We are seeking a proactive and detail-oriented
Information Security Engineer with a strong focus on triage and user support. This role is critical in our front-line defense, responsible for quickly assessing security alerts, supporting end users with security-related issues, and escalating incidents as needed. This role will primarily work from a ticket queue, resolving security and DLP-related events while identifying recurring patterns, process gaps, and opportunities to improve detections, streamline workflows, or reduce manual effort. The ideal candidate will have a strong technical foundation, excellent communication skills, and a passion for helping others navigate security challenges.
You will enjoy the flexibility to telecommute* from anywhere within the U.S. as you take on some tough challenges.
Primary Responsibilities:- Triage Security Alerts: Monitor and analyze security alerts from various sources (SIEM, EDR, email, etc.) to determine severity and required response
- User Support & Education: Serve as the first point of contact for security-related user issues, providing guidance, troubleshooting, and education
- Incident Escalation: Escalate confirmed or high-risk incidents to senior security engineers or incident response teams with clear documentation
- Threat Analysis: Perform initial investigation and enrichment of suspicious activity to support threat detection and response
- Tool Utilization: Leverage security tools (e.g., Splunk, CrowdStrike, Microsoft Defender, etc.) to investigate and resolve issues
- Documentation: Maintain accurate records of incidents, resolutions, and user interactions in ticketing systems
- Collaboration: Work closely with IT, compliance, and other security team members to ensure consistent and effective security practices
- Process Improvement: Identify trends, recurring issues, and process gaps from ticket queue activity; partner with subject matter experts to improve detections, streamline workflows, and evaluate automation opportunities
- Leverage enterprise-approved AI tools to streamline workflows, automate tasks, and drive continuous improvement
You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear directions on what it takes to succeed in your role as well as provide development for other roles you may be interested in.
Required Qualifications:- Bachelor's degree in Cybersecurity, Information Technology, or Engineering related field
- 2+ years of experience in information security, IT support, or SOC environments
- 2+ years of experience with common security tools and platforms (e.g., SIEM, EDR, phishing analysis tools)
- 2+ years of experience with security fundamentals (networking, endpoint protection, identity management)
Preferred Qualifications:- Experience with scripting or automation (e.g., Python, PowerShell)
- Security certifications such as CompTIA Security+, SSCP, or equivalent
- Experience with Microsoft 365 security tools and cloud environments (Azure, AWS)
- Familiarity with ITIL or similar service management frameworks
- Experience with DLP Platforms (e.g. Broadcom, Zscaler, Proofpoint,)
- Understanding of data classification models and encryption standards
- Excellent communication and interpersonal skills, with a customer-first mindset
- Ability to work in a fast-paced environment and manage multiple priorities
*All Telecommuters will be required to adhere to UnitedHealth Group's Telecommuter Policy.
Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you'll find a far-reaching choice of benefits and incentives. The salary for this role will range from $72,800 to $130,000 annually based on full-time employment. We comply with all minimum wage laws as applicable.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants.