onsite
Senior Advisor, Product Security - DevSecOps - The Cigna Group
Security Engineer
Senior security advisor who partners with engineering to embed automated DevSecOps practices, secure CI/CD pipelines, and application security controls into modern product development cycles.
About the role
Key Responsibilities
- Collaborate with development squads to integrate security controls throughout the software development lifecycle, ensuring safe and scalable product releases.
- Design, develop, and maintain automated security tooling (SAST, DAST, dependency scanning, secret detection) within CI/CD pipelines.
- Define security standards, policies, and best‑practice guidelines for cloud‑native and containerized applications.
- Conduct threat modeling, risk assessments, and security reviews for new features and architectural changes.
- Provide mentorship and training to engineers on secure coding practices and DevSecOps methodologies.
Requirements
- 5+ years of hands‑on experience implementing security automation in CI/CD environments (Jenkins, GitLab, Azure DevOps, etc.).
- Deep knowledge of application security testing tools (SAST, DAST, SCA) and secure coding standards.
- Proficiency with cloud platforms (AWS, Azure, GCP) and container orchestration (Kubernetes, Docker).
- Strong scripting/programming skills (Python, Bash, PowerShell) for building custom security solutions.
- Excellent communication and stakeholder‑management abilities to influence cross‑functional teams.