Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
UnitedHealth Group's Optum division in the Philippines seeks a Public Cloud Compliance Lead to join our security and compliance program. You will collaborate with engineering, product and business teams to align cloud environments with SOC 2, HIPAA, NIST 800-53 and other standards, and provide SME guidance on controls and policies.
You will design, implement and validate security controls across Azure, AWS and GCP, perform audits, and drive automation for ongoing compliance and reporting.
Requisition number: 2384481
Job category: Technology
Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together.
This role is to collaborate across Optum engineering, products and business teams in UHG to enhance and modernize the identified scope of work, own and maintain Optum Public Cloud Security, Audit and Compliance responsibilities.
Public Cloud - Cloud Compliance Lead
Compliance Framework: Ensure Optum cloud environments are aligned with regulatory and industry standards such as but not limited to SOC 2, HIPAA, HiTRUST, NIST 800-53, and/or other standards required and approved by Optum.
Design Consultation : Provide support and consolation as a SME to ensure security and compliance boundary is defined, and control consideration are aligned with applicable compliance standards, Optum policies, security and infrastructure principles.
Control interpretation: interpret the most current version of the compliance standard consistently and in alignment with industry best practice and Optum practice to establish technical and operational requirements and services.
Assessment and Validation: Participate and/or perform audit/compliance/security assessment of controls and compliance; including but not limited to perform continues compliance assessments and audit as required; and execute quarterly validation, attestation and reporting as required
Policy and Procedure: Build and maintain enterprise cloud policies as appropriate for Optum's cloud environment and aligned to applicable standards / best practices.
Operational and Technical Support : Provide SME support to Public Cloud Operational, Engineering and Product teams to ensure Optum Public Cloud environment meets all policy, statements, control requirements. Overall management of Optum Public Cloud security, audit and compliance posture. Customer consulting / office hours. Monitor and support automation
Develop and maintain automated / AI driven compliance process and procedures documents that support Optum's compliance certifications and audit.
Comply with the terms and conditions of the employment contract, company policies and procedures, and any and all directives (such as, but not limited to, transfer and/or re-assignment to different work locations, change in teams and/or work shifts, policies in regards to flexibility of work benefits and/or work environment, alternative work arrangements, and other decisions that may arise due to the changing business environment). The Company may adopt, vary or rescind these policies and directives in its absolute discretion and without any limitation (implied or otherwise) on its ability to do so
5 to 7 years of cloud Security and compliance experience (PCI DSS SOC 2, HIPAA, HiTRUST, NIST 800-53 etc.)
5 to 7 years of healthcare technical operations (support to engineering teams, support tickets / request from customers, automation etc.)
Strong understanding of cloud architecture and the ability to interpret technical evidence (system logs, configurations).
Functional experience in Azure, AWS and GCP security and security tools (Defender for Cloud, AWS GuardDuty, GCP Command Center, KMS, etc.)
Functional experience with SaaS security tools (Palo Alto, Aviatrix, Tenable, Splunk, Github etc.)
Preferred: Relevant industry certifications like Certified Cloud Security Professional (CCSP), PCI DSS Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), or CSP Security Professional certification.
Proficiency in scripting languages (e.g., Python, SQL) for automation is highly desired.
Reduce duplication and normalized multiple security and compliance standards Timely and accurate responses to audit and compliance requests Build security and compliance pattern across all 3 CSPs for reuse and automation Automate overly burdensome compliance