Cyber Security Senior Manager - Hyderabad, India - Evernorth

    Evernorth
    Default job background
    Description

    ABOUT EVERNORTH:

    Evernorth exists to elevate health for all, because we believe health is the starting point for human potential and progress. As champions for affordable, predictable and simple health care, we solve the problems others dont, wont or cant. Our innovation hub in India will allow us to work with the right talent, expand our global footprint, improve our competitive stance, and better deliver on our promises to stakeholders. We are passionate about making healthcare better by delivering world-class solutions that make a real difference.

    We are always looking upward. And that starts with finding the right talent to help us get there.

    Role Title: Cyber Security Senior Manager

    Position Summary:

    The Information Protection Senior Manager is responsible for providing general technical, operational and review support to Cigna's Information Protection (CIP) Organization.

    This role will support in enforcing standard information protection controls through infrastructure, application and third-party security assessments. Balance multiple project priorities appropriately. Work with the Cigna Information Protection team as required to support reviews, product implementations and security audits.

    Support the Regional Information Security Officer (RISO) on dashboard reporting, coordination of incident responses, risk assessments and CIP led initiatives. Assist the RISO with the overall direction and strategy of the Information Security function in collaboration with the CISOs leadership team.

    Strategically you will be responsible for delivery of the last mile execution of all Cigna Information Protection global Shared Services, developing and measuring capabilities whilst running subsequent risk mitigation Cyber Information Security Management programs.

    Job Description & Responsibilities:

    Infrastructure / Application reviews:

    • Partners with the enterprise to implement standard security solutions and capabilities that are aligned with business, technology and threat drivers
    • Performs focused risks assessments of existing or new services and technologies, security architecture, identifies design gaps, risks, and recommends enhancements
    • Communicates risk assessment findings to information security customers, or business partners. Explore risk mitigation controls
    • Serves as an information security expert and trusted advisor to partners in IT and the business
    • Evaluate compliance of operation processes with Information Protection policies and related government regulations
    • Identifies and implements appropriate controls to effectively manage information risks as needed
    • Identifies opportunities to improve risk posture, developing solutions for remediating or mitigating risks and assessing residual risk
    • Maintains strong working relationships with individuals and groups involved in managing information risks across the organization
    • Stays abreast of current and emerging security threats and designs security architectures to mitigate them

    Service Partner Security Assessment:

    • Plan and perform site reviews of physical and IT facilities, measuring actual conditions against submitted responses. Evaluate IT processes to ensure effective information protection is practiced. Produce site visit reports with improvement recommendation. Track improvement efforts until closure
    • Perform general walkthrough evaluations of new facilities and processes under consideration. Provide recommendation to business
    • Meet with vendors and employees to resolve or track compliance issues
    • Attend demonstrations of applications and prepare reports on potential for data leakage or infrastructure security issues
    • Review any regular security reports for abnormality
    • Work with supplier chain management on contracts to include security terms
    • Escalation to the fellow CIP team on security issues related to service partners

    Support the Regional Information Security Officer:

    • Work with individual local security teams assigned to ensure security controls applied are compliant to CIP policies and standards
    • Work with the RISO on managing security incidents
    • Regular risk & activity reporting
    • Issue tracking with local security teams
    • Review and approval of application/infrastructure changes in terms of security
    • Coordinate CIP initiatives with other countries as required
    • Maintain strong working relationships with individuals and groups involved in managing information risks across the organization
    • Partner with the CIP and IT teams to implement standard security solutions and capabilities that are aligned with business, technology and threat drivers
    • Stay abreast of current and emerging security threats and security architectures to mitigate the threats
    • Recruit and develop talent that will drive the organization to higher performance

    Experience Required:

    • Min. 10+ years of experiencein Information Security / Cyber or related risk management experience.
    • Qualified candidates will typically have 8+ of professional IT experience work experience, with 3+ years of experience in a leadership type role, and 5 years in information security

    Experience Desired:

    • Experience with process and change management, reporting and incident handling
    • Experience with assessing and mitigating risk
    • Experience with contracting and negotiations
    • Health Insurance or Health Care Industry experience is a plus
    • Travel required, approximately 10%
    • Experience leading teams of over 3-5 employees

    Education and Training Required:

    • BS degree or equivalent experience
    • CISSP, CISA, CISM, CRISC or similar certifications required
    • Experience and working knowledge of HIPPA, PCI DSS & ISO 27001 certification is a plus
    • Broad high level knowledge, hands-on experience, and exposure to a wide range of IT subject areas, business, IT & physical controls

    Primary Skills:

    • Organizational courage to escalate and resolve risk issues
    • Support the end-to-end security technology posture, including end-point, network, mail, perimeter
    • Technical depth and working knowledge in networking, desktop, server, storage, software-defined-networking, virtualization and application domains
    • Effectively manage penetration testing (white box and black box) and elevate Red Team and Blue Team methodology for the region
    • Assists with optimizing and maintaining a 24x7 Global Security Operations Center (G-SOC) and Security Information Event Monitoring (SIEM)
    • Experience leading teams of over 3-5 employees
    • Maintain a constructive, team-oriented and customer-focused attitude at all times and in all settings
    • Recruit and develop talent that will drive the organization to higher performance
    • Stay abreast of technological advances and continuously research better ways to accomplish tasks, and integrate new security technologies
    • Proactively update skill set in support of technology integration and design
    • Flexible can adapt to changing organization changing business needs, technological advances and agile methodology
    • Demonstrates technical skills in infrastructure, application and third party security assessments.
    • Self-starter and shows empathy towards business requirements and able to influence changes to facilitate security

    Additional Skills:

    • Strong written and spoken English skills, demonstrated ability to communicate at high levels, both verbally and in reporting
    • A manager who regularly brings and seeks new ideas, insights and knowledge, and drives the organization to implement new programs and solutions
    • The ability to think strategically as well as successfully implement tactical plans
    • Strong interpersonal, people development and management skills; motivating others with high expectations and clear performance expectations
    • Able to inspire, motivate and lead diverse teams and the organization. A strong manager who energizes and empowers the team.
    • Strong work ethic, high drive and ability to focus. High stamina. Shows optimism and determination when facing challenges
    • Ability to work successfully with a minimum of supervision in a fast paced and sometimes pressured environment