Principal Application Security Engineer
CVS HealthAbout the role
Bring your heart to CVS Health. Every one of us at CVS Health shares a single, clear purpose: Bringing our heart to every moment of your health. This purpose guides our commitment to deliver enhanced human-centric health care for a rapidly changing world. Anchored in our brand — with heart at its center — our purpose sends a personal message that how we deliver our services is just as important as what we deliver.
Our Heart At Work Behaviors™ support this purpose. We want everyone who works at CVS Health to feel empowered by the role they play in transforming our culture and accelerating our ability to innovate and deliver solutions to make health care more personal, convenient and affordable.
Who You Are
- Deeply experienced in coding with a nuanced understanding of Object-Oriented and Functional programming concepts, capable of writing and reviewing code across multiple languages and paradigms.
- Highly passionate about building and operating secure, reliable systems at scale, with a proven track record in similar environments.
- Demonstrated ability to innovate and automate security processes and functions through code, enhancing efficiency and effectiveness.
- Demonstrated leadership skills with the ability to mentor and develop junior security engineers, fostering a culture of continuous learning and excellence within the team.
- Strong technical expertise with Application, Cloud, Data, and Network Security best practices.
- Strong technical expertise with multi-cloud environments, including container/serverless and other microservice architectures.
- Strong technical expertise with older technology stacks, including mainframes and monolithic architectures.
- Strong technical expertise with SDLC, CI/CD tools, and Deployment Automation.
- Strong technical expertise with operating security for Windows Server and Linux Server systems.
- Strong technical expertise with configuration management, version control, and DevOps operational support.
- Strong experience with implementing security measures for both applications and data, with an understanding of the unique security requirements of data warehouse technologies such as Snowflake.
- Hands-on experience with Web Application Firewalls and advanced bot detection systems like Imperva, capable of deploying and managing such systems to protect against automated threats.
Role Responsibilities
Development & Enforcement
- Develop and enforce engineering security policies and standards.
- Develop and enforce data security policies and standards.
- Drive security awareness across the organization.
- Lead the development and enforcement of comprehensive security policies and standards, integrating advanced security practices throughout the software development lifecycle to mitigate risks and align with industry-leading security protocols.
Collaboration & Expertise
- Collaborate with Engineering and Business teams to develop secure engineering practices.
- Act as a pivotal security leader, driving the integration of secure engineering practices across the organization while liaising with senior management to ensure a cohesive security strategy that aligns with business objectives.
Analysis & Configuration
- Analyze, develop, and configure security solutions across multi-cloud, on-premises, and colocation environments, ensuring application security, integrity, confidentiality, and availability of data.
- Lead security testing, vulnerability analysis, and documentation.
- Spearhead the evaluation and strategic deployment of cutting-edge security solutions, emphasizing scalability, performance, and adaptability, to fortify the organization's defense against evolving threats.
Operational Support
- Participate in operational on-call duties to support a 24/7 infrastructure across multiple regions and environments (cloud, on-premises, colocation).
- Lead by example in incident response situations, orchestrating rapid and effective responses while leveraging these experiences to bolster future resilience and response strategies.
Mentorship and Training
- Demonstrated leadership skills with developing a comprehensive mentorship program for junior engineers, including organizing regular training sessions to elevate the team's technical and security skills. This role requires a commitment to fostering a culture of continuous improvement and knowledge sharing.
Innovation and Research
- Proven track record with participation in security research and the exploration of next-generation security tools and practices. This includes encouraging the team to engage wi
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s