CVS Health logo
CVS Health

Bringing our heart to every moment of your health.

AVP, Application Security

Security EngineerSecurity EngineerFull TimeRemoteLeadTeam 10,001+Since 1963H1B No SponsorCompany SiteLinkedIn

Location

New York + 1 moreAll locations: New York | Rhode Island

Posted

5 days ago

Salary

$185.4K - $376.0K / year

Seniority

Lead

Bachelor Degree12 yrs expEnglishCloudJavaJavaScriptPythonSDLCGo

Job Description

AVP, Application Security

CVS Health

• Define and own the enterprise application security strategy, roadmap, and policy framework, aligned with CVS Health's business objectives and regulatory obligations. • Establish and enforce technical standards for secure software development, including code scanning, code vulnerability management, and secure-by-design principles. • Serve as a subject matter expert and trusted advisor to senior technology and business executives on emerging application security risks, attack trends, and industry best practices. • Drive continuous improvement across the application security program through metrics, benchmarking, and innovation. • Lead the integration of application security scanning, testing, and policy enforcement gates into CI/CD pipelines across the enterprise. • Define strategy, standards, and tooling for enterprise-wide SAST scanning. • Oversee DAST program covering pre-production and production environments. • Own the strategy, configuration, and operations of the enterprise WAF platform. • Implement and manage continuous scanning of source code repositories for secrets, misconfigurations, exposed credentials, and policy violations. • Manage the Software Composition Analysis (SCA) program to identify and remediate vulnerabilities in third-party libraries and open-source dependencies. • Oversee security configuration and policy enforcement for content delivery network infrastructure. • Own the full application security tooling portfolio. Manage vendor relationships, licensing, platform health, and roadmap alignment. • Define and maintain application security policies, standards, and operational procedures. • Ensure compliance with applicable regulatory frameworks and industry standards, including HIPAA, PCI-DSS, CCPA, NIST SSDF, and OWASP. • Build, lead, and develop a high-performing team of application security engineers, architects, and program managers. • Partner closely with Developer Experience leadership to align security tooling and practices with developer workflows, ensuring security is integrated seamlessly into agile and DevSecOps pipelines.

Job Requirements

  • 12+ years of progressive experience in information security, with at least 5 years in application security leadership roles.
  • Deep technical background in software development, including hands-on coding experience in one or more modern programming languages (e.g., Java, Python, Go, JavaScript, or similar).
  • Candidates must bring developer-level fluency to credibly engage with engineering teams, evaluate code-level risks, and drive meaningful secure coding practices.
  • Demonstrated expertise in application security engineering and secure software development lifecycle (SDLC) practices, grounded in first-hand experience building or shipping software.
  • Strong understanding of software architecture patterns, CI/CD pipelines, containerization, and cloud-native development — with the ability to assess security implications at every layer of the stack.
  • Hands-on experience managing enterprise application security tooling, including SAST, DAST, SCA, WAF, and repository scanning platforms.
  • Deep knowledge of application security standards and frameworks, including OWASP Top 10, NIST SSDF, and relevant regulatory requirements (HIPAA, PCI-DSS, CCPA).
  • Proven ability to influence engineering culture and drive security adoption at scale within agile development environments.
  • Strong leadership skills with experience building and managing cross-functional technical teams and influencing senior stakeholders.
  • Excellent communication and presentation skills; ability to translate complex security concepts for both technical and non-technical audiences.

Benefits

  • Medical, dental, and vision coverage
  • Paid time off
  • Retirement savings options
  • Wellness programs
  • Comprehensive benefits package

Related Categories

Related Job Pages

More Security Engineer Jobs

Worth AI logo

Security Engineer

Worth AI

AI Data-Driven Credit Score For Every Business 💸✨

Full TimeRemoteTeam 11-50H1B No Sponsor

• Own the vulnerability scanning program across endpoints, servers, and cloud infrastructure • Triage, prioritize, and track findings through remediation, partnering with engineering and IT owners • Monitor and report on remediation SLAs; escalate aging or high-severity findings • Maintain vulnerability management documentation, metrics, and recurring reporting • Improve our identity management program through improvements in configurations, automations, to simultaneously improve security and user experience • Monitor and harden AWS environments: IAM, security groups, S3, CloudTrail, GuardDuty, Security Hub, Config • Implement and maintain security guardrails and baseline configurations across AWS accounts • Investigate and respond to cloud security alerts and incidents • Support least-privilege access reviews and cloud configuration audits • Support SAST, DAST, and dependency/SCA scanning integrated into the CI/CD pipeline • Review and triage AppSec findings with engineering teams and track remediation to closure • Participate in secure code reviews and threat modeling for new features and services • Help maintain secure development guidelines and AppSec tooling • Triage and resolve security tickets and requests within defined SLAs • Take ownership of incidents and requests through to resolution, escalating when needed • Maintain clear, accurate documentation of decisions, incidents, and remediation status • Lead or contribute to security initiatives — tooling rollouts, control implementations, audit and compliance prep • Collaborate with engineering, IT, and compliance to embed security into everyday workflows • Communicate risk, status, and trade-offs clearly to both technical and non-technical stakeholders

