Sr. Associate General Counsel, Cyber Security and Privacy - Remote
Minneapolis, Hennepin County, Minnesota, 55400, USA
Listed on 2026-02-10
-
IT/Tech
Cybersecurity, Information Security
Overview
United Health Group is a health care and well-being company that's dedicated to improving the health outcomes of millions around the world. We are comprised of two distinct and complementary businesses, United Healthcare and Optum, working to build a better health system for all. Here, your contributions matter as they will help transform health care for years to come. Make an impact with a team that shares your passion for helping others.
Join us to start Caring. Connecting. Growing together.
The Sr. Associate General Counsel - Cyber Security & Privacy will support the Deputy General Counsel (DGC) for Cyber Security & Privacy in providing high quality, pragmatic legal counsel on a broad range of cybersecurity, privacy, and data protection matters. This position will be the front-line lead attorney on cyber security events. Additionally, this role will provide substantive legal analysis, issue spotting, and operational guidance and will partner closely with the Enterprise Privacy Office (EPO), Enterprise Security & Resiliency Office (ESRO), Technology, Human Resources, and other cross functional stakeholders to help the organization meet rapidly evolving privacy and cybersecurity regulatory requirements.
Youll enjoy the flexibility to work remotely from anywhere within the U.S. as you take on some tough challenges. For all hires in the Minneapolis or Washington, D.C. area, you will be required to work in the office a minimum of four days per week.
Primary Responsibilities- Privacy, Cybersecurity & Data Protection Legal Support
- Analyze and advise on legal obligations related to United Health Group's handling of personal and confidential information, including HIPAA, state privacy laws, U.S. federal privacy/security laws, and emerging global privacy regulations
- Support compliance efforts related to cybersecurity, privacy, and data security frameworks and regulations (e.g., NYDFS)
- Stay apprised of changing state/federal laws and requirements and develop practical recommendations on privacy/security requirements for business operations, vendor engagements, and product development
- Assist with drafting, updating, and operationalizing privacy, cybersecurity, and data protection policies, procedures, standards, and guidelines
- Cyber Incident & Investigation Support
- Lead and run a cyber event and investigation from discovery through investigation/forensics to fulfillment of state and federal notice requirements
- Support the DGC in cyber incident preparedness and response, including participating in tabletop exercises and reviewing incident assessments
- Assist in evaluating incidents involving personal or confidential data, privacy/security investigations, and regulatory reporting obligations
- Regulatory & Compliance Advisory
- Monitor, interpret, and assist with implementation of new and emerging privacy, cybersecurity, and data protection laws
- Review and advise on IT development, acquisition, and data architecture matters (e.g., data localization, cross border transfers)
- Support legal analysis for insider risk and Red Flags program requirements
- Cross Functional Collaboration & Business Partnership
- Partner with ESRO teams, Technology, Corporate Security, Communications, and other legal partners to deliver coordinated, well reasoned guidance
- Assist business leaders in understanding privacy and cybersecurity risks and recommended mitigations
- Provide consultative legal support to help business teams operate in compliance with privacy and cybersecurity expectations
- Training, Operational Support & Program Enablement
- Develop and deliver legal training related to privacy, cybersecurity, data protection, and information risk management
- Support day to day operational legal needs arising within the Enterprise Privacy Office and ESRO
- Assist with preparing materials and documentation for internal audits, stakeholder briefings, or regulatory inquiries
Youll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in.
Required Qualifications- 8+ years of experience in…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).