Principal Cybersecurity Analyst
Job Description
In Raleigh, NC with a hybrid work arrangement, enjoy a competitive salary range of USD 112,700 to 193,200 per year, plus a robust benefits package that includes incentive and recognition programs, equity stock purchase opportunities, and 401k contributions. UnitedHealth Group’s Optum Technology Cyber Defense team invites you to lead the design and implementation of Splunk SOAR playbooks and AI powered automation to elevate cybersecurity operations, collaborating closely with Cyber Defense, SOC, and incident response teams.
Responsibilities
- Architect, build, and sustain Splunk SOAR playbooks, automations, and custom actions to streamline security operations
- Convert complex security operations and incident response needs into scalable, resilient automation solutions
- Seamlessly integrate SOAR workflows with security tools, APIs, and enterprise platforms
- Design and deploy AI-powered defenses addressing complex cyber challenges while emphasizing responsible AI use
- Collaborate with Cyber Defense, SOC, and incident response teams to proactively identify automation opportunities and optimize workflows
- Leverage enterprise-approved AI tools to automate repetitive tasks and drive ongoing process improvements
- Provide senior technical leadership, mentor analysts, and contribute to automation standards, reusable frameworks, and industry best practices
- Evaluate emerging technology trends, including AI advancements, to inform solution design and strategic innovation
Requirements
- 6+ years of Python development experience
- 6+ years of cybersecurity experience
- Hands-on Splunk SOAR experience, including development of custom applications and actions
- Proficiency in Python, API integrations, and automation design
- Experience with GitHub and project/work tracking tools such as GitHub Projects
- Working knowledge of cloud platforms (AWS, Azure, and GCP)
- Proven ability to translate ambiguous or complex requirements into scalable technical solutions
Technologies
- Splunk SOAR, Splunk Enterprise Security (ES)
- Splunk SPL, Python
- GitHub, AWS, Azure, GCP
- APIs
Benefits
- Comprehensive benefits package
- Incentive and recognition programs
- Equity stock purchase
- 401k contribution
Preferred Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, or a related technology field (or equivalent professional experience)
- Experience with Splunk Enterprise Security (ES) and Splunk SPL
- Experience with CI/CD and source control practices for security automation content
- Experience creating reusable automation frameworks
- Experience with AI agents, LLM-integrated workflows, or AI-assisted analyst workflows
- Familiarity with AI governance concepts, including approval workflows, guardrails, and human-in-the-loop design
Application Deadline
This posting will remain active for a minimum of 2 business days or until a sufficient candidate pool is gathered. The posting may close early due to volume of applicants.