Principal — Technology Risk & Governance
Enterprise point of contact for Technology Risk across the Cigna Information Protection organization, Global Infrastructure & Operations, and Audit. Operated within HIPAA and SOX regulatory control environments.
- Built an enterprise vulnerability governance framework covering 10,000+ assets; reduced mean time to remediate critical findings by 18% within the first 12 months.
- Established centralized reporting and governance for vulnerabilities, audit issues and technology debt, giving executives visibility into risk posture and remediation performance across four business units.
- Drove cross-organization accountability, accelerating closure of multiple audit findings and reducing the open critical vulnerability backlog by more than 20%.
- Partnered with security, infrastructure and audit teams to align with HIPAA and internal SOX controls, achieving zero control failures in annual audit cycles.