Jobs and Careers
CV

Sr Analyst, Information Security - Cyber resiliency

CVS Health
Work At Home-Arizona, United States, United Statesfull_timeVerifiedPosted 5 Feb 2026
💰 $144,200/yr($72,100/yr$144,200/yr)

About the role

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.

Position Summary
Provides operational support for CVS Health’s Digital, Data, Analytics & Technology (DDAT) Cyber Resiliency team, guiding colleagues in facilitating Cyber Resiliency activities across the enterprise.  Responsible for meeting goals, priorities, and timelines in support of the DDAT Cyber Resiliency Program.  Contribute toward development and implementation of policies, procedures, and controls ensuring compliance with Cyber Resiliency NIST framework.  Conducts risk assessments to identify areas of potential non-compliance and assist with developing strategies to mitigate risks.  Seek to continuously improve controls, processes, and systems to enhance the effectiveness and efficiency of the Cyber Resiliency program.  Provide training and education to colleagues across all levels of the organization on Cyber Resiliency requirements and industry best practices.  Oversees preparation and submission of required Cyber resiliency reports to management, DDAT, Audit Services, external auditors, and regulators.  Coordinate activities of internal and external assessments, including supporting audit planning, execution, and follow up.  Collaborate with key stakeholders, including management, Legal, Internal Audit, and external assessors, ensuring alignment and support of the Cyber Resiliency Program.  Monitor and assist with enforcing adherence to policies, standards, procedures, and controls through regular assessments and audits.

Required Qualifications

  • 2-3 years of GRC or Cyber resiliency experience, internal audit, external assessments, risk management, regulatory compliance, and information security in a corporate environment
  • Working knowledge of Information Security policies and procedures; experience supporting GRC programs
  • Working knowledge and understanding of cyber resiliency concepts and frameworks
  • Assist in development, implementation, and maintenance of the organization’s cyber resiliency program, ensuring adherence to regulatory requirements and industry best practices.
  • Plan, coordinate, and execute testing of internal controls to evaluate their effectiveness in mitigating risks and ensuring accuracy of reporting.
  • Understanding of disaster recovery, cyber incident response, crisis management and business continuity testing concepts
  • Maintain documentation of processes, controls, and testing related to cyber resiliency requirements; create and prepare metrics and reporting on findings and recommendations for management.
  • Solid understanding of relevant regulations and frameworks aligning to NIST 800 and NIST CSF Frameworks, ISO, HITRUST, HIPPA, PCI, ZTMM
  • Possess security architecture and engineering knowledge including zero trust concepts.
  • Demonstrates analytical and problem-solving skills with ability to analyze and interpret operational data, trends, assess risks effectively, and make recommendations for improvement.
  • Possess excellent verbal and written communications skills to effectively engage and advise stakeholders at all levels of the organization. 
  • Demonstrate attention to detail


Preferred Qualifications

Knowledge of:

  • Information security policies, procedures and risk management
  • Regulatory standards including SOX, SOC, HIPAA, PCI, and HITRUST
  • NIST or ISO Cyber Resiliency frameworks
  • Security architecture, networking, and network related systems
  • Cyber incident response and disaster recovery processes

Skill in:

  • Interpersonal and collaboration skills  
  • Customer service and relationship building
  • Effective time management

Ability To:

  • Execute on assigned tasks, providing timely feedback to customers/stakeholders/teammates
  • Collaborate across many teams in a large-scale environment

Education

  • Bachelor's or certifications in cybersecurity preferred

Anticipated Weekly Hours

40

Time Type

Full time

Pay Range

The typical pay range for this role is:

$72,100.00 - $144,200.00

This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls.  The actual base salary offer will depen

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

CVS Health

View company profile →