Optum is a global organization that delivers care, aided by technology to
help millions of people live healthier lives. The work you do with our
team will directly improve health outcomes by connecting people with the
care, pharmacy benefits, data and resources they need to feel their best.
Here, you will find a culture guided by inclusion, talented peers,
comprehensive benefits and career development opportunities. Come make an
impact on the communities we serve as you help us advance health
optimization on a global scale. Join us to start
Caring. Connecting. Growing together.
Identity is the security perimeter of the modern enterprise. Every login,
token, and policy decision flows through our Identity Platform, and a
growing portfolio of productized identity experiences is built on top of
it. When it works, no one notices. When it does not, everything stops.
This is a senior engineering leadership role on the Identity Platform
team. You will own the shared substrate that our productized identity
experiences are built on. You will own Authentication today and extend the
platform into Authorization and non-human identity as the landscape
evolves.
Primary Responsibilities:
-
This is mission-critical infrastructure that is multi-region, highly
available & low-latency
-
Set and execute the multi-year technical strategy for the platform,
including the path from AuthN today to a unified AuthN and AuthZ
platform that serves both human and non-human identities
-
Own architecture, reliability, security, and operations for platform
services at enterprise scale
-
Build the platform to perform at scale and support growth, with a solid
focus on self-service adoption and easy integration for product teams
that build on top
-
Partner with Principal Engineering, Product Engineering, TPM, Security,
and Ops to align roadmaps and drive execution
-
Act as the senior engineering voice for the platform in India. Raise the
technical bar, grow leaders, and build a team people want to join
-
Set the standard for how AI transforms engineering work across the team,
including how software is designed, written, tested, and operated
-
Comply with the terms and conditions of the employment contract, company
policies and procedures, and any and all directives (such as, but not
limited to, transfer and/or re-assignment to different work locations,
change in teams and/or work shifts, policies in regard to flexibility of
work benefits and/or work environment, alternative work arrangements,
and other decisions that may arise due to the changing business
environment). The Company may adopt, vary or rescind these policies and
directives in its absolute discretion and without any limitation
(implied or otherwise) on its ability to do so
Required Qualifications:
-
Undergraduate degree or equivalent experience
-
Hands-on expertise with modern identity protocols, including OIDC,
OAuth 2.0, SAML, JWT, MFA, and session and token architectures
-
Proven track record architecting and operating highly available,
low-latency distributed systems that power mission-critical workloads
at scale
-
Solid cloud-native fundamentals, including AWS, GCP, or Azure;
Kubernetes; API design; event-driven architectures; and modern
observability
-
Demonstrated ability to set multi-year technical strategy and drive it
through multiple teams of engineers and engineering leaders
-
Security-first engineering mindset. Threat modeling, hardening, and
incident response are core disciplines, not afterthoughts
-
Actively pushing the frontier of AI in engineering. You have moved
beyond using AI tools for personal productivity and are reshaping how
your teams build, review, test, and operate software, with measurable
gains in velocity and quality
Preferred Qualifications:
-
Experience with password less and phishing-resistant authentication,
including passkeys, FIDO2, and WebAuthn
-
Experience operating in regulated environments such as healthcare,
financial services, or government
-
Depth in modern AuthZ, including policy-as-code (OPA, Cedar) and
fine-grained or relationship-based access models (ReBAC,
Zanzibar-style)
-
Familiarity with non-human and workload identity, including
short-lived credentials, secrets management, and SPIFFE or SPIRE
-
Practical understanding of agentic AI identity, including how AI
agents authenticate, act on behalf of users, and are governed
-
Exposure to fraud and abuse detection, bot mitigation, or risk-based
authentication.
At UnitedHealth Group, our mission is to help people live healthier
lives and make the health system work better for everyone. We believe
everyone - of every race, gender, sexuality, age, location and income -
deserves the opportunity to live their healthiest life. Today, however,
there are still far too many barriers to good health which are
disproportionately experienced by people of color, historically
marginalized groups and those with lower incomes. We are committed to
mitigating our impact on the environment and enabling and delivering
equitable care that addresses health disparities and improves health
outcomes - an enterprise priority reflected in our mission.