EngineerJobs.io
← Back to all jobs

Job Description

UnitedHealth Group is seeking a Principal Threat Intelligence Engineer to expand and integrate threat intelligence capabilities across its security ecosystem. In this role, you will help operationalize intelligence-led detection and response by ingesting, normalizing, enriching, and automating threat data workflows used by CTI, SOC, IR, and other SecOps teams.

This position is based in Washington, DC with a remote work setup and a salary range of USD 112,700 to 193,200 per year. A minimum of 3+ years of relevant experience is required.

What you’ll do

  • Deploy, integrate, and maintain a threat intelligence platform integrated into United Health’s security tooling ecosystem
  • Integrate threat intelligence into SIEM platforms (example: Splunk) to support detection use cases and alert enrichment
  • Use agentic AI, LLMs, and related capabilities to improve the speed and availability of contextualized threat intelligence for CTI, SOC, IR, and other SecOps teams
  • Build and deploy technology-supported workflows to run intelligence use cases across environments including SOC, IR, Insider Risk, Fraud, Red Team, and Threat Hunt
  • Develop and maintain SOAR playbooks for automated threat response and enrichment, leveraging SOAR to optimize intelligence workflows
  • Orchestrate workflows across security tools to reduce manual analysis and improve response time
  • Build and maintain integrations between threat intelligence feeds (commercial, open-source, ISACs) and internal security platforms
  • Integrate and operationalize TIPs such as MISP, OpenCTI ThreatConnect, Anomali, and ThreatQuotient with enterprise security tools
  • Create pipelines to ingest, normalize, deduplicate, and enrich Indicators of Compromise (IOCs) and threat data
  • Correlate intelligence with telemetry from SIEM, EDR, NDR, and cloud security tools to improve detection fidelity
  • Enable automated enrichment of alerts using threat intelligence data within SIEM workflows

Required qualifications

  • 3+ years of experience in a cyber threat intelligence, cyber security engineering, incident response, or malware analysis role with a strong emphasis on tool and technology integration
  • Proficiency in Python (primary) for automation, API integrations, and data processing
  • Proficiency in one or more of: Java, JavaScript/Node.js, or Go for service development
  • Experience with REST APIs, JSON, and STIX/TAXII protocols
  • Experience with data parsing, transformation, and pipeline development
  • Experience with scripting in Bash and/or PowerShell
  • Demonstrated familiarity with Git and CI/CD pipelines
  • Demonstrated familiarity with OSes and platforms including Linux (Ubuntu, CentOS, RHEL, Kali), AWS, Docker, Windows Server (NT through 2012), Active Directory, and Mac OS X
  • Experience applying AI within a threat intelligence framework, including LLM, MCP server configuration, RAG, and related processes
  • Hands-on experience with TIPs such as MISP, OpenCTI, ThreatConnect, and Anomali
  • Experience integrating multiple intelligence feeds and formats
  • Solid experience with SIEM platforms: Splunk, Microsoft Sentinel, IBM QRadar, Elastic
  • Experience building detection rules, correlation searches, and dashboards
  • Proven understanding of log ingestion, normalization, and enrichment pipelines
  • Experience with SOAR platforms such as Cortex XSOAR, Splunk SOAR, Swimlane, and Tines
  • Development experience with playbooks/runbooks for automated response
  • Proven knowledge of structured threat data formats: STIX and TAXII

Technologies you may work with

  • Python, Java, JavaScript/Node.js, Go
  • REST APIs, JSON, STIX/TAXII
  • Bash, PowerShell, Git, CI/CD
  • Linux (Ubuntu, CentOS, RHEL, Kali), AWS, Docker
  • Windows Server (NT through 2012), Active Directory, Mac OS X
  • LLMs, MCP server configuration, RAG
  • MISP, OpenCTI, ThreatConnect, Anomali, Splunk, Microsoft Sentinel, IBM QRadar, Elastic
  • Cortex XSOAR, Splunk SOAR, Swimlane, Tines
  • ThreatQuotient, EDR, NDR, IOcs, TIPs, SIEM, SOAR

Benefits

  • Comprehensive benefits package
  • Incentive and recognition programs
  • Equity stock purchase
  • 401k contribution (all benefits are subject to eligibility requirements)

Preferred qualifications

  • Relevant certifications (examples: GCTI, GCIA, CISSP, Splunk certifications)
  • Experience in large-scale security operations or SOC environments
  • Familiarity with MITRE ATT&CK and other intelligence frameworks
  • Familiarity with data engineering technologies (examples: Kafka, Spark, Elasticsearch)
  • Experience with cloud platforms (AWS, Azure, GCP) and security integrations
  • Experience in threat hunting and detection engineering

Similar Jobs