Sr. Analyst (Cybersecurity) Corporate IT Audit
CVS HealthAbout the role
Bring your heart to CVS Health. Every one of us at CVS Health shares a single, clear purpose: Bringing our heart to every moment of your health. This purpose guides our commitment to deliver enhanced human-centric health care for a rapidly changing world. Anchored in our brand — with heart at its center — our purpose sends a personal message that how we deliver our services is just as important as what we deliver.
Our Heart At Work Behaviors™ support this purpose. We want everyone who works at CVS Health to feel empowered by the role they play in transforming our culture and accelerating our ability to innovate and deliver solutions to make health care more personal, convenient and affordable.
***This position will be classified as hybrid and will be filled in either Woonsocket, RI or Hartford, CT. Additional locations may be considered at management discretion***
Position Summary
- The Sr. Analyst (Cybersecurity) Corporate IT Audit will be a key member of the Data, Digital, Analytics and Technology (DDAT) Internal Audit team and will participate in the execution of internal audits. This role is responsible for delivering high quality cyber & IT internal audit results under the direction of IT Audit Managers and Directors, including planning, performing IT risk assessments, and developing and executing test plans to assess design and effectiveness. Key focus areas are technology risk assessments inclusive of cyber security assessments, and the ability to document and review critical internal controls, and communicating with / reporting audit findings to the business line management.
- CVS Health follows a 3-days in office (generally Tuesday, Wednesday, and Thursday) hybrid work model providing office-based colleagues the ability to flex between working in the office and working from home based on the work you need to accomplish. By applying to this position, you understand that you will be considered for opportunities at these multiple locations: Cumberland, RI (Headquarters); Hartford, CT. Should you accept a position, we will take your preferred work location into consideration and will attempt to accommodate.
Primary Job Duties and Responsibilities:
Audit Execution:
- Effectively perform and document Cyber Security & Technology audit activities in accordance with professional standards and the organization’s audit methodology.
- Execute testing and create work paper documentation.
- Understand procedures, results and business impacts; and document and express such understanding in both written and verbal form.
- Perform detail testing as defined by the test program to define, analyze and validate information.
- Create clear and accurate documentation and workflows of cyber security & technology processes and testing results and exceptions.
- Lead individual cyber security project components project components and testing areas; oversee the work of more junior auditors and/or interns.
Audit Reporting/Communication:
- Interacts with various levels of Internal Audit and DDAT line management business line management to resolve issues in a timely manner and to maintain effective communications.
- Reports related audit findings to audit and DDAT management.
Audit Team Support:
- Meets administrative reporting requirements and supports department initiatives.
- Demonstrates a commitment to integrity and the company code of conduct, and a respect for diversity and inclusion.
- Contribute to overall Internal Audit Department team norms to promote a positive environment and improve team effectiveness.
- Keep current of relevant cybersecurity & technology developments and evolving IT risk areas.
Required Qualifications:
- 3+ years experience in IT Audit, Cyber Security assessments, Controls Assessment, Control Validation, Risk Assessment, or Risk Consultant.
- CISSP Professional Designation
- Ability to travel up to 10%.
- Familiarity with the following concepts:
- Ability to coach experienced IT auditors.
- Demonstrated knowledge of risk assessment and familiarity with tools and techniques used to provide control and monitoring mechanisms.
- Demonstrated knowledge of IT audit methodologies and control frameworks of IT platforms, cyber security processes, systems and controls, including areas such as network security, logical access and change management controls at an infrastructure and application level, databases and systems maintenance.
- Knowledge of various network architectures, services, systems, applications, development platforms, network/security technologies.
- Proficiency in information security tools to exploit vulnerabilities in networks and applicat
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s