Cyber Security Lead Analyst

4 days ago


Hyderabad, Telangana, India Cigna Healthcare Full time ₹ 5,00,000 - ₹ 8,00,000 per year

Cyber Security Lead Analyst - HIH - Evernorth

Job Description Summary:

Provides counsel and advice to top management on significant Information Protection matters, often requiring coordination between organizations. Viewed as an expert in a specific aspect of information security. Undertakes complex projects requiring additional specialized technical knowledge. Makes well-thought-out decisions on complex or ambiguous information security issues. Provides architectural oversight and direction for enterprise-wide security technology. Ensures high-level integration of application development with information security policies and strategies. Stays up-to-date on the direction of emerging industry standards. Identifies, evaluates, conducts, schedules and leads technical analyses functions to ensure all applicable IS security requirements are met. Provides technical analysis of requirements necessary for the protection of all information processed, stored, or transmitted by systems. Coordinates with users to determine requirements. Conducts security reviews of external service providers and outsourcing vendors and systems reviews to ensure appropriate security implementation. Focuses on providing thought leadership and technical expertise across multiple disciplines. Recognized internally as "the go-to person" for the most complex Information Protection assignments.

Job Description:

Position Summary: 

The Information Protection Lead Analyst - Penetration Testing is responsible for conducting vulnerability assessments, threat modeling, penetration tests, and red team campaigns of Cigna's IT infrastructure and applications. This role will work closely with the Information Protection Senior Manager to identify, evaluate, and remediate potential weaknesses in Cigna's systems using both manual and automated methods.

As a member of the Cyber Security Incident Response Team, this role will provide second and third level incident response services to the global Cigna enterprise to address Cyber Security threats to the enterprise.  Daily activities will include analysis of logs, memory and disc artifacts and the use of a variety of commercial and open source security tools to respond to and triage threats in global enterprise. This role will focus on Threat Hunting and Incident Response capabilities within Cloud Service Provider environments.

About Cigna:

Cigna is a global health service company dedicated to helping the people we serve improve their health, well-being, and peace of mind. But we don't just care about your well –being, we care about your career health too. That's why when you work with us, you can count on a different kind of career – you'll make a difference, learn a ton and share in changing the way people think about healthcare. 

Responsibilities :

  • Lead and execute internal and external penetration tests against corporate web applications, APIs, networks, Windows and Unix variants to discover vulnerabilities
  • Lead and execute mobile application penetration tests for both Android and iOS based devices
  • Create comprehensive and accurate penetration testing reports with recommendations for appropriate remediation
  • Develop scripts, tools or methodologies to enhance Cigna's penetration testing processes
  • Experience in application vulnerability assessment tools (e.g. Burp, Checkmarx, AppScan, WebInspect, Cenzic, etc.)
  • Experience with network and server assessment tools (e.g. Nessus, metasploit, nmap, nikto, etc.)
  • Understanding of web application frameworks (React, Springboot, Ruby on Rails, J2EE, PHP, ASP.NET)
  • Strong experience in manual and automated techniques for penetration testing and executing vulnerability assessments
  • Knowledge of Windows and *nix-based operating systems
  • Knowledge of networking fundamentals and common attacks
  • Coding/scripting experience in modern scripting languages (e.g. Python, Ruby, PowerShell)
  • Mobile application coding experience with Android/iOS based platforms (e.g. Java, Swift, Objective C)
  • Exploit development and validation skills
  • Ability to analyze vulnerabilities, appropriately characterize threats, and provide remediation recommendations
  • Understanding of core Internet protocols (e.g. DNS, HTTP, TCP, UDP, TLS, IPsec)
  • Understanding of encryption fundamentals (symmetric/asymmetric, ECB/CBC operations, AES, etc.)
  • Demonstrated ability to coordinate people and lead teams to project/activity completion and the ability to work in a team environment, sharing workloads and responsibilities

Qualifications:

  • High School diploma; Bachelor's degree preferred
  • 5-8 years or more of penetration testing experience
  • One or more professional certifications such as OSCP, OSCE, GWAPT, GSEC, GPEN, GXPN
  • Passionate about security and finding new ways to break into systems as well as defend them
  • Strong analytical and problem solving skills with the ability to "think outside the box"
  • Ability to work in a flexible environment where requirements and procedures continuously evolve
  • Strong oral and written communication skills, including a demonstrated ability to prepare documentation and presentations for technical and non-technical audiences

About Evernorth Health Services

Evernorth Health Services, a division of The Cigna Group, creates pharmacy, care and benefit solutions to improve health and increase vitality. We relentlessly innovate to make the prediction, prevention and treatment of illness and disease more accessible to millions of people. Join us in driving growth and improving lives.



