> Markdown version of [/jobs/ext/2572488-principal-network-detection-response-engineer](https://www.wearedevelopers.com/jobs/ext/2572488-principal-network-detection-response-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Network Detection & Response Engineer - **Company:** Unitedhealth Group Inc - **Location:** Washington, DC, United States (Remote available) - **Experience:** Experienced - **Salary:** $112,700.0 - $193,200.0 - **Contract:** Permanent contract - **Skills:** Microsoft Azure, Border Gateway Protocol, Complex Networks, Cyber Security, System Configuration, Deep Packet Inspection, Domain Name System (DNS), Intrusion Detection and Prevention, Network Security, Pcap, Network Architecture, Network Forensics, Network Protocols, Performance Tuning, Security Information and Event Management, Systems Integration, TCP/IP, Wireshark, EndPointSecurity, Cloud-native Network Functions (CNF), Transport Layer Security, Google Cloud, Mitre Att&ck, Mttr, Cyber Threat Analysis, HybridCloud, Amazon Virtual Private Cloud (VPC), Cybercrime, Cyber Warfare, Splunk, Serverless Computing, Security Orchestration, Automation & Response - **Published:** August 31, 2026 - **Apply:** https://www.dice.com/job-detail/386b2db2-e636-409a-99ba-a8ecbbff9f17 ## About the Role * 5+ years of professional experience in cybersecurity engineering, network security, or intrusion detection/prevention * 3+ years of hands-on experience deploying, configuring, and tuning Network Detection & Response (NDR) or Network Traffic Analysis (NTA) platforms (e.g., Corelight, Darktrace, ExtraHop, Zeek/Bro, Suricata) * 3+ years of experience analyzing network protocols (e.g., TCP/IP, DNS, TLS, BGP) and conducting deep packet inspection using tools such as Wireshark, Zeek, or Suricata * 3+ years of experience integrating network telemetry and security alerts into enterprise SIEM (e.g., Splunk, Sentinel) and SOAR tools, * Industry certifications in information security or network security (e.g., CISSP, GCIA, GCIH, GNFA, CCNP Security) * Experience engineering security detections for cloud networks and cloud-native services (e.g., AWS VPC Traffic Mirroring, Azure Network Watcher, Google Cloud Platform Packet Mirroring) * Knowledge of the MITRE ATT&CK framework with demonstrated success mapping network detections to adversary techniques * Solid background in decrypting or inspecting SSL/TLS traffic and analyzing encrypted network sessions * Proven ability to communicate complex technical security risks and detection strategies to senior engineering and leadership stakeholders *All employees working remotely will be required to adhere to UnitedHealth Group's Telecommuter Policy ## Description As a Principal Network Detection & Response Engineer within our Cyber Operations Group team, you will lead the architecture, deployment, and continuous optimization of enterprise-wide Network Detection and Response (NDR) capabilities. In this role, you will be instrumental in protecting critical enterprise assets by analyzing network telemetry, developing advanced threat detection logic, and orchestrating rapid response strategies against sophisticated cyber threats. You will collaborate closely with threat intelligence, incident response, and infrastructure teams to design resilient, cutting-edge security monitoring solutions across hybrid-cloud and on-premises environments. You'll enjoy the flexibility to work remotely * from anywhere within the U.S. as you take on some tough challenges. For all hires in the Minneapolis or Washington, D.C. area, you will be required to work in the office a minimum of four days per week., * Lead the strategy, architectural design, and optimization of Network Detection & Response (NDR) and network security monitoring platforms across hybrid enterprise environments * Develop, test, and tune high-fidelity detection signatures, behavioral rules, and anomaly detection models to identify advanced persistent threats (APTs) and zero-day vulnerabilities * Analyze complex network traffic, packet captures (PCAP), flow data, and encrypted telemetry to uncover evasive malicious activity and lateral movement * Drive automated response workflows and integration between NDR tools, SIEM, SOAR, and Endpoint Detection & Response (EDR) platforms to minimize Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) * Partner with Threat Hunting, Threat Intelligence, and Incident Response teams to translate emerging cyber threat tactics, techniques, and procedures (TTPs) into actionable detections * Conduct technical reviews, risk assessments, and architectural evaluations of proposed network infrastructure changes to ensure alignment with security detection objectives * Mentor senior and junior security engineers, providing technical guidance, rule reviews, and subject matter expertise in network defense and threat hunting You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Best Job Search Websites of 2025](https://www.wearedevelopers.com/magazine/368-the-best-job-search-websites-of-2025) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)