Principal Network Detection & Response Engineer

UnitedHealth-Grou

Eden Prairie (MN)

Hybrid

USD 113,000 - 193,000

Full time

36 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Comprehensive benefits package
Incentive and recognition programs
Equity stock purchase plan
401k contribution

Job summary

UnitedHealth Group is seeking a Principal Network Detection & Response Engineer to lead architecture, deployment, and optimization of enterprise-wide NDR capabilities across hybrid environments.

You will develop high-fidelity detections, analyze network telemetry, and drive automated response with SIEM/SOAR/EDR integrations while collaborating with Threat Hunting and Incident Response teams.

Qualifications

  • 5+ years of professional experience in cybersecurity engineering, network security, or intrusion detection/prevention.
  • 3+ years deploying and tuning NDR or Network Traffic Analysis platforms (e.g., Corelight, Darktrace, ExtraHop, Zeek/Bro, Suricata).
  • 3+ years analyzing network protocols and performing deep packet inspection with Wireshark, Zeek, or Suricata.
  • 3+ years integrating network telemetry into enterprise SIEM (e.g., Splunk, Sentinel) and SOAR.
  • Industry certifications in information security or network security (e.g., CISSP, GCIA, GCIH, GNFA, CCNP Security).
  • Cloud network detections experience (AWS/Azure/GCP) and MITRE ATT&CK mapping knowledge.
  • SSL/TLS traffic inspection capabilities and encrypted session analysis.

Responsibilities

  • Lead the strategy, design, and optimization of NDR and network security monitoring across hybrid environments.
  • Develop, test, and tune high-fidelity detection signatures and anomaly detection models.
  • Analyze complex network traffic and PCAP data to uncover malicious activity and lateral movement.
  • Drive automated response workflows and integration between NDR, SIEM, SOAR, and EDR.
  • Collaborate with Threat Hunting, Threat Intelligence, and Incident Response teams for detections.
  • Perform risk assessments and architecture reviews to align with detection objectives.
  • Mentor security engineers with technical guidance and rule reviews.

Skills

Cybersecurity engineering
Network security
NDR platforms
Packet analysis
SIEM/SOAR integration
Threat hunting
Mentoring

Education

Information security certifications

Tools

Corelight
Darktrace
ExtraHop
Zeek/Bro
Suricata
Wireshark
Splunk
SOAR
EDR

Job description

Improve the lives of others while Caring. Connecting. Growing together.

Job Description - Principal Network Detection & Response Engineer (2362093)

Principal Network Detection & Response Engineer - 2362093

Optum Tech is a global leader in health care innovation. Our teams develop cutting-edge solutions that help people live healthier lives and help make the health system work better for everyone. From advanced data analytics and AI to cybersecurity, we use innovative approaches to solve some of health care’s most complex challenges. Your contributions here have the potential to change lives. Ready to build the next breakthrough? Join us to start Caring. Connecting. Growing together.

As a Principal Network Detection & Response Engineer within our Cyber Operations Group team, you will lead the architecture, deployment, and continuous optimization of enterprise-wide Network Detection and Response (NDR) capabilities. In this role, you will be instrumental in protecting critical enterprise assets by analyzing network telemetry, developing advanced threat detection logic, and orchestrating rapid response strategies against sophisticated cyber threats. You will collaborate closely with threat intelligence, incident response, and infrastructure teams to design resilient, cutting-edge security monitoring solutions across hybrid-cloud and on-premises environments.

You’ll enjoy the flexibility to work remotely * from anywhere within the U.S. as you take on some tough challenges. For all hires in the Minneapolis or Washington, D.C. area, you will be required to work in the office a minimum of four days per week.

Primary Responsibilities
  • Lead the strategy, architectural design, and optimization of Network Detection & Response (NDR) and network security monitoring platforms across hybrid enterprise environments
  • Develop, test, and tune high-fidelity detection signatures, behavioral rules, and anomaly detection models to identify advanced persistent threats (APTs) and zero-day vulnerabilities
  • Analyze complex network traffic, packet captures (PCAP), flow data, and encrypted telemetry to uncover evasive malicious activity and lateral movement
  • Drive automated response workflows and integration between NDR tools, SIEM, SOAR, and Endpoint Detection & Response (EDR) platforms to minimize Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR)
  • Partner with Threat Hunting, Threat Intelligence, and Incident Response teams to translate emerging cyber threat tactics, techniques, and procedures (TTPs) into actionable detections
  • Conduct technical reviews, risk assessments, and architectural evaluations of proposed network infrastructure changes to ensure alignment with security detection objectives
  • Mentor senior and junior security engineers, providing technical guidance, rule reviews, and subject matter expertise in network defense and threat hunting

You’ll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in.

