Sr. Cloud Security Engineer Job at The Cigna Group, Bloomfield, CT

cmN3ck5YeG1nNzZ4TldkOWNrNU1iTUxRSnc9PQ==
  • The Cigna Group
  • Bloomfield, CT

Job Description

Location/Schedule:

Bloomfield, CT onsite minimum of 3 days per week, 9:00 AM - 5:30 PM M-F with occasional off-hours

Role Summary:

This role is a hands-on cloud and application security engineering position focused on modernizing and operating AWS WAF, API security, and application security posture at scale. The work emphasizes automation, policy-as-code, AI assisted analysis, and operational execution, with minimal emphasis on leadership or executive engagement. The contractor will design, build, tune, and operate AWS WAF and API security capabilities, migrate WAF policy management to GitHub based CI/CD, enhance visibility through AWS Security Lake, and automate remediation workflows to reduce manual effort and improve detection fidelity.

Primary Responsibilities:

  • Implement, operate, and tune AWS WAF, Firewall Manager, Shield Advanced, and related AWS security services.
  • Migrate and maintain AWS WAF policies as code using GitHub SaaS, including CI/CD workflows, versioning, testing, and rollback.
  • Build automation (Terraform, Python) to deploy, manage, and validate WAF and application security controls at scale.
  • Integrate WAF, API, and application security telemetry into AWS Security Lake to support detection, investigation, and analytics.
  • Apply AI assisted techniques to:
  • Reduce WAF false positives
  • Improve rule tuning and coverage
  • Accelerate threat detection and log analysis
  • Develop automation and scripts to produce actionable outputs from the API Ownership Framework, improving visibility and accountability.
  • Evaluate and enhance application security posture management (ASPM) and API ownership across cloudnative applications.
  • Define and implement No name remediation requirements, ensuring API posture findings are prioritized, actionable, and consumable by engineering teams.
  • Support day to day operations of cloud and application security tooling, including troubleshooting, optimization, and routine automation.
  • Partner directly with application and platform engineers to integrate WAF, API, and application security controls into CI/CD pipelines.

Required Skills & Experience:

  • Strong hands-on experience with AWS WAF operations and tuning
  • Practical experience with policy-as-code and GitHub based CI/CD pipelines
  • Experience integrating security logs and findings into AWS Security Lake or similar platforms
  • Hands-on experience with API security platforms (e.g., Noname or equivalent)
  • Strong automation skills using Terraform and Python
  • Experience with application security posture management and cloudnative architectures (containers, serverless, microservices)
  • Ability to translate security findings into clear, actionable remediation guidance

Experience & Education:

  • Bachelor’s degree in Computer Science or related field (or equivalent experience) is preferred but not requred
  • 8+ years of hands-on security engineering experience, primarily in cloud, application, or API security · AWS Security Specialty, GIAC Cloud Security Automation (GCSA) and/or CCSP preferred

Job Tags

For contractors, 3 days per week

Similar Jobs

MyCare Medical

Outpatient Primary Care Physician Job at MyCare Medical

 ...Driven Medical Family in the Houston Region! MyCare Medical is a managed care company, providing primary care to older adults and...  ...should be compassionate, personal, and go above the routine. We are physician-founded and dyad-led, built with a focus on supporting our providers... 

Denali Water Solutions LLC

Class a Lead Support Driver - Requisition # 3843 Job at Denali Water Solutions LLC

About Company: Denali is the leading organic recycling company on a mission to unlock the power of unused food and organics, transforming them into resources to feed, fuel and replenish the earth. Our work is essential to keeping water clean, reducing the need for...

The Middlesex Corporation

Welder Job at The Middlesex Corporation

Description The Middlesex Corporation is a nationally recognized and award-winning leader in the heavy civil construction industry. Since 1972, the family business founded by Robert W. Pereira has developed an extensive client and project list through its consistent...

Synchronous Solutions, Inc.

UiPath Developer Contractor (Remote) Job at Synchronous Solutions, Inc.

SynchSolutions is looking for a UiPath Developer who will deliver Automation Projects in the Automation Program Portfolio. This position is 100% remote with no travel and will be a fulltime 1099 / C2C position. Due to the sensitivity of the public sector applicants must...

Accountants One

Staff Accountant/Accounts Receivable Job at Accountants One

 ...We have a repeat client in Norcross that is looking for a Staff Accountant with a heavy A/R focus. Position Summary This is a full-time, 100% in-office role based in Norcross, GA. The Staff Accountant will be responsible for managing the full accounts receivable...