Principle Cybersecurity Analyst - Remote
Washington, District of Columbia, 20001, USA
Listed on 2026-08-07
-
IT/Tech
Cybersecurity, Security Management & Operations, Information Security & Data Protection
Principal Threat Intelligence Engineer
Join the Enterprise Information Security (EIS) team at United Health Group, one of the world's largest health care companies. The EIS team is responsible for cybersecurity across our organization, supporting our business and members by reducing risk, rapidly responding to threats, focusing on business resiliency and securing new acquisitions.
The Principal Threat Intelligence Engineer is responsible for deployment and integration of threat intelligence technical capabilities across United Health Group's security ecosystem. The role focuses on ingesting, normalizing, and enriching threat intelligence information, integrating Threat Intelligence Platforms (TIPs) and intelligence sources with security tooling (e.g., SIEM, SOAR, EDR), and deploying automated intelligence-enabled detection and response workflows. The ideal candidate combines solid software engineering skills with deep cybersecurity domain knowledge to transform raw threat data into actionable intelligence that enhances detection, response, and risk mitigation.
This technical role focuses on building automation, data pipelines, and detection mechanisms to proactively defend infrastructure against threats of varying technical sophistication.
The Principal Threat Intelligence Engineer is expected to execute the delivery of technical intelligence solutions to CTI, SOC, Threat Detection, and Threat Hunting teams that accelerate the processing and dissemination of intelligence, increase speed of detection, and enable rapid response.
Primary responsibilities include:
- Deploy, integrate, and maintain a threat intelligence platform that is integrated into United Health's security tooling ecosystem
- Integrate threat intelligence into SIEM platforms (e.g., Splunk) for detection use cases and alert enrichment
- Efficiently employ agentic AI, LLMs, and other associated capabilities to increase the availability and speed of delivery of contextualized threat intelligence to CTI, SOC, IR, and other Sec Ops members
- Build, and deploy technology-supported workflows to execute diverse intelligence use cases across SOC, IR, Insider Risk, Fraud, Red Team, Threat Hunt, and other stakeholder environments
- Develop and maintain SOAR playbooks for automated threat response and enrichment; utilize SOAR to optimize intelligence workflows
- Orchestrate workflows across security tools to reduce manual analysis and response time
- Build and maintain integrations between threat intelligence feeds (commercial, open-source, ISACs) and internal security platforms
- Integrate and operationalize Threat Intelligence Platforms (e.g., MISP, OpenCTI Threat Connect, Anomali, Threat Quotient) with enterprise security tools
- Develop pipelines to ingest, normalize, deduplicate, and enrich Indicators of Compromise (IOCs) and threat data
- Correlate intelligence with telemetry from SIEM, EDR, NDR, and cloud security tools to improve detection fidelity
- Enable automated enrichment of alerts using threat intelligence data within SIEM workflows
Required qualifications include:
- 3+ years of experience in a cyber threat intelligence, cyber security engineering, incident response or malware analysis role with heavy emphasis on tool and technology integration
- Proficiency in one or more of:
Python (primary) for automation, API integrations, and data processing, Java, JavaScript/Node.js, or Go for service development - Experience with: REST APIs, JSON, STIX/TAXII protocols, Data parsing, transformation, and pipeline development, Scripting (Bash, Power Shell)
- Demonstrated familiarity with version control (Git) and CI/CD pipelines
- Demonstrated familiarity with a variety of OS's and platforms including Linux (Ubuntu, CentOS, RHEL, Kali), AWS, Docker, Windows Server (NT through 2012), Active Directory, Mac OS X
- Experiences with AI employment in a threat intelligence framework including LLM, MCP server configuration, RAG and associated processes
- Hands-on experience with TIPs such as: MISP, OpenCTI, Threat Connect, Anomali
- Experience integrating multiple intelligence feeds and formats
- Solid experience with SIEM platforms:
Splunk, Microsoft Sentinel, IBM QRadar, Elastic - Experience building detection rules, correlation searches, and dashboards
- Proven understanding of log ingestion, normalization, and enrichment pipelines
- Experience with SOAR platforms such as Cortex XSOAR, Splunk SOAR, Swimlane, Tines
- Development experience with playbooks/runbooks for automated response
- Proven knowledge of structured threat data formats (STIX, TAXII)
Preferred qualifications include:
- Relevant certifications (e.g., GCTI, GCIA, CISSP, Splunk certifications)
- Experience in large-scale security operations or SOC environments
- Familiarity with MITRE ATT&CK and other intelligence frameworks
- Familiarity with data engineering technologies (Kafka, Spark, Elasticsearch)
- Experience with cloud platforms (AWS, Azure, GCP) and security integrations
- Experience in threat hunting and detection engineering
Pay is based on several factors including but not…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).