Optum Logo

Optum

Information Security Risk Auditor - San Juan PR

Posted 5 Days Ago
Be an Early Applicant
In-Office
San Juan
Senior level
In-Office
San Juan
Senior level
The Info Security Risk Auditor supports information security policies, conducts audits, manages risk assessments, ensures compliance, and drives security awareness within the organization.
The summary above was generated by AI
Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together.
The Info Security Risk Auditor is responsible for supporting and enforcing information security policies, standards, and procedures to safeguard proprietary, personal, and privileged electronic data. This role works closely with user departments and cross-functional teams to implement robust security controls, drive compliance, and foster a culture of security awareness.
Primary Responsibilities:
  • Risk & Governance
    • Align security policies and standards with IT infrastructure frameworks (ISO 27001, NIST, ITIL)
    • Lead policy exception and risk management, including logging, assessment, and mitigation
    • Conduct vendor tier assessments, clarify tiering logic, and ensure correct application of security reviews
    • Oversee remediation of critical/high vulnerabilities, verify aging data, and confirm with SLOs on unresolved exploits
    • Support overall application security governance
  • Compliance & Certification
    • Ensure compliance with regulatory requirements (ISO 27001, NYDFS, NIST)
    • Lead and support ISO 27001/ISMS program implementation and audits for assigned geographies/scope
    • Maintain and update compliance trackers, dashboards, and reporting frameworks
    • Perform audits to identify control gaps and implement corrective action plans
    • Monitor compliance with corrective actions and address non-compliance issues
    • Review and attest security attributes for applications, including MFA, orientation, data type, and access provisioning
  • Incident Management & Investigation
    • Facilitate and lead security incident investigations, including physical security, fire safety, access control, and environmental controls
    • Ensure proper logging and escalation of incidents
    • Coordinate with other teams for incident related activities
  • Security Awareness & Training
    • Drive security awareness campaigns, training, and infographics for employees and contractors
    • Track and report on training completion rates, phishing metrics, and awareness initiatives
    • Develop and communicate security content, including videos and best practices
  • Stakeholder Engagement & Communication
    • Communicate professionally with stakeholders and end users through multiple channels
    • Collaborate with business, and other concerned teams for regulatory reporting and audit support
    • Provide consulting and support for customer audits, contract reviews, and acquired entity compliance
  • Physical Security & Site Compliance
    • Conduct physical compliance walks, assess fire safety, access control, secure printing, and data privacy at sites

*** ENGLISH PROFICIENCY ASSESSMENT WILL BE REQUIRED AFTER APPLICATION ***
You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear direction on what it takes to succeed in your role as well as provide development for other roles you may be interested in.
Required Qualifications:
  • 4+ years of information security experience or related experience
  • Related experience with ISO27001 (ISMS), HITRUST CSF, NIST Cybersecurity Framework, SOC Type1/2
  • Professional proficiency both with English and Spanish
  • Proven auditing skills and ability to manage risk assessments/projects independently
  • Proven excellent verbal and written communication skills
  • Proven solid presentation skills, especially the ability to explain technology to non-technical personnel
  • Demonstrated ability to work independently, meet deadlines, and maintain stakeholder confidence

Preferred Qualifications:
  • Certifications: CISSP, CISA, ISO27001 Lead Implementer or Lead Auditor
  • Experience in physical security, compliance walks, and site-level assessments

At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission.
UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations.
UnitedHealth Group is a drug - free workplace. Candidates are required to pass a drug test before beginning employment.
#PRLinkedIn

Top Skills

Hitrust Csf
Iso 27001
Itil
Nist
Soc Type1/2

Similar Jobs at Optum

2 Days Ago
In-Office or Remote
San Juan, PRI
Junior
Junior
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
As a Collections Representative, you will resolve claims and ensure accurate processing while improving patients' financial experiences. Duties include reviewing claims, communicating with payers, and meeting performance goals.
Top Skills: ExcelMicrosoft OutlookMicrosoft Word
3 Days Ago
In-Office
San Juan, PRI
Junior
Junior
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
The COB Auditor resolves provider and member issues, performs root cause analysis, and verifies insurance coverage through various platforms while ensuring compliance with health regulations.
Top Skills: DiamondFacetsExcelNicePulseUnet
5 Days Ago
In-Office
San Juan, PRI
Junior
Junior
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
The SME/Team Lead supports agents in a call center, resolving customer issues and ensuring operational efficiency through coaching and collaboration.
Top Skills: ExcelMicrosoft ProjectMS OfficeOnenote

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account