Job Closed
This listing is no longer active.
Bringing our heart to every moment of your health.
Senior Security Engineer – Active Directory
Location
California
Posted
10 days ago
Salary
$102.0K - $203.9K / year
Seniority
Senior
Job Description
Senior Security Engineer – Active Directory
CVS Health
• Lead the security hardening and governance of Active Directory (AD) and Microsoft Entra ID (Azure AD) environments, reducing attack surfaces and enforcing secure identity configurations • Identify, assess, and remediate identity and access management vulnerabilities, including privilege escalation risks, excessive permissions, and lateral movement attack paths • Design and implement enterprise identity security controls, including privileged access management, tiered administration, secure delegation, Conditional Access, and authentication protections • Partner with Cybersecurity, Red Team, and Infrastructure teams to validate findings, drive remediation efforts, and strengthen overall security posture • Monitor and investigate security events, threats, and indicators of compromise using tools such as Microsoft Security, Splunk, CrowdStrike, BloodHound, and Qualys • Develop and maintain security standards, conduct security assessments, and support compliance and audit initiatives (SOX, PCI, HIPAA) through remediation of identity-related findings
Job Requirements
- 5–7 years of experience supporting and securing enterprise Active Directory environments
- 5–7 years of hands‑on experience administering Active Directory in multi‑domain or complex environments, with a strong emphasis on security
- 4–6 years of experience administering Azure and Azure Active Directory, including identity security controls
- 5+ years of experience working with Windows Server and Windows operating systems
- 3–5 years of experience using PowerShell for administration, automation, and security remediation
- 4–6 years of experience with vulnerability management, security hardening, and remediation of enterprise systems
Benefits
- medical, dental, and vision coverage
- paid time off
- retirement savings options
- wellness programs
- other resources
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Define and own the enterprise application security strategy, roadmap, and policy framework, aligned with CVS Health's business objectives and regulatory obligations. • Establish and enforce technical standards for secure software development, including code scanning, code vulnerability management, and secure-by-design principles. • Serve as a subject matter expert and trusted advisor to senior technology and business executives on emerging application security risks, attack trends, and industry best practices. • Drive continuous improvement across the application security program through metrics, benchmarking, and innovation. • Lead the integration of application security scanning, testing, and policy enforcement gates into CI/CD pipelines across the enterprise. • Define strategy, standards, and tooling for enterprise-wide SAST scanning. • Oversee DAST program covering pre-production and production environments. • Own the strategy, configuration, and operations of the enterprise WAF platform. • Implement and manage continuous scanning of source code repositories for secrets, misconfigurations, exposed credentials, and policy violations. • Manage the Software Composition Analysis (SCA) program to identify and remediate vulnerabilities in third-party libraries and open-source dependencies. • Oversee security configuration and policy enforcement for content delivery network infrastructure. • Own the full application security tooling portfolio. Manage vendor relationships, licensing, platform health, and roadmap alignment. • Define and maintain application security policies, standards, and operational procedures. • Ensure compliance with applicable regulatory frameworks and industry standards, including HIPAA, PCI-DSS, CCPA, NIST SSDF, and OWASP. • Build, lead, and develop a high-performing team of application security engineers, architects, and program managers. • Partner closely with Developer Experience leadership to align security tooling and practices with developer workflows, ensuring security is integrated seamlessly into agile and DevSecOps pipelines.
• Own the vulnerability scanning program across endpoints, servers, and cloud infrastructure • Triage, prioritize, and track findings through remediation, partnering with engineering and IT owners • Monitor and report on remediation SLAs; escalate aging or high-severity findings • Maintain vulnerability management documentation, metrics, and recurring reporting • Improve our identity management program through improvements in configurations, automations, to simultaneously improve security and user experience • Monitor and harden AWS environments: IAM, security groups, S3, CloudTrail, GuardDuty, Security Hub, Config • Implement and maintain security guardrails and baseline configurations across AWS accounts • Investigate and respond to cloud security alerts and incidents • Support least-privilege access reviews and cloud configuration audits • Support SAST, DAST, and dependency/SCA scanning integrated into the CI/CD pipeline • Review and triage AppSec findings with engineering teams and track remediation to closure • Participate in secure code reviews and threat modeling for new features and services • Help maintain secure development guidelines and AppSec tooling • Triage and resolve security tickets and requests within defined SLAs • Take ownership of incidents and requests through to resolution, escalating when needed • Maintain clear, accurate documentation of decisions, incidents, and remediation status • Lead or contribute to security initiatives — tooling rollouts, control implementations, audit and compliance prep • Collaborate with engineering, IT, and compliance to embed security into everyday workflows • Communicate risk, status, and trade-offs clearly to both technical and non-technical stakeholders
• The Digital Product Manager (DPM) is responsible for defining, delivering, and optimizing cybersecurity products, platforms, controls, data capabilities, and AI-enabled solutions across Allstate's Cybersecurity, Controls, and Compliance (ACC) organization. • This role owns product strategy, roadmap, backlog, and outcome delivery, helping the organization improve security operations, strengthen controls, reduce enterprise risk, and enable secure-by-design technology practices. • The DPM partners with Cyber Operations, Product Security, Technology Risk, Compliance, Engineering, Architecture, and business stakeholders to build scalable, measurable, and high-impact security products that drive operational efficiency, compliance readiness, and risk reduction. • Define and execute product vision, strategy, roadmap, and success metrics. • Translate security, risk, compliance, and operational needs into scalable product capabilities. • Prioritize initiatives that improve security workflows, controls, data quality, AI enablement, automation, and platform adoption. • Align product outcomes to enterprise risk reduction and business objectives. • Translate cyber operations needs into testable hypotheses, epics, and user stories; lead discovery and framing to drive measurable outcomes. • Lead discovery, requirements gathering, and product framing efforts. • Partner with security, engineering, risk, compliance, and business stakeholders to identify opportunities and define solutions. • Own backlog management, prioritization, and Agile delivery processes. • Partner closely with engineering and architecture teams to deliver secure, scalable solutions. • Drive iterative releases and ensure alignment across cross-functional teams. • Deliver data-driven insights and executive reporting to support decision-making and prioritization.
SAP Security Consultant – S/4HANA Public Cloud
DyFlex SolutionsYour SAP Gold Partner for S/4HANA, Business ByDesign, Ariba and Analytics solutions.
• Serve as the lead SAP Security resource across multiple concurrent SAP S/4HANA Public Cloud projects and support engagements • Translate business and compliance requirements into SAP security configuration, role design, and authorisation concepts • Design and implement security solutions within the SAP Public Cloud environment • Run client workshops, lead security-focused meetings, and maintain strong stakeholder relationships throughout project delivery • Collaborate closely with functional consultants and project leads to ensure security is embedded from requirements through to go-live • Provide ongoing security support and advice to clients as part of the Aftercare support model • Analyse client requests critically and provide proactive guidance, including advising against approaches that may not serve the client's long-term interests • Manage and context-switch across multiple projects and support queues simultaneously, maintaining quality and standards across all engagements • Contribute to knowledge sharing within the Public Cloud practice team



