Principle Cybersecurity Analyst - Remote

Posted Yesterday
Be an Early Applicant
Hiring Remotely in Washington, DC, USA
In-Office or Remote
113K-193K Annually
Mid level
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
The Role
Designs, deploys, and integrates threat intelligence platforms and data pipelines; enriches and normalizes IOCs; integrates TIPs with SIEM, EDR, NDR, and SOAR; builds automated detection, enrichment, and response playbooks; leverages LLM/agentic AI for intelligence delivery; supports CTI, SOC, IR, threat hunting, and other SecOps stakeholders to improve detection fidelity and reduce response time.
Summary Generated by Built In
Requisition Number: 2360901
Explore opportunities with the Enterprise Information Security (EIS) team at UnitedHealth Group. Join one of the world's largest health care companies and become part of the first line of defense against security threats. We are focused on strengthening our cyber defenses, ransomware resiliency, vulnerability mitigation, and securing all aspects of our systems and data globally. We are passionate about protecting the sensitive data of our members and providers. We are committed to leveraging every tool, partnership and process needed to enhance our security posture. It is our duty to protect the information of those we serve while Caring. Connecting. Growing together.
The Enterprise Information Security (EIS) team is responsible for cybersecurity across our organization. We support our business and members by reducing risk, rapidly responding to threats, focusing on business resiliency and securing new acquisitions.
The Principal Threat Intelligence Engineer is responsible for deployment and integration of threat intelligence technical capabilities across United Health Group's security ecosystem. The role focuses on ingesting, normalizing, and enriching threat intelligence information, integrating Threat Intelligence Platforms (TIPs) and intelligence sources with security tooling (e.g., SIEM, SOAR, EDR), and deploying automated intelligence-enabled detection and response workflows. The ideal candidate combines solid software engineering skills with deep cybersecurity domain knowledge to transform raw threat data into actionable intelligence that enhances detection, response, and risk mitigation. This technical role focuses on building automation, data pipelines, and detection mechanisms to proactively defend infrastructure against threats of varying technical sophistication.
The Principal Threat Intelligence Engineer is expected to execute the delivery of technical intelligence solutions to CTI, SOC, Threat Detection, and Threat Hunting teams that accelerate the processing and dissemination of intelligence, increase speed of detection, and enable rapid response. The Principal Threat Intelligence Engineer will work closely with and in support of the Senior Principal Threat Intelligence Engineer and members of CTI and other security operations teams to execute a roadmap of technology improvements intended to optimize the efficiency and impact of CTI operations.
You'll enjoy the flexibility to work remotely * from anywhere within the U.S. as you take on some tough challenges. For all hires in the Minneapolis or Washington, D.C. area, you will be required to work in the office a minimum of four days per week.
Primary Responsibilities:
  • Deploy, integrate, and maintain a threat intelligence platform that is integrated into United Health's security tooling ecosystem
  • Integrate threat intelligence into SIEM platforms (e.g., Splunk) for detection use cases and alert enrichment
  • Efficiently employ agentic AI, LLMs, and other associated capabilities to increase the availability and speed of delivery of contextualized threat intelligence to CTI, SOC, IR, and other SecOps members
  • Build, and deploy technology-supported workflows to execute diverse intelligence use cases across SOC, IR, Insider Risk, Fraud, Red Team, Threat Hunt, and other stakeholder environments
  • Develop and maintain SOAR playbooks for automated threat response and enrichment; utilize SOAR to optimize intelligence workflows
  • Orchestrate workflows across security tools to reduce manual analysis and response time
  • Build and maintain integrations between threat intelligence feeds (commercial, open-source, ISACs) and internal security platforms
  • Integrate and operationalize Threat Intelligence Platforms (e.g., MISP, OpenCTI ThreatConnect, Anomali, ThreatQuotient) with enterprise security tools
  • Develop pipelines to ingest, normalize, deduplicate, and enrich Indicators of Compromise (IOCs) and threat data
  • Correlate intelligence with telemetry from SIEM, EDR, NDR, and cloud security tools to improve detection fidelity
  • Enable automated enrichment of alerts using threat intelligence data within SIEM workflows

You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in.
Required Qualifications:
  • 3+ years of experience in a cyber threat intelligence, cyber security engineering, incident response or malware analysis role with heavy emphasis on tool and technology integration
  • Proficiency in one or more of:
    Python (primary) for automation, API integrations, and data processing,
    Java, JavaScript/Node.js, or Go for service development
  • Experience with:
    • REST APIs, JSON, STIX/TAXII protocols
    • Data parsing, transformation, and pipeline development
    • Scripting (Bash, PowerShell)
  • Demonstrated familiarity with version control (Git) and CI/CD pipelines
  • Demonstrated familiarity with a variety of OS's and platforms including Linux (Ubuntu, CentOS, RHEL, Kali), AWS, Docker, Windows Server (NT through 2012), Active Directory, Mac OS X
  • Experiences with AI employment in a threat intelligence framework including LLM, MCP server configuration, RAG and associated processes
  • Hands-on experience with TIPs such as: MISP, OpenCTI, ThreatConnect, Anomali
  • Experience integrating multiple intelligence feeds and formats
  • Solid experience with SIEM platforms: Splunk, Microsoft Sentinel, IBM QRadar, Elastic
  • Experience building detection rules, correlation searches, and dashboards
  • Proven understanding of log ingestion, normalization, and enrichment pipelines
  • Experience with SOAR platforms such as Cortex XSOAR, Splunk SOAR, Swimlane, Tines
  • Development experience with playbooks/runbooks for automated response
  • Proven knowledge of structured threat data formats (STIX, TAXII)

