Senior Information Security Risk Analyst - Multiple Locations

Careers at UnitedHealth Group

We're creating opportunities in every corner of the health care marketplace to improve lives while we're building careers. At UnitedHealth Group, we support you with the latest tools, advanced training and the combined strength of high caliber co-workers who share your passion, your energy and your commitment to quality. Join us and start doing your life's best work. SM


Compassion. It's the starting point for health care providers like you and it's what drives us every day as we put our exceptional skills together with a real feeling of caring for others. This is a place where your impact goes beyond providing care one patient at a time. Because here, every day, you're also providing leadership and contributing in ways that can affect millions for years to come. Ready for a new path? Learn more, and start doing your life's best work. SM

Our teams are helping people from around the world. We can bring out your best as you put your listening, analytical and problem solving skills to work in a setting that is geared to helping improve lives and enhance health care for millions. Here, you'll discover a wealth of pathways for professional growth within Customer Service, Billing, Claims, Enrollment & Eligibility and across our global economy. Join us and find out why this is the place to do your life's best work. SM

Combine two of the fastest-growing fields on the planet with a culture of performance, collaboration and opportunity and this is what you get. Leading edge technology in an industry that's improving the lives of millions. Here, innovation isn't about another gadget, it's about making health care data available wherever and whenever people need it, safely and reliably. There's no room for error. Join us and start doing your life's best work.(sm)

As a Senior Information Security Risk Analyst, you would support information security policies, standards and procedures to secure and protect data residing on systems. Work directly with Third Party user departments to implement procedures and systems for the protection, conservation and accountability of proprietary, personal or privileged electronic data. Generally work is self-directed and not prescribed. Works with less structured, more complex issues. Serves as a resource to others.

Primary Responsibilities:
  • Participation in Third Party assessment and review
  • Understand and enforce General Computing Controls of Third Party organization structure
  • Communicate with Third Party stakeholders/end users through multiple communication methods
  • Develop and maintain procedure documentation.
  • Identify security administration deficiencies, recommend improvements, and assist to implement corrective action
  • Execution of reporting (Daily/Weekly/Monthly)
  • Understand and scope properly Third Party organization structure to apply necessary controls to be assessed
  • Perform and manage Control/Risk Assessment and remediation of identified findings as per process documents
  • Ensure Third Party compliance to the business agreement, policies, procedures, & regulations along with ability to map controls and compliance requirements
  • Review Third Party supplied policies & procedures, internal/external assessment reports, agreements and provide feedback
  • Executive summaries with recommendations & direction regarding remediation efforts and disposition of the third party
  • Communicate, escalate, and track Third Party remediation progress on assessment remediation activities
  • Understand information security risks that are inherent to a business and articulate those risks in business terms
  • Maintain current knowledge on information security topics and their applicability program requirements
  • Engage DPO regarding any escalation/delays/deviations during assessment/remediation
  • Comply with the terms and conditions of the employment contract, company policies and procedures, and any and all directives (such as, but not limited to, transfer and/or re-assignment to different work locations, change in teams and/or work shifts, policies in regards to flexibility of work benefits and/or work environment, alternative work arrangements, and other decisions that may arise due to the changing business environment). The Company may adopt, vary or rescind these policies and directives in its absolute discretion and without any limitation (implied or otherwise) on its ability to do so

Required Qualifications:
  • Experience in auditing/security assessments
  • Experience working with senior levels of management
  • Security expertise including knowledge on different security risk assessment frameworks (NIST/Octave), standards (ISO27001/HITRUST/ITIL/Cobit), and act such as (HIPAA/GLBA).
  • Experience in examining the SSAE 16 Audit, SOC 2, PCI DSS, NY Cyber Security and other security audit report
  • Knowledge and understanding of different security products (web/email filtering, disk encryption, vulnerability testing, antivirus, DLP, firewall etc.)
  • Knowledge on technology/software development methodologies, application security, and OWASP Top 10 guidelines
  • Advance level experience in MS Word, MS Excel, and MS PowerPoint etc.
  • Ability to document assessment work papers and preparing assessment report
  • Ability to manage Third Party assessment independently with minimal supervision
  • Good follow-up skills and detail oriented
  • Strong Communication and Presentation Skills

Preferred Qualifications:
  • Possess good project management skills

Careers with Optum. Here's the idea. We built an entire organization around one giant objective; make health care work better for everyone. So when it comes to how we use the world's large accumulation of health-related information, or guide health and lifestyle choices or manage pharmacy benefits for millions, our first goal is to leap beyond the status quo and uncover new ways to serve. Optum, part of the UnitedHealth Group family of businesses, brings together some of the greatest minds and most advanced ideas on where health care has to go in order to reach its fullest potential. For you, that means working on high performance teams against sophisticated challenges that matter. Optum, incredible ideas in one incredible company and a singular opportunity to do your life's best work.(sm)

Diversity creates a healthier atmosphere: Optum is an Equal Employment Opportunity/Affirmative Action employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, disability status, sexual orientation, gender identity or expression, marital status, genetic information, or any other characteristic protected by law.

Optum is a drug-free workplace. © 2021 Optum Global Solutions (Philippines) Inc. All rights reserved.

Job Keywords: Senior Information Security Risk Analyst, Cebu City, Cebu, Taguig City, Quezon City, Muntinlupa, Alabang, National Capital Region, NCR