Jobs and Careers
CV

Lead Director, Threat Hunting

CVS Health
Work At Home-West Virginia, United States, United Statesfull_timeVerifiedPosted 11 Feb 2025
💰 $288,400/yr($144,200/yr$288,400/yr)

About the role

Bring your heart to CVS Health. Every one of us at CVS Health shares a single, clear purpose: Bringing our heart to every moment of your health. This purpose guides our commitment to deliver enhanced human-centric health care for a rapidly changing world. Anchored in our brand — with heart at its center — our purpose sends a personal message that how we deliver our services is just as important as what we deliver.
 
Our Heart At Work Behaviors™ support this purpose. We want everyone who works at CVS Health to feel empowered by the role they play in transforming our culture and accelerating our ability to innovate and deliver solutions to make health care more personal, convenient and affordable.

Job Description:

The CVS Threat Hunting teams mission is to proactively discover, document, and report evidence of previously undetected threats on enterprise networks, servers, workstations, and network devices. Through investigation of the environment, the Threat Hunting teams goals is to reduce dwell time of adversaries and thus reduce their impact on the organization, and directly enhance incident detection capabilities through advanced analysis techniques, both human-driven and automated.

CVS is looking for a results-driven leader to join our growing cybersecurity team. In this role, the leader will be responsible for developing, implementing, and managing the organizations Threat  Hunt team within the Cyber Defense Organization. The leader will oversee a team of threat hunters responsible for identifying, analyzing, and mitigating cyber threats before they can cause significant damage to our organization.

This role is ideal for someone with a deep understanding of cybersecurity, who thrives in a collaborative environment and enjoys the challenge of solving complex security puzzles. You will be an essential part of a forward-thinking security operations team, helping to continually evolve our threat detection capabilities, improve response times, and ultimately protect the integrity of our critical systems and sensitive data. If you're passionate about staying ahead of emerging threats and have a penchant for proactive defense, we want to hear from you.

Key Responsibilities:

  • Lead and develop a high performing threat hunting team, providing strategic direction and technical guidance
  • Implement the organizations Threat Hunting Framework to impose cost and reduce dwell time
  • Develop and maintain key performance indicators (KPIs), key risk indicators (KRIs), and other business critical metrics to measure the value and effectiveness of the program
  • Collaborate with internal Cyber Defense teams such as Cyber Threat Intelligence, SOC and Incident Response, Adversarial Operations, Platform Engineering, and Data Analytics to improve detection and response capabilities
  • Provide reporting to Executive Leadership team to actively progress the security goals of CVS

Requirements:

  • 10+ years of experience in a cybersecurity role, with a strong focus on threat hunting, incident response, or advanced threat detection.
  • 8+ years of experience with analyzing attack vectors, utilizing intrusion detection systems (IDS), endpoint detection and response (EDR) tools, SIEM, and other security technologies.
  • 3+ years of proficiency with scripting languages (Python, PowerShell, etc.) for automation and analysis tasks.
  • 5+ years of experience with threat intelligence platforms and frameworks (e.g., MITRE ATT&CK, STIX/TAXII).
  • 8+ years of experience conducting analysis, with the ability to identify patterns and correlations within large datasets.
  • 2+ years of experience  with malware analysis, reverse engineering, and common exploit techniques.

Preferred Qualifications:

  • Strong communication skills, both written and verbal, with the ability to present technical findings to non-technical stakeholders.
  • Ability to work in an evolving environment while managing multiple priorities.
  • Relevant certifications such as Certified Ethical Hacker (CEH), GIAC Cyber Threat Intelligence (GCTI), Certified Information Systems Security Professional (CISSP), or GIAC Security Essentials (GSEC).
  • Experience with cloud security (AWS, Azure, GCP).
  • Familiarity with network traffic analysis and protocols (e.g., DNS, HTTP, SSL/TLS).
  • Knowledge of advanced malware techniques and/or reverse engineering.

Education:

  • Bachel

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

CVS Health

View company profile →