×
Register Here to Apply for Jobs or Post Jobs. X

Sr. Principal Threat Intelligence Engineer- Remote or Hybrid in MN or DC

Remote / Online - Candidates ideally in
Washington, District of Columbia, 20022, USA
Listing for: UnitedHealth Group
Full Time, Remote/Work from Home position
Listed on 2026-08-08
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Security Management & Operations
Salary/Wage Range or Industry Benchmark: 134600 - 230800 USD Yearly USD 134600.00 230800.00 YEAR
Job Description & How to Apply Below

Explore opportunities with the Enterprise Information Security (EIS) team at United Health Group. Join one of the world's largest health care companies and become part of the first line of defense against security threats. We are focused on strengthening our cyber defenses, ransomware resiliency, vulnerability mitigation, and securing all aspects of our systems and data globally. We are passionate about protecting the sensitive data of our members and providers.

We are committed to leveraging every tool, partnership and process needed to enhance our security posture. It is our duty to protect the information of those we serve while Caring. Connecting. Growing together.

The Enterprise Information Security (EIS) teamis responsible forcybersecurity across our organization. We support our business and members by reducing risk, rapidly responding to threats, focusing on businessresiliencyand securing new acquisitions.

The Senior Principal Threat Intelligence Engineer is responsible for designing, deploying and integrating threat intelligence technical capabilities across United Health Group's security ecosystem. The role focuses on ingesting, normalizing, and enriching threat intelligence information, integrating Threat Intelligence Platforms (TIPs) and intelligence sources with security tooling (e.g., SIEM, SOAR, EDR), and deploying automated intelligence-enabled detection and response workflows. The ideal candidate combines solid software engineering skills with deep cybersecurity domain knowledge to transform raw threat data into actionable intelligence that enhances detection, response, and risk mitigation.

This technical role focuses on building automation, data pipelines, and detection mechanisms to proactively defend infrastructure against threats of varying technical sophistication.

The Senior Principal Threat Intelligence Engineer is expected to conceptualize, guide, and execute the delivery of technical intelligence solutions to CTI, SOC, Threat Detection, and Threat Hunting teams that accelerate the processing and dissemination of intelligence, increase speed of detection, and enable rapid response.

The Senior Principal Threat Intelligence Engineer will be a key driver of the technology development and deployment agenda within the CTI space at United Health Group to include tool selection, architectural design, tool development, and operational support. This role will have a primary voice in design decisions, tool selection, and tool development, and will be expected to exert senior influence and operate autonomously as required.

You’ll enjoy the flexibility to work remotely
* from anywhere within the U.S. as you take on some tough challenges. For all hires in the Minneapolis or Washington, D.C. area, you will be required to work in the office a minimum of four days per week.

Primary Responsibilities:
  • Deploy, integrate, and maintain a threat intelligence platform that is integrated into United Health's security tooling ecosystem
  • Integrate threat intelligence into SIEM platforms (e.g., Splunk) for detection use cases and alert enrichment
  • Efficiently employ agentic AI, LLMs, and other associated capabilities to increase the availability and speed of delivery of contextualized threat intelligence to CTI, SOC, IR, and other Sec Ops members
  • Design, build, and deploy technology-supported workflows to execute diverse intelligence use cases across SOC, IR, Insider Risk, Fraud, Red Team, Threat Hunt, and other stakeholder environments
  • Develop and maintain SOAR playbooks for automated threat response and enrichment; utilize SOAR to optimize intelligence workflows
  • Orchestrate workflows across security tools to reduce manual analysis and response time
  • Design, build, and maintain integrations between threat intelligence feeds (commercial, open-source, ISACs) and internal security platforms
  • Integrate and operationalize Threat Intelligence Platforms (e.g., MISP, OpenCTI Threat Connect, Anomali, Threat Quotient) with enterprise security tools
  • Develop pipelines to ingest, normalize, deduplicate, and enrich Indicators of Compromise (IOCs) and threat data
  • Correlate intelligence with telemetry from SIEM, EDR, NDR, and…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary