Optum
Senior Information Security Engineering - Risk GRC, Vendor, Education Training & Awareness
Be an Early Applicant
The role involves ensuring compliance with policies, remediating security risks, managing vendor risk, and providing guidance on security frameworks and policies.
Requisition Number: 2365782
Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together.
Primary Responsibilities:
Required Qualifications:
At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone - of every race, gender, sexuality, age, location and income - deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission.
Optum is a drug-free workplace. © 2026 Optum Global Solutions (Philippines) Inc. All rights reserved.
Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together.
Primary Responsibilities:
- Ensure compliance to the business agreement, policies, procedures, & regulations along with ability to map controls and compliance requirements
- Perform information security policies review based on industry best practice and framework gap
- Monitors information security risks and drives remediation of policy exceptions
- Establishes compliance with data privacy regulation
- Identify process and security gaps, recommend improvements, and assist to implement corrective action.
- Identify required process improvements to proactively address risks/vulnerabilities/threats
- Perform and manage Control/Risk Assessment and remediation of identified findings as per process documents
- Establish a baseline of vendor risk, identify areas of potential exposure, develop and align vendor risk management strategies with Client's goals and objectives, and execute program ensuring consistency
- Support the design and implementation of a common and consistent vendor risk management (VRM) program to effectively manage vendor risk in accordance with internal policy and Federal/State Regulatory requirements
- Maintain current knowledge on quality management and information security topics and their applicability program requirements
- Serves as POC (Point of Contact) in lead's absence
- Create executive summaries with recommendations & direction regarding remediation efforts and disposition of the third party
- Communicate professionally with stakeholders/end users through multiple communication
- Define risk thresholds, develop, and implement a risk framework, remediate identified gaps, governing the process
- Manage the process of granting and expiring exceptions to policies and control standards through the GRC platform
- Establish real-time actionable dashboards for Policies and Standard and Risk Management
- Monthly review of High and Critical risks with risk owners and executive leadership
- Establish an Executive dashboard to provide visibility into the goals and KPI's
- Perform control testing to evaluate the maturity and effectiveness of implemented security controls based on HITRUST/ NIST 800-53 revision 2 Framework.
- Comply with the terms and conditions of the employment contract, company policies and procedures, and any and all directives (such as, but not limited to, transfer and/or re-assignment to different work locations, change in teams and/or work shifts, policies in regard to flexibility of work benefits and/or work environment, alternative work arrangements, and other decisions that may arise due to the changing business environment). The Company may adopt, vary or rescind these policies and directives in its absolute discretion and without any limitation (implied or otherwise) on its ability to do so
Required Qualifications:
- 5 + years of technical experience in Information Security
- 5+ years GRC platform implementation and migration experience for different tool (such as NAVEX Service Now, LogicGate, Rsam, Perimeter)
- 5+ years IT Auditing skills and the ability to manage risk assessments / projects independently
- Experience with federal cyber security standards (such as NIST 800-53)
- Proven excellent communication skills both verbal and written
- Good presentation skills particularly ability to present technology elements in manner personnel can follow and act
- Good understanding of ISO27001 and Security Core Concepts
- Good understanding of Risk Register, risk acceptance and risk exceptions
At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone - of every race, gender, sexuality, age, location and income - deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission.
Optum is a drug-free workplace. © 2026 Optum Global Solutions (Philippines) Inc. All rights reserved.
Similar Jobs at Optum
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
The role involves IAM implementation and development with SailPoint, user access certification, and client support while ensuring compliance with policies.
Top Skills:
CyberarkDelineaExcelPythonRSailpoint Identity NowSQL
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Design, build, and support Cerner Scheduling systems, focusing on troubleshooting, healthcare data analysis, and workflow improvement. Collaborate with teams while adhering to SOPs and communicating effectively.
Top Skills:
Cerner SchedulingExcel
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
The Tech Support Analyst resolves technical issues, maintains exceptional customer service, and logs interactions within an incident management tool while adhering to company policies.
Top Skills:
Java Plug-InsMs Office SuiteRightfaxTableauWindows 10
What you need to know about the Chicago Tech Scene
With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.
Key Facts About Chicago Tech
- Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
- Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
- Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
- Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

