> Markdown version of [/jobs/ext/1039621-information-protection-senior-advisor-cloud-vulnerability-management](https://www.wearedevelopers.com/jobs/ext/1039621-information-protection-senior-advisor-cloud-vulnerability-management). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Protection Senior Advisor - (Cloud Vulnerability Management) - **Company:** Cigna - **Location:** Bloomington, MN, United States (Remote available) - **Experience:** Expert - **Salary:** $124,600.0 - $207,600.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), JavaScript (Programming Language), Amazon Web Services, Data Analysis, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Continuous Integration, Data Security, Internet Service Provider, Python (Programming Language), Systems Development Life Cycle, Red Hat Enterprise Linux, Software Engineering, Systems Integration, Software Vulnerability Management, Circleci, Google Cloud, Cloud Platform System, Multi-Cloud, Gitlab-ci, Kubernetes, Information Technology, Prisma Cloud Platform, Oracle Cloud Infrastructure, Devsecops, Docker, Jenkins, Static Application Security Testing, Vulnerability Analysis, Programming Languages, Dynamic Application Security Testing - **Published:** June 23, 2026 - **Apply:** https://cigna.wd5.myworkdayjobs.com/cignacareers/job/Bloomington-MN/Information-Protection-Senior-Advisor----Cloud-Vulnerability-Management-_26007137 ## About the Role * 5+ years of experience in information security, vulnerability management, cloud security, DevSecOps, or a related field * Hands-on experience with cloud vulnerability and security tools such as Wiz, Prisma Cloud, TwistLock, Aqua, StackRox (Red Hat ACS), Cloud Conformity, Tenable, or similar * Experience securing cloud environments across AWS, Azure, Google Cloud Platform, and other major cloud providers (e.g., OCI, Alibaba) * Strong knowledge of DevSecOps practices, including container security, Docker, and Kubernetes * Experience integrating security into CI/CD pipelines and the software development lifecycle (SDLC) * Proven ability to perform risk-based vulnerability assessments and communicate impact to technical and non-technical stakeholders * Experience developing automation to improve security operations and remediation efficiency * Strong understanding of security frameworks, risk models, and industry best practices * Demonstrated ability to operate in a complex, matrixed environment-leading initiatives, influencing stakeholders, and driving outcomes * Strong analytical, problem-solving, and communication skills, * Bachelor's degree in Information Security, Computer Science, or a related field * Experience with application security testing tools (SAST, DAST, IAST, SCA) * Familiarity with programming languages such as Python, Java, or JavaScript * Experience with CI/CD tools such as Jenkins, GitLab CI/CD, or CircleCI * Experience in a regulated industry such as healthcare, financial services, or government * Relevant certifications such as CISSP, CISM, or similar If you will be working at home occasionally or permanently, the internet connection must be obtained through a cable broadband or fiber optic internet service provider with speeds of at least 10Mbps download/5Mbps upload. ## Description Are you passionate about strengthening cloud security at scale? This role leads the strategy and technical evolution of the enterprise cloud vulnerability management program-driving secure-by-design practices and measurable risk reduction across a complex, multi-cloud environment. You will partner across engineering, architecture, and security teams to integrate security governance into cloud development processes and ensure vulnerabilities are identified, prioritized, and remediated effectively., * Lead the strategy and continuous evolution of a best-in-class cloud vulnerability management program, advancing automation, analytics, and risk-based prioritization to improve detection and remediation outcomes * Design and implement scalable strategies, workflows, and procedures for identifying, assessing, prioritizing, remediating, and reporting vulnerabilities across public and private cloud environments * Partner with cloud architecture, engineering, and application development teams to maintain comprehensive visibility into vulnerabilities and drive timely risk reduction across large-scale cloud environments * Integrate security best practices and governance into cloud development processes, enabling secure-by-design development and DevSecOps adoption * Deliver and continuously enhance vulnerability and remediation metrics, using KPIs to demonstrate program effectiveness, reduce risk, and drive accountability * Develop and execute integration and automation strategies across multiple vulnerability management and cloud security toolsets * Perform risk-based technical assessments to evaluate exposure and recommend mitigation strategies * Monitor security alerts and advisories and coordinate cross-functional response to ensure vulnerabilities are properly addressed * Analyze vulnerability data to identify trends, emerging risks, and opportunities to strengthen security posture * Translate technical risks into clear, business-aligned insights, effectively communicating urgency and impact to technical and non-technical stakeholders * Lead cross-functional discussions, build consensus, and influence stakeholders across engineering and business teams to accelerate remediation outcomes * Communicate program status, priorities, risks, and progress to leadership and key stakeholders, including accomplishments, blockers, and next steps * Stay current on emerging threats, vulnerabilities, and industry best practices to continuously improve program effectiveness ## Related Videos - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Road to MLOps: How Verivox Transitioned to AWS](https://www.wearedevelopers.com/videos/1050-the-road-to-mlops-how-verivox-transitioned-to-aws) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Enterprise-Cloud-Native - Fast-Paced Development & Deployment in a Highly Secure Banking Environment](https://www.wearedevelopers.com/videos/671-enterprise-cloud-native-fast-paced-development-deployment-in-a-highly-secure-banking-environment) - [Serverless: Past, Present and Future](https://www.wearedevelopers.com/videos/34-serverless-past-present-and-future) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)