Principal Threat Intelligence Engineer
Agentic Ai
Artificial Intelligence
Cybersecurity Tools
Data Security
Engineer
Incident Response
Information Security
InfoSec
Investigative Skills
Llm Rag
Project Management
Risk Management
Security
Security Automation
Security Information And Event Management
Security Operations
Security Testing
SOAR
Solution Architecture
Threat Hunting
Threat Intel Platforms
Threat Intelligence
Threat Intelligence Platform
Tip Integration
Job Description
UnitedHealth Group is looking for a Principal Threat Intelligence Engineer (remote in Washington, DC) to deploy and integrate threat intelligence capabilities across its security ecosystem. In this role, you will help turn threat data into actionable intelligence by building the pipelines, workflows, and integrations that support CTI, SOC, IR, and other SecOps teams.
This position supports a modern approach to intelligence operations, combining threat intelligence platforms, SIEM enrichment, and automation (including agentic AI and LLM-enabled capabilities) to increase the speed and availability of contextualized intelligence. The goal is to reduce manual effort while improving detection fidelity across security tooling.
Responsibilities
- Deploy, integrate, and maintain a threat intelligence platform integrated into United Health’s security tooling ecosystem
- Integrate threat intelligence into SIEM platforms (for example, Splunk) to support detection use cases and alert enrichment
- Use agentic AI, LLMs, and related capabilities to improve availability and speed of delivery of contextualized threat intelligence for CTI, SOC, IR, and other SecOps members
- Build and deploy technology-supported workflows for intelligence use cases across SOC, IR, Insider Risk, Fraud, Red Team, and Threat Hunt environments
- Develop and maintain SOAR playbooks for automated threat response and enrichment, using SOAR to optimize intelligence workflows
- Orchestrate workflows across security tools to reduce manual analysis and response time
- Build and maintain integrations between threat intelligence feeds (commercial, open-source, ISACs) and internal security platforms
- Integrate and operationalize TIPs such as MISP, OpenCTI ThreatConnect, Anomali, and ThreatQuotient with enterprise security tools
- Develop pipelines to ingest, normalize, deduplicate, and enrich Indicators of Compromise (IOCs) and threat data
- Correlate intelligence with telemetry from SIEM, EDR, NDR, and cloud security tools to improve detection fidelity
- Enable automated enrichment of alerts using threat intelligence data within SIEM workflows
Requirements
- 3+ years of experience in a cyber threat intelligence, cyber security engineering, incident response, or malware analysis role, with heavy emphasis on tool and technology integration
- Proficiency in one or more of: Python (primary) for automation, API integrations, and data processing
- Proficiency in one or more of: Java, JavaScript/Node.js, or Go for service development
- Experience with REST APIs, JSON, and STIX/TAXII protocols
- Experience with data parsing, transformation, and pipeline development
- Experience with scripting (Bash, PowerShell)
- Demonstrated familiarity with Git and CI/CD pipelines
- Demonstrated familiarity with operating systems and platforms including Linux (Ubuntu, CentOS, RHEL, Kali), AWS, Docker, Windows Server (NT through 2012), Active Directory, and Mac OS X
- Experience applying AI in a threat intelligence framework, including LLM, MCP server configuration, RAG, and associated processes
- Hands-on experience with TIPs such as MISP, OpenCTI, ThreatConnect, and Anomali
- Experience integrating multiple intelligence feeds and formats
- Solid experience with SIEM platforms: Splunk, Microsoft Sentinel, IBM QRadar, Elastic
- Experience building detection rules, correlation searches, and dashboards
- Proven understanding of log ingestion, normalization, and enrichment pipelines
- Experience with SOAR platforms such as Cortex XSOAR, Splunk SOAR, Swimlane, and Tines
- Development experience with playbooks/runbooks for automated response
- Proven knowledge of structured threat data formats (STIX, TAXII)
Benefits
- Comprehensive benefits package
- Incentive and recognition programs
- Equity stock purchase
- 401k contribution (all benefits subject to eligibility requirements)
Preferred Qualifications
- Relevant certifications (for example, GCTI, GCIA, CISSP, Splunk certifications)
- Experience in large-scale security operations or SOC environments
- Familiarity with MITRE ATT&CK and other intelligence frameworks
- Familiarity with data engineering technologies such as Kafka, Spark, Elasticsearch
- Experience with cloud platforms (AWS, Azure, GCP) and security integrations
- Experience in threat hunting and detection engineering