AI That Elevates the Impact of ALL Responders
IT & Security Engineer
Location
United States
Posted
2 days ago
Salary
$110K - $130K / year
Seniority
Senior
Job Description
IT & Security Engineer
GovWorx
• Own architecture strategy and hands-on delivery for IT & Security engineering initiatives. • Translate security and IT objectives into actionable workflows, automation patterns, and documentation. • Mentor team members on technical troubleshooting, configuration, and best practices; foster a security-first culture. • Evaluate and recommend technologies to improve security posture, service reliability, and operational efficiency. • Own end-to-end identity lifecycle management using Okta as the primary IAM platform. • Maintain and refine RBAC/ABAC models, least-privilege controls, and provisioning workflows. • Implement and support SSO, MFA, SCIM, conditional access, and session security controls. • Conduct periodic access reviews and maintain audit documentation for GovWorx compliance frameworks. • Serve as SME for Jamf (macOS) and Intune (Windows): secure baselines, configuration profiles, provisioning, and compliance enforcement. • Maintain Zero Trust device posture: encryption, patching, MDM enforcement, automated remediation, and application access controls. • Manage and tune the EDR deployment for detection quality and incident readiness. • Deploy self-service endpoint capabilities to minimize employee friction and ensure timely application access. • Maintain centralized logging and monitoring pipelines across identity, endpoint, and SaaS systems. • Create and refine detection alerts for high-signal, low-noise event visibility. • Lead technical investigation during security events: evidence gathering, forensic analysis, containment, and remediation recommendations. • Collaborate with the Head of IT & Security on incident prioritization, communication, and business-impact decisions. • Maintain and optimize core SaaS, collaboration, and IT platforms for reliability and scalability. • Own hardware and software lifecycle management: procurement, deployment, inventory, and secure decommissioning. • Maintain and regularly test backup, continuity, and disaster recovery processes. • Maintain system diagrams, runbooks, SOPs, and internal knowledge articles. • Support GovWorx compliance frameworks through control enforcement, audit evidence collection, and documentation. • Maintain SaaS application and OAuth integration inventory; review and control privileged access and scope boundaries. • Manage lifecycle of service accounts, API keys, certificates, and secrets; enforce secure storage and automated rotation. • Assist in vendor security evaluations, risk assessments, and risk register contributions.
Job Requirements
- 5+ years of experience in IT, security engineering, or a combined technical role.
- Hands-on expertise with Okta (SSO, SCIM, MFA, lifecycle management) and RBAC/ABAC access models.
- Proficiency with Jamf Pro and Microsoft Intune for endpoint management and compliance enforcement.
- Experience with EDR platforms, SIEM tooling, and centralized logging infrastructure.
- Working knowledge of Zero Trust architecture principles and their practical application.
- Experience supporting compliance frameworks (SOC 2, NIST, ISO 27001, or similar).
- Familiarity with incident response practices, forensic analysis, and chain-of-custody procedures.
- Ability to write and maintain scripts or automation (Python, Bash, or equivalent) for operational tasks.
- Strong written and verbal communication; able to translate technical concepts for non-technical stakeholders.
- U.S. citizen or authorized to work in the United States.
Benefits
- Health Benefits
- Flexible Time Off
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Contribute to developing strategic and tactical planning for FSQR activities across the NA region and take responsibility for executing the process for the Canada FSQR team • Lead and develop team talent through succession planning for key roles, performance management, coaching, mentoring, and recruitment processes • Analyze, review, and interpret external regulations as well as customer and supplier standards, then implement necessary policies and procedures to ensure compliance with applicable laws and regulations for the Canada POD • Establish and maintain leadership partnerships and relationships with key stakeholders across cross-functional teams to promote an integrated safety and quality culture and support business strategies • Independently facilitate resolution of highly complex issues and proactively anticipate risks, implementing preventive measures or mitigation plans as appropriate • Support development and escalation of new innovations, continuous improvement initiatives, and process sustainment • Support base and non-base capital investments for Canada and the broader NA regions to maintain and enhance food safety management systems and product safety • Other duties as assigned
Senior Security Engineer
GoFundMe.orgGoFundMe.org is a registered 501(c)(3) nonprofit organization that works closely with GoFundMe.
• Partner with engineering teams to improve security through consultation, education, tooling, and process improvements. • Perform targeted code reviews and security assessments when investigating high-risk designs, vulnerabilities, or security-sensitive features. • Help evaluate emerging AI technologies and development practices. • Notice recurring security challenges and contribute to scalable solutions that reduce risk across the organization. • Help handle application vulnerability reports received through third-party sources. • Command incidents and facilitate post-mortem investigations. • Participate in on-call rotation and take your turn shouldering operational toil for the team.
• Write documentation required for Authority to Operate (ATO) • Support performance scans, analyze logs, monitor and report vulnerabilities • Investigate and analyze issues and incidents • Development of cybersecurity architecture • Provide programming services for specific systems and applications • Participate in systems analysis, design definition, software development, systems test, implementation, and maintenance • Analyze coding problems and develop improvements to procedures • Design, develop, troubleshoot, debug, and implement software code
Information Security Engineer Consultant
OptumOptum, part of the UnitedHealth Group family of businesses, is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together. At Optum, we support your well-being with an understanding team, extensive benefits and rewarding opportunities. By joining us, you’ll have the resources to drive system transformation while we help you take care of your future. We recognize the power of connection to drive change, improve efficiency and make a difference in health care. Join a team where your skills and ideas can make an impact and where collaboration is key to creating technology that produces healthier outcomes.
