Senior Manager - Endpoint Compliance and Hardening
CVS HealthAbout the role
Bring your heart to CVS Health. Every one of us at CVS Health shares a single, clear purpose: Bringing our heart to every moment of your health. This purpose guides our commitment to deliver enhanced human-centric health care for a rapidly changing world. Anchored in our brand — with heart at its center — our purpose sends a personal message that how we deliver our services is just as important as what we deliver.
Our Heart At Work Behaviors™ support this purpose. We want everyone who works at CVS Health to feel empowered by the role they play in transforming our culture and accelerating our ability to innovate and deliver solutions to make health care more personal, convenient and affordable.
Position Summary
The Endpoint Compliance and Hardening - Senior Manager is responsible for designing, implementing, and managing the Enterprise Security Policy Configuration Management and File Integrity Monitoring strategy to safeguard critical systems and data. This role ensures that file systems, file configuration changes, and secure hardening configurations are current and continuously monitored to protect against unauthorized modifications, contributing to the overall cybersecurity posture. The Endpoint Compliance and Hardening Senior Manager combines technical expertise with leadership skills to guide teams and align security operations with business objectives.
Key Responsibilities
Strategy and Leadership
Develop and manage the organization's file integrity monitoring and secure hardening configuration policy framework, ensuring alignment with security and business objectives.
Lead a team of configuration specialists, providing leadership, mentorship, and technical guidance.
Stay informed of emerging security threats, compliance requirements, and best practices related to secure configurations.
File Integrity Monitoring and Secure Hardening Configuration Management
Define and enforce File Integrity Monitoring policies and procedures to ensure the integrity of critical files and systems.
Lead the team to establish baselines for normal file states and monitor for unauthorized or suspicious changes.
Lead regular audits and reviews of FIM processes to identify and address gaps.
Define, implement, and maintain secure configurations for operating systems, databases, applications, and network devices (e.g., firewalls, routers).
Ensure consistent application of security baselines (e.g., CIS Benchmarks, NIST guidelines) across the enterprise.
Oversee the deployment, configuration, and management of File Integrity Monitoring tools and solutions (Qualys, Splunk, etc.).
Regularly review and update policies to reflect changes in the threat landscape or regulatory requirements.
Collaboration and Integration
Work closely with IT, DevOps, and Security Operations teams to ensure file integrity monitoring and secure hardening configuration policies are integrated into system and application lifecycles.
Partner with compliance and risk teams to ensure file integrity monitoring and secure hardening configurations meet regulatory standards (e.g., PCI DSS, HIPAA, SOX).
Provide guidance and support during internal and external audits.
Incident Detection and Response
Collaborate with Security Operations Center (SOC) and Incident Response teams to investigate file integrity monitoring alerts and security incidents.
Ensure proper logging, alerting, and reporting mechanisms are in place for timely detection and response.
Contribute to forensic investigations by providing detailed logs and evidence from FIM systems.
Monitoring and Reporting
Implement tools and processes to continuously monitor and enforce secure configurations (e.g., vulnerability scanners, configuration management tools).
Develop and deliver executive-level reports on compliance with configuration policies, including metrics on policy adherence and risk mitigation.
Lead root cause analysis and remediation efforts for configuration-related security incidents.
Continuous Improvement and Training
Promote a culture of security awareness and best practices within the organization.
Drive automation initiatives to streamline configuration management processes.
Provide training and resources to ensure teams understand and adhere to secure configuration policies.
Risk Prioritization and Management
Prioritize vulnerabilities based on risk assessments, considering factors such as expl
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s