Info Protection Advisor-App Security Eng- Hybrid

cigna

Bloomfield (CT)

Remote

USD 156.000 - 172.000

Vollzeit

Vor 9 Tagen
Bewerbungsgenerator

Schick keinen Standard-Lebenslauf — erstelle einen Lebenslauf und ein Anschreiben, die genau auf diese Rolle zugeschnitten sind.

Schaffe es an den ATS-Filtern vorbei

Benefits dieser Stelle

Health benefits
401(k)
Paid time off
Tuition reimbursement

Zusammenfassung

The Cigna Group is seeking an application security specialist to help integrate security into the software development lifecycle. You will assist with code reviews, risk assessments, and secure CI/CD practices to protect applications across cloud environments.

Join a team focused on reducing risk and improving security across products. Telecommuting is permitted, with a competitive salary and comprehensive benefits, including health, retirement, and education support.

Qualifikationen

  • Bachelor's degree in Computer Science or related field and 5 years of experience.
  • Integrating security at every phase of the Software Development Lifecycle.
  • Identifying threats and vulnerabilities early in design.
  • Using SAST/DAST tools to analyze code and apps for vulnerabilities.
  • Applying secure coding standards across languages (OWASP Top 10).
  • Identifying, prioritizing, and remediating vulnerabilities with Nessus, Qualys, Burp Suite.
  • Secure identity management including OAuth, SAML, and JWT.
  • Embedding security into CI/CD pipelines (DevSecOps).
  • GitHub Actions and Jenkins for DevSecOps integration.
  • Cloud app security including container security.
  • Assessing risk and compliance with NIST/ISO 27001.
  • Detecting and responding to app-level security incidents.

Aufgaben

  • Assist with security inspection of code and CI/CD deployment framework to improve speed and security.
  • Serve as subject matter expert on application security in SDLC design and lifecycle.
  • Perform risk assessments of services and architectures and recommend security enhancements.
  • Assist with secure code reviews and AppSec assessments across development teams.
  • Support automated security controls in CI/CD pipelines and DevSecOps practices.
  • Educate teams on remediation of vulnerabilities detected by SAST/DAST tools.
  • Establish and maintain secure coding standards and best practices.

Kenntnisse

Application security
CI/CD
DevSecOps
SAST/DAST
Nessus
Qualys
Burp Suite
GitHub Actions
Jenkins
OAuth
SAML
JWT

Ausbildung

Bachelor's degree in Computer Science

Tools

Nessus
Qualys
Burp Suite
GitHub Actions
Jenkins

Jobbeschreibung

Responsibilities:
  • Assist with the inspection of application code for security issues, building a new framework to help our software developers deploy faster and more securely through CI/CD Integration, or performing assessments on existing software development lifecycle practices to ensure security standards are met.
  • Act as a subject matter expert on application security to improve and further integrate security best practices into product design and software development lifecycles (SDLC) of the organization.
  • Perform focused risks assessments of existing or new services and technologies, security architecture, identifies design gaps, risks, and recommends security enhancements.
  • Assist development teams with secure code reviews and other AppSec assessments to educate development teams on security weaknesses and vulnerabilities.
  • Assist with the implementation and management of automated security controls as part of CICD pipelines and DevSecOps philosophies.
  • Assist with the education of development teams on the remediation of vulnerabilities detected in SAST, SCA, and DAST security tools.
  • Establish and maintain secure coding standards and best practices to provide guidance and training to development teams on security best practices.

Telecommuting permitted.

Qualifications:
  • Bachelor’s degree in Computer Science or related field and 5 years of experience.
  • Full term of experience must include: Integrating security at every phase of the Software Development Lifecycle;
  • Identifying potential threats and vulnerabilities early in the design phase;
  • Using SAST/DAST tools and techniques to analyze source code and running applications for vulnerabilities;
  • Utilizing secure coding standards, including OWASP Top 10 and SEI Cert, across multiple languages;
  • Identifying, prioritizing, and remediating vulnerabilities using tools including Nessus, Qualys, and Burp Suite;
  • Secure identity management including authentication, authorization mechanisms, and role-based controls using tools including OAuth, SAML, and JWT;
  • Embedding security into CI/CD pipelines;
  • GitHub Actions for DevSecOps Integration; Jenkins for DevSecOps Integration;
  • Securing applications deployed in cloud environments, including container security;
  • Assessing application risk and compliance with security standards including NIST and ISO 27001; and
  • Detecting, analyzing, and responding to application-level security incidents.

Telecommuting permitted.

Salary Range: $155,958-$171,900/year

For this position, we anticipate offering an annual salary of 103,100 - 171,900 USD / yearly, depending on relevant factors, including experience and geographic location.

This role is also anticipated to be eligible to participate in an annual bonus plan.

