PitchMeAI
UnitedHealth Group

Chief Information Security Officer (CISO) - Digital, Data & Consumer Engineering

UnitedHealth Group · Eden Prairie, MN

This listing has closed — view similar roles below.

  • On site
  • Full-time
  • $271,950 / year
  • Eden Prairie, MN

Job highlights

  • Lead information security for Optum Digital Office.
  • Develop and implement risk management strategy.
  • Interface between CDO and Enterprise Security.
  • Manage security initiatives and compliance.
  • Remote role within the U.S.

About the role

Chief Information Security Officer (CISO) - Digital, Data & Consumer Engineering

UnitedHealth Group is a health care and well-being company dedicated to improving the health outcomes of millions worldwide. We are comprised of two distinct and complementary businesses, UnitedHealthcare and Optum, working to build a better health system for all. Here, your contributions matter as they will help transform health care for years to come. Make an impact with a team that shares your passion for helping others. Join us to start Caring. Connecting. Growing together.

About the Role

The Optum Digital Office (CDO) Chief Information Security Officer (CISO) is the senior information security leader for the CDO, supporting multiple digital and data functions across all UnitedHealth Group lines of business. This role reports directly to the VP of the Enterprise Security Office and is part of the Enterprise Security & Resilience Office (ESRO). The CDO CISO applies deep security expertise and solid business acumen to lead a comprehensive information risk management strategy that anticipates, identifies, and mitigates risk effectively. As the primary interface between the CDO and ESRO, the CISO ensures alignment between enterprise security programs and UnitedHealth Group's unique operating environment, including its regulatory landscape, customer needs, competitive pressures, and value drivers.

You'll enjoy the flexibility to work remotely from anywhere within the U.S. as you take on some tough challenges.

For all hires within 30 minutes of an office in Minnesota or Washington, D.C., you'll be required to work a minimum of four days per week in-office.

Primary Responsibilities

  • Serve as the strategic information security leader, advising on security requirements for business initiatives and programs.
  • Drive implementation of the UHG ESRO strategy within the CDO organization.
  • Prioritize and advocate for security initiatives that align with enterprise strategy and a risk-based approach.
  • Act as the executive point of contact for strategic information security issues within the CDO technology platforms.
  • Represent the CDO's specific security needs to corporate executive leadership, including IT, Legal, Compliance, and Privacy.
  • Maintain active communication with CDO executive leadership to understand business and technology objectives and associated information risks.
  • Ensure technology plans and programs comply with UHG's information risk management policies and frameworks.
  • Stay current on emerging security topics and apply them creatively to the CDO's technology platforms and environments.
  • Lead the CDO Security Office, including oversight of Business Information Security Officers (BISOs) and Segment Information Security Officers (SISOs).
  • Engage proactively with the CDO, impacted technology partners, and affiliates during security incidents or critical vulnerabilities, ensuring timely and comprehensive response in coordination with Cyber Defense - Cyber Incident Response Team (CIRT).
  • Assist other Technology and Business leadership resources in management of Acquisition resources as part of merger activity when applicable to the CDO.

You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role, as well as provide development for other roles you may be interested in.

Required Qualifications

  • 15+ years of information security experience in multiple roles.
  • 5+ years in a leadership role (Director level or above).
  • 5+ years of experience working with external auditors, regulatory bodies, and customers around Information Security specific subject matter.
  • Experience with multiple information security frameworks (ISO, NIST, HITRUST, etc.).
  • Experience with Credential Service Provider technologies, Interoperability frameworks, Identity Access Management, and related concepts.
  • Risk management experience to include identification, prioritization, and mitigation of risk.
  • Demonstrated communication, crisis management, and leadership skills.
  • Proven project management skills, detail orientation, and displays/instills operational excellence.
  • Track record of making data-driven recommendations and decisions following discovery, analysis, verification, etc.
  • Executive presence and excellent client relationship management skills with senior management on issues and key risks to the business (presentations, executive summaries, etc.).
  • History of maintaining effectiveness and composure in difficult or complex situations.
  • Ability to negotiate and influence without authority.
  • Bachelor's degree in computer science, Information Systems, or a related field, or equivalent experiences.

Preferred Qualifications

  • Professional certifications such as CISSP, CISM, CISA, and/or HCISPPM.
  • Master's degree (MBA, MIS, or similar).
  • All employees working remotely will be required to adhere to UnitedHealth Group's Telecommuter Policy.

