Engaging technical teams in planning and addressing security risk of UHG solutions throughout the technology stack in strategic programs.
Developing metrics and dashboard in collaboration with cross-functional teams that demonstrate current state of risks, indicators of progress, and business alignment. Executes follow-through by helping projects and programs build capabilities that provide data required to support metrics.
Works in active partnership with technical stakeholders (solution, infrastructure, and application architects) to deliver security cloud governance.
Develops security domain expertise and technical objectives that will enable successful and secure delivery of project and program goals, thereby supporting the growth and evolution of UnitedHealth Group.
Is able to understand requirements driven through policy, regulatory and legal mandates and be able to rationalize them with various technology and business leaders
Establishes security criteria based on business, compliance, risk reduction and use case.
Recommends security controls, improvements, upgrades, and/or purchases
Support the engineering of technology solutions that adopt Secure DevOps, Cloud (IaaS, PaaS, SaaS) in a healthcare industry
Build protection profiles, standards and architecture and engineering patterns around required controls
Look for opportunities to automate security specification and verification in the delivery process
Engage with delivery teams to drive empowerment and self-service security knowledge
- Undergraduate degree or equivalent experience.
10+ years of experience providing technical security engineering support for complex enterprise security projects/programs for large healthcare or cloud based enterprise organizations
5+ years with designing and engineering secure solutions within various IaaS, PaaS, SaaS cloud platforms
Strong experience with Secure DevOps
Designed security engineering patterns
Strong understanding of cyber security defense strategies
Fluency with IT governance standards including NIST, CSA, and other technical standards
Experience complying with regulatory guidance at the State and Federal level to include but not limited to HIPAA/HITECH, CMS/HHS/MARS-E and/or CFR Part 11
Experience executing security engineering processes within agile methodologies. Industry-specific certifications, including one or more of the following: CISSP, CCSP
Participated in leading agile programs from requirements or design
Strong Oral and written communications skills to enable effective and meaningful information exchange between technical and non-technical people across multiple levels of organizational structure
Bachelor Degree in engineering, computer science, Software Engineering or related subject
Our mission is to help people live healthier lives and to help make the health system work better for everyone.A Fortune 5 company, we're focused on helping people live healthier lives while making the health system work better for everyone. Here, we seek to empower people with the information, gu...