At The Cigna Group, you’ll enjoy a comprehensive range of benefits, with a focus on supporting your whole health. Starting on day one of your employment, you’ll be offered several health-related benefits including medical, vision, dental, and well-being and behavioral health programs. We also offer 401(k), company paid life insurance, tuition reimbursement, a minimum of 18 days of paid time off per year, paid holidays, and leaves of absence. For more details on our employee benefits programs, click here.

About The Cigna Group

Doing something meaningful starts with a simple decision, a commitment to changing lives. At The Cigna Group, we’re dedicated to improving the health and vitality of those we serve. Through our divisions Cigna Healthcare and Evernorth Health Services, we are committed to enhancing the lives of our clients, customers and patients. Join us in driving growth and improving lives.

Qualified applicants will be considered without regard to race, color, age, disability, sex, childbirth (including pregnancy) or related medical conditions including but not limited to lactation, sexual orientation, gender identity or expression, veteran or military status, religion, national origin, ancestry, marital or familial status, genetic information, status with regard to public assistance, citizenship status or any other characteristic protected by applicable equal employment opportunity laws.

If you need a reasonable accommodation to complete the online application process, please email seeyourself@thecignagroup.com for assistance. Please note that this email inbox is dedicated to accommodation requests only and cannot provide application updates or accept resumes.

The Cigna Group has a tobacco-free policy and reserves the right not to hire tobacco/nicotine users in states where that is legally permissible. Candidates in such states who use tobacco/nicotine will not be considered for employment unless they enter a qualifying smoking cessation program prior to the start of their employment. These states include: Alabama, Alaska, Arizona, Arkansas, Delaware, Florida, Georgia, Hawaii, Idaho, Iowa, Kansas, Maryland, Massachusetts, Michigan, Nebraska, Ohio, Pennsylvania, Texas, Utah, Vermont, and Washington State.

Qualified applicants with criminal histories will be considered for employment in a manner consistent with all federal, state and local ordinances.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.

oder ziehe deine Datei hierhin.

Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Info Protection Advisor-App Security Eng- Hybrid
Info Protection Advisor-App Security Eng- Hybrid

Cigna Health and Life Insurance Company • Bloomfield (CT)

Remote
USD 156.000 - 172.000
Telecommuting permitted
Annual bonus potential
Senior Full Stack Developer- Senior Advisor
Senior Full Stack Developer- Senior Advisor

cigna • Tallahassee (FL)

Vor Ort
USD 130.000 - 217.000
Health benefits
401(k)
Life insurance
+3
Technology Development Program (TECDP) - Cyber Security Track - Start Date: July 12, 2027
Technology Development Program (TECDP) - Cyber Security Track - Start Date: July 12, 2027

Cigna Healthcare • Bloomfield (CT)

Hybrid
USD 72.000 - 121.000
Medical benefits
Vision & Dental coverage
401(k)
+3
Senior Principal, Enterprise Identity & Access Management Architect
Senior Principal, Enterprise Identity & Access Management Architect

The Cigna Group • Bloomfield (CT)

Hybrid
USD 175.000 - 291.000
Health, vision, dental benefits
401(k) plan
Life insurance
+2
Information Protection Advisor - SSP & CMMC Programs
Information Protection Advisor - SSP & CMMC Programs

The Cigna Group • BLOOMINGTON (MN)

Hybrid
USD 103.000 - 172.000
Annual bonus plan
Medical, vision, dental benefits
401(k)
+1
The Cigna Group's Technology Development Program - Cybersecurity Track Summer Internship
The Cigna Group's Technology Development Program - Cybersecurity Track Summer Internship

The Cigna Group • Bloomfield (CT)

Vor Ort
USD 34.000 - 45.000
Senior Full Stack Developer- Senior Advisor
Senior Full Stack Developer- Senior Advisor

Evicore Healthcare • Newton (MA)

Vor Ort
USD 130.000 - 217.000
Annual bonus plan
Medical, vision, dental benefits
401(k)
VP, Strategic Intelligence & Market Insights
VP, Strategic Intelligence & Market Insights

The Cigna Group • Philadelphia

Vor Ort
USD 256.000 - 384.000
Annual bonus opportunity
Comprehensive benefits package
Application Development Senior Advisor- Hybrid
Application Development Senior Advisor- Hybrid

The Cigna Group • Bloomfield (CT)

Hybrid
USD 154.000 - 204.000
Health benefits
401(k)
Tuition reimbursement
+1
Software Engineering Advisor- Hybrid
Software Engineering Advisor- Hybrid

Cigna Health and Life Insurance Company • Bloomfield (CT)

Hybrid
USD 154.000 - 186.000
Health benefits
401(k) plan
Tuition reimbursement
+1