This position is no longer accepting applications
Closed on September 5, 2026.
This role is filled — get an email when new Artificial Intelligence roles open on EngineerJobs.io:
Principal Threat Intelligence Engineer
Get alerted when similar jobs are posted — set up a New Artificial Intelligence jobs on EngineerJobs.io alert.
See other roles at UnitedHealth Group.
Job Description
UnitedHealth Group is seeking a Principal Threat Intelligence Engineer to expand and integrate threat intelligence capabilities across its security ecosystem. In this role, you will help operationalize intelligence-led detection and response by ingesting, normalizing, enriching, and automating threat data workflows used by CTI, SOC, IR, and other SecOps teams.
This position is based in Washington, DC with a remote work setup and a salary range of USD 112,700 to 193,200 per year. A minimum of 3+ years of relevant experience is required.
What you’ll do
- Deploy, integrate, and maintain a threat intelligence platform integrated into United Health’s security tooling ecosystem
- Integrate threat intelligence into SIEM platforms (example: Splunk) to support detection use cases and alert enrichment
- Use agentic AI, LLMs, and related capabilities to improve the speed and availability of contextualized threat intelligence for CTI, SOC, IR, and other SecOps teams
- Build and deploy technology-supported workflows to run intelligence use cases across environments including SOC, IR, Insider Risk, Fraud, Red Team, and Threat Hunt
- Develop and maintain SOAR playbooks for automated threat response and enrichment, leveraging SOAR to optimize intelligence workflows
- Orchestrate workflows across security tools to reduce manual analysis and improve response time
- Build and maintain integrations between threat intelligence feeds (commercial, open-source, ISACs) and internal security platforms
- Integrate and operationalize TIPs such as MISP, OpenCTI ThreatConnect, Anomali, and ThreatQuotient with enterprise security tools
- Create pipelines to ingest, normalize, deduplicate, and enrich Indicators of Compromise (IOCs) and threat data
- Correlate intelligence with telemetry from SIEM, EDR, NDR, and cloud security tools to improve detection fidelity
- Enable automated enrichment of alerts using threat intelligence data within SIEM workflows
Required qualifications
- 3+ years of experience in a cyber threat intelligence, cyber security engineering, incident response, or malware analysis role with a strong emphasis on tool and technology integration
- Proficiency in Python (primary) for automation, API integrations, and data processing
- Proficiency in one or more of: Java, JavaScript/Node.js, or Go for service development
- Experience with REST APIs, JSON, and STIX/TAXII protocols
- Experience with data parsing, transformation, and pipeline development
- Experience with scripting in Bash and/or PowerShell
- Demonstrated familiarity with Git and CI/CD pipelines
- Demonstrated familiarity with OSes and platforms including Linux (Ubuntu, CentOS, RHEL, Kali), AWS, Docker, Windows Server (NT through 2012), Active Directory, and Mac OS X
- Experience applying AI within a threat intelligence framework, including LLM, MCP server configuration, RAG, and related processes
- Hands-on experience with TIPs such as MISP, OpenCTI, ThreatConnect, and Anomali
- Experience integrating multiple intelligence feeds and formats
- Solid experience with SIEM platforms: Splunk, Microsoft Sentinel, IBM QRadar, Elastic
- Experience building detection rules, correlation searches, and dashboards
- Proven understanding of log ingestion, normalization, and enrichment pipelines
- Experience with SOAR platforms such as Cortex XSOAR, Splunk SOAR, Swimlane, and Tines
- Development experience with playbooks/runbooks for automated response
- Proven knowledge of structured threat data formats: STIX and TAXII
Technologies you may work with
- Python, Java, JavaScript/Node.js, Go
- REST APIs, JSON, STIX/TAXII
- Bash, PowerShell, Git, CI/CD
- Linux (Ubuntu, CentOS, RHEL, Kali), AWS, Docker
- Windows Server (NT through 2012), Active Directory, Mac OS X
- LLMs, MCP server configuration, RAG
- MISP, OpenCTI, ThreatConnect, Anomali, Splunk, Microsoft Sentinel, IBM QRadar, Elastic
- Cortex XSOAR, Splunk SOAR, Swimlane, Tines
- ThreatQuotient, EDR, NDR, IOcs, TIPs, SIEM, SOAR
Benefits
- Comprehensive benefits package
- Incentive and recognition programs
- Equity stock purchase
- 401k contribution (all benefits are subject to eligibility requirements)
Preferred qualifications
- Relevant certifications (examples: GCTI, GCIA, CISSP, Splunk certifications)
- Experience in large-scale security operations or SOC environments
- Familiarity with MITRE ATT&CK and other intelligence frameworks
- Familiarity with data engineering technologies (examples: Kafka, Spark, Elasticsearch)
- Experience with cloud platforms (AWS, Azure, GCP) and security integrations
- Experience in threat hunting and detection engineering