UnitedHealth Group

Principle Cybersecurity Analyst - Remote

UnitedHealth Group$112K — $193K *
US-AnywhereRemote in Washington, DC
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3+ years of experience in cyber threat intelligence, cybersecurity engineering, incident response, or malware analysis with a focus on integration
  • Proficiency in Python for automation and data processing; familiarity with Java, JavaScript/Node.js, or Go
  • Experience with REST APIs, JSON, STIX/TAXII protocols, and data pipeline development
  • Demonstrated familiarity with version control (Git) and CI/CD pipelines
  • Hands-on experience with Threat Intelligence Platforms (TIPs) such as MISP or ThreatConnect
  • Solid experience with SIEM platforms like Splunk or Microsoft Sentinel
  • Familiarity with using AI and machine learning in threat intelligence frameworks.

Responsibilities

  • Deploy, integrate, and maintain a threat intelligence platform within the security ecosystem
  • Integrate threat intelligence into SIEM platforms for detection and alert enrichment
  • Utilize AI and other capabilities to enhance the delivery of contextualized threat intelligence
  • Develop and maintain SOAR playbooks for automated threat response
  • Build and deploy workflows to execute intelligence use cases across various security functions
  • Orchestrate workflows across security tools to reduce manual analysis time
  • Correlate threat intelligence with telemetry to improve detection capabilities.

Benefits

  • Comprehensive benefits package
  • Incentive and recognition programs
  • Equity stock purchase options
  • 401k contribution with employer matching
  • Remote work flexibility for positions outside of Minneapolis or Washington, D.C.
Full Job Description
The Principal Threat Intelligence Engineer is responsible for deployment and integration of threat intelligence technical capabilities across United Health Group's security ecosystem. The role focuses on ingesting, normalizing, and enriching threat intelligence information, integrating Threat Intelligence Platforms (TIPs) and intelligence sources with security tooling (e.g., SIEM, SOAR, EDR), and deploying automated intelligence-enabled detection and response workflows. The ideal candidate combines solid software engineering skills with deep cybersecurity domain knowledge to transform raw threat data into actionable intelligence that enhances detection, response, and risk mitigation. This technical role focuses on building automation, data pipelines, and detection mechanisms to proactively defend infrastructure against threats of varying technical sophistication.

The Principal Threat Intelligence Engineer is expected to execute the delivery of technical intelligence solutions to CTI, SOC, Threat Detection, and Threat Hunting teams that accelerate the processing and dissemination of intelligence, increase speed of detection, and enable rapid response. The Principal Threat Intelligence Engineer will work closely with and in support of the Senior Principal Threat Intelligence Engineer and members of CTI and other security operations teams to execute a roadmap of technology improvements intended to optimize the efficiency and impact of CTI operations.

You'll enjoy the flexibility to work remotely * from anywhere within the U.S. as you take on some tough challenges. For all hires in the Minneapolis or Washington, D.C. area, you will be required to work in the office a minimum of four days per week.

Primary Responsibilities:

  • Deploy, integrate, and maintain a threat intelligence platform that is integrated into United Health's security tooling ecosystem
  • Integrate threat intelligence into SIEM platforms (e.g., Splunk) for detection use cases and alert enrichment
  • Efficiently employ agentic AI, LLMs, and other associated capabilities to increase the availability and speed of delivery of contextualized threat intelligence to CTI, SOC, IR, and other SecOps members
  • Build, and deploy technology-supported workflows to execute diverse intelligence use cases across SOC, IR, Insider Risk, Fraud, Red Team, Threat Hunt, and other stakeholder environments
  • Develop and maintain SOAR playbooks for automated threat response and enrichment; utilize SOAR to optimize intelligence workflows
  • Orchestrate workflows across security tools to reduce manual analysis and response time
  • Build and maintain integrations between threat intelligence feeds (commercial, open-source, ISACs) and internal security platforms
  • Integrate and operationalize Threat Intelligence Platforms (e.g., MISP, OpenCTI ThreatConnect, Anomali, ThreatQuotient) with enterprise security tools
  • Develop pipelines to ingest, normalize, deduplicate, and enrich Indicators of Compromise (IOCs) and threat data
  • Correlate intelligence with telemetry from SIEM, EDR, NDR, and cloud security tools to improve detection fidelity
  • Enable automated enrichment of alerts using threat intelligence data within SIEM workflows


You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in.

