Jobs Companies CVS Health Staff Application Security Engineer - Blue Team

Über diese Staff Application Security Engineer - Blue Team Stelle bei CVS Health

CVS Health · Vor Ort · CA - Work from home

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.

Staff Application Security Engineer – Blue Team

Who Are You

  • A senior defensive security practitioner with deep engineering expertise and the ability to design, develop, and influence security solutions across the enterprise.
  • Highly experienced in protecting applications, cloud platforms, data assets, and infrastructure through proactive detection, prevention, response, and resilience strategies.
  • Passionate about building secure and scalable systems while driving continuous security improvements through automation and innovation.
  • A recognized subject matter expert in application security, cloud security, data security, and network security from a Blue Team / defensive operations perspective.
  • Comfortable leading security initiatives in complex environments including cloud-native architectures, distributed systems, hybrid infrastructures, and legacy platforms.
  • Able to provide technical leadership during security incidents while remaining calm and effective in high-pressure situations.
  • Skilled at influencing engineering teams, mentoring peers, and driving organization-wide adoption of secure-by-design principles.

Role Responsibilities:

Development & Enforcement

  • Design, implement, and maintain defensive security controls across applications, cloud platforms, data systems, and network environments.
  • Develop and enforce enterprise-wide application and data security standards, policies, and best practices.
  • Embed security controls into SDLC processes, CI/CD pipelines, and deployment automation frameworks.
  • Lead security architecture reviews and ensure alignment with organizational security objectives.
  • Establish security governance frameworks that improve confidentiality, integrity, availability, and resiliency.

Collaboration & Expertise

  • Partner with Engineering, Infrastructure, Architecture, and Business teams to embed secure-by-design practices across products and services.
  • Serve as a trusted advisor and technical leader for Application Security, Cloud Security, and Secure Development practices.
  • Influence technical decision-making and security strategy across multiple teams and business units.
  • Drive organization-wide security awareness and operational readiness initiatives.

Analysis & Configuration

  • Monitor, detect, investigate, and respond to security events, vulnerabilities, threats, and incidents.
  • Lead vulnerability assessments, remediation planning, risk prioritization, and validation efforts across application and data platforms.
  • Design, evaluate, and optimize defensive controls across cloud-native, hybrid, and on-premises environments.
  • Conduct security assessments, threat modeling exercises, and architecture reviews to identify and mitigate risks.
  • Implement advanced security solutions across multi-cloud, colocation, and enterprise environments.

Operational Support

  • Participate in a rotational on-call schedule, including off-hours, nights, weekends, and holidays, supporting a 24x7 operational environment.
  • Lead security incident response activities including investigation, containment, eradication, recovery, and post-incident reviews.
  • Develop, maintain, and continuously improve incident response, detection, escalation, and recovery playbooks.
  • Drive operational improvements that strengthen incident readiness and cyber resilience.

Mentorship & Training

  • Mentor and coach engineers on secure coding practices, security engineering principles, and defensive operations.
  • Provide guidance to development and operational teams on security best practices and emerging threats.
  • Support training initiatives that improve security maturity across the organization.
  • Foster a culture of shared responsibility for security and operational excellence.

Innovation and Research

  • Research emerging threats, vulnerabilities, attack techniques, and security technologies.
  • Evaluate and recommend new security tools, platforms, and defensive capabilities.
  • Automate security operations using code and Security-as-Code principles to improve efficiency and scalability.
  • Improve threat detection, monitoring, alerting, and response capabilities through innovation and continuous improvement.

Strategic Planning

  • Contribute to long-term security strategy, architecture roadmaps, and technology planning initiatives.
  • Define and drive enterprise security objectives and key performance indicators.
  • Partner with leadership to prioritize security investments and risk reduction activities.
  • Develop standards and practices that improve cyber resilience, redundancy, business continuity, and recovery capabilities.

Basic Qualifications

  • 7+ years of experience in security engineering, application security, cloud security, or defensive security operations.
  • 3+ years of experience securing modern cloud platforms including AWS, Azure, and GCP.
  • 3+ years of experience with Docker, Kubernetes, Infrastructure-as-Code, and Security-as-Code methodologies.
  • 3+ years of experience in one or more programming or scripting languages such as Python, Java, C#, JavaScript, Shell, or PowerShell.
  • 3+ years of experience in networking, identity management, authentication, authorization, and threat mitigation techniques.

