Explore opportunities with the Enterprise Information Security (EIS) team at UnitedHealth Group. Join one of the world's largest health care companies and become part of the first line of defense against security threats. We are focused on strengthening our cyber defenses, ransomware resiliency, vulnerability mitigation, and securing all aspects of our systems and data globally. We are passionate about protecting the sensitive data of our members and providers. We are committed to leveraging every tool, partnership and process needed to enhance our security posture. It is our duty to protect the information of those we serve while Caring. Connecting. Growing together.
The Enterprise Information Security (EIS) team is responsible for cybersecurity across our organization. We support our business and members by reducing risk, rapidly responding to threats, focusing on business resiliency and securing new acquisitions.
The Segment Information Security Officer (SISO) is responsible for overseeing the segment information risk management program and supports Enterprise Information Security (EIS) processes and programs. The SISO is an EIS process expert and acts as a central point of contact for security process issues and questions. The SISO is deemed a critical integration point with business leadership teams and is considered a change agent for the business in understanding security risks and the role and responsibilities of EIS, as well as ensuring that EIS fully understands and is engaged to support the needs and objectives of the business.
The SISO provides management and strategic support, reports to the Business Information Security Officer (BISO) and works as a delegate of EIS
You'll enjoy the flexibility to work remotely* from anywhere within the U.S. as you take on some tough challenges. For all hires in the Minneapolis or Washington, D.C. area, you will be required to work in the office a minimum of four days per week.
Primary Responsibilities:
- Assist in enterprise and EIS risk management processes and execution
- Partner with segment technology and business leadership to guide segment-level risk management and operational execution
- Partner with segment stakeholders to represent the Information Security capabilities of UHG to both current and prospective customers
- Partner with segment stakeholders to support customer and regulatory audits of the Information Security Program
- Responsible for review and advisory oversight of external party contractual security requirements
- Provide leadership, guidance, team direction, problem resolution and accountability for the performance of managers and/or senior level professional staff
- Primary support role, as needed, for the BISO and Office of Information Security
- Significant level of communications (oral and written) to senior management on risk management concepts, as well as specific project risks and risk mitigation options/scenarios
- Maintains a deep understanding of the business, their customers, and service-delivery models. This understanding includes strategic business initiatives and goals, key systems and key contacts within the business and IT
- Maintains current knowledge on information security topics and their applicability to UHG and assigned segment
You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in.
Required Qualifications:
- Bachelor's degree or 10+ years of information technology experience
- 5+ years of information security experience in a large, highly regulated enterprise
- 2+ years of experience working with external auditors, regulatory bodies, and customers
- 1+ years of experience reviewing security contracts
- Experience with interpretation and application of policy and standards
- Experience with multiple information security frameworks (ISO, NIST, HITRUST, PCI, GLBA and/or FDIC etc.)
- Proven subject matter expert knowledge of technology risk management and security operations
- Risk management experience to include identification, prioritization, and mitigation of risk
- Proven understanding of business risks and business objectives
- Ability to make quality, data-driven recommendations and decisions following discovery, analysis, verification, etc.
Preferred Qualifications:
- Technical security certification required (CISSP/CISM)
- Financial technical expertise and general knowledge of the financial industry
- Demonstrated executive presence and has excellent communication and client relationship management skills with senior management on issues and key risks to the business (presentations, executive summaries, etc.)
*All employees working remotely will be required to adhere to UnitedHealth Group's Telecommuter Policy.
Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you'll find a far-reaching choice of benefits and incentives. The salary for this role will range from $112,700 - $193,200 annually based on full-time employment. We comply with all minimum wage laws as applicable.
Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants.
At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission.
UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations.
UnitedHealth Group is a drug - free workplace. Candidates are required to pass a drug test before beginning employment.
#BI-Hybrid
Skills Required
- Bachelor's degree or 10+ years of information technology experience
- 5+ years of information security experience in a large, highly regulated enterprise
- 2+ years of experience working with external auditors, regulatory bodies, and customers
- 1+ years of experience reviewing security contracts
- Experience interpreting and applying policies and standards
- Experience with multiple information security frameworks, including ISO, NIST, HITRUST, PCI, GLBA, or FDIC
- Subject matter expertise in technology risk management and security operations
- Risk management experience involving risk identification, prioritization, and mitigation
- Understanding of business risks and business objectives
- Ability to make data-driven recommendations and decisions following discovery, analysis, and verification
- Technical security certification such as CISSP or CISM
- Financial technical expertise and general knowledge of the financial industry
- Executive presence and excellent communication and client relationship management skills with senior management
Optum Compensation & Benefits Highlights
-
Healthcare Strength — Official materials highlight copay and HSA medical plan choices with in‑network preventive care at 100%, prescription coverage, and low/no‑cost virtual visits, plus company HSA contributions. Dental preventive services are 100% in network, and mental health resources include an EAP and premium Calm access.
-
Parental & Family Support — Programs include six weeks paid parental leave, up to two weeks paid caregiver leave, and Bright Horizons back‑up care with enhanced family supports. Adoption assistance up to $10,000 for full‑time employees reinforces family‑oriented benefits.
-
Equity Value & Accessibility — Financial benefits include an Employee Stock Purchase Plan at a 10% discount, expanding access to equity ownership.
Optum Insights
What We Do
Optum, part of the UnitedHealth Group family of businesses, is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together. At Optum, we support your well-being with an understanding team, extensive benefits and rewarding opportunities. By joining us, you’ll have the resources to drive system transformation while we help you take care of your future. We recognize the power of connection to drive change, improve efficiency and make a difference in health care. Join a team where your skills and ideas can make an impact and where collaboration is key to creating technology that produces healthier outcomes.
Gallery
Optum Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
Optum has three workplace models that balance the needs of the business and the responsibilities of each role. These models, core on‑site (5 days/week), hybrid (4 days/week) and telecommute or fully remote, vary by country, role and location.