Required Qualifications:

  • 3+ years of experience in a cyber threat intelligence, cyber security engineering, incident response or malware analysis role with heavy emphasis on tool and technology integration
  • Proficiency in one or more of:
    Python (primary) for automation, API integrations, and data processing,
    Java, JavaScript/Node.js, or Go for service development
  • Experience with:
    • REST APIs, JSON, STIX/TAXII protocols
    • Data parsing, transformation, and pipeline development
    • Scripting (Bash, PowerShell)
  • Demonstrated familiarity with version control (Git) and CI/CD pipelines
  • Demonstrated familiarity with a variety of OS's and platforms including Linux (Ubuntu, CentOS, RHEL, Kali), AWS, Docker, Windows Server (NT through 2012), Active Directory, Mac OS X
  • Experiences with AI employment in a threat intelligence framework including LLM, MCP server configuration, RAG and associated processes
  • Hands-on experience with TIPs such as: MISP, OpenCTI, ThreatConnect, Anomali
  • Experience integrating multiple intelligence feeds and formats
  • Solid experience with SIEM platforms: Splunk, Microsoft Sentinel, IBM QRadar, Elastic
  • Experience building detection rules, correlation searches, and dashboards
  • Proven understanding of log ingestion, normalization, and enrichment pipelines
  • Experience with SOAR platforms such as Cortex XSOAR, Splunk SOAR, Swimlane, Tines
  • Development experience with playbooks/runbooks for automated response
  • Proven knowledge of structured threat data formats (STIX, TAXII)


Preferred Qualifications:

  • Relevant certifications (e.g., GCTI, GCIA, CISSP, Splunk certifications)
  • Experience in large-scale security operations or SOC environments
  • Familiarity with MITRE ATT&CK and other intelligence frameworks
  • Familiarity with data engineering technologies (Kafka, Spark, Elasticsearch)
  • Experience with cloud platforms (AWS, Azure, GCP) and security integrations
  • Experience in threat hunting and detection engineering


*All employees working remotely will be required to adhere to UnitedHealth Group's Telecommuter Policy.

Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you'll find a far-reaching choice of benefits and incentives. The salary for this role will range from $112,700 - $193,200 annually based on full-time employment. We comply with all minimum wage laws as applicable.

Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants.

About UnitedHealth Group

UnitedHealth Group is a medical facility. They offer health technology, health finance, and pharmacy services. They are utilizing clinical data and intelligence to assist in the redesign, automation, and deployment of technology to streamline administrative operations and clinical decision-making. Payment systems for both consumers and providers are critical components of a health-care system.

UnitedHealth Group Careers

Joining UnitedHealth Group means becoming part of a diverse team dedicated to making a difference. As a leader in health services and innovation, our company offers a variety of job opportunities that allow professionals to leverage their skills, drive innovation, and improve lives. Work You’ll Do At UnitedHealth Group, you’ll contribute to a mission-focused environment where your expertise will influence the health and well-being of people worldwide. Our employment opportunities span across a wide range of disciplines, from healthcare specialists to data analysts, ensuring that your career journey is both dynamic and rewarding. Transform Healthcare with Your Expertise UnitedHealth Group stands at the forefront of health innovation. Our team collaborates to deliver solutions that lead to better patient outcomes. Working with us, you’ll find yourself at the intersection of technology, healthcare, and leadership, providing key insights that drive industry transformation. Join Our Global Team As part of our team, you’ll engage with over 300,000 professionals globally, dedicated to building a diverse and inclusive workplace. UnitedHealth Group is not just a company; it’s a community where you can grow your career through continuous learning and leadership opportunities. Our commitment to diversity training ensures that every team member can thrive. UnitedHealth Group Career Development We are committed to your professional growth. Explore career paths filled with promising job opportunities and internships that will harness your potential and expand your capabilities. Whether you’re a seasoned professional or a recent graduate, you’ll find that our career development programs support your ambition at every level. Innovative Work Environment At UnitedHealth Group, innovation is at the core of our operations. We encourage our team to bring forward-thinking ideas that challenge the status quo and lead to breakthrough improvements in patient care. Be Part of a Great Team Our culture fosters a collaborative and supportive environment where every member’s contribution is valued. Enjoy the benefits of being part of a global team that’s committed to making a difference in people’s lives. Future-Proof Your Career With UnitedHealth Group, your career is future-proof. Dive into a range of positions that offer both challenges and rewards. Our robust support system includes unmatched training, development programs, and certification support to propel your career forward. Stay Connected Join Our Team Discover the right position that matches your skills and interests. We are always hiring and look for passionate, curious, and solution-driven team players. Search UnitedHealth Group jobs today and take the first step towards a fulfilling career. Keep Up to Date Stay informed with career tips, insider perspectives, and industry-leading insights you can use today—all from the people who work here. Read Careers Blog Job Alert Emails Customize your subscription to receive job alerts, the latest news, and insider tips tailored to your preferences. Explore the exciting and rewarding opportunities that await at UnitedHealth Group.
Learn more about UnitedHealth Group
Size
350,000 employees
Market Cap
$493.1 billion
Industry
Net Income
$15.4 billion
Founded
1974
5 Year Trend
+9.2%
Revenue
$257.1 billion
NASDAQ

Similar Jobs

More Jobs at UnitedHealth Group

More Information Technology Jobs

Find similar Principle Cybersecurity Analyst - Remote jobs: