Principal Security Engineer - Splunk & SIEM Engineering - Remote

Posted Yesterday
Be an Early Applicant
Hiring Remotely in Raleigh, NC, USA
In-Office or Remote
113K-193K Annually
Mid level
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
The Role
Serve as the Splunk SME to design, build, and optimize enterprise Splunk infrastructure; lead log onboarding from acquisitions; design data ingestion, parsing, and CIM normalization; ensure reliable, high-availability log pipelines across cloud/on-prem/SaaS; support SOC detection, dashboards, and alerts; develop onboarding playbooks; mentor security engineers and coordinate cross-functional teams.
Summary Generated by Built In
Requisition Number: 2369995
Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together.
We are seeking a highly experienced Principal Security Engineer to lead Splunk engineering and onboarding efforts across acquired entities. This role will serve as the Splunk Subject Matter Expert (SME) and play a critical leadership role in integrating newly acquired environments into the enterprise security monitoring ecosystem.
The ideal candidate blends deep technical expertise in Splunk infrastructure with strong program leadership, ensuring scalable log ingestion, normalization, and operational excellence across diverse environments.
You'll enjoy the flexibility to work remotely * from anywhere within the U.S. as you take on some tough challenges. For all hires in the Minneapolis or Washington, D.C. area, you will be required to work in the office a minimum of four days per week.
Primary Responsibilities:
  • Splunk Engineering & SME Leadership
    • Serve as the primary Splunk SME, providing architecture guidance, troubleshooting support, and strategic direction
    • Design, build, and optimize enterprise-scale Splunk infrastructure (indexers, search heads, forwarders, clustering, and cloud/hybrid deployments)
    • Define standards, best practices, and governance for Splunk usage, data onboarding, and content development
    • Lead performance tuning, capacity planning, and cost optimization initiatives
  • Acquisition Integration & Log Onboarding
    • Lead onboarding of logs from newly acquired entities into Splunk, including:
      • Log source identification and prioritization
      • Data ingestion architecture design
      • Field extraction, parsing, and normalization
    • Partner with acquisition teams, IT, and security stakeholders to ensure timely and complete visibility
    • Develop repeatable onboarding playbooks and integration frameworks for rapid scaling
    • Ensure alignment with enterprise security use cases, compliance requirements, and detection strategies
  • Security Data Engineering & Operations
    • Implement and maintain secure, reliable log pipelines across cloud, on-prem, and SaaS environments
    • Ensure high availability and resilience of Splunk services
    • Oversee data quality, integrity, and retention policies
    • Support SOC operations by enabling efficient search, dashboards, alerts, and detection content
  • Collaboration & Leadership
    • Act as a technical leader and mentor to security engineers and analysts
    • Collaborate with cross-functional teams (Cloud, Infrastructure, DevOps, Security Operations)
    • Influence and drive adoption of standardized logging and monitoring practices
    • Communicate technical strategies and risks to senior leadership

You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in.
Required Qualifications:
  • 4+ years of experience in security engineering, SIEM, or data platform engineering
  • 3+ years of experience with Splunk Enterprise and/or Splunk Cloud
  • Experience managing and scaling Splunk infrastructure
  • Solid experience onboarding logs across:
  • Cloud platforms (AWS, Azure, GCP)
  • Network/security devices
  • Endpoints, SaaS, and custom applications
  • Data ingestion (UF/HF, APIs, syslog, cloud-native integrations)
  • Parsing, CIM normalization, and knowledge objects
  • Proven solid scripting skills (Python, Bash, or similar)

Preferred Qualifications:
  • Experience with Security Operations (SOC) and detection engineering
  • Experience supporting M&A / acquisition integrations
  • Knowledge of SOAR platforms and automation
  • Familiarity with frameworks such as MITRE ATT&CK

*All employees working remotely will be required to adhere to UnitedHealth Group's Telecommuter Policy
Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you'll find a far-reaching choice of benefits and incentives. The salary for this role will range from $112,700 - $193,200 annually based on full-time employment. We comply with all minimum wage laws as applicable.
Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants.
At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission.
UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations.
UnitedHealth Group is a drug - free workplace. Candidates are required to pass a drug test before beginning employment.

Skills Required

  • 4+ years of experience in security engineering, SIEM, or data platform engineering
  • 3+ years of experience with Splunk Enterprise and/or Splunk Cloud
  • Experience managing and scaling Splunk infrastructure (indexers, search heads, forwarders, clustering, cloud/hybrid deployments)
  • Experience onboarding logs from cloud platforms (AWS, Azure, GCP)
  • Experience onboarding logs from network/security devices, endpoints, SaaS, and custom applications
  • Data ingestion experience (Universal Forwarder/Heavy Forwarder, APIs, syslog, cloud-native integrations)
  • Parsing, CIM normalization, and knowledge objects
  • Proven scripting skills (Python, Bash, or similar)
  • Experience with Security Operations (SOC) and detection engineering
  • Experience supporting M&A / acquisition integrations
  • Knowledge of SOAR platforms and automation
  • Familiarity with frameworks such as MITRE ATT&CK

What the Team is Saying

Optum Compensation & Benefits Highlights

  • Leave & Time Off Breadth PTO accrues each pay period with eight paid U.S. holidays plus a floating holiday, and generous time away is consistently emphasized. This breadth supports planned and unplanned time off beyond standard vacation days.
  • Parental & Family Support Six weeks of paid parental leave, up to two weeks of paid caregiver leave, Bright Horizons back‑up care, and adoption assistance signal strong family-oriented support. EAP access with counseling sessions further extends help to employees and their households.
  • Wellbeing & Lifestyle Benefits Company‑paid short‑ and long‑term disability, Calm app membership, tuition reimbursement, commuter and FSA accounts, and broad employee discounts expand everyday wellbeing resources. Free or low‑cost virtual visits complement these lifestyle supports.

Optum Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Eden Prairie, MN
160,000 Employees
Year Founded: 2011

What We Do

Optum, part of the UnitedHealth Group family of businesses, is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together. At Optum, we support your well-being with an understanding team, extensive benefits and rewarding opportunities. By joining us, you’ll have the resources to drive system transformation while we help you take care of your future. We recognize the power of connection to drive change, improve efficiency and make a difference in health care. Join a team where your skills and ideas can make an impact and where collaboration is key to creating technology that produces healthier outcomes.

Gallery

Gallery
Gallery
Gallery

Optum Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Optum has three workplace models that balance the needs of the business and the responsibilities of each role. These models, core on‑site (5 days/week), hybrid (4 days/week) and telecommute or fully remote, vary by country, role and location.

Typical time on-site: Not Specified
HQEden Prairie, MN
Metro Manila, Philippines
Cebu, Philippines
Davao, Philippines
Ann Arbor, MI
Atlanta, GA
Baltimore, MD
Bengaluru, India
Chennai, India
Dallas, TX
Detroit, MI
Dublin, Ireland
Hartford, CT
Houston, TX
Hyderabad, India
Jacksonville, FL
Las Vegas, NV
Letterkenny, Ireland
Louisville, KY
Madison, WI
Minneapolis, MN
Nashville, TN
New Delhi, India
Philadelphia, PA
Phoenix, AZ
Pune, India
Raleigh, NC
San Diego, CA
Washington, DC
Learn more

Similar Jobs

Optum Logo Optum

Data Engineer

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office or Remote
Raleigh, NC, USA
160000 Employees
113K-193K Annually

Optum Logo Optum

Operations Manager

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office or Remote
Durham, NC, USA
160000 Employees
113K-193K Annually

Optum Logo Optum

Senior Network Contract Manager - Remote Commutable to NC

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office or Remote
Charlotte, NC, USA
160000 Employees
92K-164K Annually

Optum Logo Optum

Cybersecurity Analyst

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Remote or Hybrid
Raleigh, NC, USA
160000 Employees
113K-193K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account