Cloud Security Compliance Engineer
UnitedHealth Group · Muntinlupa City, National Capital Region, Philippines ·
- Employment
- Contract
- Category
- Security
- Experience
- 5+ years
UnitedHealth Group · Muntinlupa City, National Capital Region, Philippines ·
xai · Palo Alto, CA; New York, NY; Washington, DC
medable · USA - Alaska
DTCC · Tampa, FL, United States
Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together.
Primary Responsibilities:
Public Cloud - Cloud Compliance Lead
Compliance Framework: Ensure Optum cloud environments are aligned with regulatory and industry standards such as but not limited to SOC 2, HIPAA, HiTRUST, NIST 800-53, and/or other standards required and approved by Optum.
Design Consultation: Provide support and consolation as a SME to ensure security and compliance boundary is defined, and control consideration are aligned with applicable compliance standards, Optum policies, security and infrastructure principles.
Control interpretation: interpret the most current version of the compliance standard consistently and in alignment with industry best practice and Optum practice to establish technical and operational requirements and services.
Assessment and Validation: Participate and/or perform audit/compliance/security assessment of controls and compliance; including but not limited to perform continues compliance assessments and audit as required; and execute quarterly validation, attestation and reporting as required
Policy and Procedure: Build and maintain enterprise cloud policies as appropriate for Optum's cloud environment and aligned to applicable standards / best practices.
Operational and Technical Support: Provide SME support to Public Cloud Operational, Engineering and Product teams to ensure Optum Public Cloud environment meets all policy, statements, control requirements. Overall management of Optum Public Cloud security, audit and compliance posture. Customer consulting / office hours. Monitor and support automation
Develop and maintain automated / AI driven compliance process and procedures documents that support Optum's compliance certifications and audit.
Qualifications:
· 5 to 7 years of cloud Security and compliance experience (PCI DSS SOC 2, HIPAA, HiTRUST, NIST 800-53 etc.)
· 5 to 7 years of healthcare technical operations (support to engineering teams, support tickets / request from customers, automation etc.)
· Strong understanding of cloud architecture and the ability to interpret technical evidence (system logs, configurations).
· Functional experience in Azure, AWS and GCP security and security tools (Defender for Cloud, AWS GuardDuty, GCP Command Center, KMS, etc.)
· Functional experience with SaaS security tools (Palo Alto, Aviatrix, Tenable, Splunk, Github etc.)
Preferred: Relevant industry certifications like Certified Cloud Security Professional (CCSP), PCI DSS Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), or CSP Security Professional certification.
Proficiency in scripting languages (e.g., Python, SQL) for automation is highly desired.
Metrics:
Reduce duplication and normalized multiple security and compliance standards Timely and accurate responses to audit and compliance requests Build security and compliance pattern across all 3 CSPs for reuse and automation Automate overly burdensome compliance
Oscar Health · New York, New York, United States