Requisition Number: 2358822 Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together. Primary Responsibilities: - Lead and conduct highly complex security incident investigations across endpoints (memory and disk), network traffic, and cloud environments, including Azure and Microsoft 365 - Perform advanced incident investigation and in-depth log analysis by correlating data from multiple sources such as SIEM, EDR, network security devices, and cloud platforms to accurately identify scope and impact - Act as the final escalation point for critical and high-severity security incidents, providing expert guidance and decisive incident handling - Conduct static and dynamic malware analysis, including reverse engineering of exploits, and analyze adversary tactics, techniques, and procedures (TTPs) to understand attacker behavior - Map attacker activities and observed behaviors to industry-recognized frameworks such as MITRE ATT&CK, NIST to ensure structured analysis and reporting - Execute effective containment actions during incidents, including isolating compromised systems, blocking malicious traffic, disabling accounts, and applying emergency controls to limit spread and impact - Acquire digital evidence from compromised environments, including disk images, memory dumps, system logs, and network traffic, using forensically sound methodologies - Maintain a strict chain of custody by ensuring all evidence is properly documented, securely stored, and protected from tampering throughout the investigation lifecycle - Analyze forensic artifacts such as file systems, registry entries, event logs, and memory structures to identify indicators of compromise and malicious activity - Perform memory forensics to detect running processes, injected or malicious code, credential theft mechanisms, and other in-memory threats that may not be present on disk - Validate that eradication activities are fully completed and ensure affected systems are securely restored to normal operations without residual risk - Prepare comprehensive incident reports detailing timelines, root cause analysis, impact assessment, indicators of compromise (IOCs), and remediation actions taken - Collaborate with Security and Engineering teams to automate repetitive tasks such as alert enrichment, containment workflows, response actions, and ticket creation to improve efficiency and consistency - Leverage internal and external threat intelligence feeds to enrich investigations with contextual insights, including known malicious IPs, domains, threat actor profiles, and attacker methodologies - Work closely with cross-functional teams to ensure coordinated and timely execution of incident response activities - Continuously enhance detection and response capabilities by recommending improvements to SIEM and EDR platforms, tuning detection rules, developing better queries, and identifying logging gaps - Handle Priority 1 (P1), Priority 2 (P2) and other critical incidents with urgency, ensuring rapid response, clear stakeholder communication, and minimal business disruption - Monitor and report on key performance indicators (KPIs) such as Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) to measure and improve incident response effectiveness - Comply with the terms and conditions of the employment contract, company policies and procedures, and any and all directives (such as, but not limited to, transfer and/or re-assignment to different work locations, change in teams and/or work shifts, policies in regard to flexibility of work benefits and/or work environment, alternative work arrangements, and other decisions that may arise due to the changing business environment). The Company may adopt, vary or rescind these policies and directives in its absolute discretion and without any limitation (implied or otherwise) on its ability to do so a { text-decoration: none; color: #464feb; } tr th, tr td { border: 1px solid #e6e6e6; } tr th { background-color: #f5f5f5; } Required Qualifications: - 5+ years of hands-on experience in Major Security Incident Management, including: - Case management - War room facilitation - Paging / on-call coordination - Security bridge management - Solid log analysis experience across multiple security domains, including: - SIEM platforms - Endpoint security - Perimeter/network security - Threat intelligence feeds - Email security solutions - Proven experience in Sandbox Analysis for malware and suspicious file investigation - Hands-on Digital Forensics experience, including evidence collection, analysis, and reporting - Solid understanding and application of security frameworks, including: - MITRE ATT&CK - MITRE D3FEND - NIST (incident response, security controls, or related standards) - Practical experience with forensic tools, such as: - Magnet AXIOM Forensics - REMnux - X-Ways Forensics - EnCase - Forensic Toolkit (FTK) - Or equivalent forensic tools Preferred Qualifications: - Relevant security certifications, such as: - CHFI (Computer Hacking Forensic Investigator) - EnCE (EnCase Certified Examiner) - ACE (AccessData Certified Examiner) - GCFA / GCFE - GIAC Certified Incident Handler (GCIH) - Microsoft Security Operations Analyst Associate (SC-200) - Advanced understanding of adversary behavior, including: - Adversary Tactics, Techniques, and Procedures (TTPs) - Cyber Kill Chain methodologies - Expert-level application of MITRE ATT&CK and MITRE D3FEND - Solid working knowledge of NIST frameworks, particularly: - NIST 800-61 (Computer Security Incident Handling Guide) - Experience handling major security incident scenarios, such as: - Ransomware attacks - Distributed Denial of Service (DDoS) - Advanced Persistent Threats (APT) - Business Email Compromise (BEC) - Fundamental understanding of application and networking protocols, including: - Application protocols: HTTP, DNS, FTP, etc. - Networking protocols: TCP, UDP, ARP, ICMP, etc. - Ability to analyze packet capture (PCAP) files using tools such as Wireshark - Knowledge of operating system internals, including: - Virtual memory and paging mechanisms - Malware techniques used to evade detection At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone - of every race, gender, sexuality, age, location and income - deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission. Optum is a drug-free workplace. © 2026 Optum Global Solutions (Philippines) Inc. All rights reserved.




