Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together.
Primary Responsibilities:
- Monitor Azure Defender and Optum Security Platform to identify vulnerabilities, misconfigurations, and security risks across cloud, infrastructure, and application environments
- Triage security findings and determine appropriate remediation paths, performing hands on remediation when within scope and creating actionable work items for development teams when code level fixes are required
- Oversee remediation efforts by development teams to ensure application functionality while maintaining industry best level security practices
- Perform direct remediation of cloud, infrastructure, and configuration issues, including production environments when appropriate and in accordance with change and risk management practices
- Review application level security findings and apply secure coding knowledge to assess severity, validate findings, and recommend remediation approaches aligned with security best practices
- Track, manage, and report vulnerability remediation efforts to ensure compliance with defined SLAs, release timelines, and enterprise security mandates
- Attend ESRO public cloud monthly calls and manage follow up work resulting from new security publications, standards, and Optum wide mandates
- Coordinate security remediation work with Product Owners, Scrum Masters, and Release Engineers to plan releases and hotfixes, balancing risk reduction with delivery commitments
- Communicate security risks, remediation status, and release impacts clearly to technical and non technical stakeholders, providing guidance on secure design and implementation where needed
- Comply with the terms and conditions of the employment contract, company policies and procedures, and any and all directives (such as, but not limited to, transfer and/or re-assignment to different work locations, change in teams and/or work shifts, policies in regards to flexibility of work benefits and/or work environment, alternative work arrangements, and other decisions that may arise due to the changing business environment). The Company may adopt, vary or rescind these policies and directives in its absolute discretion and without any limitation (implied or otherwise) on its ability to do so
Required Qualifications:
- Undergraduate degree or equivalent experience
- 4+ years combined experience in cloud security, secure code development, and/or Azure Cloud engineering supporting large-scale production enterprise environments
- 2+ years of hands on experience securing Microsoft Azure environments, including Microsoft Defender for Cloud (Azure Defender), Azure resource configuration, identity, networking, and remediation of cloud security risks and misconfigurations
- Hands-on experience performing direct remediation of security issues, including cloud configuration fixes, infrastructure hardening, policy enforcement, and production changes following change, risk, and RRB approval processes
- Hands-on experience using GitHub for source control, including creating, reviewing, and merging pull requests in accordance with security and change standards
- Experience using enterprise security platforms such as the Optum Security Platform or equivalent tools for vulnerability detection, risk tracking, and remediation management
- Experience with enterprise application development languages and technologies such as Java, C#, and REST based services deployed in cloud environments
- Experience working with GitHub Actions or similar CI/CD tooling to support secure build, validation, and deployment workflows
- Experience tracking vulnerability remediation against defined SLAs, release timelines, and enterprise security mandates
- Practical experience reviewing, understanding, and modifying application code to assess security findings and recommend or implement secure remediation approaches
- Familiarity with Agile/Scrum delivery models and coordinating security work with Product Owners, Scrum Masters, Release Engineers, and change approvers
- Solid working knowledge of application security best practices and common vulnerability classes, including authentication and authorization flaws, secrets management, input validation, injection risks, and secure dependency management
- Proven ability to triage security findings across cloud, infrastructure, and application layers and determine appropriate remediation paths independently
- Proven ability to create clear, actionable remediation work items for development teams when fixes are outside direct remediation scope and to oversee remediation through PR review and release completion
- Demonstrated solid written and verbal communication skills, with the ability to clearly communicate security risks, remediation status, and release impacts to both technical and non technical stakeholders
- Demonstrated ability to operate as a self directed individual contributor with minimal day to day supervision
At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission.
#Gen
Skills Required
- Undergraduate degree or equivalent experience
- 4+ years of combined experience in cloud security, secure code development, and/or Azure Cloud engineering supporting large-scale production enterprise environments
- 2+ years of hands-on experience securing Microsoft Azure environments, including Microsoft Defender for Cloud, Azure resource configuration, identity, networking, and remediation of cloud security risks and misconfigurations
- Hands-on experience performing direct remediation of security issues, including cloud configuration fixes, infrastructure hardening, policy enforcement, and production changes following change, risk, and RRB approval processes
- Hands-on experience using GitHub for source control, including creating, reviewing, and merging pull requests according to security and change standards
- Experience using enterprise security platforms such as the Optum Security Platform or equivalent tools for vulnerability detection, risk tracking, and remediation management
- Experience with enterprise application development languages and technologies such as Java, C#, and REST-based services deployed in cloud environments
- Experience with GitHub Actions or similar CI/CD tooling for secure build, validation, and deployment workflows
- Experience tracking vulnerability remediation against defined SLAs, release timelines, and enterprise security mandates
- Practical experience reviewing, understanding, and modifying application code to assess security findings and recommend or implement secure remediation approaches
- Familiarity with Agile/Scrum delivery models and coordinating security work with Product Owners, Scrum Masters, Release Engineers, and change approvers
- Solid knowledge of application security best practices and common vulnerability classes, including authentication and authorization flaws, secrets management, input validation, injection risks, and secure dependency management
- Ability to triage security findings across cloud, infrastructure, and application layers and independently determine remediation paths
- Ability to create actionable remediation work items for development teams and oversee remediation through pull-request review and release completion
- Strong written and verbal communication skills for communicating security risks, remediation status, and release impacts to technical and nontechnical stakeholders
- Ability to operate as a self-directed individual contributor with minimal day-to-day supervision
Optum Compensation & Benefits Highlights
-
Healthcare Strength — Official materials highlight copay and HSA medical plan choices with in‑network preventive care at 100%, prescription coverage, and low/no‑cost virtual visits, plus company HSA contributions. Dental preventive services are 100% in network, and mental health resources include an EAP and premium Calm access.
-
Parental & Family Support — Programs include six weeks paid parental leave, up to two weeks paid caregiver leave, and Bright Horizons back‑up care with enhanced family supports. Adoption assistance up to $10,000 for full‑time employees reinforces family‑oriented benefits.
-
Equity Value & Accessibility — Financial benefits include an Employee Stock Purchase Plan at a 10% discount, expanding access to equity ownership.
Optum Insights
What We Do
Optum, part of the UnitedHealth Group family of businesses, is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together. At Optum, we support your well-being with an understanding team, extensive benefits and rewarding opportunities. By joining us, you’ll have the resources to drive system transformation while we help you take care of your future. We recognize the power of connection to drive change, improve efficiency and make a difference in health care. Join a team where your skills and ideas can make an impact and where collaboration is key to creating technology that produces healthier outcomes.
Gallery
Optum Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
Optum has three workplace models that balance the needs of the business and the responsibilities of each role. These models, core on‑site (5 days/week), hybrid (4 days/week) and telecommute or fully remote, vary by country, role and location.