Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Information Security Risk | , |

$72.8k - $130k

divvyDOSE

Associate Information Security Risk Auditor (Compliance Management Lifecycle)

Optum is a global organization that delivers care, aided by technology, to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together.

The Associate Information Security Risk Auditor (Compliance Management Lifecycle) is an early-career contributor responsible for supporting the assessment and validation of security risk policies and their associated standards across their full lifecycle. This role focuses on evaluating policies and their standards and testing against their requirements to confirm adherence. When evaluating policies and control adequacy they may need to refer to regulatory obligations, and leading frameworks (e.g., NIST CSF, ISO/IEC 27001). The auditor works closely with policy, procedure and control owners, risk teams, and technology stakeholders to confirm remediation adequacy, identify gaps, validate evidence, and recommend improvements. Strong attention to detail, analytical skills, and the ability to communicate findings clearly are essential.

You will enjoy the flexibility to telecommute* from anywhere within the U.S. as you take on some tough challenges.

Primary Responsibilities:
  • Control testing/ Action Plan Validation
    • Lead assessments of controls, action plans, processes
    • Validate that evidence accurately measures control effectiveness
    • Maintain audit-ready documentation and assist in tracking metric adherence and reporting accuracy
  • Compliance & Evidence Review
    • Perform periodic reviews of controls and procedures to test for control effectiveness
    • Escalate control effectiveness gap delays in remediation
    • Support alignment verification against frameworks (e.g., NIST CSF, ISO 27001) and obligations (e.g., SOX, SOC 2)
  • Stakeholder Support & Reporting
    • Prepare draft summary assessment results for management review
    • Participate in governance meetings and provide input on control validation status
    • Assist in control design efforts including inputs to governance routines and policy requirements
  • Core Responsibilities
    • Conduct independent control and process validation
    • Support policy refresh reviews
    • Ensure audit documentation and evidence traceability are complete and accurate
    • Collaborate with risk and compliance teams to track remediation progress Contribute to process improvement initiatives, including automation opportunities
  • Core Competencies
    • Risk Knowledge: Understanding of risk management and control frameworks and regulatory frameworks (NIST, ISO, SOX)
    • Risk & Compliance Awareness: Ability to assess metric-to-control mapping and evidence adequacy
    • Analytical Skills: Strong attention to detail in reviewing metric data and audit evidence
    • Communication: Ability to prepare clear reports and communicate effectively
    • Tool Familiarity: Experience with GRC platforms and metric reporting tools

You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear directions on what it takes to succeed in your role as well as provide development for other roles you may be interested in.

Required Qualifications:
  • Associate's degree (or higher) in Information Security, Risk Management, Business, or related field
  • 3+ years of experience in information security auditing, compliance, or risk management as policy governance and control effectiveness
  • 1+ years of experience working collaboratively across teams in a matrixed environment
  • Intermediate level of experience with control design and operation, GRC tools, and evidence collection processes
Preferred Qualifications:
  • Bachelor's degree in Information Security, Risk Management, Business, or related field
  • Certifications such as CISA, CRISC

*All Telecommuters will be required to adhere to UnitedHealth Group's Telecommuter Policy.

Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you'll find a far-reaching choice of benefits and incentives. The salary for this role will range from $72,800 to $130,000 annually based on full-time employment. We comply with all minimum wage laws as applicable.

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants.

At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location, and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups, and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission.

UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations.

UnitedHealth Group is a drug - free workplace. Candidates are required to pass a drug test before beginning employment.

#RPO #GREEN

Vacancy posted 5 hours ago
Similar jobs that could be interesting for youBased on the Information Security Risk | , | in United States vacancy
  •  ...MANTECH seeks a motivated, career and customer-oriented Information Systems Security Manager to join our team in Colorado Springs, CO. The ISSM...  ...on Joint Security Implementation Guidance (JSIG) and Risk Management Framework (RMF) Information Security Continuous... 
    Risk
    Full time
    Work at office
    Local area

    MANTECH

    Colorado Springs, CO
    5 hours ago
  • $99k - $225k

     ...Booz Allen Hamilton in Huntsville, Alabama is seeking an Information Security Risk Specialist. In this role, you will assess cyber risks for military clients, develop mitigation plans, and guide them through actionable plans. The candidate should have experience with security... 
    Risk

    Booz Allen Hamilton

    Huntsville, AL
    1 day ago
  •  ...technical teams, government stakeholders, and security governance bodies. The position requires...  ...in DoD cybersecurity frameworks and the Risk Management Framework (RMF), with...  ...of 5 years of recent experience in DoD Information Systems Security and/or Cybersecurity roles... 
    Risk
    Remote job
    Full time
    Temporary work
    Flexible hours

    jobgether

    United States
    3 days ago
  • General information Job Posting Title Cyber Security Engineer Date Thursday, April 16, 2026 City San Antonio State TX Country United...  ...supporting JCC2 operational systems. - Conducts risk assessments, vulnerability scans, and threat analysis... 
    Risk
    Minimum wage
    Full time
    Contract work
    Temporary work
    Work experience placement

    Maximus

    Elmendorf, TX
    5 hours ago
  •  ...Overview: Job Title: GIS IT Security - Intermediate Location: Austin, TX Experience...  ...security frameworks, evaluates cyber risks, and supports continuous improvement of...  ...cybersecurity assessments . Advise and inform business leaders on supplier information... 
    Risk

    Purple Drive

    Austin, TX
    2 days ago
  •  ...MANTECH seeks a motivated, career and customer-oriented Information System Security Officer (ISSO) to join our team in Winchester, VA. Responsibilities...  .... Conduct required IS vulnerability scans according to risk assessment parameters. Develop Plan of Action and... 
    Risk
    Work at office

    MANTECH

    Winchester, VA
    5 hours ago
  •  .... We are currently looking for a Sr. IT Security Analyst in the United States. This hands...  ...and reduce organizational risk. In addition to defending systems, you will...  ...related field. ~ Strong understanding of information security principles, frameworks, and regulatory... 
    Risk
    Remote job
    Full time
    Temporary work
    Flexible hours

    jobgether

    United States
    4 days ago
  •  ...Booz Allen Hamilton is seeking an information security risk specialist to assess cyber risks for military clients and develop mitigation plans. You'll work closely with clients to guide them through a security action plan, translating complex security concepts effectively... 
    Risk
    Remote work

    Booz Allen Hamilton

    Colorado Springs, CO
    19 hours ago
  •  ...IT Security - Advanced Roles and Responsibility Location: Austin, TX - onsite Duration...  ...strong knowledge in IT controls, risk assessments, and testing of security measures...  ...security, confidentiality, integrity, information protection and availability of data Conduct... 
    Risk

    Software Technology Inc

    Austin, TX
    2 days ago
  •  ...Gurgaon Location: Sohna Road, Gurgaon (India) Role Category: IT & Information Security - Other Posted: 2 days ago | Openings: 2 | Applicants: 100+ 4...  ...‑on exposure to GDPR, DPDP Act, ISO 27001, audit support and risk management. CTC: 12–25 LPA based on skills and experience.... 
    Risk

    Miracle Corporate Solutions Ltd

    New York, NY
    3 days ago
  •  ...government connectivity. You will play a key part in ensuring security controls, audit readiness, and regulatory compliance...  ...CMMC or similar frameworks) ~ Strong understanding of information security controls, risk management, and compliance methodologies ~ Excellent... 
    Risk
    Remote job
    Full time
    Flexible hours

    jobgether

    United States
    6 days ago
  •  ...Risk Management Role *Local candidates strongly preferred. Candidate must be comfortable working onsite at least 3 days each...  ...policies and processes for the Virginia Department of Health (VDH) Information Security Program. They provide hands-on development of risk models,... 
    Risk
    Local area
    3 days per week

    Software Technology Inc

    Richmond, VA
    2 days ago
  •  ...Position Overview The Information Systems Security Administrator (ISSA) is responsible for supporting the security, compliance, and operational...  ...with an alternative path. Passive execution is institutional risk. Build Beyond Yourself. If your function depends on your... 
    Risk
    Full time
    Contract work
    Work at office
    Monday to Thursday
    Flexible hours

    MSI Defense Solutions, LLC

    Mooresville, NC
    3 days ago
  •  ...Lead with 8+ years of expertise in IT Risk Management, Audit, and Compliance . The...  ...of ISO 27001, NIST 800-53, vendor security assessments, and cloud security controls...  ...Bachelor's degree in Computer Science, Information Security, or a related field. Minimum... 
    Risk

    Macpower Digital Assets Edge

    Cupertino, CA
    5 hours ago
  •  ...Information Security Manager We are searching for an Information Security Manager to join a great team with an industry-leading client with...  ...and support, business continuity/disaster recovery, enterprise risk management. ~ Have a full understanding of the current... 
    Risk

    THORNDALE PARTNERS

    Peachtree Corners, GA
    2 days ago
  • $144.51k

     ...Information Security Manager Job Number: 25597 Functional Area: Information Technology Department: MA Green High Performance Computing...  .... ( This senior, hands-on role spans security architecture, risk management, compliance, and policy for a nationally recognized... 
    Risk
    Full time
    Visa sponsorship

    Massachusetts Institute of Technology

    Cambridge, MA
    2 days ago
  •  ...This role is responsible for assessing, analyzing, and reporting on security risks related to third party technologies, services, and contractual agreements. As a subject matter expert for information security requirements within the vendor contract review process, the... 
    Risk
    Contract work

