Attack Surface Management Security Architect - Remote or Hybrid in MN or DC
Eden Prairie, Hennepin County, Minnesota, 55344, USA
Listed on 2026-05-27
-
IT/Tech
Cybersecurity, Systems Engineer, Information Security
Optum Tech is a global leader in health care innovation. Our teams develop cutting‑edge solutions that help people live healthier lives and help make the health system work better for everyone. From advanced data analytics and AI to cybersecurity, we use innovative approaches to solve some of health care's most complex challenges. Your contributions here have the potential to change lives.
Ready to build the next breakthrough? Join us to start Caring. Connecting. Growing together.
The Security Architect serves as a technical security authority supporting mergers and acquisitions (M&A) security implementation programs. This role is responsible for defining, influencing, and implementing security architectures and controls that are being developed to be included within Optum's current security portfolio, while ensuring integrations are executed securely, efficiently, and in alignment with enterprise risk tolerance.
The Security Architect serves as a senior technical authority responsible for defining, enabling, and governing the organization’s Attack Surface Management (ASM) strategy and capabilities. This role focuses on identifying, monitoring, and reducing external security exposure across internet‑facing infrastructure, email systems, SaaS platforms, and the dark web. Operating at the intersection of security architecture, threat intelligence, infrastructure, and operations, the Security Architect translates external risk signals into actionable architectures, standards, and remediation strategies.
The role partners closely with Enterprise Security, SOC, Threat Intelligence, Infrastructure, Email, Cloud, Application, and Product teams to ensure attack surface visibility is comprehensive, risks are prioritized effectively, and security controls are implemented in alignment with enterprise risk tolerance. Success in this role requires strong architectural judgment, the ability to lead through influence without direct authority, and comfort operating in environments with incomplete or rapidly evolving information.
You’ll enjoy the flexibility to work remotely
* from anywhere within the U.S. as you take on some tough challenges. For all hires in the Minneapolis or Washington, D.C. area, you will be required to work in the office a minimum of four days per week.
- Serve as the architectural owner for Attack Surface Management, accountable for strategy, tooling, architecture, and risk alignment
- Lead the design and enablement of dark web monitoring capabilities to identify credential leakage, data exposure, brand abuse, and emerging external threats
- Architect and oversee SMTP and email security integrations, including migration and enablement using Proofpoint
- Enable and govern external vulnerability and exposure scanning, leveraging tools such as Shodan, Xpanse, and Tenable
- Define architectural patterns for discovering, classifying, and correlating external assets across infrastructure, cloud, SaaS, and third‑party services
- Partner with SOC and Threat Intelligence teams to ope rationalise ASM findings into detection, alerting, and response workflows
- Translate external exposure data into risk‑based insights for technical and executive stakeholders
- Act as a trusted advisor to business and technology leaders by clearly articulating external risk, architectural trade‑offs, and remediation options
- Drive alignment across multiple teams with competing priorities using influence rather than authority
- Leverage enterprise‑approved AI tools to enhance productivity and innovation by streamlining workflows and automating repetitive tasks
- Evaluate emerging trends to drive continuous improvement and strategic innovation
- Own and evolve security architecture standards and reference designs related to:
- Attack Surface Management (ASM / EASM)
- External asset discovery and inventory
- Email and messaging security (SMTP, gateways, SaaS email platforms)
- Internet‑facing network, cloud, and application exposure
- Define integration patterns between ASM tooling and:
- SIEM and SOAR platforms
- Ticketing and remediation workflows
- Identity and access management systems
- Evaluate and document external security risks,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).