Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together.
The Security Operations Center provides 24/7/365 monitoring, analyzes, and responds to cybersecurity alerts for the organization. Provides rapid response to incoming security alerts, enriches those alerts with an initial triage effort and ensures the proper team is engaged for response.
- Monitors work queues for alerts of potential network threats, intrusions, and/or compromises.
- Assess validity and scope to determine if the alert is actionable and determine remediation steps required.
- Confirm accuracy of the alerting information.
- Identify malicious behaviors.
- Determine remediation actions needed.
- Escalate incident to proper team for response and remediation.
- Participate in and provide leadership to specialized guild related activities and projects.
- Mentor and provide guidance to associate and cybersecurity analysts.
- Experience and knowledge conducting analysis of cybersecurity threats.
- Experience in cybersecurity event monitoring/analysis in a Security Operations Center environment.
- Efficient documentation of triage details, sources of information, and recommendations for response.
- Develop strong relationships with technical personnel from various disciplines to assist with projects, process improvements, and process documentation.
- Subject matter expert in specific processes, systems, and/or tools related to cybersecurity.
- Leverage enterprise-approved AI tools to streamline workflows, automate tasks, and drive continuous improvement
You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear directions on what it takes to succeed in your role as well as provide development for other roles you may be interested in.
Required Skills:
- HS Diploma required.
- 4 years of experience in Cybersecurity.
- Any one of the following Certification in cybersecurity required. (e.g. Security+, CCNA Cyber Ops, CCSP, GCIA, GCIH, CEH, CySA+, OSCP, etc.)
- 4 years of experience with any of the industry recognized analysis frameworks (Kill Chain, Diamond Model, MITRE ATT&CK, NIST Incident Response, etc.)
- 4 years of experience with fundamental security and network concepts (Operating systems, intrusion/detection, TCP/IP, ports, etc.)
- 4 years of experience with any one of the fundamental securities related to cloud platforms (AWS, Azure, GCP, etc.)
- 4 years of experience in demonstrating triage and investigative skills utilizing multiple security sensors including documentation and debriefing of incidents
- Willing to work in a team-oriented 24/7 SOC environment; flexibility to work on a rotating schedule (including occasional shift work)
Preferred Skills:
- Bachelor's degree preferred.
- Experience working with SOAR Automation and developing SOAR playbooks.
*All Telecommuters will be required to adhere to UnitedHealth Group's Telecommuter Policy.
Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you'll find a far-reaching choice of benefits and incentives. The hourly pay for this role will range from $91,700 to $163,700 per hour based on full-time employment. We comply with all minimum wage laws as applicable.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants.
At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location, and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups, and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission.
UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations.
UnitedHealth Group is a drug - free workplace. Candidates are required to pass a drug test before beginning employment.
#RPO, #GREEN
Skills Required
- High school diploma
- 4 years of experience in Cybersecurity
- Certification in cybersecurity (e.g., Security+, CCNA Cyber Ops, CCSP, GCIA, GCIH, CEH, CySA+, OSCP)
- 4 years experience with industry-recognized analysis frameworks (Kill Chain, Diamond Model, MITRE ATT&CK, NIST Incident Response)
- 4 years experience with fundamental security and network concepts (Operating systems, intrusion/detection, TCP/IP, ports)
- 4 years experience with security-related aspects of cloud platforms (AWS, Azure, GCP)
- 4 years demonstrating triage and investigative skills using multiple security sensors, with documentation and debriefing of incidents
- Experience in cybersecurity event monitoring/analysis in a Security Operations Center environment
- Experience and knowledge conducting analysis of cybersecurity threats
- Efficient documentation of triage details, information sources, and response recommendations
- Willingness to work in a team-oriented 24/7 SOC environment with flexibility for rotating schedules and occasional shift work
- Leverage enterprise-approved AI tools to streamline workflows and automate tasks
- Subject matter expert in specific cybersecurity processes, systems, and/or tools
- Bachelor's degree
- Experience with SOAR automation and developing SOAR playbooks
Optum Compensation & Benefits Highlights
-
Leave & Time Off Breadth — PTO accrues each pay period with eight paid U.S. holidays plus a floating holiday, and generous time away is consistently emphasized. This breadth supports planned and unplanned time off beyond standard vacation days.
-
Parental & Family Support — Six weeks of paid parental leave, up to two weeks of paid caregiver leave, Bright Horizons back‑up care, and adoption assistance signal strong family-oriented support. EAP access with counseling sessions further extends help to employees and their households.
-
Wellbeing & Lifestyle Benefits — Company‑paid short‑ and long‑term disability, Calm app membership, tuition reimbursement, commuter and FSA accounts, and broad employee discounts expand everyday wellbeing resources. Free or low‑cost virtual visits complement these lifestyle supports.
Optum Insights
What We Do
Optum, part of the UnitedHealth Group family of businesses, is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together. At Optum, we support your well-being with an understanding team, extensive benefits and rewarding opportunities. By joining us, you’ll have the resources to drive system transformation while we help you take care of your future. We recognize the power of connection to drive change, improve efficiency and make a difference in health care. Join a team where your skills and ideas can make an impact and where collaboration is key to creating technology that produces healthier outcomes.
Gallery
Optum Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
Optum has three workplace models that balance the needs of the business and the responsibilities of each role. These models, core on‑site (5 days/week), hybrid (4 days/week) and telecommute or fully remote, vary by country, role and location.