Optum Logo

Optum

Director Information Security Risk Management

Posted 4 Hours Ago
Be an Early Applicant
In-Office
Gurgaon, Gurugram, Haryana
Expert/Leader
In-Office
Gurgaon, Gurugram, Haryana
Expert/Leader
Serve as the business information security officer for cloud engineering teams, driving cloud risk governance, embedding security-by-design and DevSecOps, leading risk assessments and vulnerability management, advising senior stakeholders, and operationalizing controls and metrics aligned to NIST, CIS, HITRUST and HIPAA to improve cloud security posture.
The summary above was generated by AI
Requisition Number: 2363634
Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together.
As a Business Information Security Officer (BISO), you will be a key member of the ESRO organization, serving as the primary security partner for business and cloud engineering teams. This role is focused on enabling secure cloud engineering and innovation by providing strategic and hands-on support across risk management, cloud security consulting, secure architecture, and vulnerability management.
You will act as the trusted advisor to senior business and technology leaders, translating enterprise security strategy into actionable guidance tailored to secure, cloud platforms and engineering practices. The BISO will drive alignment between business objectives and security requirements, ensuring risks are understood, communicated, and managed within the enterprise risk appetite.
Primary Responsibilities:
  • Drive Cloud Risk Governance: Establish and enforce cloud-aligned risk frameworks; operationalize controls mapped to standards (NIST, CIS, HIPAA) with measurable effectiveness
  • Enable Proactive Risk Management: Leverage automation, analytics, and AI to identify, assess, and prioritize cloud risks for timely mitigation
  • Deliver Data-Driven Outcomes: Define and track risk and control metrics; continuously improve vulnerability management and remediation through data-driven practices
  • Enable Secure Cloud Engineering: Partner with engineering teams to embed security-by-design in architecture & CI/CD pipelines, ensuring secure configurations and scalable controls
  • Act as Trusted Security Advisor: Build solid stakeholder relationships; balance risk, speed, and business priorities while aligning with enterprise strategy and risk appetite

Functional Attributes:
  • Primary Security Partner: Act as the single ESRO point of contact for business and cloud engineering; build solid stakeholder relationships
  • Drive Security Adoption: Promote cloud security, secure development, and risk-informed decision-making across teams
  • Align Security Practices: Integrate IRM objectives with cloud and engineering workflows; identify and address risks and control gaps
  • Deliver Security Services: Lead cloud risk assessments, architecture reviews, compliance (ISMS, HITRUST), and vendor security evaluations
  • Manage Demand & Prioritization: Align security efforts with business priorities and optimize resource allocation
  • Enable Secure Cloud Architecture: Support design and implementation of secure cloud architectures and guardrails (AWS/Azure)
  • Ensure Risk-Based Compliance: Enforce policies using a risk-based approach aligned to enterprise risk appetite
  • Drive Control Effectiveness: Validate controls and lead remediation to improve security posture and reduce risk
  • Provide Practical Advisory: Guide teams on scalable security solutions (IAM, encryption, network, vulnerability remediation)
  • Communicate Clearly: Simplify and communicate risks, controls, and actions for technical and non-technical audiences
  • Lead Security Initiatives: Drive and track cloud security posture and vulnerability reduction programs
  • Support Incident Response: Partner on incident management, root cause analysis, and risk mitigation
  • Leadership Contribution: Support broader enterprise security strategy and transformation initiatives
  • Comply with the terms and conditions of the employment contract, company policies and procedures, and any and all directives (such as, but not limited to, transfer and/or re-assignment to different work locations, change in teams and/or work shifts, policies in regards to flexibility of work benefits and/or work environment, alternative work arrangements, and other decisions that may arise due to the changing business environment). The Company may adopt, vary or rescind these policies and directives in its absolute discretion and without any limitation (implied or otherwise) on its ability to do so

Required Qualifications:
  • 15+ years in Information Security across risk, cloud security, and architecture
  • Experience in BISO / Security Consulting / Business Security Partner roles
  • Proven experience embedding DevSecOps & security-by-design with engineering teams
  • Experience with security assessments (ISMS, HITRUST, cloud, vendor risk)
  • Experience improving cloud security posture (IAM, encryption, misconfigurations, network security)
  • Exposure to automation/AI-driven risk insights (preferred)
  • Solid hands-on expertise in AWS/Azure security architecture and controls
  • Solid understanding of vulnerability management and remediation practices
  • Familiarity with NIST, ISO 27001, CIS, HIPAA in cloud environments
  • Demonstrated ability to translate technical risks into business decisions
  • Proven solid stakeholder influence in matrixed/global environments
  • Proven excellent communication skills across technical and business audiences

At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission.

Similar Jobs at Optum

4 Hours Ago
In-Office
Junior
Junior
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Manage end-to-end delivery of Stratus Imaging implementation projects, overseeing scope, schedules, budgets, risks, and stakeholder communication. Create and maintain project plans, lead governance and cross-functional meetings, coordinate global teams and vendors, and drive continuous improvement across clinical and technical implementations.
Top Skills: CloudDatabasesDicomEnterprise Information SystemsFhirHl7Hospital Information SystemsJIRAMedical ImagingMicrosoft ProjectSmartsheetStratus Imaging
4 Hours Ago
In-Office
Expert/Leader
Expert/Leader
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Execute 1:1 direct marketing (email, SMS, direct mail) by assembling content, setting up and QAing campaigns/journeys, managing sends and list hygiene, supporting AI-assisted workflows, running tests, tracking channel KPIs, and ensuring compliance and audit-ready records within regulated (healthcare) guardrails.
Top Skills: Ai ToolsAnalytics DashboardsContent Management/TaggingDirect MailEmailJourney ToolsSmsUtm/Tracking
4 Hours Ago
In-Office
Mid level
Mid level
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Design, implement, and optimize conversational AI and data ingestion quality gates for NLP and LLM-based solutions. Monitor performance, apply reinforcement/self-improving techniques, ensure ethical AI practices, and collaborate with cross-functional teams to productionize research into scalable, reliable conversational search and analytics capabilities.
Top Skills: Agentic FrameworksDatabricksGenerative AiHugging Face TransformersLarge Language Models (Llms)Openai ApiPower BIPythonRSQLTableau

What you need to know about the Kolkata Tech Scene

When considering the industries shaping India's tech scene, gaming might not immediately come to mind. However, in the last decade, increased internet usage and greater access to mobile devices have catapulted the industry to new heights, with Kolkata-based companies like Virtualinfocom, Red Apple Technologies and Digitoonz, at the forefront, driving the design and animation of new gaming titles for players.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account