Optum, part of the UnitedHealth Group family of businesses, is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together. At Optum, we support your well-being with an understanding team, extensive benefits and rewarding opportunities. By joining us, you’ll have the resources to drive system transformation while we help you take care of your future. We recognize the power of connection to drive change, improve efficiency and make a difference in health care. Join a team where your skills and ideas can make an impact and where collaboration is key to creating technology that produces healthier outcomes.
Senior Information Security Engineering - Risk GRC, Vendor, Education Training & Awareness
Location
Philippines
Posted
10 days ago
Salary
0
Seniority
Senior
Job Description
Senior Information Security Engineering - Risk GRC, Vendor, Education Training & Awareness
Optum
Requisition Number: 2365782 Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together. Primary Responsibilities: - Ensure compliance to the business agreement, policies, procedures, & regulations along with ability to map controls and compliance requirements - Perform information security policies review based on industry best practice and framework gap - Monitors information security risks and drives remediation of policy exceptions - Establishes compliance with data privacy regulation - Identify process and security gaps, recommend improvements, and assist to implement corrective action. - Identify required process improvements to proactively address risks/vulnerabilities/threats - Perform and manage Control/Risk Assessment and remediation of identified findings as per process documents - Establish a baseline of vendor risk, identify areas of potential exposure, develop and align vendor risk management strategies with Client's goals and objectives, and execute program ensuring consistency - Support the design and implementation of a common and consistent vendor risk management (VRM) program to effectively manage vendor risk in accordance with internal policy and Federal/State Regulatory requirements - Maintain current knowledge on quality management and information security topics and their applicability program requirements - Serves as POC (Point of Contact) in lead's absence - Create executive summaries with recommendations & direction regarding remediation efforts and disposition of the third party - Communicate professionally with stakeholders/end users through multiple communication - Define risk thresholds, develop, and implement a risk framework, remediate identified gaps, governing the process - Manage the process of granting and expiring exceptions to policies and control standards through the GRC platform - Establish real-time actionable dashboards for Policies and Standard and Risk Management - Monthly review of High and Critical risks with risk owners and executive leadership - Establish an Executive dashboard to provide visibility into the goals and KPI's - Perform control testing to evaluate the maturity and effectiveness of implemented security controls based on HITRUST/ NIST 800-53 revision 2 Framework. - Comply with the terms and conditions of the employment contract, company policies and procedures, and any and all directives (such as, but not limited to, transfer and/or re-assignment to different work locations, change in teams and/or work shifts, policies in regard to flexibility of work benefits and/or work environment, alternative work arrangements, and other decisions that may arise due to the changing business environment). The Company may adopt, vary or rescind these policies and directives in its absolute discretion and without any limitation (implied or otherwise) on its ability to do so Required Qualifications: - 5 + years of technical experience in Information Security - 5+ years GRC platform implementation and migration experience for different tool (such as NAVEX Service Now, LogicGate, Rsam, Perimeter) - 5+ years IT Auditing skills and the ability to manage risk assessments / projects independently - Experience with federal cyber security standards (such as NIST 800-53) - Proven excellent communication skills both verbal and written - Good presentation skills particularly ability to present technology elements in manner personnel can follow and act - Good understanding of ISO27001 and Security Core Concepts - Good understanding of Risk Register, risk acceptance and risk exceptions At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone - of every race, gender, sexuality, age, location and income - deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission. Optum is a drug-free workplace. © 2026 Optum Global Solutions (Philippines) Inc. All rights reserved.
Related Guides
Related Categories
Related Job Pages
More Risk Jobs
Role Description You are a Licensed Practical Nurse (LPN) who thrives on connecting with people through compassionate communication. You easily build meaningful relationships and support positive behavior change through partnership rather than pressure. Leveraging your practical nursing knowledge and structured care protocols, you help patients clearly understand and follow their provider-directed care plans. You bring grace under pressure and feel energized by supporting high-risk patients as they work toward improved health and stability. As a High-Risk Care Coordinator, you build trusted, ongoing relationships with high-risk patients through consistent outreach, active listening, and structured clinical support. You regularly engage patients by phone and text to address complex medical and social needs, including: - Medication management - Chronic condition monitoring - Barriers to care Using patient-centered discussion and established care protocols, you support patients in understanding and adhering to provider-directed care plans while identifying emerging risks that require escalation. This role is part of a new high-risk patient management program being built from the ground up. You will have the opportunity to help shape workflows, outreach strategies, and processes that truly work for patients and care teams. Additional Responsibilities: - Conduct regularly scheduled outbound outreach to high-risk patients to support ongoing care management, reduce avoidable utilization, and address gaps in care. - Contribute to the development of a new high-risk patient management program by helping design, test, and refine outreach workflows, documentation practices, and care coordination processes in a growing, non–enterprise EHR environment. - Perform medication reconciliation and adherence support by reviewing patient-reported medication use, identifying discrepancies, and escalating concerns to the RN or Provider. - Collect, assess, and document patient-reported symptoms, condition trends, risk indicators, and barriers to adherence within LPN scope of practice. - Provide disease-specific education, self-management reinforcement, and motivational coaching using approved materials and care pathways. - Coordinate home health services and durable medical equipment (DME) needs under RN or Provider direction to support patient safety and stability in the home. - Identify and address social determinants of health impacting high-risk patients, including access to medications, transportation, food, housing support, or financial resources. - Support coordination and monitoring for patients with complex chronic conditions, including COPD, CHF, diabetes, and hypertension, using established protocols. - Serve as a consistent point-of-contact for assigned high-risk patient panels, building trusted relationships that promote sustained engagement and accountability. - Recognize changes in patient status, emerging risks, or non-adherence patterns and escalate promptly through defined clinical pathways. - Provide feedback to Clinical Operations and Clinical Leadership to support continuous improvement of high-risk patient management programs. Qualifications - Completed an accredited practical nursing (LPN) program, with at least two years of prior nursing experience in care coordination, population health, or chronic disease support. - Licensed as a Licensed Practical Nurse (LPN) and credentialed in good standing in the applicable state(s) of practice. - Experience making structured, outbound calls, preferably in a call-center environment, and feel confident engaging patients proactively by phone. - Experience supporting high-risk patients with chronic conditions, care management, or utilization reduction preferred. - Comfortable performing medication reconciliation, structured symptom monitoring, and care coordination under RN or provider oversight. - Strong patient communication skills, including the ability to engage, motivate, and support patients using patient-centered techniques. - Compassionate communicator with strong active listening abilities. - Highly organized, dependable, and emotionally intelligent, with the ability to manage ongoing patient panels. - Proficient in EHR documentation and care management or population health tracking tools. - Able to multitask effectively in a fast-paced outreach environment with strong time management and follow-through skills. Benefits - Medical, dental, and vision coverage. - Generous time off plans. - Development program that starts with onboarding and continues throughout your career. Company Description Oasis Health Partners (Oasis) is building healthier communities by advancing primary care. We partner with patients, providers, and plans to provide personalized, local care for seniors in towns across America. We believe that patients’ needs come first, and that primary care is the foundation of patient-centric healthcare. Together, we will boldly advance primary care for those that need it most.
Role Description Apogee is engaging contract Risk Analysts at the journeyman level to expand RRAG's research and production capacity. The Risk Analyst is a proficient practitioner who can scope, research, and deliver written analytical products with limited supervision. The role reports to the Team Leader, RRAG, and collaborates with Apogee's Senior Risk Advisors and the firm's Cyber and Physical Risk practice. This is a contract engagement structured for analysts who want substantive research work tied to a published product line, without the overhead of a full-time billet. Key Responsibilities - Conduct primary and open-source intelligence research across one or more of the 12 Nexus of Risk domains: cyber, physical security, people, operational, financial, technology, safety, strategic, reputation, compliance and regulatory, supply chain, and geopolitical. - Produce written analytical products including flat-rate client advisories, sector briefings, alert notifications, and content for subscription-tier