> Markdown version of [/jobs/ext/2516176-sr-principal-threat-intelligence-engineer-remote-or-hybrid-in-mn-or-dc](https://www.wearedevelopers.com/jobs/ext/2516176-sr-principal-threat-intelligence-engineer-remote-or-hybrid-in-mn-or-dc). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Principal Threat Intelligence Engineer- Remote or Hybrid in MN or DC - **Company:** Unitedhealth Group Inc - **Location:** Washington, DC, United States (Remote available) - **Experience:** Expert - **Salary:** $134,600.0 - $230,800.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Active Directory, Adobe InDesign, Artificial Intelligence, Amazon Web Services, Apple Mac Systems, Microsoft Azure, Bash Shell, Ubuntu (Operating System), CentOS, Cloud Computing Security, Cyber Security, Computer Telephony Integration, Information Engineering, Linux, Elasticsearch, Intrusion Detection and Prevention, Intrusion Detection Systems, JSON, Python (Programming Language), Kali Linux, Windows Servers, Node.Js, Open Source Technology, Windows PowerShell, Red Hat Enterprise Linux, Red Team (Cyber Security), Server Administration, Service Development Studio, Security Information and Event Management, Software Engineering, Data Processing, Scripting, Google Cloud, In-Plane Switching (IPS), Data Ingestion, Large Language Models, Apache Spark, QRadar, Malware, Cyber Threat Analysis, Firewalls (Computer Science), Git, Cybercrime, Microsoft Sentinel, Cortex XSOAR Platform, Apache Kafka, Restful APIs, Splunk, Software Version Control, Data Pipelines, Api Management, Docker, Security Orchestration, Automation & Response - **Published:** August 3, 2026 - **Apply:** https://dejobs.org/x/x/976F944F8E354DE0B114AF7CFC4B60FF/job/ ## About the Role * 5+ years of experience in a cyber threat intelligence, cyber security engineering, incident response or malware analysis role with heavy emphasis on tool and technology integration * Proven solid coding ability is essential for this role due to the need for automation, integration, and data engineering * Proficiency in one or more of: * Python (primary) for automation, API integrations, and data processing * Java, JavaScript/Node.js, or Go for service development * Experience with: * REST APIs, JSON, STIX/TAXII protocols * Data parsing, transformation, and pipeline development * Scripting (Bash, PowerShell) * Demonstrated familiarity with version control (Git) and CI/CD pipelines * Demonstrated familiarity with a variety of OS's and platforms including Linux (Ubuntu, CentOS, RHEL, Kali), AWS, Docker, Windows Server (NT through 2012), Active Directory, Mac OS X * Experiences with AI employment in a threat intelligence framework including LLM, MCP server configuration, RAG and associated processes. * Hands-on experience with TIPs such as: MISP, OpenCTI, ThreatConnect, Anomali * Experience integrating multiple intelligence feeds and formats * Proven understanding of IOC lifecycle management and enrichment techniques * Solid experience with SIEM platforms: Splunk, Microsoft Sentinel, IBM QRadar, Elastic * Experience building detection rules, correlation searches, and dashboards * Demonstrated understanding of log ingestion, normalization, and enrichment pipelines * Experience with SOAR platforms such as Cortex XSOAR, Splunk SOAR, Swimlane, Tines * Development of playbooks/runbooks for automated response * Proven knowledge of orchestration across multiple security tools, * Relevant certifications (e.g., GCTI, GCIA, CISSP, Splunk certifications) * Demonstrated familiarity with EDR/XDR, IDS/IPS, firewalls, cloud security tools * Proven knowledge of structured threat data formats (STIX, TAXII) * Experience in large-scale security operations or SOC environments * Familiarity with data engineering technologies (Kafka, Spark, Elasticsearch) * Experience with cloud platforms (AWS, Azure, GCP) and security integrations * Experience in threat hunting and detection engineering *All employees working remotely will be required to adhere to UnitedHealth Group's Telecommuter Policy. ## Description The Senior Principal Threat Intelligence Engineer is responsible for designing, deploying and integrating threat intelligence technical capabilities across United Health Group's security ecosystem. The role focuses on ingesting, normalizing, and enriching threat intelligence information, integrating Threat Intelligence Platforms (TIPs) and intelligence sources with security tooling (e.g., SIEM, SOAR, EDR), and deploying automated intelligence-enabled detection and response workflows. The ideal candidate combines solid software engineering skills with deep cybersecurity domain knowledge to transform raw threat data into actionable intelligence that enhances detection, response, and risk mitigation. This technical role focuses on building automation, data pipelines, and detection mechanisms to proactively defend infrastructure against threats of varying technical sophistication. The Senior Principal Threat Intelligence Engineer is expected to conceptualize, guide, and execute the delivery of technical intelligence solutions to CTI, SOC, Threat Detection, and Threat Hunting teams that accelerate the processing and dissemination of intelligence, increase speed of detection, and enable rapid response. The Senior Principal Threat Intelligence Engineer will be a key driver of the technology development and deployment agenda within the CTI space at United Health Group to include tool selection, architectural design, tool development, and operational support. This role will have a primary voice in design decisions, tool selection, and tool development, and will be expected to exert senior influence and operate autonomously as required. You'll enjoy the flexibility to work remotely * from anywhere within the U.S. as you take on some tough challenges. For all hires in the Minneapolis or Washington, D.C. area, you will be required to work in the office a minimum of four days per week., * Deploy, integrate, and maintain a threat intelligence platform that is integrated into United Health's security tooling ecosystem * Integrate threat intelligence into SIEM platforms (e.g., Splunk) for detection use cases and alert enrichment * Efficiently employ agentic AI, LLMs, and other associated capabilities to increase the availability and speed of delivery of contextualized threat intelligence to CTI, SOC, IR, and other SecOps members * Design, build, and deploy technology-supported workflows to execute diverse intelligence use cases across SOC, IR, Insider Risk, Fraud, Red Team, Threat Hunt, and other stakeholder environments * Develop and maintain SOAR playbooks for automated threat response and enrichment; utilize SOAR to optimize intelligence workflows * Orchestrate workflows across security tools to reduce manual analysis and response time * Design, build, and maintain integrations between threat intelligence feeds (commercial, open-source, ISACs) and internal security platforms * Integrate and operationalize Threat Intelligence Platforms (e.g., MISP, OpenCTI ThreatConnect, Anomali, ThreatQuotient) with enterprise security tools * Develop pipelines to ingest, normalize, deduplicate, and enrich Indicators of Compromise (IOCs) and threat data * Correlate intelligence with telemetry from SIEM, EDR, NDR, and cloud security tools to improve detection fidelity * Enable automated enrichment of alerts using threat intelligence data within SIEM workflows You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in. ## Related Videos - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)