Cyber Security Lead Analyst
ABOUT EVERNORTH:
Evernorth℠ exists to elevate health for all, because we believe health is the starting point for human potential and progress. As champions for affordable, predictable and simple health care,
we solve the problems others don’t, won’t or can’t.
Our innovation hub in India will allow us to work with the right talent, expand our global footprint, improve our competitive stance, and better deliver on our promises to stakeholders. We are passionate about making healthcare better by delivering world-class solutions that make a real difference.
We are always looking upward. And that starts with finding the right talent to help us get there.
Required Experience & Education:
· Bachelor’s degree in information security, computer science, or a related discipline.
· 6 - 8 years of experience in cybersecurity, threat management, CSIRT, SOC, vulnerability management, or related defense functions.
· Demonstrated experience coordinating enterprise‑scale threat triage and remediation activities, particularly for external exposure.
· Relevant professional certifications (e.g., GCIH, GCIA, CRISC, CISSP, or equivalent) are desirable.
· Strong passion for cybersecurity, emerging threats, and attacker tradecraft, balanced with a practical remediation and risk‑reduction focus.
· Ability to adapt to evolving tools, threats, and operational models.
· Strong oral and written communication skills, including experience producing documentation and presentations for technical and executive audiences.
Position Overview:
The Cyber Security Lead Analyst is responsible for owning the triage, analysis, and remediation coordination of public‑facing cyber threats across The Cigna Group’s expanding external attack surface. This role drives threat workflows from initial discovery through risk‑based prioritization and coordinated remediation, leveraging attack surface management platforms and emerging AI‑driven discovery technologies.
The position extends enterprise threat management capabilities by integrating threat intelligence, vulnerability management, and exposure telemetry across infrastructure, applications, cloud environments, and third‑party services. Operating in close alignment with Cyber Defense, CSIRT, and Attack Surface Management functions, the role enables continuous, follow‑the‑sun coordination to ensure timely response to externally exposed risk.
At the Lead Analyst level, this role provides technical leadership, independent judgment, and operational ownership, ensuring threat management activities are executed consistently with global security standards, policies, and risk management objectives.
Responsibilities
· Own the triage, analysis, and remediation coordination of externally exposed vulnerabilities, misconfigurations, and threat findings identified through attack surface management platforms, vulnerability scanning, automated testing, and AI‑driven discovery.
· Drive risk‑based prioritization by correlating exposure data with threat intelligence, attacker activity, exploitability, and business impact.
· Act as a central coordination point across threat intelligence, CSIRT, vulnerability management, cloud security, application, and infrastructure teams to accelerate remediation of internet‑facing risk.
· Partner directly with remediation owners to define remediation approaches, track execution, escalate material risk, and ensure closure aligned to enterprise SLAs and risk tolerance.
· Analyze internal and external cyber threat intelligence to identify active, emerging, or likely‑to‑be‑exploited threats relevant to the organization’s public attack surface.
· Assess adversary tactics, techniques, and indicators to support threat‑informed decision‑making and incident response readiness.
· Enable continuous, global threat operations by supporting handoffs, documentation, and coordination across regions and service providers.
· Ensure threat management practices, tooling usage, and remediation workflows align with enterprise security standards, policies, and governance requirements.
· Provide audit‑ready evidence, analysis, and subject‑matter expertise to support regulatory, internal, and third‑party assessments related to threat and exposure management.
· Maintain strong working relationships with IT, cloud, application, risk, governance, and third‑party teams responsible for managing external risk.
· Contribute to the continuous improvement of attack surface and threat management processes, incorporating new tooling, AI‑driven discovery capabilities, and evolving attacker techniques.
· Define, track, and analyze KPIs and KRIs to support leadership visibility, operational oversight, and risk‑based decision‑making.
· Contribute threat intelligence insights to enterprise risk assessments and executive‑level reporting.
· Review application and infrastructure changes for external exposure and security risk implications.
· Produce clear, actionable security reporting and communicate risk findings effectively to technical and non‑technical stakeholders.
Required Skills:
· Strong understanding of cyber threat management, attack surface management, and external exposure risk.
· Ability to independently analyze, correlate, and prioritize threat and vulnerability data from multiple discoveries and intelligence sources.
· Working knowledge of vulnerability management, application security, and cloud security platforms.
· Solid understanding of attacker techniques targeting public‑facing enterprise environments.
· Strong foundation in networking, operating systems, web technologies, and enterprise platforms.
· Knowledge of cloud service models (SaaS, PaaS, IaaS) and associated security risks.
· Ability to assess severity, prioritize remediation, and clearly communicate risk to diverse audiences.
· Strong understanding of the cyber threat intelligence lifecycle and analytical tradecraft.
· Demonstrated ability to translate threat intelligence into enterprise‑relevant risk context.
· Proven stakeholder coordination skills across security operations, engineering, risk, governance, and third parties.
· Ability to operate independently in fast‑paced, high‑visibility environments with minimal oversight.
· Strong written and verbal communication skills with an audit‑ready, documentation‑focused mindset.
· Strong analytical and problem‑solving skills with attention to detail.
· Ability to provide technical guidance and influence improvements to threat and exposure management practices.
· Working knowledge of OWASP Top 10 and web application security fundamentals.
Location & Hours of Work
- Full-time position, working 45 hours per week. Expected overlap with US hours as appropriate – Evening or Night Shift
- Primarily based in the Innovation Hub in Hyderabad, India in a hybrid working model (3 days WFO and 2 days WAH)
Equal Opportunity Statement
Evernorth is an Equal Opportunity Employer actively encouraging and supporting organization-wide involvement of staff in diversity, equity, and inclusion efforts to educate, inform and advance both internal practices and external work with diverse client populations.
About Evernorth Health Services
Evernorth Health Services, a division of The Cigna Group, creates pharmacy, care and benefit solutions to improve health and increase vitality. We relentlessly innovate to make the prediction, prevention and treatment of illness and disease more accessible to millions of people. Join us in driving growth and improving lives.