Threat Intelligence Analyst
Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together.
The Online Threat Intelligence Analyst supports Corporate Security by identifying, capturing, and processing threat-related information sourced from open-source and online environments that may impact the company, executives, employees, facilities, or critical assets.
Operating under established procedures and escalation guidelines, the analyst monitors and reviews online OSINT sources-including social media platforms, forums, messaging applications, and traditional media-to detect potential threats, concerning narratives, or indicators of targeting. Information is collected, documented, and processed to enable further analysis by senior intelligence analysts and threat management personnel.
Primary Responsibilities:
- Monitor and review open-source and online environments for potential threats, concerning behaviors, or indicators of targeting directed at the company, its executives, employees, facilities, or operations
- Identify and capture threat-related content from social media, online forums, blogs, messaging platforms, and other publicly available digital sources
- Triage online threat information to determine relevance, credibility, and potential risk indicators based on established criteria and guidance
- Accurately document and log online threat information, source details, timestamps, and contextual observations in approved tracking systems, case management tools, or intelligence repositories
- Conduct initial processing of collected information, organizing content to support downstream analysis by senior analysts and Threat Management or Executive Protection teams
- Draft concise factual summaries of identified online threats or concerning content for review, escalation, or incorporation into intelligence products
- Escalate time-sensitive or credible threat indicators in accordance with defined protocols and supervisory guidance
- Support senior analysts with information collection, basic research, and content verification related to online threat cases or investigative efforts
- Maintain operational discipline by adhering to documentation standards, privacy considerations, and handling requirements for sensitive information
- Collaborate with Corporate Security partners and intelligence team members to ensure consistent threat intake and information-sharing practices
- Support rotational operational coverage, as required, to ensure continuity of online threat monitoring and intake functions
- Comply with the terms and conditions of the employment contract, company policies and procedures, and any and all directives (such as, but not limited to, transfer and/or re-assignment to different work locations, change in teams and/or work shifts, policies in regards to flexibility of work benefits and/or work environment, alternative work arrangements, and other decisions that may arise due to the changing business environment). The Company may adopt, vary or rescind these policies and directives in its absolute discretion and without any limitation (implied or otherwise) on its ability to do so
Required Qualifications:
- 3+ years of experience in intelligence, investigations, security operations, online research, or a related analytical field; relevant academic experience or internships may be considered
- Familiarity with open-source intelligence (OSINT) concepts, social media platforms, and online research techniques
- Proficiency with standard office productivity tools (e.g., Microsoft Office applications)
- Demonstrated ability to review and process online content efficiently while identifying relevant threat-related details
- Proven solid written communication skills, with the ability to document information clearly, accurately, and objectively
- Proven high attention to detail and ability to follow defined intake, documentation, and escalation procedures
- Proven ability to work effectively in a structured, process-driven environment handling sensitive or high-interest information
- Proven solid organizational skills with the ability to manage multiple information streams and competing priorities
- Proven attention to detail and information accuracy
- Proven structured analytic thinking within defined guidelines
- Proven operational discipline and adherence to procedures
- Proven clear and objective written communication
- Proven information organization and documentation
- Proven sound judgment and escalation awareness
- Proven collaboration and teamwork
- Proven professional discretion when handling sensitive information
Working Conditions
- In-person role based within the Regional Security Operations Center in Gurgaon, India
- Fast-paced, detail-oriented operational environment supporting threat awareness and protective intelligence functions
- Shift‑based schedule supporting 24/7/365 operational coverage, including nights and weekends
At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission.