Job Description
Information Protection Senior Advisor
Remote
United States Work atHome
time type
Full time
job requisition id
24002609
The Cigna Group Incident Response Teamis looking for a security professional to detect and respond to cyber threats on premise as well in the cloud. Viewed as an expert in a specific aspect of information security. Undertakes complex projects requiring additional specialized technical knowledge. Makes well-thought-out decisions on complex or ambiguous information security issues. Provides architectural oversight and direction for enterprise-wide security technology. Ensures high-level integration of application development with information security policies and strategies. Stays up-to-date on the direction of emerging industry standards. Identifies, evaluates, conducts, schedules and leads technical analyses functions to ensure all applicable IS security requirements are met. Provides technical analysis of requirements necessary for the protection of all information processed, stored, or transmitted by systems. Acts as a resource for direction, training and guidance for less experienced staff. This role requires practical experience responding to cloud security events in a large, global environment.
- Conduct network forensics, host forensics, log analysis, and malware triage in support of Incident Response investigations
- Monitor information security events to identify potential incidents for remediation
- Participate in small and large scale security investigations
- Develop comprehensive and accurate reports and presentations for both technical and executive audiences.
- Effectively communicate investigative findings and strategy to technical staff, executive leadership and legal counsel.
- Interface with Cloud Engineering teams to provide security perspective during
- Work with security and IT operations to implement remediation plans in response to incidents.
- Work hand-in-hand with other Security Advisors and all relevant stakeholders to identify, remediate and bring closure to all potential security related threats
- Document incident response SOPs and playbooks
- Identify gaps and recommend improvements to enterprise technology environment across all platforms, with a goal to enhance the overall security posture of Cigna.
- Event monitoring process and technical improvements.
- Participate in Internal/External Compliance Audits
- Produce Weekly/Monthly/Yearly Incident Response KPI/KRI metrics
- Participate in an on-call rotation
- Potential involvement in Red Team campaigns
- Perform other duties as assigned
Qualifications
- Bachelor’s degree preferred
- Ideally 3 years or more experience with Disk and Memory forensics, Network Security, network traffic analysis and log analysis, static and dynamic malware analysis
- Knowledgeable and experienced with Cloud security
- Thorough understanding of enterprise security controls in Active Directory / Windows and UNIX environments
- Excellent verbal and written communication and presentation skills.
- Understanding of information risk management concepts.
- Experience leveraging the Cyber Kill Chain and MITRE Attack Framework
- Ability to diagnose and troubleshoot technical issues, excellent problem solving skills
- Experience using incident response and analysis tools such as Volatility, wireshark, sysinternal, Splunk, Tanium, EnCase, F-Response, SIFT, REMnux,
- Experience deobfuscating potentially malicious content.
- Experience doing static and dynamic malware analysis.
- Experience with one or more scripting languages such as Perl, Python, Bash and PowerShell highly desired.
- Exceptional understanding of the cyber threat landscape, attack surfaces, and threats associated with each
- Experience leading team members, directing staff priorities and completing reviews to ensure quality work products preferred
- Ability to travel up to 10%
- Ability to successfully interface with internal clients
- Ability to document and explain technical details in a concise, understandable manner
- Ability to manage and balance own time among multiple tasks, and lead junior staff when require and to work independently and as part of a team