)
  • Experience engineering security detections for cloud networks and cloud-native services (e.g., AWS VPC Traffic Mirroring, Azure Network Watcher, GCP Packet Mirroring)
  • Knowledge of the MITRE ATT&CK framework with demonstrated success mapping network detections to adversary techniques
  • Solid background in decrypting or inspecting SSL/TLS traffic and analyzing encrypted network sessions
  • Proven ability to communicate complex technical security risks and detection strategies to senior engineering and leadership stakeholders

*All employees working remotely will be required to adhere to UnitedHealth Group's Telecommuter Policy
Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you'll find a far-reaching choice of benefits and incentives. The salary for this role will range from $112,700 - $193,200 annually based on full-time employment. We comply with all minimum wage laws as applicable.
Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants.
At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission.
UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations.
UnitedHealth Group is a drug - free workplace. Candidates are required to pass a drug test before beginning employment.

Skills Required

  • 5+ years of professional experience in cybersecurity engineering, network security, or intrusion detection and prevention
  • 3+ years of hands-on experience deploying, configuring, and tuning Network Detection and Response or Network Traffic Analysis platforms
  • 3+ years of experience analyzing TCP/IP, DNS, TLS, BGP, and other network protocols
  • 3+ years of experience conducting deep packet inspection using Wireshark, Zeek, or Suricata
  • 3+ years of experience integrating network telemetry and security alerts into enterprise SIEM and SOAR tools
  • Industry certifications in information security or network security, such as CISSP, GCIA, GCIH, GNFA, or CCNP Security
  • Experience engineering security detections for cloud networks and cloud-native services, including AWS, Azure, or GCP networking tools
  • Knowledge of the MITRE ATT&CK framework and experience mapping network detections to adversary techniques
  • Experience decrypting or inspecting SSL and TLS traffic and analyzing encrypted network sessions
  • Ability to communicate complex technical security risks and detection strategies to senior engineering and leadership stakeholders

What the Team is Saying

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Eden Prairie, MN
160,000 Employees
Year Founded: 2011

What We Do

Optum, part of the UnitedHealth Group family of businesses, is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together. At Optum, we support your well-being with an understanding team, extensive benefits and rewarding opportunities. By joining us, you’ll have the resources to drive system transformation while we help you take care of your future. We recognize the power of connection to drive change, improve efficiency and make a difference in health care. Join a team where your skills and ideas can make an impact and where collaboration is key to creating technology that produces healthier outcomes.

Gallery

Gallery
Gallery
Gallery

Optum Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Optum has three workplace models that balance the needs of the business and the responsibilities of each role. These models, core on‑site (5 days/week), hybrid (4 days/week) and telecommute or fully remote, vary by country, role and location.

Typical time on-site: Not Specified
HQEden Prairie, MN
Metro Manila, Philippines
Cebu, Philippines
Davao, Philippines
Ann Arbor, MI
Atlanta, GA
Baltimore, MD
Bengaluru, India
Chennai, India
Dallas, TX
Detroit, MI
Dublin, Ireland
Hartford, CT
Houston, TX
Hyderabad, India
Jacksonville, FL
Las Vegas, NV
Letterkenny, Ireland
Louisville, KY
Madison, WI
Minneapolis, MN
Nashville, TN
New Delhi, India
Philadelphia, PA
Phoenix, AZ
Pune, India
Raleigh, NC
San Diego, CA
Washington, DC
Learn more

Similar Jobs

Optum Logo Optum

Per Diem Patient Services Representative Associate

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Saint Paul, MN, USA
160000 Employees
16-29 Hourly

Optum Logo Optum

Credentialing Representative

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Eden Prairie, MN, USA
160000 Employees
18-32 Hourly

Optum Logo Optum

Epic MyChart Analyst - Remote

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office or Remote
Eden Prairie, MN, USA
160000 Employees
73K-130K Annually

Optum Logo Optum

Asymmetric Defense Engineer - Remote or Office-Based in MN or DC

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office or Remote
Eden Prairie, MN, USA
160000 Employees
113K-193K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account