We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Director of Information Security - Remote

Optum
401(k)
United States, Minnesota, Eden Prairie
11000 Optum Circle (Show on map)
Aug 22, 2025

Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together.

Optum Insight partners with payers, providers, governments and life sciences companies to simplify and enhance clinical, administrative and financial processes through software-enabled services and analytics, while advancing value-based care. Our differentiated products, technology insights, clinical expertise and analytics support the entire health system - ultimately delivering better experiences for consumers.

Optum Insight Technology and Engineering is a critical function in Optum Insight driving the innovation and value we provide our customers and partners. This team is focused on products, solutions, platform / enabling capability development, product development lifecycle, engineering excellence and connectivity to Optum Technology.

As Director of Information Security at Optum, you will lead the development and execution of a comprehensive, enterprise-wide security strategy that safeguards the integrity, confidentiality, and availability of critical systems and data across the organization's diverse solutions portfolio. This role is pivotal in aligning security initiatives with business objectives and regulatory requirements, driving automation and scalability in remediation efforts, and proactively managing risk through continuous assessment, threat analysis, and incident response. You will collaborate closely with executive leadership, IT, legal, compliance, and business units to embed security into every layer of operations, while mentoring a high-performing team of security professionals and ensuring adherence to industry standards such as NIST, ISO 27001, HIPAA, and PCI-DSS.

You'll enjoy the flexibility to work remotely * from anywhere within the U.S. as you take on some tough challenges.

Primary Responsibilities:



  • Developing an integrated enterprise-wide security program across Optum solutions portfolios
  • Develop, implement, and maintain a comprehensive information security strategy aligned with business objectives and regulatory requirements
  • Analyze security assessments, vulnerability scans, and penetration test results to identify and prioritize risks
  • Automation of the security remediation function to be able to scale as new business enters the portfolio
  • Oversee the identification, assessment, and mitigation of security risks across the enterprise
  • Oversee the identification, assessment, and mitigation of security risks across the enterprise
  • Direct incident response planning and investigation of security breaches and assist with disciplinary and legal matters associated with such breaches
  • Collaborate with executive leadership, IT, legal, compliance, and business units to ensure security is embedded in all aspects of operations
  • Manage security audits, risk assessments, and compliance initiatives (e.g., ISO 27001, NIST, GDPR, HIPAA)
  • Lead and mentor a team of security professionals, fostering a culture of security awareness and continuous improvement
  • Stay current with emerging threats, technologies, and regulatory changes, and advise leadership on appropriate actions
  • Collaborate with IT, DevOps, and application teams to ensure timely and effective remediation
  • Maintain documentation of remediation activities, including risk assessments, mitigation strategies, and validation results
  • Ensure compliance with internal security policies, industry standards, and regulatory requirements (e.g., NIST, ISO 27001, HIPAA, PCI-DSS)



You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in.

Required Qualifications:



  • 10+ years of experience in cybersecurity, with a focus on vulnerability management and remediation
  • Proven experience developing and implementing enterprise-wide security programs
  • Experience with security tools such as Defender, Tenable, Rapid7
  • Deep knowledge of security frameworks, standards, and regulations (e.g., NIST, ISO, CIS, SOC 2)
  • Solid understanding of operating systems (Windows, Linux), networking, and cloud environments (AWS, Azure, GCP)
  • Familiarity with scripting languages (e.g., Python, PowerShell, Bash) for automation of remediation tasks



Preferred Qualifications:



  • Relevant certifications such as CISSP, CEH, OSCP, or CompTIA Security+
  • Experience with SIEM, EDR, and SOAR platforms
  • Proven solid analytical and problem-solving skills with attention to detail



*All employees working remotely will be required to adhere to UnitedHealth Group's Telecommuter Policy

Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you'll find a far-reaching choice of benefits and incentives. The salary for this role will range from $132,200 to $226,600 annually based on full-time employment. We comply with all minimum wage laws as applicable.

Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants.

At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission.

UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations.

UnitedHealth Group is a drug - free workplace. Candidates are required to pass a drug test before beginning employment.

Applied = 0

(web-5cf844c5d-jtghc)