Information Protection Senior Advisor

The Cigna Group

Bloomfield, CT

JOB DETAILS
SKILLS
Agile Programming Methodologies, Amazon Web Services (AWS), AngularJS, Application Framework, Applications Security, Architectural Services, Automation, Best Practices, Broadband, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Cloud Applications, Cloud Computing, Communication Skills, Computer Science, Computer Security, Continuous Deployment/Delivery, Continuous Improvement, Continuous Integration, Cross-Functional, Establish Priorities, Fiber Optic Cable, HIPAA (Health Insurance Portability and Accountability Act), Healthcare, Industry Standards, Information/Data Security (InfoSec), Internet Security, Internet Service Providers, Java, Leadership, Maintain Compliance, Microsoft Windows Azure, Multitasking, Needs Assessment, Negotiation Skills, Operational Strategy, PCI-DSS, Process Improvement, Protective Services, Python Programming/Scripting Language, Regulatory Compliance, Regulatory Requirements, Risk Management, Scripting (Scripting Languages), Security Analysis, Security Attacks, Security Monitoring, Security Software, Software Development, Software Testing, State Ordinances, Team Lead/Manager, Team Player, Technical Leadership, Technical Support, Test Automation, Test Tools, Threat Modeling, Unix Shell Programming, Work From Home
LOCATION
Bloomfield, CT
POSTED
4 days ago

Product Security Senior Advisor

Position Summary:

We are looking for a highly skilled Product Security Senior Advisor to join our team, focusing on security tools automation for DevSecOps. This role will work directly with developers and cross-functional teams to integrate security tools within our development pipelines, ensuring robust security measures are in place across our products and applications. The ideal candidate will have extensive experience with Automated Application Security Testing tools (Example: SAST, DAST, SCA etc), and a proven track record of working on multiple pipeline integrations. This individual will contribute to major technology initiatives aimed at revolutionizing health services and the healthcare delivery system in the United States.

Job Description & Responsibilities:

  • Collaborate daily with development teams to identify and address security needs.

  • Design, develop, and implement automated security solutions within CI/CD pipelines.

  • Integrate and manage Automated Application Security Testing tools (Example: SAST, DAST, SCA, MAST etc.) across multiple development pipelines.

  • Assist in the architectural design and implementation of secure software and systems.

  • Conduct security assessments, threat modeling, and vulnerability analysis to ensure robust security measures.

  • Develop and maintain security testing services and tools to support secure development practices.

  • Provide technical guidance and support to development teams on security best practices.

  • Stay updated on the latest security trends, threats, and technologies to continuously improve our security posture.

  • Foster strong communication and collaborative relationships with development teams to promote a culture of security.

  • Ensure compliance with industry standards and regulatory requirements.

  • Maximize the security efficiency (operational, performance, and cost) of application assets.

Experience Required:

  • 8 plus years of experience in cybersecurity, with a focus on application and product security

  • Bachelor's or Master's degree in Computer Science, Information Security, or a related field.

  • Proven expertise in automating security solutions within development pipelines (CI/CD)

  • Strong understanding of various pipeline touchpoints and integration methods.

  • Cloud experience (AWS, Azure, Google Cloud) is highly desirable.

  • Familiarity with modern security technologies, practices, and standards.

  • Strong knowledge of secure software development practices and principles.

  • Industry certifications such as CISSP, CISM, CEH, or similar are preferred.

  • Excellent leadership and team management skills.

  • Strong communication, relationship-building, and negotiation skills.

  • Ability to work effectively in an Agile environment.

Experience Desired:

  • Knowledge of regulatory and compliance frameworks (e.g., GDPR, HIPAA, PCI-DSS).

  • Hands-on experience with security automation and orchestration.

  • Proficiency in programming and scripting languages relevant to security (e.g., Python, Java, Shell scripting).

  • Ability to manage and prioritize multiple projects in a fast-paced environment.

Education and Training Required:

  • Advanced degree (Master's or higher) in Computer Science, Information Security, or a related field.

  • Relevant industry certifications.

  • Additional training in secure software development, application security, and risk management is highly desirable.

Primary Skills:

  • Advanced expertise in secure software development practices, application security, and security tool integration.

  • Proficiency in Angular and Java for security-related software development and integration.

Additional Skills:

  • Extensive experience with AWS and other cloud platforms, with a focus on securing cloud-based applications and services.

  • Hands-on experience with application security frameworks and tools, including security automation and orchestration.

If you will be working at home occasionally or permanently, the internet connection must be obtained through a cable broadband or fiber optic internet service provider with speeds of at least 10Mbps download/5Mbps upload.

About The Cigna Group

Doing something meaningful starts with a simple decision, a commitment to changing lives. At The Cigna Group, we're dedicated to improving the health and vitality of those we serve. Through our divisions Cigna Healthcare and Evernorth Health Services, we are committed to enhancing the lives of our clients, customers and patients. Join us in driving growth and improving lives.

Qualified applicants will be considered without regard to race, color, age, disability, sex, childbirth (including pregnancy) or related medical conditions including but not limited to lactation, sexual orientation, gender identity or expression, veteran or military status, religion, national origin, ancestry, marital or familial status, genetic information, status with regard to public assistance, citizenship status or any other characteristic protected by applicable equal employment opportunity laws.

If you need a reasonable accommodation to complete the online application process, please email seeyourself@thecignagroup.com for assistance. Please note that this email inbox is dedicated to accommodation requests only and cannot provide application updates or accept resumes.

The Cigna Group has a tobacco-free policy and reserves the right not to hire tobacco/nicotine users in states where that is legally permissible. Candidates in such states who use tobacco/nicotine will not be considered for employment unless they enter a qualifying smoking cessation program prior to the start of their employment. These states include: Alabama, Alaska, Arizona, Arkansas, Delaware, Florida, Georgia, Hawaii, Idaho, Iowa, Kansas, Maryland, Massachusetts, Michigan, Nebraska, Ohio, Pennsylvania, Texas, Utah, Vermont, and Washington State.

Qualified applicants with criminal histories will be considered for employment in a manner consistent with all federal, state and local ordinances.

About the Company

T

The Cigna Group