AVP, Application Security

Job not on LinkedIn

🕒 Yesterday

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of CVS Health

CVS Health

10,000+ employees

Founded 1963

🏥 Healthcare

⚕️ Healthcare Insurance

🛒 Retail

Healthcare • Healthcare Insurance • Retail

CVS Health is a leading American healthcare company dedicated to improving health access and affordability. The company focuses on a comprehensive approach that includes health services, health insurance, and pharmacy benefits management. Through its subsidiaries, such as Aetna and CVS Caremark, CVS Health offers a range of services that facilitate wellness, condition management, and affordable prescription drug coverage. CVS Health operates neighborhood pharmacies, provides mail-order pharmacy services, and manages specialty medication programs, aiming to make healthcare convenient and accessible for everyone. Driven by a mission to connect people with essential care services, CVS Health is committed to fostering healthier communities and supporting the wellbeing of all individuals.

📋 Description

• Define and own the enterprise application security strategy, roadmap, and policy framework, aligned with CVS Health's business objectives and regulatory obligations. • Establish and enforce technical standards for secure software development, including code scanning, code vulnerability management, and secure-by-design principles. • Serve as a subject matter expert and trusted advisor to senior technology and business executives on emerging application security risks, attack trends, and industry best practices. • Drive continuous improvement across the application security program through metrics, benchmarking, and innovation. • Lead the integration of application security scanning, testing, and policy enforcement gates into CI/CD pipelines across the enterprise. • Define strategy, standards, and tooling for enterprise-wide SAST scanning. • Oversee DAST program covering pre-production and production environments. • Own the strategy, configuration, and operations of the enterprise WAF platform. • Implement and manage continuous scanning of source code repositories for secrets, misconfigurations, exposed credentials, and policy violations. • Manage the Software Composition Analysis (SCA) program to identify and remediate vulnerabilities in third-party libraries and open-source dependencies. • Oversee security configuration and policy enforcement for content delivery network infrastructure. • Own the full application security tooling portfolio. Manage vendor relationships, licensing, platform health, and roadmap alignment. • Define and maintain application security policies, standards, and operational procedures. • Ensure compliance with applicable regulatory frameworks and industry standards, including HIPAA, PCI-DSS, CCPA, NIST SSDF, and OWASP. • Build, lead, and develop a high-performing team of application security engineers, architects, and program managers. • Partner closely with Developer Experience leadership to align security tooling and practices with developer workflows, ensuring security is integrated seamlessly into agile and DevSecOps pipelines.

🎯 Requirements

• 12+ years of progressive experience in information security, with at least 5 years in application security leadership roles. • Deep technical background in software development, including hands-on coding experience in one or more modern programming languages (e.g., Java, Python, Go, JavaScript, or similar). • Candidates must bring developer-level fluency to credibly engage with engineering teams, evaluate code-level risks, and drive meaningful secure coding practices. • Demonstrated expertise in application security engineering and secure software development lifecycle (SDLC) practices, grounded in first-hand experience building or shipping software. • Strong understanding of software architecture patterns, CI/CD pipelines, containerization, and cloud-native development — with the ability to assess security implications at every layer of the stack. • Hands-on experience managing enterprise application security tooling, including SAST, DAST, SCA, WAF, and repository scanning platforms. • Deep knowledge of application security standards and frameworks, including OWASP Top 10, NIST SSDF, and relevant regulatory requirements (HIPAA, PCI-DSS, CCPA). • Proven ability to influence engineering culture and drive security adoption at scale within agile development environments. • Strong leadership skills with experience building and managing cross-functional technical teams and influencing senior stakeholders. • Excellent communication and presentation skills; ability to translate complex security concepts for both technical and non-technical audiences.

🏖️ Benefits

• Medical, dental, and vision coverage • Paid time off • Retirement savings options • Wellness programs • Comprehensive benefits package

Apply Now

Similar Jobs

🕒 Yesterday

Allstate

10,000+ employees

🛡️ Insurance

💸 Finance

Product Manager responsible for defining and delivering cybersecurity products at Allstate. Collaborates with stakeholders to enhance security operations and compliance readiness.

AWS

Azure

Cloud

Cyber Security

Google Cloud Platform

🕒 Yesterday

SEI

1001 - 5000

💸 Finance

💳 Fintech

🏢 Enterprise

AI Cybersecurity Engineer serving as a technical security lead for AI initiatives at SEI. Architecting secure platforms to protect organization against evolving AI-powered threats.

AWS

Azure

Cloud

Cyber Security

Docker

ERP

Google Cloud Platform

Java

Kubernetes

Python

PyTorch

RPA

Scikit-Learn

Tensorflow

Go

🕒 Yesterday

van den Boom & Associates LLC

51 - 200

💸 Finance

📋 Compliance

Director leading managed security services managing Secure + MDR offering for life sciences clients in a build-phase leadership role. Overseeing security operations, compliance programs, and client engagement.

🕒 2 days ago

Ford Motor Company

10,000+ employees

🚘 Automotive

🚗 Transport

🏭 Manufacturing

Cyber Security Engineer focusing on engineering practical vulnerability risk solutions at Ford. Collaborating with teams to implement security controls across cloud and enterprise environments.

Ansible

Azure

Cloud

Cyber Security

Distributed Systems

Google Cloud Platform

Python

Terraform

🕒 2 days ago

Lyric - Clarity in motion.

201 - 500

⚕️ Healthcare Insurance

💳 Fintech

☁️ SaaS

Staff Security Engineer designing, implementing, and operating security technologies at Lyric. Collaborating on security controls in cloud ecosystems and corporate infrastructure.

AWS

Azure

Cyber Security

Kubernetes

Python

Terraform