    3B Staffing LLC

    Charlotte, NC
    2 days ago
  •  ...ROLE: Cyber Security Engineer LOCATION: Onsite 2 days per week in NYC (Local candidates...  ...vulnerability detection, threat and risk analysis, network intrusion, securing technology...  .... Guides Cyber Governance and Information Protection team and makes informed... 
    Risk
    Local area
    2 days per week

    Sparktek

    Hauppauge, NY
    2 days ago
  •  ...Risk Management Consultant Define end to end governance workflows for: Risk identification and intake Risk review and validation...  ...risks. Engage key stakeholders across business, technology, security, and governance functions to validate risk requirements and... 
    Risk
    Contract work
    For contractors

    Lumen Solutions Group Inc.

    Austin, TX
    2 days ago
  •  ...Cyber Risk And Data Protection Team Member We are the leading provider of professional...  ...those risks and improve their cyber security posture. We serve a diverse base of clients...  ...focused certifications: Certified Information Systems Security Professionals® (CISSP®)... 
    Risk

    RSM Co.

    Charlotte, NC
    2 days ago
  •  ...Qualifications: ~7-9 years of related experience in cyber security or information technology ~ Prior performance in roles such as...  ...Access Program Implementation Guide (JSIG) Experience with the Risk Management Framework (RMF) authorization process... 
    Risk

    3B Staffing LLC

    Hanscom Air Force Base, MA
    2 days ago
  •  ...resolve potential issues to help enhance and secure a large enterprise network. The position...  ...vulnerability detection, threat and risk analysis, network intrusion, securing technology...  .... Guides Cyber Governance and Information Protection team and makes informed security... 
    Risk
    Flexible hours

    Samprasoft

    New York, NY
    3 days ago
  •  ...landscape, assess the maturity of their cyber security capabilities, and define a strategy to...  ...market. Team management with good information security technical expertise and ability...  ...strategies to manage identified risks and ensure adoption and adherence to standards... 
    Risk
    Work experience placement

    Diverse Lynx

    Edison, NJ
    1 day ago
  •  ...A company is looking for a Cyber Security Advisor. Key Responsibilities Develop and maintain...  ...practices Assess cybersecurity risks, perform security reviews, and develop risk...  ...Qualifications 7+ years of experience in IT, Information Security, Compliance, Audit, or Risk 5+... 
    Risk
    Remote work

    Virtual Vocations Inc

    United States
    2 days ago
  •  ...recommending, implementing and utilizing security defense systems to reduce the...  ...Must have a Bachelors degree in Management Information Systems. Experience ~ Must have two...  ...manner. Must be able to perform technical risk assessments and implement corrective actions... 
    Risk
    Local area

    Parkland Health and Hospital System

    Dallas, TX
    10 hours ago
  • $105k - $125k

     ...Job Type Full-time Description The Senior Information Security Analyst protects Company organizational systems and data by supporting and enhancing security operations, risk management, and security controls. This role performs advanced analysis and responds... 
    Risk
    Full time

    Johnson and Quin, Inc

    Niles, IL
    1 day ago
  • $107k - $214.5k

     ...looking for team members to join our Cyber Risk and Data Protection practice. The...  ...address those risks and improve their cyber security posture. We serve a diverse base of clients...  ...focused certifications: Certified Information Systems Security Professionals (CISSP);... 
    Risk
    Work experience placement
    Internship
    Local area

    RSM US LLP

    Charlotte, NC
    2 days ago
  •  ...Information Security Manager Home-based with UK Travel Full Time, Permanent Band 4 / £55,000 - £63,000 (dependent on experience) Here...  ...contracts Lead and support: Information security risk management, security incident management and investigations,... 
    Risk
    Permanent employment
    Full time
    Contract work
    Remote work
    Work from home
    Home office
    Flexible hours

    Serco

    United States
    5 hours ago
  •  ...recommending, implementing and utilizing security defense systems to reduce the...  ...Must have a Bachelors degree in Management Information Systems. Experience ~ Must have six...  ...manner. Must be able to perform technical risk assessments and implement corrective actions... 
    Risk
    Local area

    Parkland Health and Hospital System

    Dallas, TX
    10 hours ago
  •  ...Job: Dimondale, MI - IT - DTMB - Cyber Security - MCS - IT Security Analyst 3 Job...  ...around NIST Controls and ability to perform risk assessments. • Ability to coach/train...  ...9 at 10am EST. Monitor and advise on information security issues related to the systems... 
    Risk
    Local area
    Relocation

    My3Tech Inc

    Lansing, MI
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Information Security Risk | , |. Be the first to apply!