Information Protection Lead Analyst - HIH - Evernorth

HIH - Hyderabad, India

⚠️ We'll shut down after Aug 1st - try foo🦍 for all jobs in tech ⚠️

The Cigna Group

Discover The Cigna Group, a global health company committed to improve the health and vitality of those we serve.

View all jobs at The Cigna Group

Apply now Apply later

Information Protection Lead Analyst - HIH - Evernorth

Job Description:

Position Summary: 

The Information Protection Lead Analyst - Penetration Testing is responsible for conducting vulnerability assessments, threat modeling, penetration tests, and red team campaigns of Cigna’s IT infrastructure and applications. This role will work closely with the Information Protection Senior Manager to identify, evaluate, and remediate potential weaknesses in Cigna’s systems using both manual and automated methods.

As a member of the Cyber Security Incident Response Team, this role will provide second and third level incident response services to the global Cigna enterprise to address Cyber Security threats to the enterprise.  Daily activities will include analysis of logs, memory and disc artifacts and the use of a variety of commercial and open source security tools to respond to and triage threats in global enterprise. This role will focus on Threat Hunting and Incident Response capabilities within Cloud Service Provider environments.

About Cigna:

Cigna is a global health service company dedicated to helping the people we serve improve their health, well-being, and peace of mind. But we don’t just care about your well –being, we care about your career health too. That’s why when you work with us, you can count on a different kind of career – you’ll make a difference, learn a ton and share in changing the way people think about healthcare. 

Responsibilities :

  • Lead and execute internal and external penetration tests against corporate web applications, APIs, networks, Windows and Unix variants to discover vulnerabilities
  • Lead and execute mobile application penetration tests for both Android and iOS based devices
  • Create comprehensive and accurate penetration testing reports with recommendations for appropriate remediation
  • Develop scripts, tools or methodologies to enhance Cigna’s penetration testing processes
  • Experience in application vulnerability assessment tools (Burp OR ZAP.)
  • Experience with network and server assessment tools (e.g. Nessus, metasploit, nmap, nikto, etc.)
  • Understanding of web application frameworks (React, Springboot, Ruby on Rails, J2EE, PHP, ASP.NET)
  • Strong experience in manual and automated techniques for penetration testing and executing vulnerability assessments
  • Knowledge of Windows and *nix-based operating systems
  • Knowledge of networking fundamentals and common attacks
  • Coding/scripting experience in modern scripting languages (e.g. Python, Ruby, PowerShell)
  • Understanding of Android/iOS based platforms (e.g. Java, Swift, Objective C)
  • Exploit development and validation skills
  • Ability to analyze vulnerabilities, appropriately characterize threats, and provide remediation recommendations
  • Understanding of core Internet protocols (e.g. DNS, HTTP, TCP, UDP, TLS, IPsec)
  • Understanding of encryption fundamentals (symmetric/asymmetric, ECB/CBC operations, AES, etc.)
  • Demonstrated ability to coordinate people and lead teams to project/activity completion and the ability to work in a team environment, sharing workloads and responsibilities

Qualifications:

  • High School diploma; Bachelor's degree preferred
  • 5-8 years or more of penetration testing experience
  • One or more professional certifications such as

    PNPT, CBBH, CPTS, OSCP GPEN, GWAPT, GMOB

  • Passionate about security and finding new ways to break into systems as well as defend them
  • Strong analytical and problem solving skills with the ability to “think outside the box”
  • Ability to work in a flexible environment where requirements and procedures continuously evolve
  • Strong oral and written communication skills, including a demonstrated ability to prepare documentation and presentations for technical and non-technical audiences

About Evernorth Health Services

Evernorth Health Services, a division of The Cigna Group, creates pharmacy, care and benefit solutions to improve health and increase vitality. We relentlessly innovate to make the prediction, prevention and treatment of illness and disease more accessible to millions of people. Join us in driving growth and improving lives.

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  1  0  0

Tags: AES Android APIs ASP.NET C Cloud DNS Encryption Exploit GMOB GPEN GWAPT Incident response iOS IT infrastructure Java Metasploit Nessus Nmap Open Source OSCP Pentesting PHP PowerShell Python Red team Ruby Scripting TLS UNIX Vulnerabilities Windows

Perks/benefits: Career development Startup environment

Region: Asia/Pacific
Country: India

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.