Info Protection Advisor-App Security Eng- Hybrid

Cigna

• $155K — $171K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science or related field with 5 years of experience.
  • Experience integrating security throughout the Software Development Lifecycle.
  • Proficient in identifying threats and vulnerabilities during the design phase.
  • Skilled in using SAST/DAST tools for vulnerability analysis.
  • Familiar with secure coding standards like OWASP Top 10 and SEI Cert across multiple languages.
  • Experience with tools for vulnerability remediation such as Nessus, Qualys, and Burp Suite.
  • Knowledge of secure identity management and authentication mechanisms.

Responsibilities

  • Inspect application code for security issues and build frameworks for secure CI/CD integration.
  • Act as a subject matter expert to enhance security practices in product design and SDLC.
  • Conduct risk assessments of services and technologies, identifying design gaps and recommending enhancements.
  • Support development teams with secure code reviews and AppSec assessments.
  • Implement and manage automated security controls in CI/CD pipelines.
  • Educate teams on remediating vulnerabilities detected by security tools.
  • Establish and maintain secure coding standards and provide training to development teams.

Benefits

  • Comprehensive health benefits including medical, vision, and dental from day one.
  • Well-being and behavioral health programs available.
  • 401(k) plan with company contributions.
  • Company-paid life insurance.
  • Tuition reimbursement for further education.
  • Minimum of 18 days of paid time off per year, plus paid holidays.
  • Leaves of absence for personal needs.
Full Job Description
Cigna-Evernorth Services Inc. seeks an Info Protection Advisor - Applic Security Eng for the Bloomfield, CT location to collaborate with software development teams to lead and support Application Security activities that guide the design, development and security of code and code repositories for cloud-hosted and open-source applications.

Responsibilities:
• Assist with the inspection of application code for security issues, building a new framework to help our software developers deploy faster and more securely through CI/CD Integration, or performing assessments on existing software development lifecycle practices to ensure security standards are met.
• Act as a subject matter expert on application security to improve and further integrate security best practices into product design and software development lifecycles (SDLC) of the organization.
• Perform focused risks assessments of existing or new services and technologies, security architecture, identifies design gaps, risks, and recommends security enhancements.
• Assist development teams with secure code reviews and other AppSec assessments to educate development teams on security weaknesses and vulnerabilities.
• Assist with the implementation and management of automated security controls as part of CICD pipelines and DevSecOps philosophies.
• Assist with the education of development teams on the remediation of vulnerabilities detected in SAST, SCA, and DAST security tools.
• Establish and maintain secure coding standards and best practices to provide guidance and training to development teams on security best practices.
• Telecommuting permitted.

Qualifications:
• Bachelor's degree in Computer Science or related field and 5 years of experience.
• Full term of experience must include: Integrating security at every phase of the Software Development Lifecycle;
• Identifying potential threats and vulnerabilities early in the design phase;
• Using SAST/DAST tools and techniques to analyze source code and running applications for vulnerabilities;
• Utilizing secure coding standards, including OWASP Top 10 and SEI Cert, across multiple languages;
• Identifying, prioritizing, and remediating vulnerabilities using tools including Nessus, Qualys, and Burp Suite;
• Secure identity management including authentication, authorization mechanisms, and role-based controls using tools including OAuth, SAML, and JWT;
• Embedding security into CI/CD pipelines;
• GitHub Actions for DevSecOps Integration; Jenkins for DevSecOps Integration;
• Securing applications deployed in cloud environments, including container security;
• Assessing application risk and compliance with security standards including NIST and ISO 27001; and
• Detecting, analyzing, and responding to application-level security incidents.
• Telecommuting permitted.

Salary Range: $155,958-$171,900/year

If you will be working at home occasionally or permanently, the internet connection must be obtained through a cable broadband or fiber optic internet service provider with speeds of at least 10Mbps download/5Mbps upload.

For this position, we anticipate offering an annual salary of 103,100 - 171,900 USD / yearly, depending on relevant factors, including experience and geographic location.

This role is also anticipated to be eligible to participate in an annual bonus plan.

At The Cigna Group, you'll enjoy a comprehensive range of benefits, with a focus on supporting your whole health. Starting on day one of your employment, you'll be offered several health-related benefits including medical, vision, dental, and well-being and behavioral health programs. We also offer 401(k), company paid life insurance, tuition reimbursement, a minimum of 18 days of paid time off per year, paid holidays, and leaves of absence. For more details on our employee benefits programs, click here.

Similar Jobs

More Jobs at Cigna

More Information Technology Jobs

Find similar Info Protection Advisor-App Security Eng- Hybrid jobs: