Manager, Cyber Security
Manager, Cyber Security – APAC
Position Summary:
The Manager, Cyber Security is responsible for providing general technical, operational and risk management support to Cigna's Information Protection (CIP) Asia Pacific (APAC) team. This role will support in enforcing standard information protection controls through infrastructure, application and third-party security assessments. Work with the Enterprise Cigna Information Protection team as required to support vulnerability assessments, assisting with penetration tests, tracking and remediation of findings.
This role will work closely with the CIP APAC team to identify, evaluate, and remediate potential weaknesses in Cigna’s systems, using both manual and automated methods. In addition, this role will support the dashboard reporting, coordination of incident responses, risk assessments and other CIP led initiatives & shared services.
About Cigna:
Cigna is a global health service company dedicated to helping the people we serve improve their health, well-being, and peace of mind. But we don’t just care about your well–being, we care about your career health too. That’s why, when you work with us, you can count on a different kind of career – you’ll make a difference, learn a ton, and share in changing the way people think about healthcare.
Job Description & Responsibilities**:**
- Perform issue tracking and resolution with local technology and business teams
- Collaborate with local and International Business Continuity Management team to ensure local BCP/DR controls are compliant with CIP policies & standards and regulatory requirements.
- Work with CIP APAC team and key stakeholders to managing security incidents relevant to the APAC region
- Assist in the review and approval of application/infrastructure changes in terms of security
- Assist in producing accurate security reports with remediation recommendations and communicating risks to technology teams.
- Assist in performing local regulatory reviews/assessments and evaluate compliance of requirements from the local security regulatory notices.
- Assist CIP and technology teams to implement standard security solutions and capabilities that are aligned with business, technology and threat drivers
- Maintain strong working relationships with individuals and groups involved in managing information risks across the organization
- Stay abreast of current and emerging security threats and security architectures to mitigate the threats
- Collaborate with CIP shared services to ensure timely and effective service delivery to the APAC region.
- Monitor progress of staff awareness of phishing tests and awareness training.
Skills required:
- Demonstrated ability to work as both an individual contributor and a team player in a fast paced environment.
- Demonstrated ability to identify cyber security risks and develop treatment plans working with key stakeholders
- Coordinate with people and teams to forecast activity completion and the ability to work in a team environment, sharing workloads and responsibilities.
- Knowledge of Windows and *nix-based operating systems.
- Understanding of core Internet protocols (e.g. TCP, UDP, DNS, TLS, IPsec) and the OSI model.
- Understanding of encryption fundamentals (symmetric/asymmetric, ECB/CBC operations, AES, etc.).
- Understanding of Cloud environments such as SaaS, PaaS and IaaS.
- Understanding of OWASP.
- Knowledge of networking fundamentals and common attacks.
- Ability to analyze vulnerabilities and misconfigurations, appropriately characterize threats, and provide remediation recommendations.
Qualifications:
- Bachelor's degree in Technology, Computer Science or related subjects preferred.
- Strong understanding of security frameworks, standards, and best practices (e.g., NIST CSF, ISO 27001, PCIDSS v.4).
- Knowledge and experience in Singapore Technology related regulations (e.g. MAS Technology Risk Management Guideline).
- 5 years or more of security operations or security governance, risk and compliance experience.
- CISSP, CRISC or similar certifications desired
- Passionate about security and finding new ways to protect systems as well as break them
- Strong analytical and problem solving skills, with the ability to “think outside the box”.
- Ability to work in a flexible environment with evolving requirements and procedures.
- Strong oral and written communication skills, including a demonstrated ability to prepare documentation and presentations for technical and non-technical audiences.
Specific Responsibilities under Monetary Authority of Singapore (MAS) Individual Accountability and Conduct Guidelines (IACG)
- This role is designated as a Material Risk Personnel (MRPs) under the MAS IACG.
- Support senior management in the oversight of technology and information security risks, ensuring risks are identified, mitigated, monitored, and reported in line with MAS TRMG and MAS IACG.
- Manage material cyber and technology risks within scope, including timely escalation of risks, incidents, and control weaknesses.
- Ensures risk‑based decisions, documented risk acceptance, and audit‑ready records of assessments, decisions, and remediation.
- Ensure incidents with potential regulatory, customer, or material business impact are escalated without undue delay and subject to post‑incident review.
- Supports the senior manager in fulfilling MAS IACG responsibilities through clear risk reporting, ownership assignment, issue tracking, and escalation of overdue or high residual risks.
- Oversees third‑party and outsourcing security risks, including escalation of material supplier risks impacting regulatory compliance or operational resilience.
- Demonstrates sound conduct and prudent risk management, proactively challenging practices that expose the organization to unmanaged cyber or technology risk.
About The Cigna Group
Doing something meaningful starts with a simple decision, a commitment to changing lives. At The Cigna Group, we’re dedicated to improving the health and vitality of those we serve. Through our divisions Cigna Healthcare and Evernorth Health Services, we are committed to enhancing the lives of our clients, customers and patients. Join us in driving growth and improving lives.