  • Hyderabad, Telangana, India Cigna Healthcare Full time ₹ 15,00,000 - ₹ 28,00,000 per year

    Cyber Security Lead Analyst – APAC Position Summary:We are seeking a highly skilled and experienced Cybersecurity Lead Analyst to join our team. This crucial role will focus on Cyber Governance of Contact Centers ensuring the integrity and protection of our systems and data. The ideal candidate will have extensive experience in contact centers and will...


  • Hyderabad, Telangana, India The Cigna Group Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Position Summary: The Cyber Security Lead Analyst  - Penetration Testing is responsible for conducting vulnerability assessments, threat modeling, penetration tests, and red team campaigns of Cigna's IT infrastructure and applications. This role will work closely with the Information Protection Senior Manager to identify, evaluate, and remediate potential...


  • Hyderabad, Telangana, India Madre Integrated Engineering Full time

    Job Role:As a Cyber Security Analyst, they will be responsible for safeguarding the digital infrastructure of our clients. Following the protocols and services put forward by global cybersecurity leaders you will detect, remediate and secure the information security systems of our clients.Key Responsibilities• Monitor, analyze, and respond to security...


  • Hyderabad, Telangana, India Principal Global Services Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    Responsibilities:Security Operations Centre T4 – Experience 7 – 9 yrs.Ready to work in 24*7*365 environment.Must have hands on experience in handling security incidents investigations and response in the cloud environment (AWS, Azure). Role will involve monitoring, investigating end-to-end and responding to the real time security incidents targeting...


  • Hyderabad, Telangana, India Cigna Healthcare Full time ₹ 1,04,000 - ₹ 1,30,878 per year

    Position Summary:We are looking for a highly skilled Cyber Security Lead Analyst to support the Business Information Security Officer (BISO) function within Cigna's Information Protection (CIP) team. This role is responsible for enhancing the organization's cybersecurity posture by aligning with enterprise policies, regulatory requirements, and industry...


  • Hyderabad, Telangana, India Kfin Technologies Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    SOC Lead- Cyber Security SOC Lead:Good Understanding of CIS controls and implementation of OS Hardening parameters for Windows and Linux.SOC Operations, Hands on Experience in configuring and SIEM Implementation, DLP Implementation, Threat Detection and Analysis, Threat hunting Vulnerability Assessment, WAF, CISCO Umbrella, PAM, DAM, Email Security, VAPT...


  • Hyderabad, Telangana, India Wipro Full time ₹ 5,00,000 - ₹ 15,00,000 per year

    Wipro Limited (NYSE: WIT, BSE: 507685, NSE: WIPRO) is a leading technology services and consulting company focused on building innovative solutions that address clients' most complex digital transformation needs. Leveraging our holistic portfolio of capabilities in consulting, design, engineering, and operations, we help clients realize their boldest...


  • Hyderabad, Telangana, India GE VERNOVA Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    **Job Description Summary****Lead software security architect responsible for coordinating across a portfolio of products that are deployed in Critical National Infrastructure (CNI) environments globally. Grid Software is the leading software provider for the real-time operations of national and regional electricity grids globally. In addition, the software...

  • CyberSecurity Lead

    1 week ago


    Hyderabad, Telangana, India QYLIS Cloud Data & Cyber Security Services Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    About QylisQylis is a leading provider of innovative cybersecurity solutions. We are committed to empowering organizations to safeguard their digital assets, mitigate cyber threats, and optimize their operations.Job DescriptionAs the Cybersecurity Department Head, you will play a pivotal role in driving the growth and success of our cybersecurity practice....


  • Hyderabad, Telangana, India QYLIS Cloud Data & Cyber Security Services Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    10+ years of IT/cybersecurity experience with 4+ years as a Security Architect.Strong knowledge of security frameworks and standards (NIST CSF, ISO 27001, TOGAF, SABSA, MITRE ATT&CK).Expertise in cloud security (Azure, AWS, GCP) and cloud-native security controls.Solid understanding of SIEM, SOC, IAM, PAM, DLP, EDR, IDS/IPS, WAF, PKI, and encryption...