deliverables. - Apply structured analytic techniques to evaluate likelihood, impact, and intersection effects across risk domains, consistent with the Nexus of Risk methodology. - Use the Tacilent platform and adjacent intelligence tooling to support research workflows, evidence tracking, and product publication. - Maintain analytical rigor consistent with the Nexus of Risk taxonomy and Apogee editorial standards, including academic register in framework references and clear separation between framework content and illustrative examples. - Contribute research inputs to RRAG-supported assets, including the Risk Apogee podcast, the RRAG webinar series, and LinkedIn distribution content. - Participate in weekly editorial planning and product review with the RRAG team. Qualifications - Three to seven years of professional experience in risk analysis, intelligence analysis, cybersecurity research, threat intelligence, geopolitical analysis, or a directly related research function. - Bachelor's degree in a relevant field, such as intelligence studies, security studies, international relations, computer science, risk management, criminal justice, public policy, or comparable. - Demonstrated portfolio of written analytical products. Candidates should be prepared to share two to three sanitized writing samples. - Working command of at least one Nexus domain, with analytical literacy across adjacent domains. - Proficiency with OSINT methods, source evaluation, and structured sourcing. - Strong written English. Ability to write to a defined editorial voice and to revise efficiently against feedback. - Capacity to operate independently on contract, manage deliverable timelines, and communicate proactively with the Team Leader, RRAG. Preferred Qualifications - Working knowledge of one or more risk management frameworks, such as NIST Cybersecurity Framework 2.0, NIST AI Risk Management Framework, ISO 31000, ISO 27001, COSO ERM, CMMC 2.0, or FAIR. - Prior experience in government, intelligence community, military, law enforcement, or regulated industry settings. - Relevant certifications, including but not limited to CISSP, CISM, CRISC, CFE, PSP, CPP, Security+, GIAC, or recognized intelligence analyst credentials. - Experience producing subscription-based intelligence or commercial advisory products. - Comfort with platform-based analytical workflows and AI-assisted research tooling. - Experience supporting executive or board-level audiences. Engagement Terms - Contract role, structured as 1099 or W-2 contractor depending on jurisdiction and analyst preference. - Remote within the United States. Occasional travel for client engagements or firm offsites at Apogee expense. - Hourly or project-based compensation, market-competitive and commensurate with experience and domain depth. - Initial engagement scoped at six months, with renewal contingent on deliverable performance and ongoing product demand. - Apogee retains exclusive ownership of work product. Standard contractor confidentiality, non-disclosure, and intellectual property provisions apply. How to Apply Submit a current resume, two to three writing samples (sanitized as needed), and a one-paragraph statement of risk domain emphasis to information@apogeeglobalrms.com with the subject line "RRAG Risk Analyst Contract Application." Applications are reviewed on a rolling basis.
• Conduct primary and open-source intelligence research across one or more of the 12 Nexus of Risk domains: cyber, physical security, people, operational, financial, technology, safety, strategic, reputation, compliance and regulatory, supply chain, and geopolitical. • Produce written analytical products including flat-rate client advisories, sector briefings, alert notifications, and content for subscription-tier deliverables. • Apply structured analytic techniques to evaluate likelihood, impact, and intersection effects across risk domains, consistent with the Nexus of Risk methodology. • Use the Tacilent platform and adjacent intelligence tooling to support research workflows, evidence tracking, and product publication. • Maintain analytical rigor consistent with the Nexus of Risk taxonomy and Apogee editorial standards, including academic register in framework references and clear separation between framework content and illustrative examples. • Contribute research inputs to RRAG-supported assets, including the Risk Apogee podcast, the RRAG webinar series, and LinkedIn distribution content. • Participate in weekly editorial planning and product review with the RRAG team.
• Monitor dashboards daily to identify derivative risk across the retail book — surfacing concentrations, early assignment events, near-expiry ITM positions, and accounts requiring action, and triaging each case on its merits. • Monitor automations during option liquidations and escalate anomalies and failures to Engineering, and ensure changes are implemented to avoid mass failures and stay compliant with policies. • Execute option assignment and exercise workflows, account restrictions, position liquidations, and remediation for early assignment, uncovered positions, corporate actions, and ad hoc trade requests from other teams. • Review derivative scenarios and assess how each affects margin, buying power, and firm exposure — applying working knowledge of dynamic collateral and strategy re-pairing to size and execute remediation actions. • Complete weekly and monthly CIRO audit requirements, documenting findings and controls in JIRA and partnering with the Senior Specialist on any remediation needed. • Build and maintain monitoring tools using SQL, Python, and AI tooling — contributing to dashboards and maintaining automation scripts that surface daily risk views and exposure trackers. • Contribute data, queries, and visualizations that feed team discussions and Risk Committee reporting. • Apply CIRO IDPC margin rules to derivative positions in day-to-day decisions and escalate ambiguous or material cases to the Senior Specialist or Team Lead. • Complete ad hoc trades and tasks as assigned by the Senior Specialist or Team Lead.