Preferred Qualifications

  • Experience designing and operating defensive security controls within cloud-native, containerized, and distributed application environments.
  • Experience implementing data protection controls and supporting regulatory and compliance requirements including GDPR, CCPA, or similar frameworks.
  • Demonstrated experience designing and implementing enterprise-scale security controls and security automation solutions.
  • Deep understanding of networking, software-defined networking (SDN), zero-trust architectures, and cloud security models.
  • Experience performing threat modeling, security architecture reviews, and secure design assessments.
  • Ability to develop and interpret network, sequence, application architecture, and data flow diagrams.
  • Experience with compliance and security frameworks such as NIST, PCI DSS, HIPAA, HITRUST, ISO 27001, SOC 2, or CSA.
  • Experience securing enterprise data platforms, analytics environments, and data warehouses including Snowflake and similar technologies.
  • Experience defining and implementing cyber resilience, business continuity, backup, redundancy, and recovery strategies.
  • Relevant industry certifications such as CISSP, CCSP, GSEC, GIAC, AWS Security Specialty, Azure Security Engineer Associate, or equivalent.

Education

  • Bachelor’s degree from an accredited college or university, or equivalent combination of education and relevant work experience (High School Diploma/GED plus 4 years of related experience)

Pay Range

The typical pay range for this role is:

$130,295.00 - $260,590.00


This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls.  The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors.  This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above.  This position also includes an award target in the company’s equity award program. 
 

Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.

Great benefits for great people

We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.

This full‑time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well‑being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.


Additional details about available benefits are provided during the application process and on
Benefits Moments.

We anticipate the application window for this opening will close on: 09/22/2026

Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.

Bereit, sich bei CVS Health zu bewerben?
Bei CVS Health bewerben

Wie sich dieses Gehalt für Application Security vergleicht

Diese Stelle zahlt $195,443/yrim Einklang mit der üblichen Spanne für Application Security Stellen.

$118,200 dem Median $180,000 $262,220

Übliche Spanne $148,512–$223,750/yr, aus 258 vergleichbaren Application Security Anzeigen auf JobsRadar (Vergütung auf USD hochgerechnet). Gehaltseinblicke für Application Security ansehen →

Über CVS Health

Our Work Experience is the combination of everything that's unique about us: our culture, our core values, our company meetings, our commitment to sustainability, our recognition programs, but most importantly, it's our people. Our employees are self-disciplined, hard working, curious, trustworthy, humble, and truthful. They make choices according to what is best for the team, they live for opportunities to collaborate and make a difference, and they make us the #1 Top Workplace in the area.

Alle Jobs bei CVS Health ansehen →

Ähnliche Jobs

DXC Technology
Security Web Application Firewall (WAF) Engineer
DXC Technology
⚡ Früh bewerben MEX - DIF - MEXICO CITY Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 2 Std.
Moniepoint
Application Security Engineer
Moniepoint
⚡ Früh bewerben Remote, Nigeria · standortgebunden
● Neu 👁 Gesehen ✓ Beworben vor 4 Std.
Roblox
Principal Security Software Engineer, Application Security
Roblox
⚡ Früh bewerben San Mateo, CA, United States Vor Ort $326,060–$385,050
● Neu 👁 Gesehen ✓ Beworben vor 6 Std.
Roblox
Senior Security Software Engineer, Application Security
Roblox
⚡ Früh bewerben San Mateo, CA, United States Vor Ort $269,170–$326,060
● Neu 👁 Gesehen ✓ Beworben vor 6 Std.
Ironclad
Staff Application Security Engineer
Ironclad
⚡ Früh bewerben San Francisco Hybrid $170,000–$190,000
● Neu 👁 Gesehen ✓ Beworben vor 10 Std.
CS
Security Engineer - Application Security (Senior)
Cogent Security
⚡ Früh bewerben Remote, US · standortgebunden $100,000–$300,000
● Neu 👁 Gesehen ✓ Beworben vor 10 Std.
Anduril Industries
Senior Product Security Engineer
Anduril Industries
⚡ Früh bewerben London, England, United Kingdo... Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 12 Std.
Anduril Industries
Staff Product Security Engineer
Anduril Industries
⚡ Früh bewerben London, England, United Kingdo... Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 12 Std.
Rockwell Automation
Software Engineer Product Security
Rockwell Automation
⚡ Früh bewerben Bengaluru, India Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 13 Std.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei CVS Health

Alle Jobs bei CVS Health ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos