UnitedHealth Group - Eden Prairie, MN

posted 4 months ago

Full-time - Mid Level
Remote - Eden Prairie, MN
Insurance Carriers and Related Activities

About the position

Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data, and resources they need to feel their best. Here, you will find a culture guided by diversity and inclusion, talented peers, comprehensive benefits, and career development opportunities. Come make an impact on the communities we serve as you help us advance health equity on a global scale. Join us to start Caring. Connecting. Growing together. Join UnitedHealth Groups Enterprise Information Security (EIS) organization if you want to be the first-line defense against securing the largest healthcare company in the world against security threats. We are focused on transformation by strengthening our cyber defenses, ransomware resiliency, mitigating vulnerabilities, and better securing all aspects of our company, globally. We are vigilant and passionate about protecting the sensitive data of our members and providers and are committed to leveraging every tool, partnership and process needed to enhance our security posture. It is our duty to protect the information of those we serve and help fulfill our mission of making the health care system work better for everyone. In this role, you will monitor security intake technologies for reports of security incidents, perform analysis on cybersecurity alerts in both On-Premises or Cloud environments, and provide engineering consulting and implementation expertise in support of new initiatives. You will also review security tools for opportunities to improve alerting for the SOC team, produce detailed incident reports and security recommendations, and mentor analysts, providing training and guidance through complex incidents. Strong collaboration skills are essential as you will lead security, policy, and privacy-related events and incidents, manage containment and remediation efforts of affected assets, and hold stakeholders accountable for remediation actions. You will also integrate and collaborate with other subject matter experts throughout the organization and influence the creation and/or adoption of new standards and procedures.

Responsibilities

  • Monitor security intake technologies for reports of security incidents
  • Perform analysis on cybersecurity alerts in both On-Premises or Cloud environments
  • Provide engineering consulting and implementation expertise in support of new initiatives
  • Review security tools for opportunities to improve alerting for the SOC team
  • Produce detailed incident reports and security recommendations
  • Mentor analysts, providing training and guidance through complex incidents
  • Strong ability to collaborate, delegate tasks and drive deadline compliance in a highly regulated, time sensitive environment
  • Lead security, policy and privacy related events and incidents
  • Manage containment and remediation efforts of affected assets, IOCs, and TTPs
  • Hold stakeholders accountable for remediation actions
  • Integrate and collaborate with other subject matter experts throughout the organization
  • Liaison with Cyber Defense, Privacy, Compliance, Legal, and Architecture teams
  • Identify deficiencies in processes and tools, recommend security controls and/or corrective actions for mitigating technical and business risk
  • Contribute to Lessons Learned Meetings
  • On-Call duties may be required

Requirements

  • High School Diploma/GED or higher
  • 4+ years of IT Security or Cyber Security experience in any of the following areas: Incident Response, Email Security, Data Protection/Governance, Cybersecurity threat detection, monitoring, and reporting, Cyber Intelligence and Threat Hunting, Vulnerability Management
  • 2+ years of experience in any of the following: Experience analyzing attack vectors, current threats, and security remediation strategies, Experience with SIEM technologies, EDR technologies, and/or Asset isolation tools, Networking experience (including the OSI Model, TCP/IP, DNS, HTTP, SMTP), System Administration, and Security Architecture, Experience in public cloud platforms, including Azure, AWS, and Google Cloud Platform
  • Advanced level of proficiency with global privacy regulations (NY Cyber, GDPR, LGPD, CERT-In)
  • Ability to work 2nd shift hours, Sunday-Wednesday (4 10-hour days) starting between 12pm - 2pm, ending around 10
  • Ability to work off shift hours if needed
  • Ability to obtain NAC clearance
  • Willing to obtain Information Technology Industry Certification within 9 months of hire

Nice-to-haves

  • Undergraduate Degree
  • Spanish language skills
  • PowerShell, KQL, or Python scripting experience
  • CISSP, CISA, GCIH, CEH, CHFI, CCSP, SEC+, Net+, A+
  • Understanding of NIST 800-61, Cyber Kill Chain, and MITRE ATT&CK framework

Benefits

  • Comprehensive benefits package
  • Incentive and recognition programs
  • Equity stock purchase
  • 401k contribution
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service