Florida
Full TimeRemoteTeam 10,001+Since 1931H1B Sponsor

• The Digital Product Manager (DPM) is responsible for defining, delivering, and optimizing cybersecurity products, platforms, controls, data capabilities, and AI-enabled solutions across Allstate's Cybersecurity, Controls, and Compliance (ACC) organization. • This role owns product strategy, roadmap, backlog, and outcome delivery, helping the organization improve security operations, strengthen controls, reduce enterprise risk, and enable secure-by-design technology practices. • The DPM partners with Cyber Operations, Product Security, Technology Risk, Compliance, Engineering, Architecture, and business stakeholders to build scalable, measurable, and high-impact security products that drive operational efficiency, compliance readiness, and risk reduction. • Define and execute product vision, strategy, roadmap, and success metrics. • Translate security, risk, compliance, and operational needs into scalable product capabilities. • Prioritize initiatives that improve security workflows, controls, data quality, AI enablement, automation, and platform adoption. • Align product outcomes to enterprise risk reduction and business objectives. • Translate cyber operations needs into testable hypotheses, epics, and user stories; lead discovery and framing to drive measurable outcomes. • Lead discovery, requirements gathering, and product framing efforts. • Partner with security, engineering, risk, compliance, and business stakeholders to identify opportunities and define solutions. • Own backlog management, prioritization, and Agile delivery processes. • Partner closely with engineering and architecture teams to deliver secure, scalable solutions. • Drive iterative releases and ensure alignment across cross-functional teams. • Deliver data-driven insights and executive reporting to support decision-making and prioritization.

United States
$120K - $193.7K / year
DyFlex Solutions logo

Senior SAP Security Consultant – S/4HANA Public Cloud

DyFlex Solutions

Your SAP Gold Partner for S/4HANA, Business ByDesign, Ariba and Analytics solutions.

Full TimeRemoteTeam 51-200H1B No Sponsor

• Serve as the lead SAP Security resource across multiple concurrent SAP S/4HANA Public Cloud projects and support engagements • Translate business and compliance requirements into SAP security configuration, role design, and authorisation concepts • Design and implement security solutions within the SAP Public Cloud environment • Run client workshops, lead security-focused meetings, and maintain strong stakeholder relationships throughout project delivery • Collaborate closely with functional consultants and project leads to ensure security is embedded from requirements through to go-live • Provide ongoing security support and advice to clients as part of the Aftercare support model • Analyse client requests critically and provide proactive guidance, including advising against approaches that may not serve the client's long-term interests • Manage and context-switch across multiple projects and support queues simultaneously, maintaining quality and standards across all engagements • Contribute to knowledge sharing within the Public Cloud practice team

Australia
SEI logo

AI Cybersecurity Engineer

SEI

We’re 4,000 employee entrepreneurs on a mission to build brave futures℠ through the power of connection.

Full TimeRemoteTeam 1,001-5,000H1B Sponsor

• Design and architect enterprise-grade, secure AI security platforms that protect ML models, training pipelines, inference systems, and AI-driven applications from sophisticated adversarial attacks • Define and drive the technical vision and security roadmap for all AI/ML initiatives across the organization, embedding security into the complete AI lifecycle from development through deployment and monitoring • Lead architectural reviews and provide authoritative technical guidance on security architecture patterns, threat models, and risk mitigation strategies for AI systems • Establish security standards and frameworks for AI development, incorporating OWASP LLM Top 10, MITRE ATLAS, NIST AI Risk Management Framework, and other industry best practices • Develop security controls for AI model training, validation, deployment, and monitoring including input/output filtering, model integrity validation, and behavioral anomaly detection • Implement data security and privacy controls across AI workflows including sensitive data detection, data loss prevention for AI prompts and responses, and confidential computing techniques • Build automated security testing frameworks for continuous validation of AI model security posture and detection of adversarial attack patterns • Engineer AI-powered security detection systems leveraging machine learning for threat hunting, anomaly detection, and behavioral analytics • Communicate complex technical concepts to non-technical executives and business leaders, translating security risks into business impact and strategic recommendations • Serve as the technical authority and trusted advisor on AI security matters for senior leadership including CISO and CTO • Develop and enforce AI security governance policies, standards, and guidelines that ensure ethical, safe, and compliant use of AI across the enterprise • Establish AI model governance frameworks addressing model validation, bias detection, explainability requirements, and audit trails • Implement continuous monitoring and observability for AI systems to detect model drift, performance degradation, and security anomalies in real-time

Pennsylvania
$160K - $200K / year