Principal Threat Intelligence Engineer
Agentic Ai
Artificial Intelligence
Cybersecurity Tools
Data Security
Incident Response
Information Security
InfoSec
Investigative Skills
Llm Rag
Project Management
Risk Management
Security
Security Automation
Security Information And Event Management
Security Operations
Security Testing
SOAR
Solution Architecture
Threat Hunting
Threat Intel Platforms
Threat Intelligence
Threat Intelligence Platform
Tip Integration
Job Description
UnitedHealth Group is seeking a Principal Threat Intelligence Engineer to expand and integrate threat intelligence capabilities across its security ecosystem. In this role, you will help operationalize intelligence-led detection and response by ingesting, normalizing, enriching, and automating threat data workflows used by CTI, SOC, IR, and other SecOps teams.
This position is based in Washington, DC with a remote work setup and a salary range of USD 112,700 to 193,200 per year. A minimum of 3+ years of relevant experience is required.
What you’ll do
- Deploy, integrate, and maintain a threat intelligence platform integrated into United Health’s security tooling ecosystem
- Integrate threat intelligence into SIEM platforms (example: Splunk) to support detection use cases and alert enrichment
- Use agentic AI, LLMs, and related capabilities to improve the speed and availability of contextualized threat intelligence for CTI, SOC, IR, and other SecOps teams
- Build and deploy technology-supported workflows to run intelligence use cases across environments including SOC, IR, Insider Risk, Fraud, Red Team, and Threat Hunt
- Develop and maintain SOAR playbooks for automated threat response and enrichment, leveraging SOAR to optimize intelligence workflows
- Orchestrate workflows across security tools to reduce manual analysis and improve response time
- Build and maintain integrations between threat intelligence feeds (commercial, open-source, ISACs) and internal security platforms
- Integrate and operationalize TIPs such as MISP, OpenCTI ThreatConnect, Anomali, and ThreatQuotient with enterprise security tools
- Create pipelines to ingest, normalize, deduplicate, and enrich Indicators of Compromise (IOCs) and threat data
- Correlate intelligence with telemetry from SIEM, EDR, NDR, and cloud security tools to improve detection fidelity
- Enable automated enrichment of alerts using threat intelligence data within SIEM workflows
Required qualifications
- 3+ years of experience in a cyber threat intelligence, cyber security engineering, incident response, or malware analysis role with a strong emphasis on tool and technology integration
- Proficiency in Python (primary) for automation, API integrations, and data processing
- Proficiency in one or more of: Java, JavaScript/Node.js, or Go for service development
- Experience with REST APIs, JSON, and STIX/TAXII protocols
- Experience with data parsing, transformation, and pipeline development
- Experience with scripting in Bash and/or PowerShell
- Demonstrated familiarity with Git and CI/CD pipelines
- Demonstrated familiarity with OSes and platforms including Linux (Ubuntu, CentOS, RHEL, Kali), AWS, Docker, Windows Server (NT through 2012), Active Directory, and Mac OS X
- Experience applying AI within a threat intelligence framework, including LLM, MCP server configuration, RAG, and related processes
- Hands-on experience with TIPs such as MISP, OpenCTI, ThreatConnect, and Anomali
- Experience integrating multiple intelligence feeds and formats
- Solid experience with SIEM platforms: Splunk, Microsoft Sentinel, IBM QRadar, Elastic
- Experience building detection rules, correlation searches, and dashboards
- Proven understanding of log ingestion, normalization, and enrichment pipelines
- Experience with SOAR platforms such as Cortex XSOAR, Splunk SOAR, Swimlane, and Tines
- Development experience with playbooks/runbooks for automated response
- Proven knowledge of structured threat data formats: STIX and TAXII
Technologies you may work with
- Python, Java, JavaScript/Node.js, Go
- REST APIs, JSON, STIX/TAXII
- Bash, PowerShell, Git, CI/CD
- Linux (Ubuntu, CentOS, RHEL, Kali), AWS, Docker
- Windows Server (NT through 2012), Active Directory, Mac OS X
- LLMs, MCP server configuration, RAG
- MISP, OpenCTI, ThreatConnect, Anomali, Splunk, Microsoft Sentinel, IBM QRadar, Elastic
- Cortex XSOAR, Splunk SOAR, Swimlane, Tines
- ThreatQuotient, EDR, NDR, IOcs, TIPs, SIEM, SOAR
Benefits
- Comprehensive benefits package
- Incentive and recognition programs
- Equity stock purchase
- 401k contribution (all benefits are subject to eligibility requirements)
Preferred qualifications
- Relevant certifications (examples: GCTI, GCIA, CISSP, Splunk certifications)
- Experience in large-scale security operations or SOC environments
- Familiarity with MITRE ATT&CK and other intelligence frameworks
- Familiarity with data engineering technologies (examples: Kafka, Spark, Elasticsearch)
- Experience with cloud platforms (AWS, Azure, GCP) and security integrations
- Experience in threat hunting and detection engineering