The Enterprise Information Security (EIS) team is responsible for cybersecurity across our organization. We support our business and members by reducing risk, rapidly responding to threats, focusing on business resiliency and securing new acquisitions.
The primary mission of the Cyber Threat Hunting team is to proactively identify tactics and techniques leveraged by attackers to identify security incidents. Additionally, this position is also expected to participate in other areas within Cyber Defense Operations such as Digital Forensics, detection engineering, Hunt Plan development, etc. The Senior Cybersecurity Analyst will serve as a Subject Matter Expert (SME) in multiple areas of Incident Response and Security Operations.
You'll enjoy the flexibility to work remotely * from anywhere within the U.S. as you take on some tough challenges. For all hires in the Minneapolis or Washington, D.C. area, you will be required to work in the office a minimum of four days per week.
Primary Responsibilities:- Analysis of network data (packets, logs) and endpoint data (logs, malicious artifacts) in both structured and unstructured methods
- Analysis of malware (executables, scripts, etc.) to determine indicators of compromise, and create signatures for future detection of similar samples
- Creating Threat Hunting Playbooks and Use Cases to proactively identify threats affecting UHG networks
- Participate in exercises to simulate attacks and determine responsiveness of processes and procedures
- Creating a feedback loop with security control owners to help tune systems based on the results of investigations
- Acting as a high tier escalation point for security incidents to provide technical expertise to the incident response process
- Develop content within tools to detect anomalous activity (SIEM Content, Custom Signatures, etc.)
- Identify and understand new environments and tooling.
- Leverage enterprise-approved AI tools to streamline workflows, automate tasks, and drive continuous improvement
You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in.
Required Qualifications:- 3 years of experience in Threat Hunting or Incident response
- 3 years of experience with application protocols (HTTP, DNS, FTP, etc.) and networking protocols (TCP, UDP, ARP, ICMP, etc.), and be comfortable analyzing packet capture (pcap) files in tools such as Wireshark
- 3 years experience with digital forensics as applied to host-based forensics, memory forensics, network forensics, and cloud forensics
- 3 years experience with operating system internals (virtual memory, paging, etc.) and techniques employed by malware to evade detection
- Due to FISMA US Citizenship is required
Preferred Qualifications:- Industry certifications such as CISSP or GCIH
- 5+ years of cybersecurity, digital forensics, incident response, or red teaming experience
- Experience in healthcare and/or government.
- Proven solid communication skills to translate complex technical concepts into plain English for consumption by non-technical audiences
*All employees working remotely will be required to adhere to UnitedHealth Group's Telecommuter Policy.
Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you'll find a far-reaching choice of benefits and incentives. The salary for this role will range from $91,700 to $163,700 annually based on full-time employment. We comply with all minimum wage laws as applicable.
Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants.