UnitedHealth Group · Raleigh, NCremote

Salary
$112,700–$193,200from the description
Posted
Jul 22, 2026
Location
Raleigh, NC
Last confirmed open
Jul 23, 2026

What this job asks for AI summary

A principal-level security engineering role centered on Splunk infrastructure — designing, scaling, and optimizing enterprise deployments across cloud, on-premises, and hybrid environments. A significant focus is integrating newly acquired companies into the existing security monitoring ecosystem, covering log source identification, ingestion pipeline design, parsing, and normalization. The role also supports SOC operations and involves mentoring engineers and advising senior leadership on logging and monitoring strategy.

Senior level · 4+ years · Remote · Full-time

Advertised as Principal, but the requirements read as Senior.

Must have (5)
Splunk Enterprise or Splunk Cloud · 3+ yrsAWS, Azure or GCPPython or BashSplunk CIMsyslog
Nice to have (2)
SOARMITRE ATT&CK

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 1,650 people nationally plausibly meet what this posting asks for (information security analysts). range 610–2,600

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What gives you an edge
GCP13%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
Python51%Splunk Enterprise45%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (6)

The title says 'Principal' but the requirements (4+ years total, 3+ years Splunk) are consistent with a Senior-level role; the Principal designation appears to reflect internal titling rather than org-wide technical authority.

The role is remote-US with an in-office requirement (minimum 4 days/week) for candidates in the Minneapolis or Washington, D.C. metro areas specifically. The CBSA reflects the Minneapolis headquarters; D.C. is a secondary location.

AWS, Azure, and GCP are listed together as a single log-source requirement ('Cloud platforms (AWS, Azure, GCP)') under Required Qualifications; they are emitted as separate skills because all three are distinct platforms the role must support, not interchangeable alternatives.

Python and Bash are listed as 'or similar' under Required Qualifications — Bash is captured as a separate required skill (not just an alternative) because both are explicitly named and commonly used together in this type of role; the 'or similar' qualifier means other scripting languages could substitute.

SOAR platforms and MITRE ATT&CK appear under Preferred Qualifications and are marked accordingly.

SOC/detection engineering experience and M&A integration experience are listed as preferred but name no specific technology, so they are omitted from the skills list per extraction rules.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