Optum Logo

Optum

Sr Software Engineer II - Cloud Security, Secure Code Development

Posted 2 Days Ago
Be an Early Applicant
In-Office
Hyderabad, Telangana
Senior level
In-Office
Hyderabad, Telangana
Senior level
Monitor and remediate cloud, infrastructure, configuration, and application security vulnerabilities across Microsoft Azure environments. Review secure code findings, implement fixes, coordinate remediation with development and release teams, and track compliance with security SLAs and mandates. Use GitHub and CI/CD tooling to support secure development and deployment. Communicate risks, remediation progress, and release impacts to technical and nontechnical stakeholders while following enterprise change and risk-management practices.
The summary above was generated by AI
Requisition Number: 2355265
Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together.
Primary Responsibilities:
  • Monitor Azure Defender and Optum Security Platform to identify vulnerabilities, misconfigurations, and security risks across cloud, infrastructure, and application environments
  • Triage security findings and determine appropriate remediation paths, performing hands on remediation when within scope and creating actionable work items for development teams when code level fixes are required
  • Oversee remediation efforts by development teams to ensure application functionality while maintaining industry best level security practices
  • Perform direct remediation of cloud, infrastructure, and configuration issues, including production environments when appropriate and in accordance with change and risk management practices
  • Review application level security findings and apply secure coding knowledge to assess severity, validate findings, and recommend remediation approaches aligned with security best practices
  • Track, manage, and report vulnerability remediation efforts to ensure compliance with defined SLAs, release timelines, and enterprise security mandates
  • Attend ESRO public cloud monthly calls and manage follow up work resulting from new security publications, standards, and Optum wide mandates
  • Coordinate security remediation work with Product Owners, Scrum Masters, and Release Engineers to plan releases and hotfixes, balancing risk reduction with delivery commitments
  • Communicate security risks, remediation status, and release impacts clearly to technical and non technical stakeholders, providing guidance on secure design and implementation where needed
  • Comply with the terms and conditions of the employment contract, company policies and procedures, and any and all directives (such as, but not limited to, transfer and/or re-assignment to different work locations, change in teams and/or work shifts, policies in regards to flexibility of work benefits and/or work environment, alternative work arrangements, and other decisions that may arise due to the changing business environment). The Company may adopt, vary or rescind these policies and directives in its absolute discretion and without any limitation (implied or otherwise) on its ability to do so

Required Qualifications:
  • Undergraduate degree or equivalent experience
  • 4+ years combined experience in cloud security, secure code development, and/or Azure Cloud engineering supporting large-scale production enterprise environments
  • 2+ years of hands on experience securing Microsoft Azure environments, including Microsoft Defender for Cloud (Azure Defender), Azure resource configuration, identity, networking, and remediation of cloud security risks and misconfigurations
  • Hands-on experience performing direct remediation of security issues, including cloud configuration fixes, infrastructure hardening, policy enforcement, and production changes following change, risk, and RRB approval processes
  • Hands-on experience using GitHub for source control, including creating, reviewing, and merging pull requests in accordance with security and change standards
  • Experience using enterprise security platforms such as the Optum Security Platform or equivalent tools for vulnerability detection, risk tracking, and remediation management
  • Experience with enterprise application development languages and technologies such as Java, C#, and REST based services deployed in cloud environments
  • Experience working with GitHub Actions or similar CI/CD tooling to support secure build, validation, and deployment workflows
  • Experience tracking vulnerability remediation against defined SLAs, release timelines, and enterprise security mandates
  • Practical experience reviewing, understanding, and modifying application code to assess security findings and recommend or implement secure remediation approaches
  • Familiarity with Agile/Scrum delivery models and coordinating security work with Product Owners, Scrum Masters, Release Engineers, and change approvers
  • Solid working knowledge of application security best practices and common vulnerability classes, including authentication and authorization flaws, secrets management, input validation, injection risks, and secure dependency management
  • Proven ability to triage security findings across cloud, infrastructure, and application layers and determine appropriate remediation paths independently
  • Proven ability to create clear, actionable remediation work items for development teams when fixes are outside direct remediation scope and to oversee remediation through PR review and release completion
  • Demonstrated solid written and verbal communication skills, with the ability to clearly communicate security risks, remediation status, and release impacts to both technical and non technical stakeholders
  • Demonstrated ability to operate as a self directed individual contributor with minimal day to day supervision

At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission.
#Gen

Optum Pune, Maharashtra, IND Office

Pune, India, India

Similar Jobs at Optum

5 Hours Ago
In-Office
Mid level
Mid level
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Plan, execute, and deliver clinical and non-clinical healthcare technology projects. Define scope and deliverables, create project plans, allocate resources, identify risks, coordinate clinical/admin/IT stakeholders, provide status updates, maintain compliance documentation, facilitate meetings, and leverage enterprise AI tools to streamline workflows and automate repetitive tasks.
Top Skills: Enterprise Ai ToolsIt InfrastructureMs ProjectSdlcServicenow
Yesterday
In-Office
Junior
Junior
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Assists with managing Payment Integrity Operations by overseeing team productivity, quality, coaching, onboarding, compliance, reporting, escalation handling, and process improvement. Identifies error trends, supports automation and cost reduction initiatives, develops improvement plans, maintains stakeholder relationships, and handles sensitive healthcare information in accordance with HIPAA and company policies.
Top Skills: Hipaa
Yesterday
In-Office
Senior level
Senior level
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Leads and mentors software engineers building secure, cloud-native AI applications. Designs and deploys AI agents, LLM workflows, RAG systems, and shared agent frameworks using Microsoft Azure. Owns AI-centric SDLC practices, including governance, evaluation, CI/CD, observability, testing, guardrails, and incident response. Embeds security, privacy, compliance, identity, encryption, and least-privilege controls into AI systems while contributing production code and collaborating with product, platform, security, and compliance teams.
Top Skills: Amazon Ai-DlcAnthropicAzure App ServicesAzure Cosmos DbAzure FunctionsAzure Kubernetes Service (Aks)Azure SqlAzure StorageC#ChatgptCi/CdClaudeCodexGithub Spec-KitInfrastructure As CodeJavaLangchainLanggraphManaged IdentitiesAzureNode.jsOauthOidcOpenaiPythonRagRbacSemantic KernelTypescriptVector Databases

What you need to know about the Pune Tech Scene

Once a far-out concept, AI is now a tangible force reshaping industries and economies worldwide. While its adoption will automate some roles, AI has created more jobs than it has displaced, with an expected 97 million new roles to be created in the coming years. This is especially true in cities like Pune, which is emerging as a hub for companies eager to leverage this technology to develop solutions that simplify and improve lives in sectors such as education, healthcare, finance, e-commerce and more.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account