
Information Protection Lead Analyst - HIH - Evernorth
- Hyderabad, Telangana Andhra Pradesh
- Permanent
- Full-time
- Lead and execute internal and external penetration tests against corporate web applications, APIs, networks, Windows and Unix variants to discover vulnerabilities
- Lead and execute mobile application penetration tests for both Android and iOS based devices
- Create comprehensive and accurate penetration testing reports with recommendations for appropriate remediation
- Develop scripts, tools or methodologies to enhance Cigna’s penetration testing processes
- Experience in application vulnerability assessment tools (Burp OR ZAP.)
- Experience with network and server assessment tools (e.g. Nessus, metasploit, nmap, nikto, etc.)
- Understanding of web application frameworks (React, Springboot, Ruby on Rails, J2EE, PHP, ASP.NET)
- Strong experience in manual and automated techniques for penetration testing and executing vulnerability assessments
- Knowledge of Windows and *nix-based operating systems
- Knowledge of networking fundamentals and common attacks
- Coding/scripting experience in modern scripting languages (e.g. Python, Ruby, PowerShell)
- Understanding of Android/iOS based platforms (e.g. Java, Swift, Objective C)
- Exploit development and validation skills
- Ability to analyze vulnerabilities, appropriately characterize threats, and provide remediation recommendations
- Understanding of core Internet protocols (e.g. DNS, HTTP, TCP, UDP, TLS, IPsec)
- Understanding of encryption fundamentals (symmetric/asymmetric, ECB/CBC operations, AES, etc.)
- Demonstrated ability to coordinate people and lead teams to project/activity completion and the ability to work in a team environment, sharing workloads and responsibilities
- High School diploma; Bachelor's degree preferred
- 5-8 years or more of penetration testing experience
- One or more professional certifications such as
- Strong analytical and problem solving skills with the ability to “think outside the box”
- Ability to work in a flexible environment where requirements and procedures continuously evolve
- Strong oral and written communication skills, including a demonstrated ability to prepare documentation and presentations for technical and non-technical audiences