Primary Responsibilities:- Critical severity security incident management
- Monitor security intake technologies for reports of security incidents
- Perform analysis on cybersecurity alerts in both On-Premises or Cloud environments
- Strong ability to collaborate, delegate tasks and drive deadline compliance in a highly regulated, time sensitive environment
- Lead security, policy and privacy related events and incidents
- Manage containment and remediation efforts of affected assets, IOCs, and TTPs
- Hold stakeholders accountable for remediation actions
- Mentor analysts, providing training and guidance through complex incidents
- Produce detailed incident reports and security recommendations
- Provide engineering consulting and implementation expertise in support of new initiatives
- Integrate and collaborate with other subject matter experts throughout the organization
- Liaison with Cyber Defense, Privacy, Compliance, Legal, and Architecture teams
- Review security tools for opportunities to improve alert fidelity
- Influence the creation and/or adoption of new standards and procedures
- Identify deficiencies in processes and tools, recommend security controls and/or corrective actions for mitigating technical and business risk
- Contribute to Lessons Learned Meetings
- On-Call duties may be required
Leverage enterprise-approved AI tools to streamline workflows, automate tasks, and drive continuous improvement
You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear directions on what it takes to succeed in your role as well as provide development for other roles you may be interested in.
Required Qualifications: - High School Diploma/GED
- Information Technology Industry Certification or willingness to obtain information/cybersecurity certification within nine (9) months of hire
- 3+ years of Cyber Security or IT Security experience in Cyber Security Incident Response or Email Security or Cyber Security threat detection, monitoring and reporting or Cyber Intelligence and Threat Hunting OR Vulnerability Management
- 3+ years of experience analyzing attack vectors, current threats, and security remediation strategies
- 3+ years of experience with SIEM technologies, EDR technologies, and/or Asset isolation tools
- 3+ years of experience in public cloud platforms, including Azure, AWS, and Google Cloud Platform
- Ability to work off shift hours if needed (e.g. Nights and Weekends)
Preferred Qualifications: - Undergraduate degree or equivalent experience
- PowerShell, KQL, or Python scripting experience
- CISSP, CISA, GCIH, CEH, CHFI, CCSP, SEC+, Net+, A+
- Understanding of NIST 800-61, Cyber Kill Chain, and MITRE ATT&CK framework
- Networking experience (including the OSI Model, TCP/IP, DNS, HTTP, SMTP), System Administration, and Security Architecture
- High level familiarity of global privacy regulations (NY Cyber, GDPR, LGPD, CERT-In)
- Spanish language skills
*All Telecommuters will be required to adhere to UnitedHealth Group's Telecommuter Policy.
Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you'll find a far-reaching choice of benefits and incentives. The salary for this role will range from $72,800 to $130,000 annually based on full-time employment. We comply with all minimum wage laws as applicable.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants.