Senior Information Security Risk Auditor
Job description
Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together.
You'll enjoy the flexibility to telecommute* from anywhere within the U.S. as you take on some tough challenges.
PrimaryResponsibilities
The key responsibilities of the role are as follows:
- Plan and execute risk-based assessments of control design and operating effectiveness across critical security domains (e.g., identity, access, network, cloud, data protection)
- Validate that controls are designed to mitigate identified risks and align with regulatory obligations (SOX, SOC 2, NYDFS) and leading frameworks (NIST CSF, ISO/IEC 27001)
- Review control documentation, evidence, and automation guardrails for completeness, accuracy, and scalability.
- Support the collection of data supporting regulatory and contractual obligations, coordinate reports, and conduct quality assurance of submitted evidence
- Drive timely closure of control deficiencies identified during audits or regulatory reviews within defined SLAs.
- Facilitate control governance working groups and develop executive-ready summaries highlighting control effectiveness, risk implications, and required actions
- Ensure interoperability between control governance processes and enterprise GRC platforms, continuously improving control assurance through dashboards, automation, and technology-enabled insights
- Establish, mandate, and implement standard procedures and best practices to promote compliance with applicable laws and contractual obligations across UnitedHealth Group
You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear directions on what it takes to succeed in your role as well as provide development for other roles you may be interested in.
Required
Qualifications
- High School Diploma
- 5+ years of experience working in an IT auditing, information security risk management, IT regulatory compliance, or IT Audit role
- 3+ years of experience interacting & collaborating with a variety of stakeholders (other team members, internal customers, and executives) and be able to provide measurable results without authority
- 3+ years of experience implementing, monitoring and/or auditing IT general controls for application or platform environments
- 3+ years of demonstrated knowledge of Agile software development, IT operations and logical security risks
- 2+ years of experience working with enterprise GRC platforms, control testing workflows, and deficiency remediation tracking against defined SLAs
Preferred
Qualifications
- Bachelor's degree or equivalent experience
- Ability to navigate and manage ambiguity
- Experience working in or auditing health related business operations
- Experience with issuing Service Organization Controls (SOC) reports or is a certified CISA, CISM, CISSP or HITRUST assessor
- Experience working with Mergers and Acquisitions or Non-Integrated Business Partners
- Proven desire to make a positive impact with the ability to manage multiple tasks and shift priorities
*All Telecommuters will be required to adhere to UnitedHealth Group's Telecommuter Policy.
Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you'll find a far-reaching choice of benefits and incentives. The salary for this role will range from $91,700 to $163,700 annually based on full-time employment. We comply with all minimum wage laws as applicable.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants.
At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location, and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups, and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission.
UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations.
UnitedHealth Group is a drug-free workplace. Candidates are required to pass a drug test before beginning employment.
#RPO #GREEN
Skills mentioned
Apply for this job
Use the application link supplied with this listing to apply to UnitedHealth Group. Check the destination before entering personal information.

