Sr Director, Cloud Security - Eden Prairie or Washington, DC Hybrid
Listed on 2026-01-29
-
IT/Tech
Cybersecurity, Systems Engineer, Cloud Computing
Optum Tech is a global leader in health care innovation. Our teams develop cutting-edge solutions that help people live healthier lives and help make the health system work better for everyone. From advanced data analytics and AI to cybersecurity, we use innovative approaches to solve some of health care's most complex challenges. Your contributions here have the potential to change lives.
Ready to build the next breakthrough? Join us to start Caring. Connecting. Growing together.
The Senior Director of Cloud Security is the senior leader responsible for the overall cloud security strategy and execution and golden images security for on prem and cloud systems security across the enterprise. This role leads a team focused on designing, implementing, and maintaining the foundations that enable secure cloud environments. This role also responsible securing golden images (containers, vm, etc.)
for both on-premises and in the cloud. The Senior Director partners closely with ETIPS (Enterprise Technology Infrastructure, Platforms & Services) cloud teams and other stakeholders to ensure robust, scalable, and compliant security solutions are embedded throughout the organization's technology landscape.
- Establish and mature a unified operating model for cloud and systems security, enabling seamless engagement across Enterprise security and resilience office (Engineering, Cyber, Architecture) and ETIPS teams
- Develop and enforce security standards in partnership with Security Architecture and golden image baselines in all environments, ensuring consistency, compliance, and rapid deployment
- Drive proactive security planning and operational readiness for cloud landing zones, reducing friction and enabling business agility
- Partner with ETIPS teams to embed security by default into cloud platform features, backlog grooming, and service adoption
- Measure and improve the security posture of cloud entities and system images, shifting assessments earlier in the lifecycle and supporting continuous improvement
Scope of Ownership vs. Partnership:
- Cloud security roadmap an execution
- Development, maintenance, and governance of security requirements of golden images on- premises and cloud
- Guardrails, and technical baselines for cloud and systems security
- Product engineering roadmap for core cloud security services
- Toolchain rationalization (build vs. buy vs. deprecate) for cloud and systems security platforms
- ETIPS Cloud teams for planning, policy rollout, service adoption, and integration of security features
- Business Unit CIOs and platform teams to ensure security standards are embedded in ways of working
- Cyber Defense, Incident Response, and SOC teams for incident preparedness and joint exercises, and ensuring that all cloud environments have defensive visibility
- Internal Audit, Compliance, and GRC teams for regulatory alignment and audit readiness
- Finance and Procurement for rationalization and operationalization of purchased security capabilities
- Lead and develop the Cloud and Systems Security team, providing direction, coaching, and performance management
- Design, document, and maintain secure cloud landing zones and golden images for operating systems in partnership with ETIPS
- Standardize policy execution and operational metrics across cloud and systems platforms
- Direct the product/backlog for scalable security capabilities and ensure efficient intake/prioritization with ETIPS
- Operate shared guardrails (IAM baselines, encryption, policy sets) with clear SLAs, SLOs, and health dashboards
- Make toolchain choices (build, buy, deprecate) to maximize ROI and speed to operational maturity
- Lead joint technical readiness and incident response exercises with ETIPS and partner teams
- Establish war-room protocols and continuous improvement loops, integrating lessons learned into backlog
- Serve as a trusted leader breaking down silos between Security, Infrastructure, and Application teams
- Own and lead engagement with cloud service providers (AWS, Azure, GCP): run QBRs, influence roadmaps, and accelerate adoption of platform-native security features
- Improve posture maturity for integrated…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).