Jobs and Careers
CV

Senior Adversary Operations Engineer

CVS Health
Work At Home-New York, United States, United Statesfull_timeVerifiedPosted 4 Jun 2025
💰 $203,940/yr($101,970/yr$203,940/yr)

About the role

At CVS Health, we’re building a world of health around every consumer and surrounding ourselves with dedicated colleagues who are passionate about transforming health care.

As the nation’s leading health solutions company, we reach millions of Americans through our local presence, digital channels and more than 300,000 purpose-driven colleagues – caring for people where, when and how they choose in a way that is uniquely more connected, more convenient and more compassionate. And we do it all with heart, each and every day.

Who You Are

  • Experienced Penetration Tester: Deep expertise in conducting both internal and external penetration testing to identify vulnerabilities across networks, applications, and systems. Proficient in exploiting security gaps to assess potential risks effectively.
  • Offensive Security Specialist: Proficient in using tools like Kali Linux, Metasploit, Burp Suite, Nmap, and custom scripting with Python, PowerShell, or Bash. Knowledgeable about emerging attack techniques and TTPs (Tactics, Techniques, and Procedures).
  • Purple Team Advocate: Proven experience in collaborating with blue teams to design and implement purple team exercises that enhance detection and response capabilities. Ability to translate offensive security findings into actionable defense strategies.
  • Threat Intelligence Integrator: Skilled at leveraging threat intelligence to inform penetration testing strategies, prioritize threats, and adapt techniques based on emerging adversary tactics.
  • Incident Response Collaborator: Proven track record of working with incident response teams to provide insights during active investigations and refine detection capabilities. Experience in conducting post-incident reviews to enhance security controls.
  • Risk Management-Focused: Skilled in evaluating security risks and recommending actionable solutions that align with business objectives.
  • Compliance Knowledgeable: Experienced in ensuring that penetration testing aligns with regulatory and compliance requirements such as PCI-DSS, HIPAA, NIST, and ISO 27001.
  • Innovator: Passionate about integrating offensive security practices into a comprehensive threat management strategy.

Role Responsibilities

Penetration Testing & Adversary Emulation

  • Conduct internal and external penetration tests to identify and exploit vulnerabilities.
  • Develop and execute adversary emulation scenarios to assess the effectiveness of the organization’s detection and response capabilities.
  • Utilize and maintain a comprehensive suite of penetration testing tools, including Kali Linux, Metasploit, Nmap, and custom scripts.
  • Create detailed reports with findings and actionable recommendations for remediation.

Collaboration & Purple Teaming

  • Work closely with blue teams to design and execute purple team exercises that bridge offensive and defensive security efforts.
  • Provide actionable insights to improve security monitoring, alerting, and incident response based on penetration testing results.
  • Facilitate knowledge-sharing sessions to upskill internal teams on adversary tactics, techniques, and procedures (TTPs).

Security Strategy & Risk Management

  • Contribute to the development of a comprehensive adversary operations strategy aligned with organizational risk management goals.
  • Provide executive leadership with detailed reports on security gaps, risks, and the effectiveness of security controls.
  • Prioritize remediation efforts based on risk impact and operational feasibility.

Tool Development & Automation

  • Automate common penetration testing tasks using Python, PowerShell, or Bash scripting to increase efficiency.
  • Contribute to the development of custom tools for red teaming and penetration testing.

Incident Response Support

  • Assist the incident response team by providing adversary tactics insights during active investigations.
  • Collaborate on developing threat-hunting use cases and refining detection capabilities based on attack simulations.

Required Qualifications:

  • 5+ years of hands-on experience in penetration testing, red teaming, or offensive security.
  • 3+ years of experience in Kali Linux, Metasploit, Nmap, Burp Suite, and/or other related tools.
  • 3+ years of experience in scripting languages (Python, PowerShell, Bash,etc).
  • 3+ years of experience with cloud security (AWS, Azure, GCP) and container security.

Preferred Qualifications:

  • Relevant certifications such as OSCP, OSCE, CISSP, CEH, or GPEN.
  • Experience in managing or participating in purple team exercises.
  • Familiarity with compliance standards l

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

CVS Health

View company profile →