This job has expired

This job posting is no longer active and is not accepting applications. Explore similar roles below!

UnitedHealth Group
Posted 1mo ago

Principal Security Engineer - Splunk & SIEM Engineering - Remote

UnitedHealth Group
Raleigh, North Carolina, United States
$113k-$193k/yrRemoteFull Time
Responsibilities
  • leading onboarding
  • designing infrastructure
  • mentoring engineers
Requirements
  • 4+ years security engineering experience
  • 3+ years with Splunk
  • Log onboarding across cloud/on-prem/SaaS
  • Scripting (Python/Bash)
  • EMR not required
  • Strong communication and leadership skills
Technical tools mentioned
Splunk EnterpriseSplunk CloudPythonBashAWSAzureGCPUFHFsyslogAPIsSOARMITRE ATT&CK

Job description

Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together.    

 

We are seeking a highly experienced Principal Security Engineer to lead Splunk engineering and onboarding efforts across acquired entities. This role will serve as the Splunk Subject Matter Expert (SME) and play a critical leadership role in integrating newly acquired environments into the enterprise security monitoring ecosystem.

 

The ideal candidate blends deep technical expertise in Splunk infrastructure with strong program leadership, ensuring scalable log ingestion, normalization, and operational excellence across diverse environments.

 

You’ll enjoy the flexibility to work remotely * from anywhere within the U.S. as you take on some tough challenges. For all hires in the Minneapolis or Washington, D.C. area, you will be required to work in the office a minimum of four days per week.

 

Primary Responsibilities:

  • Splunk Engineering & SME Leadership
    • Serve as the primary Splunk SME, providing architecture guidance, troubleshooting support, and strategic direction
    • Design, build, and optimize enterprise-scale Splunk infrastructure (indexers, search heads, forwarders, clustering, and cloud/hybrid deployments)
    • Define standards, best practices, and governance for Splunk usage, data onboarding, and content development
    • Lead performance tuning, capacity planning, and cost optimization initiatives
  • Acquisition Integration & Log Onboarding
    • Lead onboarding of logs from newly acquired entities into Splunk, including:
      • Log source identification and prioritization
      • Data ingestion architecture design
      • Field extraction, parsing, and normalization
    • Partner with acquisition teams, IT, and security stakeholders to ensure timely and complete visibility
    • Develop repeatable onboarding playbooks and integration frameworks for rapid scaling
    • Ensure alignment with enterprise security use cases, compliance requirements, and detection strategies
  • Security Data Engineering & Operations
    • Implement and maintain secure, reliable log pipelines across cloud, on-prem, and SaaS environments
    • Ensure high availability and resilience of Splunk services
    • Oversee data quality, integrity, and retention policies
    • Support SOC operations by enabling efficient search, dashboards, alerts, and detection content
  • Collaboration & Leadership
    • Act as a technical leader and mentor to security engineers and analysts
    • Collaborate with cross-functional teams (Cloud, Infrastructure, DevOps, Security Operations)
    • Influence and drive adoption of standardized logging and monitoring practices
    • Communicate technical strategies and risks to senior leadership

 

You’ll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in.


Required Qualifications:

  • 4+ years of experience in security engineering, SIEM, or data platform engineering
  • 3+ years of experience with Splunk Enterprise and/or Splunk Cloud
  • Experience managing and scaling Splunk infrastructure
  • Solid experience onboarding logs across:
  • Cloud platforms (AWS, Azure, GCP)
  • Network/security devices
  • Endpoints, SaaS, and custom applications

     

  • Data ingestion (UF/HF, APIs, syslog, cloud-native integrations)
  • Parsing, CIM normalization, and knowledge objects
  • Proven solid scripting skills (Python, Bash, or similar) 

 

Preferred Qualifications:

  • Experience with Security Operations (SOC) and detection engineering
  • Experience supporting M&A / acquisition integrations
  • Knowledge of SOAR platforms and automation
  • Familiarity with frameworks such as MITRE ATT&CK

 

*All employees working remotely will be required to adhere to UnitedHealth Group’s Telecommuter Policy

 

Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you’ll find a far-reaching choice of benefits and incentives. The salary for this role will range from $112,700 - $193,200 annually based on full-time employment. We comply with all minimum wage laws as applicable.

 

Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants.

 

At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone–of every race, gender, sexuality, age, location and income–deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes — an enterprise priority reflected in our mission.    

 

 

UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations.

 

UnitedHealth Group is a drug - free workplace. Candidates are required to pass a drug test before beginning employment. 



Job Details

Job: Cybersecurity Defense & Invstg

Primary Location: US-NC-Raleigh

Organization: Entrprse Information Security

Schedule: Full-time

Number of Openings: 1

About UnitedHealth Group

Provides health insurance and technology-enabled health care services.

Similar jobs

Security Engineer roles near Raleigh, North Carolina
1w
Save
Mark Applied
Hide
Senior Security Engineer, Network Security Engineering
New York or Kirkland or Raleigh or Durham
$174k-$252k/yr OnsiteFull Time
Google
GoogleNASDAQ: GOOGL: Provides online search, advertising, cloud computing, and consumer electronics.
5+ YOEBachelor's degree or equivalent, 5 years in security engineering and assessments, 5 years of coding, and 1 year leading technical teams or risk analysis.
software-defined networking (SDN), Internet Engineering Task Force (IETF), firewalls, DNS, reverse engineering, fuzzing, static analysis
2w
Save
Mark Applied
Hide
Senior Security Engineer- Threat Engineering Detection Team
Atlanta or Raleigh or Charlotte
OnsiteFull Time
Truist
TruistNYSE: TFC: Offers personal banking, business lending, and investment management services.
7+ YOERequires a bachelor's degree or equivalent and 7+ years in security engineering or cybersecurity, with expertise in detection engineering, threat modeling, Splunk, Snowflake, SQL, and complex security technologies.
Anvilogic, Splunk, Snowflake, Snowpipe, Cribl, Databahn, MySQL, PostgreSQL, SQL Server, Python, Docker, Kubernetes, MITRE ATT&CK
2w
Save
Mark Applied
Hide
Senior Security Engineer
Austin or Boston or Charleston or Charlotte or Chicago or Dallas or Durham or Harrisburg or Houston or Irvine or Kansas City or Los Angeles or Miami or Nashville or New York or Newark or Palo Alto or Pittsburgh or Portland or Raleigh or San Francisco or Seattle or Washington or Wilmington
$112k-$209k/yr HybridFull Time
K&L Gates
K&L Gates: Global law firm providing comprehensive legal and regulatory counsel.
7+ YOE7+ years cybersecurity/security engineering experience; expertise in cloud and hybrid security, DevSecOps, detection engineering, automation, incident response; Bachelor\u0002s or equivalent; relevant certifications preferred.
PowerShell, Python, REST APIs, Microsoft Graph, Azure, Microsoft Defender, Sentinel, Entra ID, Purview, Splunk, CrowdStrike, SIEM, EDR/XDR, MITRE ATT&CK
2w
Save
Mark Applied
Hide
Senior Security Engineer, Business Engagement
Raleigh, North Carolina, United States
$95k-$159k/yr OnsiteFull Time
LexisNexis
LexisNexisNYSE: RELX: Global provider of legal, regulatory, and business information analytics.
Experience in SaaS/cloud product security, partnering with Product and Engineering, knowledge of data protection/identity/application security, stakeholder engagement, and familiarity with AI-related security risks.
3w
Save
Mark Applied
Hide
Principal Security Engineer
Basking Ridge or Alpharetta or Irving or Ashburn or Temple Terrace or Cary
$121k-$231k/yr HybridFull Time
Verizon
VerizonNYSE: VZ: Provides wireless, broadband, and telecommunications services to customers.
6+ YOE6+ years network security experience, expertise in routing/switching and BGP/IGP security, SIEM/Splunk, automation with Python/Ansible/Terraform, and leadership in cross-functional projects.
Splunk, Python, Ansible, Terraform, API, ISE
4w
Save
Mark Applied
Hide
Senior Security Engineer
Research Triangle Park, North Carolina, United States
$137k-$201k/yr HybridFull Time
Cisco
CiscoNASDAQ: CSCO: Develops and sells networking hardware and cybersecurity software.
4+ YOEBachelor's plus 7 years or Master's plus 4 years; deep Splunk and Splunk ES experience, advanced SPL, data normalization, cloud security logging, SOC collaboration, and strong documentation skills.
Splunk Enterprise, Splunk Enterprise Security, SPL, Git
1mo
Save
Mark Applied
Hide
Principal Security Engineer
Redmond or Mountain View or Hillsboro or Austin or Raleigh
$143k-$275k/yr HybridFull Time
Microsoft
MicrosoftNASDAQ: MSFT: Develops software, services, devices, and cloud computing solutions.
6+ YOEBachelor's degree and 6+ years engineering experience with firmware/secure hardware design, strong coding in C/C++/Rust and familiarity with cryptography, secure boot, attestation, and debugging.
C, C++, C#, Java, JavaScript, Python, Rust, Real-Time Operating Systems (RTOS), PCIe, NVME, I3C, I2C, SPI
1mo
Save
Mark Applied
Hide
Principal Security Engineer
Basking Ridge or Alpharetta or Ashburn or Irving or Cary or Temple Terrace
$121k-$231k/yr HybridFull Time
Verizon
VerizonNYSE: VZ: Provides wireless, fiber-optic internet, and telecommunications services globally.
6+ YOE6+ years relevant experience, bachelor’s degree or equivalent experience, leadership experience, deep routing/switching and network security expertise, hands-on with Python/Ansible/Terraform, Splunk/SIEM, and network telemetry analysis.
Python, Ansible, Terraform, Splunk, Confluence, SIEM, API
This job has expired