Senior Information Security Engineering Consultant

Optum, a UnitedHealth Group Company

Calabarzon

On-site

PHP 1,200,000 - 1,800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Optum is seeking a Security Risk Analyst to perform governance, risk, and third-party risk management for healthcare vendor solutions in a global environment. You will develop GRC programs, assess controls against HIPAA and NIST, and support risk-based decision making.

You will engage with stakeholders, communicate risk, and help define remediation plans while staying current with regulatory changes and industry trends.

Qualifications

  • Bachelor's degree in information security, Risk Management, or related field (or equivalent experience).
  • 5+ years of experience in Governance, Risk & Compliance and/or Third-Party Risk Management.
  • Strong understanding of HIPAA, HITRUST, NIST 800-53 and regulatory requirements.
  • Proficiency with GRC platforms and vendor risk tools.
  • Excellent analytical, and written/spoken communication skills.

Responsibilities

  • Develop and maintain GRC frameworks aligned with goals and regulatory requirements.
  • Perform third party risk assessments focused on vendor solutions and US-based healthcare IT.
  • Ensure regulatory compliance for clients and monitor security risks.

Skills

Analytical skills
Verbal communication
Written communication
Independent work

Education

Bachelor's degree in information security

Tools

GRC platforms

Job description

Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together.

This role is responsible for conducting security risk assessments of vendor-provided solutions within a healthcare environment, focusing on the protection of sensitive health information and organizational systems. This role evaluates vendor controls against frameworks such as NIST SP 800-53 and ensures alignment with HIPAA security requirements, identifying gaps and recommending mitigation strategies. The analyst leverages knowledge of U.S. healthcare technologies (e.g., EHR systems, medical devices) and associated cybersecurity risks to support informed, risk-based decision making.

Primary Responsibilities:
  • Governance, Risk & Compliance (GRC):
    • Develop and maintain GRC frameworks aligned with organizational goals and regulatory requirements
    • Perform third party risk assessments with an emphasis on solution-specific assessments, requiring a knowledge of US-based healthcare information technology
    • Ensure compliance with regulatory requirements for our clients
    • Monitor information security risks and drive remediation of policy exceptions
    • Conduct control testing to evaluate maturity and eAectiveness of security controls (HIPAA/HITRUST/NIST 800-53)
    • Work with business stakeholders on defining risk thresholds, implementing risk frameworks, and remediate identified gaps
    • Stay current on regulatory changes, security trends, and compliance requirements
    • Create executive summary /reporting for executives
    • Serves as POC (Point of Contact) in lead's absence
  • Third-Party Risk Management (TPRM):
    • Establish a baseline of vendor risk and identify areas of potential exposure
    • Design and implement a consistent Vendor Risk Management (VRM) program with an emphasis on vendor solutions, aligned with internal policy and regulatory requirements
    • Conduct pre-contract due diligence and ongoing vendor solution risk assessments
    • Develop mitigation plans and partner with internal stakeholders to monitor vendors post-contract
    • Provide guidance to business units and sourcing teams on VRM requirements
    • Maintain structured governance for vendor risk and procurement compliance
    • Continually reassess operational risks and emerging threats related to vendors and vendor supplied solutions
    • Create executive summaries with recommendations for remediation and risk disposition
    • Track key vendor related metrics
  • Comply with the terms and conditions of the employment contract, company policies and procedures, and any and all directives (such as, but not limited to, transfer and/or re-assignment to different work locations, change in teams and/or work shifts, policies in regards to flexibility of work benefits and/or work environment, alternative work arrangements, and other decisions that may arise due to the changing business environment). The Company may adopt, vary or rescind these policies and directives in its absolute discretion and without any limitation (implied or otherwise) on its ability to do so
Required Qualifications:
  • Bachelor's degree in information security, Risk Management, or related field (or equivalent experience)
  • 5+ years of experience in Governance, Risk & Compliance and/or Third-Party Risk Management
  • Solid understanding of risk management frameworks (HIPAA, HITRUST, NIST 800 53) and regulatory requirements
  • Proficiency in GRC platforms and vendor risk management tools
  • Proven excellent analytical skills with ability to interpret large datasets and create actionable reports
  • Demonstrated solid verbal and written communication skills; ability to present recommendations to senior leadership
  • Demonstrated ability to work independently and manage complex, less-structured issues
Preferred Qualifications:
  • Experience in developing risk frameworks and dashboards
  • Familiarity with healthcare technologies such HER systems, biomedical devices, SaaS, etc.
  • Familiarity with procurement processes and vendor governance
  • Exposure to federal/state regulatory compliance requirements
  • Demonstrated ability to act as a point of contact and lead in absence of senior leadership
Key Competencies:
  • Risk Analysis & Assessment
  • Vendor Risk Management
  • Regulatory Compliance
  • Process Improvement
  • Stakeholder Communication
  • Problem Solving & Decision Making

At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission.

Optum is a drug-free workplace. © 2026 Optum Global Solutions (Philippines) Inc. All rights reserved.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Info Security Engineer - GRC and TPRM
Info Security Engineer - GRC and TPRM

Optum, a UnitedHealth Group Company • Calabarzon

On-site
PHP 600,000 - 1,200,000
Info Security Engineer - GRC and TPRM
Info Security Engineer - GRC and TPRM

Optum Philippines • Muntinlupa

On-site
PHP 900,000 - 1,400,000
Senior Information Security Risk Analyst
Senior Information Security Risk Analyst

Optum, a UnitedHealth Group Company • Manila

On-site
PHP 480,000 - 720,000
Senior Information Security Risk Analyst
Senior Information Security Risk Analyst

Optum Philippines • Manila

On-site
PHP 600,000 - 1,000,000
Sr Info Sec Engineer - Risk GRC, Vendor, Education Training & Awareness
Sr Info Sec Engineer - Risk GRC, Vendor, Education Training & Awareness

Optum • Metro Manila

Hybrid
PHP 900,000 - 1,300,000
Hybrid
Laptop Provided
Medical Plan
+11
InfoSec Engineer (GRC & Vendor Risk Management)
InfoSec Engineer (GRC & Vendor Risk Management)

Optum, a UnitedHealth Group Company • Metro Manila

Hybrid
PHP 1,000,000 - 1,400,000
Hybrid
Laptop provided by the company
Total rewards package
+13
Information Security Engineer Analyst
Information Security Engineer Analyst

Optum Philippines • Muntinlupa

On-site
PHP 480,000 - 720,000
Senior Business Systems Analyst
Senior Business Systems Analyst

Optum, a UnitedHealth Group Company • Cebu City

On-site
PHP 260,000 - 370,000
Senior IT Project Manager - Healthcare
Senior IT Project Manager - Healthcare

UnitedHealth Group • Cebu City

On-site
PHP 900,000 - 1,150,000
Senior Software Engineer I
Senior Software Engineer I

Optum, a UnitedHealth Group Company • Manila

On-site
PHP 1,200,000 - 2,000,000