via Taleo
$140K - 190K a year
Design and maintain enterprise NDR sensors and Zeek detection pipelines while improving network visibility and platform observability.
Requires at least four years in network engineering or information security, including three years with enterprise NDR technologies, plus Linux and network architecture proficiency.
Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together. The Senior Network Detection & Response Engineer supports the operational health, visibility, and performance of the enterprise NDR platform, combining security operations expertise, strong networking fundamentals, and the ability to build modern monitoring and observability tooling. This engineer serves as a platform owner and builder, delivering a reliable, well-instrumented NDR platform to Security Operations, Incident Response, and Detection Engineering teams. You’ll enjoy the flexibility to telecommute* from anywhere within the U.S. as you take on some tough challenges. Primary Responsibilities: Design, deploy, configure, and maintain enterprise Network Detection & Response (NDR) sensors, appliances, and Zeek-based detection pipelines, ensuring alert and log data delivered to SOC and Incident Response teams is complete, accurate, and timely Proactively identify and root-cause network visibility gaps — including incomplete tap/SPAN coverage, asymmetric routing, redundant HA links, and one-sided flows — using Zeek/Suricata log analysis, traffic volume baselines, synthetic traffic validation, and monitoring dashboards Partner with Network Engineering, Packet Broker, and application teams to validate tap/SPAN placement, remediate traffic engineering issues, and onboard new network segments into the NDR architecture Build and maintain platform observability using Python, REST APIs, and time series databases to monitor sensor health, data ingestion, packet throughput, and drop rates Create and modify Zeek scripts, Suricata rules, and associated detection content packs in response to customer and stakeholder requests, collaborating with Detection Engineering on broader rule strategy and coverage Define and maintain SLIs/SLOs for platform reliability and data quality, and develop technical documentation, standard operating procedures, and operational guides for NDR administration Leverage enterprise-approved AI tools to streamline workflows, automate tasks, and drive continuous improvement You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in. Required Qualifications: High School Diploma/GED 4+ years of combined experience in network engineering and/or information security, with a primary focus on network traffic analysis, network security monitoring, or threat detection 3+ years of hands-on engineering and administration experience with enterprise NDR technologies (e.g., Corelight, Zeek, Suricata, ExtraHop, Darktrace, or similar tools) 3+ years of hands-on experience with network protocols and architecture, including TCP/IP, UDP, VLANs, routing and switching, packet-level traffic analysis, and working directly on enterprise network device CLIs (e.g., Cisco, Arista, Juniper) 1+ years of hands-on experience administering and troubleshooting Linux systems from the command line Participate in an on-call rotation supporting platform availability and incident response escalations Preferred Qualifications: Bachelor's degree Experience with tap/SPAN architectures and packet broker platforms (e.g., Ixia, Gigamon, Arista) Experience developing Zeek scripts and Suricata rules in a production environment Experience integrating security telemetry with SIEM or log aggregation platforms (e.g., Splunk, Elastic) Experience with network traffic visibility in a cloud environment (e.g., Azure, AWS, GCP), including VPC/VNet traffic mirroring Nice to have knowledge on Rest API: (GET, POST, PUT, DELETE, JSON payloads, OAuth, Bearer tokens) *All Telecommuters will be required to adhere to UnitedHealth Group’s Telecommuter Policy. Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you’ll find a far-reaching choice of benefits and incentives. The salary for this role will range from $91,700 to $163,700 annually based on full-time employment. We comply with all minimum wage laws as applicable. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants. At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone–of every race, gender, sexuality, age, location, and income–deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups, and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes — an enterprise priority reflected in our mission. Diversity creates a healthier atmosphere: UnitedHealth Group is an Equal Employment Opportunity/Affirmative Action employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, disability status, sexual orientation, gender identity or expression, marital status, genetic information, or any other characteristic protected by law. UnitedHealth Group is a drug-free workplace. Candidates are required to pass a drug test before beginning employment. #RPO, #GREEN
This job posting was last updated on 10/7/2026