UnitedHealth Group

Manager Information Security Engineer - Remote or Hybrid in MN or DC

UnitedHealth Group Eden Prairie, Minnesota, United States · $92K–$164K/yr

Hospitals and Health Care · 10,001+ employees

7 h ago
security Mid (2-5 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The manager will lead Connected Device Security and Data Protection programs, developing strategic roadmaps and operational frameworks for a healthcare environment. They will also establish an Insider Threat Program and collaborate with cross-functional teams to ensure effective cyber risk reduction.

What they look for

Cybersecurity Data protection Insider risk management Connected device security IoMT IoT DLP Information protection Risk management Vulnerability management Network segmentation Healthcare technology Compliance Strategic planning Leadership AI tools

Requirements

Candidates must have a bachelor's degree in a relevant field or equivalent experience, along with at least 3 years of progressive cybersecurity experience. Additionally, the role requires 2 years of experience in data protection or insider risk management and 1 year of leadership experience.

Benefits

Comprehensive benefits package Incentive programs Recognition programs Equity stock purchase 401k contribution

Full description

Optum Insight is improving the flow of health data and information to create a more connected system. We remove friction and drive alignment between care providers and payers, and ultimately consumers. Our deep expertise in the industry and innovative technology empower us to help organizations reduce costs while improving risk management, quality and revenue growth. Ready to help us deliver results that improve lives? Join us to start Caring. Connecting. Growing together.

As the Cybersecurity Manager leading Connected Device Security and Data Protection, you will be responsible for leading the organization’s Connected Device Security (IoT/IoMT) and Data Protection & Insider Risk programs across a shared services healthcare environment. You will develop, implement, and mature security capabilities that protect medical devices, connected technologies, sensitive data, and critical healthcare information assets. Additionally, you will establish and mature an Insider Threat Program including governance, technology, processes, investigative workflows, stakeholder engagement, and program metrics. In this role, you will leverage enterprise-approved AI tools to streamline workflows, automate data protection analytics, and drive continuous operational improvements. Working closely with Security Operations, Incident Response, Security Engineering, Clinical Engineering, Compliance, Privacy, Legal, HR, and IT, you will ensure a coordinated, frictionless approach to cyber risk reduction and drive program outcomes.

You’ll enjoy the flexibility to work remotely * from anywhere within the U.S. as you take on some tough challenges. For all hires in the Minneapolis or Washington, D.C. area, you will be required to work in the office a minimum of four days per week.

Primary Responsibilities:

  • Lead Connected Device Security (IoMT/IoT) and Data Protection & Insider Risk teams, developing strategic program roadmaps aligned with organizational cybersecurity objectives
  • Drive the standardized deployment and operational management of Data Loss Prevention (DLP), Information Protection, and Insider Risk Management capabilities across shared services healthcare environments
  • Establish repeatable deployment frameworks, standard architectures, configuration baselines, and operational runbooks to ensure continuous monitoring and prevent policy and configuration drift
  • Design, implement, and mature an Insider Threat Program, establishing governance, policies, investigative workflows, case management, and escalation criteria
  • Lead risk-based Connected Device Security processes for medical devices (IoMT), IoT, and connected technologies, including inventory management, visibility, vulnerability management, and network segmentation
  • Develop, implement, and maintain healthcare-aligned KPIs, KRIs, operational dashboards, and metrics to measure control effectiveness, operational maturity, and risk reduction outcomes
  • Partner with Security Engineering, Security Operations, Clinical Engineering, Biomedical Engineering, Privacy, Compliance, Legal, HR, and IT stakeholders to ensure aligned cyber risk reduction
  • Ensure program alignment with regulatory frameworks including HIPAA, HITECH, NIST Cybersecurity Framework, NIST 800-53, CIS Controls, and HITRUST standards
  • Use enterprise-approved AI tools to streamline workflows, automate threat detection analytics, and drive continuous operational improvement across data protection and device security programs
  • Evaluate emerging cybersecurity trends, threat vectors, and automated tools to inform solution design and strategic innovation

You’ll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in.

Required Qualifications:

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Engineering, Healthcare Technology, or a related field OR equivalent cybersecurity experience in lieu of degree
  • 3+ years of progressive cybersecurity experience in an enterprise environment
  • 2+ years of experience implementing or managing Data Loss Prevention (DLP), Information Protection, or Insider Risk capabilities
  • 1+ years of experience in a leadership, management, or technical team lead role, mentoring and developing security professionals
  • 1+ years of experience with connected device security, IoMT, IoT, or healthcare technology security environments

Preferred Qualifications:

  • Relevant cybersecurity certifications such as CISSP, CISM, or HCISPP
  • Hands-on experience with Microsoft Purview (DLP, Information Protection, Insider Risk Management), Microsoft Defender XDR, and Microsoft Sentinel
  • Experience with medical device security platforms (e.g., Ordr, Armis, Nozomi, Claroty), vulnerability management tools, and Microsoft Entra ID
  • Experience utilizing ServiceNow and Power BI (or equivalent dashboarding tools) to build operational security metrics and executive dashboards
  • In-depth understanding of healthcare cybersecurity frameworks and regulations, including HIPAA, HITECH, NIST CSF, NIST 800-53, CIS Controls, and HITRUST
  • Demonstrated ability to build cybersecurity programs and lead cross-functional investigations across Legal, HR, and Compliance

*All employees working remotely will be required to adhere to UnitedHealth Group’s Telecommuter Policy

Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you’ll find a far-reaching choice of benefits and incentives. The salary for this role will range from $91,700 - $163,700 annually based on full-time employment. We comply with all minimum wage laws as applicable.

Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants.

At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone–of every race, gender, sexuality, age, location and income–deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes — an enterprise priority reflected in our mission.

UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations.

UnitedHealth Group is a drug-free workplace. Candidates are required to pass a drug test before beginning employment.

Similar roles