Bringing our heart to every moment of your health.
Staff Security Engineer
Location
United States
Posted
27 days ago
Salary
$130.3K - $260.6K / year
Seniority
Lead
Job Description
Staff Security Engineer
CVS Health
Role Description CVS Health is looking for a Staff Security Engineer that is responsible for designing, implementing, and maintaining security measures to protect the organization’s digital infrastructure. This role requires deep hands-on expertise with security platforms, technologies, and frameworks, and is critical in safeguarding sensitive data and ensuring compliance with security standards and regulations. What we expect of you: - Familiarizing themselves with the capabilities of each tool in our security stack. - Understanding the standard operating procedures of the Security Platform team and stakeholders. - Onboarding, parsing, and monitoring data for the security platform. - Troubleshooting any potential issues with the security platform. - Partner with systems and security architecture, application, databases and storage teams. - Creating visualizations, queries, detections, and automations required for the functioning/use of the platform. - Understands the Enterprise logs and acquires knowledge on the relevant processes need for project delivery. - Participate in entire software lifecycle development, testing, CI/CD and production operations. - Documents platform processes, workflows, and systems for reference and knowledge-sharing purposes. - Implements data quality checks and validation processes to ensure the accuracy, completeness, and consistency of the data. - Provide technical guidance and solutions for Cyber Defense team members. - Be a team player and work with team members for business solutions and implementations. Qualifications - 7+ years of Information Security experience. - 3+ years of experience with Python. - 3+ years of experience with SQL or SQL-like languages. - 5+ years of hands-on experience with a major cloud platform (GCP, AWS, Azure). - 4+ years of admin experience with major datalake and/or SIEM platforms. Requirements - 7+ years of experience with SOAR. - 5+ years of experience with Databricks. - 5+ years of experience with common scripting and programming languages such as Python, HTML, JavaScript, and CSS. - 5+ years of experience with SIEMs such as Splunk, ELK, LogRhythm, QRadar, Logpoint, Sentinel, Chronicle, etc. - Excellent communication and presentation skills. Education - Bachelor degree from accredited university or equivalent work experience (HS diploma + 4 years relevant experience). Benefits - Comprehensive benefits package designed to support the physical, emotional, and financial well-being of colleagues and their families. - Medical, dental, and vision coverage. - Paid time off. - Retirement savings options. - Wellness programs and other resources, based on eligibility. Pay Range The typical pay range for this role is: $130,295.00 - $260,590.00. This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company’s equity award program.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Cyber Security Specialist
RadixA Radix está sempre no topo das Melhores Empresas para se trabalhar porque: Temos profissionais comprometidos, dedicados, curiosos e inovadores. O espírito de equipe é a nossa maior força. Trabalhamos de forma cooperativa e sabemos que estamos juntos, remando na mesma direção. Temos um ambiente diverso, que valoriza equidade e inclusão. Nossa jornada de trabalho é flexível e em quase todos os projetos é possível trabalhar de qualquer lugar do Brasil. Valorizamos o bem-estar e o cuidado com as nossas pessoas, com programas de apoio à saúde mental, psiquiatra e médico consultor disponíveis.
Role Description A primeira coisa que você precisa saber é que aqui você não vai cair na rotina. A Radix desenvolve soluções para empresas de diferentes setores e indústrias. Cada projeto tem suas tecnologias, soluções e prazos e você terá oportunidade de atuar e experimentar diferentes desafios. OT Cybersecurity Specialist: - Perform targeted OT cybersecurity maturity reviews focused on asset visibility, network exposure, and uncontrolled access paths. - Identify and document gaps that contribute to unknown or unquantified cyber risk in critical production environments. - Validate that critical assets are properly inventoried, reachable across networks, and assigned to a responsible owner. - Validate actual network reachability and communication paths between IT, OT, and vendor access points. - Assess vendor and remote access mechanisms, identifying persistent, shared, or unmonitored connections. - Evaluate incident containment readiness, including the ability to isolate assets and identify response constraints. - Produce concise, site-level exposure summaries, including prioritized risks and key findings for Security and Operations teams. Benefits - Assistência Médica Nacional (para o titular e dependentes, com quarto privativo). - Assistência odontológica nacional (para o titular e dependentes). - Vale refeição / alimentação flexível. - Auxílio home office. - Day off (no mês do aniversário). - Wellhub (antigo Gympass). - Licença Maternidade (6 meses) e Paternidade (20 dias) estendidas. - Auxílio creche para filhos de até 3 anos (por filho). - Apoio em saúde mental com a Wellz. - Clube de Vantagens com descontos em diversos parceiros. - Convênio com instituições de ensino e cursos de idioma. - Desenvolvimento Profissional (Universidade Corporativa). - Parceria com empresa de coworkings no Brasil. - Programa de Qualidade de Vida e Bem-Estar. - Médico consultor para acompanhamento de radixers. - Planos de incentivos.
• Design, implement, and maintain security controls, processes, and architectures across major cloud environments. • Conduct risk assessments, penetration tests, vulnerability management, and system hardening for cloud services and workloads. • Collaborate closely with engineering, DevOps, compliance, and business stakeholders to enable secure solution delivery and effective risk management. • Build and maintain Infrastructure as Code (IaC) security practices (Terraform, CloudFormation) and work within CI/CD pipelines to embed security in the software development lifecycle. • Partner with the GRC team to ensure compliance automation tooling is implemented effectively across required scope. • Serve as subject matter expert on cloud security technologies, best practices, and emerging threats while providing mentorship to other engineers. • Lead incident investigations, performing root cause analysis and driving remediation actions. • Participate in weekly on-call rotation with the security engineering team. • Operate and mature our CSPM/CNAPP program, driving posture management, misconfiguration remediation, and continuous control monitoring.
Cybersecurity Network Engineer
Accenture Federal ServicesWe believe in the power of change, harnessed in ways that matter for our country and communities.
• The Cybersecurity Engineer will be responsible for ensuring that all information systems' Ports, Protocols, and Services (PPS) accessible to managed networks are registered in the PPSM central registry. • They must protect and use PPS according to the latest vulnerability assessment reports and implement them as per the current DoD STIGs on network infrastructure and application security. • The engineer will review software, hardware, and PPS against approved lists, perform access blocking as per policies. • They will manage PPSM in support of network changes, such as cloud migrations.
• Own and manage the IT general controls (ITGCs) component of the ICFR compliance program while supporting the build out of the ITGCs & IT Application controls (ITAC) for the SOX program from the ground up, leveraging existing frameworks and controls where applicable • Partner with Finance, IT, and business stakeholders to identify and document key controls over financial reporting, ensuring controls are designed and in place ahead of audit cycles • Ensure ITGCs and ITACs supporting financial systems are properly documented and operating as intended • Serve as the primary point of contact for external auditors, coordinating evidence requests, walkthroughs, and finding remediation • Build and maintain a controls inventory with clear ownership, documentation standards, and readiness status • Work cross-functionally with control owners to ensure gaps are identified early and remediation plans are in place before audit periods • Develop and report on compliance readiness and control health to senior leadership • Drive continuous improvement in the efficiency and effectiveness of the SOX Compliance system (AuditBoard) and related technologies • Maintain current knowledge of emerging risks, industry trends, and regulatory changes relevant to the business and the audit profession • Expand ownership to include SOC 1&2, PCI DSS, and NIST compliance programs, building a unified compliance function • Lead a small team of compliance specialists, providing mentorship, prioritization, and ensuring alignment across the aforementioned compliance initiatives