Compensation and Benefits

Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you'll find a far-reaching choice of benefits and incentives.

The salary for this role will range from $200,400 to $343,500 annually based on full-time employment. We comply with all minimum wage laws as applicable.

About UnitedHealth Group

At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone—of every race, gender, sexuality, age, location, and income—deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups, and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission.

UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations.

UnitedHealth Group is a drug-free workplace. Candidates are required to pass a drug test before beginning employment.

Key skills/competency

  • Information Security Leadership
  • Risk Management
  • Cybersecurity Strategy
  • Regulatory Compliance
  • Identity and Access Management (IAM)
  • Information Security Frameworks (NIST, ISO, HITRUST)
  • Incident Response
  • Executive Communication
  • Project Management
  • Data Security

Skills & topics

  • Chief Information Security Officer
  • CISO
  • Information Security
  • Cybersecurity
  • Risk Management
  • Digital Security
  • Data Security
  • Healthcare IT
  • Security Leadership
  • Compliance
  • NIST
  • ISO
  • HITRUST
  • IAM
  • UHG
  • UnitedHealth Group
  • Optum
  • Remote

How to get hired

  • Tailor your resume: Highlight 15+ years of information security experience and 5+ years in leadership roles. Emphasize experience with security frameworks (NIST, ISO, HITRUST), risk management, and IAM.
  • Showcase leadership skills: Detail your experience in communication, crisis management, and influencing without authority. Provide examples of executive presence and client relationship management.
  • Demonstrate technical expertise: Mention specific security frameworks, Credential Service Provider technologies, and interoperability frameworks you've worked with.
  • Prepare for executive interviews: Be ready to discuss strategic security initiatives, risk mitigation, and how you align security with business objectives.
  • Understand UHG's mission: Articulate how your security leadership contributes to UnitedHealth Group's goal of improving health outcomes.

Technical preparation

Master multiple information security frameworks.,Deep understanding of IAM and related concepts.,Experience with Credential Service Providers.,Proficiency in risk identification and mitigation.

Behavioral questions

Describe a complex security crisis you managed.,How do you influence without direct authority?,Provide an example of a data-driven decision.,How do you balance business needs with security?

Frequently asked questions

What are the key responsibilities for the Chief Information Security Officer (CISO) at UnitedHealth Group?
The CISO for the Optum Digital Office at UnitedHealth Group is responsible for leading the information security strategy, managing information risk, ensuring compliance with security policies and frameworks, and acting as the primary liaison between the CDO and the Enterprise Security Office. This includes overseeing security initiatives, managing incidents, and advising on security requirements for business programs.
What qualifications are required for the CISO role at UnitedHealth Group?
Required qualifications include at least 15 years of information security experience with 5+ years in a leadership role, experience with various information security frameworks (ISO, NIST, HITRUST), risk management, and demonstrated communication and crisis management skills. A Bachelor's degree in a related field or equivalent experience is also necessary.
What is the work arrangement for the CISO position at UnitedHealth Group?
This position offers the flexibility to work remotely from anywhere within the U.S. However, for hires located within 30 minutes of an office in Minnesota or Washington, D.C., a minimum of four days per week in-office work is required.
What are the preferred qualifications for the CISO role?
Preferred qualifications include professional certifications such as CISSP, CISM, CISA, and/or HCISPPM, as well as a Master's degree (MBA, MIS, or similar). Adherence to UnitedHealth Group's Telecommuter Policy is also required for remote employees.
How does UnitedHealth Group approach diversity and inclusion in hiring for the CISO role?
UnitedHealth Group is an Equal Employment Opportunity employer. They consider qualified applicants without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, aiming to provide equitable care and opportunities to all.
What is the salary range for the Chief Information Security Officer (CISO) at UnitedHealth Group?
The annual salary for this full-time role ranges from $200,400 to $343,500, based on factors such as local labor markets, education, work experience, and certifications.
What kind of security frameworks does UnitedHealth Group utilize?
UnitedHealth Group utilizes multiple information security frameworks, including but not limited to ISO, NIST, and HITRUST, as part of their enterprise security strategy and risk management approach.
Does UnitedHealth Group require a drug test for new hires in the CISO position?
Yes, UnitedHealth Group is a drug-free workplace, and candidates are required to pass a drug test before beginning employment for this position.