Jobs and Careers
CV

Senior Manager - Data Protection

CVS Health
Woonsocket, United Statesfull_timeVerifiedPosted 31 Jul 2025
💰 $260,590/yr($106,605/yr$260,590/yr)

About the role

At CVS Health, we’re building a world of health around every consumer and surrounding ourselves with dedicated colleagues who are passionate about transforming health care.

As the nation’s leading health solutions company, we reach millions of Americans through our local presence, digital channels and more than 300,000 purpose-driven colleagues – caring for people where, when and how they choose in a way that is uniquely more connected, more convenient and more compassionate. And we do it all with heart, each and every day.

Position Summary

We are seeking a highly skilled and experienced Senior Manager of Application Data Security to oversee and ensure the security of business applications data, focusing on classification, encryption, activity monitoring, data security controls and governance. This leadership role will be responsible for managing the design, implementation, and continuous improvement of data security strategies across our application portfolio. The Senior Manager will collaborate with cross-functional teams to create and maintain robust data protection frameworks, ensuring compliance with industry regulations, contractual obligations and organizational policies.

Primary Job Duties & Responsibilities:

  • Develop and implement comprehensive data security governance frameworks that align with business goals, industry best practices and regulatory requirements.

  • Drive and communicate vision and strategy for application data security aligned with overall business goals, industry trends and best practices.

  • Lead a team of data security and privacy engineers, build and retain talent, provide technical guidance and mentorship to team members ensuring high-quality deliverables.

  • Lead the development and enforcement of data security policies, standards, and procedures for application data protection.

  • Lead efforts to continuously evaluate and improve application security practices, tools, and processes.

  • Lead the design, implementation, and management of advanced encryption strategies for sensitive application data both at rest and in transit.

  • Oversee the implementation and management of activity monitoring solutions for detecting and responding to suspicious activities across applications and data environments.

  • Collaborate with incident response teams to investigate and mitigate potential data security breaches and unauthorized access.

  • Work with development, engineering, and operations teams to ensure secure application deployment, and risk mitigation during the application lifecycle.

  • Educate stakeholders across the organization on data security risks, best practices, and compliance obligations related to application data security.

  • Identify, assess, and prioritize security risks related to application data and provide strategic recommendations to mitigate those risks.

  • Support data protection audit, compliance, regulatory, client assurance, and third-party assessment projects.

  • Manage the sequencing and timing of project delivery with technology leadership, product, and engineering teams.

  • Lead development and maintenance of data security dashboards, KPIs, KRIs and scorecards.


Required Qualifications

  • 7+ years of steady career progression with information security work experience

  • 5+ years of proven experience with implementing data security and privacy engineering solutions.

  • 5+ years of experience in leading data security and privacy frameworks. 

  • 5+ years of recent personnel management experience with oversight of five or more direct reports.

  • 5+ years of leadership and communication skills with the ability to influence stakeholders at all levels of the organization.

  • 5+ years of experience with security controls alignment to key regulations like NIST, FIPS 140-2, ISO, HITRUST, HIPAA, PCI, CCPA, GDPR.


Preferred Qualifications

  • Strong knowledge of data protection techniques and best practices.

  • Industry certifications from PMI, ISC2, SANS, ISACA, IAPP or equivalent.

  • Knowledge of data security and privacy regulatory compliance, frameworks and standards such as PCI, HIPAA, NIST, FIPS 140-2, GDPR, CCPA.

  • Ability to manage a high degree of complexity and distill information that provides clear direction.

  • Ability to motivate others with high expectations to facilitate impact and pace of change. 

  • Agility to deal with a constantly changing business environments.

  • Comfortable operating within areas of ambiguity to iterate and make progress in a consistent manner.

  • Foster collaborative

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

CVS Health

View company profile →