Get more replies from employers
Send a job-specific resume in minutes.
The Cigna Group in Singapore seeks a Manager, Cyber Security – APAC to support information protection across the APAC region. You will help enforce controls, conduct vulnerability assessments, and assist with penetration testing and remediation of findings.
You will work with CIP APAC to identify weaknesses, track risks, and produce security reports, while coordinating incident responses and regulatory reviews as needed.
The Manager, Cyber Security is responsible for providing general technical, operational and risk management support to Cigna's Information Protection (CIP) Asia Pacific (APAC) team. This role will support in enforcing standard information protection controls through infrastructure, application and third-party security assessments. Work with the Enterprise Cigna Information Protection team as required to support vulnerability assessments, assisting with penetration tests, tracking and remediation of findings.
This role will work closely with the CIP APAC team to identify, evaluate, and remediate potential weaknesses in Cigna’s systems, using both manual and automated methods. In addition, this role will support the dashboard reporting, coordination of incident responses, risk assessments and other CIP led initiatives & shared services.
Cigna is a global health service company dedicated to helping the people we serve improve their health, well-being, and peace of mind. But we don’t just care about your well–being, we care about your career health too. That’s why, when you work with us, you can count on a different kind of career – you’ll make a difference, learn a ton, and share in changing the way people think about healthcare.
Perform issue tracking and resolution with local technology and business teams
Collaborate with local and International Business Continuity Management team to ensure local BCP/DR controls are compliant with CIP policies & standards and regulatory requirements.
Work with CIP APAC team and key stakeholders to managing security incidents relevant to the APAC region
Assist in the review and approval of application/infrastructure changes in terms of security
Assist in producing accurate security reports with remediation recommendations and communicating risks to technology teams.
Assist in performing local regulatory reviews/assessments and evaluate compliance of requirements from the local security regulatory notices.
Assist CIP and technology teams to implement standard security solutions and capabilities that are aligned with business, technology and threat drivers
Maintain strong working relationships with individuals and groups involved in managing information risks across the organization
Stay abreast of current and emerging security threats and security architectures to mitigate the threats
Collaborate with CIP shared services to ensure timely and effective service delivery to the APAC region.
Monitor progress of staff awareness of phishing tests and awareness training.
Demonstrated ability to work as both an individual contributor and a team player in a fast paced environment.
Demonstrated ability to identify cyber security risks and develop treatment plans working with key stakeholders
Coordinate with people and teams to forecast activity completion and the ability to work in a team environment, sharing workloads and responsibilities.
Knowledge of Windows and *nix-based operating systems.
Understanding of core Internet protocols (e.g. TCP, UDP, DNS, TLS, IPsec) and the OSI model.
Understanding of encryption fundamentals (symmetric/asymmetric, ECB/CBC operations, AES, etc.).
Understanding of Cloud environments such as SaaS, PaaS and IaaS.
Understanding of OWASP.
Knowledge of networking fundamentals and common attacks.
Ability to analyze vulnerabilities and misconfigurations, appropriately characterize threats, and provide remediation recommendations.
Bachelor's degree in Technology, Computer Science or related subjects preferred.
Strong understanding of security frameworks, standards, and best practices (e.g., NIST CSF, ISO 27001, PCIDSS v.4).
Knowledge and experience in Singapore Technology related regulations (e.g. MAS Technology Risk Management Guideline).
5 years or more of security operations or security governance, risk and compliance experience.
CISSP, CRISC or similar certifications desired
Passionate about security and finding new ways to protect systems as well as break them
Strong analytical and problem solving skills, with the ability to “think outside the box”.
Ability to work in a flexible environment with evolving requirements and procedures.
Strong oral and written communication skills, including a demonstrated ability to prepare documentation and presentations for technical and non-technical audiences.
This role is designated as a Material Risk Personnel (MRPs) under the MAS IACG.
Support senior management in the oversight of technology and information security risks, ensuring risks are identified, mitigated, monitored, and reported in line with MAS TRMG and MAS IACG.
Manage material cyber and technology risks within scope, including timely escalation of risks, incidents, and control weaknesses.
Ensures risk‑based decisions, documented risk acceptance, and audit‑ready records of assessments, decisions, and remediation.
Ensure incidents with potential regulatory, customer, or material business impact are escalated without undue delay and subject to post‑incident review.
Supports the senior manager in fulfilling MAS IACG responsibilities through clear risk reporting, ownership assignment, issue tracking, and escalation of overdue or high residual risks.
Oversees third‑party and outsourcing security risks, including escalation of material supplier risks impacting regulatory compliance or operational resilience.
Demonstrates sound conduct and prudent risk management, proactively challenging practices that expose the organization to unmanaged cyber or technology risk.
Doing something meaningful starts with a simple decision, a commitment to changing lives. At The Cigna Group, we’re dedicated to improving the health and vitality of those we serve. Through our divisions Cigna Healthcare and Evernorth Health Services, we are committed to enhancing the lives of our clients, customers and patients. Join us in driving growth and improving lives.