Information Protection Advisor - SSP & CMMC Programs

The Cigna GroupSt. Louis, Bloomington, Bloomfield, Connecticut, Missouri, MinnesotaOn-siteFull-timeStaff, 8–12 yearsListed 1 hour ago

Apply now

About this role

Help Protect and Strengthen Federal Security Compliance

Are you passionate about security, compliance, and protecting sensitive information? The Cigna Group is seeking an Information Protection Advisor to support our federal compliance programs and help ensure our systems meet evolving cybersecurity and regulatory requirements.

In this role, you will partner with business, technology, cybersecurity, and control teams to maintain accurate, audit-ready security documentation and support compliance initiatives aligned with federal standards. Your work will directly contribute to protecting critical systems, improving operational readiness, and supporting compliance with frameworks such as CMMC and NIST.

This is an excellent opportunity for a detail-oriented professional who enjoys collaborating across teams, solving complex documentation challenges, and driving quality and consistency in security and compliance processes.

Responsibilities:

- Develop, Update, & Maintain assigned federal System Security Plans (SSPs) and related compliance documentation to ensure accuracy, completeness, and audit readiness.
- Partner with system owners, control owners, engineering teams, and subject matter experts to validate control implementations, system boundaries, and security documentation.
- Track documentation updates, open items, remediation activities, and evidence requirements through completion.
- Gather, organize, and maintain control evidence and supporting artifacts in approved repositories.
- Support compliance assessments, audits, and certification activities by coordinating documentation, responding to requests, and monitoring deliverables.
- Identify documentation gaps, inconsistencies, and potential compliance concerns, escalating issues when appropriate.
- Maintain compliance artifacts including POA&Ms, policies, procedures, control mappings, assessment records, and remediation documentation.
- Support CMMC readiness efforts through control mapping, evidence collection, gap assessments, issue tracking, and remediation follow-up.
- Assist with defining and maintaining compliance scope, system boundaries, inventories, and asset populations supporting federal operations.
- Contribute to templates, procedures, and quality reviews that improve consistency, efficiency, and documentation standards across the compliance program.
- Communicate project status, risks, and priorities while managing multiple deliverables and deadlines.
- Support additional security, regulatory, contractual, and audit-related initiatives as business needs evolve.

Required Qualifications:

- 4+ years of relevant experience in information security, IT risk, compliance, audit, cybersecurity, or a related field with a bachelor's degree; or 8+ years of relevant experience in lieu of a degree.
- Working knowledge of risk management, compliance, audit, and security control documentation practices.
- Experience interpreting NIST requirements and translating them into actionable documentation and compliance activities.
- Strong organizational skills with the ability to manage multiple priorities and deadlines.
- Demonstrated attention to detail and commitment to documentation accuracy and quality.
- Excellent written and verbal communication skills.
- Ability to collaborate effectively with technical teams, business partners, and control owners.
- Self-motivated, action-oriented, and capable of working independently while exercising sound judgment.

Preferred Qualifications

- Experience creating, maintaining, or supporting federal System Security Plans (SSPs).
- Experience with Cybersecurity Maturity Model Certification (CMMC), NIST SP 800-171, NIST SP 800-53, or Department of Defense (DoD) security requirements.
- Experience managing POA&Ms, control narratives, evidence mappings, system inventories, diagrams, policies, or procedures.
- Knowledge of additional security and compliance frameworks such as SOC 2, PCI, SOX, HITRUST, or similar standards.
- Experience supporting regulatory assessments, audits, or certification activities.
- Professional certifications such as CISSP, CISM, CISA, CCP, or CCA.
- Strong analytical, technical writing, and presentation skills.
- Proven ability to build effective relationships across business, cybersecurity, and technology teams.

If you will be working at home occasionally or permanently, the internet connection must be obtained through a cable broadband or fiber optic internet service provider with speeds of at least 10Mbps download/5Mbps upload.

For this position, we anticipate offering an annual salary of 103,100 - 171,900 USD / yearly, depending on relevant factors, including experience and geographic location.

This role is also anticipated to be eligible to participate in an annual bonus plan.

At The Cigna Group, you’ll enjoy a comprehensive range of benefits, with a focus on supporting your whole health. Starting on day one of your employment, you’ll be offered several health-related benefits including medical, vision, dental, and well-being and behavioral health programs. We also offer 401(k), company paid life insurance, tuition reimbursement, a minimum of 18 days of paid time off per year, paid holidays, and leaves of absence. For more details on our employee benefits programs, click here .

About The Cigna Group

Doing something meaningful starts with a simple decision, a commitment to changing lives. At The Cigna Group, we’re dedicated to improving the health and vitality of those we serve. Through our divisions Cigna Healthcare and Evernorth Health Services, we are committed to enhancing the lives of our clients, customers and patients. Join us in driving growth and improving lives.

Qualified applicants will be considered without regard to race, color, age, disability, sex, childbirth (including pregnancy) or related medical conditions including but not limited to lactation, sexual orientation, gender identity or expression, veteran or military status, religion, national origin, ancestry, marital or familial status, genetic information, status with regard to public assistance, citizenship status or any other characteristic protected by applicable equal employment opportunity laws.

If you need a reasonable accommodation to complete the online application process, please email [email protected] for assistance.  Please note that this email inbox is dedicated to accommodation requests only and cannot provide application updates or accept resumes.

The Cigna Group has a tobacco-free policy and reserves the right not to hire tobacco/nicotine users in states where that is legally permissible. Candidates in such states who use tobacco/nicotine will not be considered for employment unless they enter a qualifying smoking cessation program prior to the start of their employment. These states include: Alabama, Alaska, Arizona, Arkansas, Delaware, Florida, Georgia, Hawaii, Idaho, Iowa, Kansas, Maryland, Massachusetts, Michigan, Nebraska, Ohio, Pennsylvania, Texas, Utah, Vermont, and Washington State.

Qualified applicants with criminal histories will be considered for employment in a manner consistent with all federal, state and local ordinances.