Preferred Qualifications:
  • Relevant certifications (e.g., GCTI, GCIA, CISSP, Splunk certifications)
  • Experience in large-scale security operations or SOC environments
  • Familiarity with MITRE ATT&CK and other intelligence frameworks
  • Familiarity with data engineering technologies (Kafka, Spark, Elasticsearch)
  • Experience with cloud platforms (AWS, Azure, GCP) and security integrations
  • Experience in threat hunting and detection engineering

*All employees working remotely will be required to adhere to UnitedHealth Group's Telecommuter Policy.
Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you'll find a far-reaching choice of benefits and incentives. The salary for this role will range from $112,700 - $193,200 annually based on full-time employment. We comply with all minimum wage laws as applicable.
Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants.
At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission.
UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations.
UnitedHealth Group is a drug - free workplace. Candidates are required to pass a drug test before beginning employment.

Skills Required

  • 3+ years in cyber threat intelligence, security engineering, incident response, or malware analysis with emphasis on tool and technology integration
  • Proficiency in one or more: Python (primary), Java, JavaScript/Node.js, or Go
  • Experience with REST APIs, JSON, STIX/TAXII protocols
  • Data parsing, transformation, and pipeline development
  • Scripting experience (Bash, PowerShell)
  • Familiarity with version control (Git) and CI/CD pipelines
  • Familiarity with multiple OS/platforms: Linux (Ubuntu, CentOS, RHEL, Kali), AWS, Docker, Windows Server (NT through 2012), Active Directory, Mac OS X
  • Experience employing AI in threat intelligence (LLM, MCP server configuration, RAG)
  • Hands-on experience with TIPs (e.g., MISP, OpenCTI, ThreatConnect, Anomali)
  • Experience integrating multiple intelligence feeds and formats
  • Experience with SIEM platforms (Splunk, Microsoft Sentinel, IBM QRadar, Elastic)
  • Experience building detection rules, correlation searches, and dashboards
  • Understanding of log ingestion, normalization, and enrichment pipelines
  • Experience with SOAR platforms (Cortex XSOAR, Splunk SOAR, Swimlane, Tines)
  • Development experience with SOAR playbooks/runbooks for automated response
  • Proven knowledge of structured threat data formats (STIX, TAXII)
  • Relevant certifications or training are listed as preferred (e.g., GCTI, GCIA, CISSP, Splunk certs)
  • Experience in large-scale SOC environments, MITRE ATT&CK familiarity, data engineering technologies (Kafka, Spark, Elasticsearch), cloud platforms (AWS, Azure, GCP), threat hunting and detection engineering

What the Team is Saying

Optum Compensation & Benefits Highlights

  • Healthcare Strength Official materials highlight copay and HSA medical plan choices with in‑network preventive care at 100%, prescription coverage, and low/no‑cost virtual visits, plus company HSA contributions. Dental preventive services are 100% in network, and mental health resources include an EAP and premium Calm access.
  • Parental & Family Support Programs include six weeks paid parental leave, up to two weeks paid caregiver leave, and Bright Horizons back‑up care with enhanced family supports. Adoption assistance up to $10,000 for full‑time employees reinforces family‑oriented benefits.
  • Equity Value & Accessibility Financial benefits include an Employee Stock Purchase Plan at a 10% discount, expanding access to equity ownership.

Optum Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Eden Prairie, MN
160,000 Employees
Year Founded: 2011

What We Do

Optum, part of the UnitedHealth Group family of businesses, is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together. At Optum, we support your well-being with an understanding team, extensive benefits and rewarding opportunities. By joining us, you’ll have the resources to drive system transformation while we help you take care of your future. We recognize the power of connection to drive change, improve efficiency and make a difference in health care. Join a team where your skills and ideas can make an impact and where collaboration is key to creating technology that produces healthier outcomes.

Gallery

Gallery
Gallery
Gallery

Optum Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Optum has three workplace models that balance the needs of the business and the responsibilities of each role. These models, core on‑site (5 days/week), hybrid (4 days/week) and telecommute or fully remote, vary by country, role and location.

Typical time on-site: Not Specified
HQEden Prairie, MN
Metro Manila, Philippines
Cebu, Philippines
Davao, Philippines
Ann Arbor, MI
Atlanta, GA
Baltimore, MD
Bengaluru, India
Chennai, India
Dallas, TX
Detroit, MI
Dublin, Ireland
Hartford, CT
Houston, TX
Hyderabad, India
Jacksonville, FL
Las Vegas, NV
Letterkenny, Ireland
Louisville, KY
Madison, WI
Minneapolis, MN
Nashville, TN
New Delhi, India
Philadelphia, PA
Phoenix, AZ
Pune, India
Raleigh, NC
San Diego, CA
Washington, DC
Learn more

Similar Jobs

Optum Logo Optum

Director, Enterprise Strategy and Partnerships - Remote

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office or Remote
Washington, DC, USA
160000 Employees
135K-231K Annually

Optum Logo Optum

Sr. Principal Threat Intelligence Engineer- Remote or Hybrid in MN or DC

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Remote or Hybrid
Washington, DC, USA
160000 Employees
135K-231K Annually

Optum Logo Optum

Counsel

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office or Remote
Washington, DC, USA
160000 Employees
159K-273K Annually

Optum Logo Optum

Forward Deployed Engineer - FDE - Remote

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Remote
United States
160000 Employees
120K-215K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account