Required Qualifications
  • 5+ years of professional experience in cybersecurity engineering, network security, or intrusion detection/prevention
  • 3+ years of hands-on experience deploying, configuring, and tuning Network Detection & Response (NDR) or Network Traffic Analysis (NTA) platforms (e.g., Corelight, Darktrace, ExtraHop, Zeek/Bro, Suricata)
  • 3+ years of experience analyzing network protocols (e.g., TCP/IP, DNS, TLS, BGP) and conducting deep packet inspection using tools such as Wireshark, Zeek, or Suricata
  • 3+ years of experience integrating network telemetry and security alerts into enterprise SIEM (e.g., Splunk, Sentinel) and SOAR tools
Preferred Qualifications
  • Industry certifications in information security or network security (e.g., CISSP, GCIA, GCIH, GNFA, CCNP Security)
  • Experience engineering security detections for cloud networks and cloud-native services (e.g., AWS VPC Traffic Mirroring, Azure Network Watcher, GCP Packet Mirroring)
  • Knowledge of the MITRE ATT&CK framework with demonstrated success mapping network detections to adversary techniques
  • Solid background in decrypting or inspecting SSL/TLS traffic and analyzing encrypted network sessions
  • Proven ability to communicate complex technical security risks and detection strategies to senior engineering and leadership stakeholders

*All employees working remotely will be required to adhere to UnitedHealth Group’s Telecommuter Policy

Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you’ll find a far-reaching choice of benefits and incentives. The salary for this role will range from $112,700 - $193,200 annually based on full-time employment. We comply with all minimum wage laws as applicable.

Application Deadline

This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants.

At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone–of every race, gender, sexuality, age, location and income–deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes — an enterprise priority reflected in our mission.

UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations.

UnitedHealth Group is a drug - free workplace. Candidates are required to pass a drug test before beginning employment.

UnitedHealth Group is committed to working with and providing reasonable accommodations to individuals with physical and mental disabilities. If you need special assistance or accommodation for any part of the application process, please call 1-866-566-8715 to be connected to Recruitment Services. Recruitment Services hours of operation are 7 a.m. to 7 p.m. CT, Monday through Friday.

UnitedHealth Group is a registered service mark of UnitedHealth Group, Inc. The UnitedHealth Group name with the dimensional logo, as well as the dimensional logo alone, are both service marks for the UnitedHealth Group, Inc.

Diversity creates a healthier atmosphere: UnitedHealth Group is an Equal Employment Opportunity/Affirmative Action employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, disability status, sexual orientation, gender identity or expression, marital status, genetic information, or any other characteristic protected by law.

UnitedHealth Group is a drug-free workplace. Candidates are required to pass a drug test before beginning employment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Network Detection & Response Engineer
Principal Network Detection & Response Engineer

UnitedHealth Group • Eden Prairie (MN)

On-site
Confidential
Cyber Defense Solution Architect-Remote or Hybrid in MN or DC
Cyber Defense Solution Architect-Remote or Hybrid in MN or DC

UnitedHealth-Grou • Eden Prairie (MN)

Hybrid
USD 135,000 - 231,000
Remote work
Comprehensive benefits
Equity stock purchase plan
+1
Principal Cybersecurity Analyst, Global Security Investigations - Remote or Hybrid in MN or DC
Principal Cybersecurity Analyst, Global Security Investigations - Remote or Hybrid in MN or DC

UnitedHealth-Grou • Eden Prairie (MN)

Hybrid
USD 113,000 - 193,000
Cyber Defense Solution Architect-Remote or Hybrid in MN or DC
Cyber Defense Solution Architect-Remote or Hybrid in MN or DC

UnitedHealth Group • Eden Prairie (MN)

Hybrid
Confidential
Benefits package
Equity stock purchase
401(k) contribution
Senior Director, Data Security - Remote or Hybrid in MN and DC
Senior Director, Data Security - Remote or Hybrid in MN and DC

UnitedHealth-Grou • Eden Prairie (MN)

Hybrid
USD 159,000 - 273,000
Principal Cybersecurity Analyst, Global Security Investigations - Remote or Hybrid in MN or DC
Principal Cybersecurity Analyst, Global Security Investigations - Remote or Hybrid in MN or DC

UnitedHealth Group • Eden Prairie (MN)

Hybrid
Confidential
Remote-friendly work policy
Comprehensive benefits
Equity stock purchase
+1
Sr Director, Security Engineering (PSIRT) - Remote or Hybrid in MN or DC
Sr Director, Security Engineering (PSIRT) - Remote or Hybrid in MN or DC

UnitedHealth Group • Plymouth (MN)

Hybrid
USD 159,000 - 273,000
Director, Network Asset Intelligence & Visibility - ARMIS Platform
Director, Network Asset Intelligence & Visibility - ARMIS Platform

UnitedHealth-Grou • Basking Ridge (NJ)

Hybrid
USD 135,000 - 231,000
Senior Software Engineer
Senior Software Engineer

Optum • Washington

Hybrid
USD 92,000 - 164,000
Information Security Engineer
Information Security Engineer

UnitedHealth Group • Eden Prairie (MN)

Hybrid
Confidential