Assistant Vice President (AVP) Security Risk Management
CVS HealthAbout the role
We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.
Position Summary
The AVP Security Risk Management is responsible for reducing enterprise cybersecurity and technology risk by identifying, measuring, prioritizing, and driving treatment of material cyber and technology risks across enterprise technology environments, business processes, third-party relationships, supply chain dependencies, and merger, acquisition, and divestiture activity.
This leader defines the cyber and technology risk strategy, governance, assessment methods, control validation, and operating routines used to evaluate control effectiveness, threat exposure, technology, data, identity, resilience, third-party, and regulatory risk across internal and external stakeholders.
Reporting to the Deputy CISO, this collaborative leader partners with senior security, privacy, risk, legal, technology, procurement, corporate development, integration, and business leaders. The AVP converts internal and external cybersecurity and technology risk intelligence—including enterprise control gaps, technology control deficiencies, emerging threats, third-party exposure, supply chain dependencies, and M&A risk—into measurable risk decisions, remediation priorities, control requirements, and executive reporting that help protect CVS Health’s members, colleagues, protected health information, confidential data, critical systems, operations, and brand.
Key Responsibilities:
Evolve CVS Health’s cybersecurity and technology risk management program as a core component of the enterprise cyber and technology risk strategy, including risk taxonomy, risk appetite alignment, assessment methodology, internal and external risk identification, inherent and residual risk scoring, technology and security control validation, governance routines, issue management, and executive risk reporting.
Lead the end-to-end lifecycle of third-party cybersecurity risk assessments — including pre-contract due diligence, security architecture review, onboarding, periodic reassessment, continuous monitoring, offboarding, and risk acceptance — across thousands of vendors and business associates, ensuring decisions are transparent, evidence-based, and aligned to enterprise risk appetite.
Integrate internal enterprise risk signals and external third-party, supply chain, and M&A cyber and technology risk signals into CVS Health’s enterprise risk posture by identifying systemic exposure, technology concentration risk, control gaps, ransomware exposure, data protection risk, identity and access risk, cloud and infrastructure risk, application and platform risk, software supply chain risk, technology resilience risk, and emerging threat trends.
Lead M&A Security onboarding activities by partnering with Corporate Development, Integration Management, Legal, Privacy, Technology, and cybersecurity teams to assess cyber risk during due diligence; evaluate s
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s