Jr. Security Engineer
CVS HealthAbout the role
At CVS Health, we’re building a world of health around every consumer and surrounding ourselves with dedicated colleagues who are passionate about transforming health care.
As the nation’s leading health solutions company, we reach millions of Americans through our local presence, digital channels and more than 300,000 purpose-driven colleagues – caring for people where, when and how they choose in a way that is uniquely more connected, more convenient and more compassionate. And we do it all with heart, each and every day.
Position Summary
We are seeking a highly skilled and experienced ServiceNow Security and Data Protections Engineer to join our team. This position will be responsible for ensuring the security and integrity of data within the ServiceNow platform, implementing data protection measures, and maintaining compliance with relevant security standards and regulations. The ideal candidate will have a strong background in cybersecurity, data protection, and ServiceNow platform security configurations. The Security and Data Protection Engineer will play a crucial role in ensuring the security and protection of our systems and data inside the platform. The engineer will work closely with cross-functional teams to implement and maintain security measures, monitor for potential threats, and respond to incidents. This role requires a strong understanding of security best practices and data protection technologies inside of a complex ServiceNow implementation.
Primary duties and responsibilities:
-Assist in the Implementation and maintenance of security controls and data protection measures within the ServiceNow platform to safeguard sensitive information and ensure compliance with regulatory requirements.
- Act on security assessments and remediate security vulnerabilities and weaknesses in ServiceNow configurations and customizations.
- Collaborate with cross-functional teams to develop and implement security policies, standards, and procedures for ServiceNow development, deployment, and operations.
- Monitor and analyze security logs, alerts, and incidents related to the ServiceNow platform, and respond promptly to security incidents, conducting root cause analysis and implementing corrective actions.
- Configure and manage access controls, role-based permissions, and encryption mechanisms within the ServiceNow platform to restrict unauthorized access and protect confidential data.
- Stay current with industry trends, emerging threats, and ServiceNow platform updates related to cybersecurity and data protection and recommend and implement security enhancements accordingly.
- Collaborate with internal audit teams and external auditors to ensure that ServiceNow security controls and data protection measures meet regulatory compliance requirements.
- Debug and troubleshoot security issues, identifying and resolving issues in a timely manner.
- Document security designs, configurations, and code for future reference and knowledge sharing.
Required Skills:
- 2+ years of experience in cybersecurity, data protection, or information security roles, with a focus on securing cloud-based platforms and applications.
- 2+ years of hands-on experience in security engineering, preferably within vulnerability management or cloud security.
- 2+ years of experience within the ServiceNow platform, including reviewing access controls, managing encryption, and auditing logs.
Preferred Skills:
- ServiceNow Certified System Administrator (CSA) or other ServiceNow certifications.
- 2+ years of experience in cybersecurity principles, practices, and frameworks, such as ISO 27001, NIST Cybersecurity Framework, and GDPR.
- Experience implementing and managing security solutions within a ServiceNow environment.
- Certified Cloud Security Professional (CCSP), CompTIA Security+/Cloud+, Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or other relevant cybersecurity certifications.
- Experience with ServiceNow Governance, Risk, and Compliance (GRC) module and its integration with security and data protection processes.
- Knowledge of cloud security best practices and experience securing cloud platforms such as AWS, Azure, or Google Cloud Platform.
-Strong knowledge of network security, authentication mechanisms, identity and access management (IAM), and encryption technologies.
- Proficiency in scripting and automation using languages such as PowerShell, Python, or JavaScript.
- Excellent problem-solving skills and the ability to analyze complex security issues, prioritize tasks, and develop effective solutions.
Education:
- Bachelor’s degree or equivalent experience (HS diploma + 4 years relevant experience)
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s