Senior Security Engineer
CVS HealthAbout the role
At CVS Health, we’re building a world of health around every consumer and surrounding ourselves with dedicated colleagues who are passionate about transforming health care.
As the nation’s leading health solutions company, we reach millions of Americans through our local presence, digital channels and more than 300,000 purpose-driven colleagues – caring for people where, when and how they choose in a way that is uniquely more connected, more convenient and more compassionate. And we do it all with heart, each and every day.
POSITION SUMMARY
CVS Health offers the opportunity to design, build, and operate a world-class Purple Team capability—creating and running a test-execution platform that continuously validates and strengthens defensive controls. You will enable safe, scalable adversary emulation linked to detection and response metrics, blending offensive tradecraft, automation, and reliability engineering to deliver a production-ready system that drives measurable cyber-resilience improvements. The position also provides opportunities to leverage AI for workflow automation.
What we expect of you
Help maintain and evolve a secure, scalable adversary-emulation platform for campaign scheduling, agent orchestration, payload execution, and results cataloging.
Review commercial alternatives for Purple Team exercises using custom runners or commercial tools (e.g., Cymulate, Picus).
Provision static or ephemeral test environments via Terraform/Kubernetes across cloud and on-prem infrastructure.
Develop continuous adversarial threat-simulation tests for defensive control validation and resiliency assessment.
Generate high-fidelity telemetry for EDR, SIEM, and SOAR to measure detection coverage, latency, and control effectiveness.
Research detection brittleness, design mutation/variant tests, and enhance test cases to strengthen detection logic.
Manage work intake pipeline and ensure timely closure of ticketed requests within SLA.
Produce ATT&CK-mapped artifacts, dashboards, and coverage metrics for Detection Engineering and leadership.
Enforce platform security through RBAC, secrets management, audit logging, and execution safety controls.
Collaborate with CTI, Threat Hunt, and SOC teams to evolve test cases based on real-world threats and gaps.
REQUIRED QUALIFICATIONS
5+ years of experience in the offensive security testing space
2+ years in security automation, platform engineering, or DevSecOps.
2+ years of strong automation skills using GitHub runners and JIRA.
1+ years of experience designing tests for detection robustness and mitigating brittleness.
PREFERRED QUALIFICATIONS
Excellent working knowledge about cloud security in relation to the major CSPs.
Proficiency in scripting languages (Python, Go, Bash, PowerShell, etc.).
Deep knowledge of MITRE ATT&CK and adversary-emulation frameworks.
Understanding of detection architectures (EDR, SIEM, SOAR) and telemetry generation.
Ability to build secure, observable, fault-tolerant services.
Experience automating adversary simulation or Purple Team workflows.
Hands-on with IaC (Terraform/CloudFormation) and containerization (Docker/Kubernetes).
Familiarity with MITRE ATT&CK, D3FEND, CAPEC, and threat-informed defense methodologies.
Integration experience with ServiceNow, Jira, or enterprise workflow systems.
Exposure to graph visualization tools and automated reporting/dashboard creation.
Knowledge of tools like Swimlane, DataBricks, Archer, Slack, MS O365.
Experience with BAS tools like Cymulate and Picks among others.
Ability to manage automation request pipelines and prioritize effectively.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s