AVP, Application Security

Stelle nicht auf LinkedIn

🕒 vor 9 Tagen

🗣️🇺🇸🇬🇧 Englisch erforderlich

Jetzt Bewerben
Ähnliche Remote-Jobs finden

📊 Überprüfen Sie Ihre Lebenslauf-Bewertung für diese Stelle

Verbessern Sie Ihre Chancen auf ein Vorstellungsgespräch, indem Sie Ihre Lebenslauf-Bewertung vor der Bewerbung überprüfen.

Logo of CVS Health

CVS Health

10.000+ Mitarbeiter

Gegründet 1963

🏥 Gesundheitswesen

⚕️ Krankenversicherung

🛒 Einzelhandel

Healthcare • Healthcare Insurance • Retail

CVS Health ist ein führendes amerikanisches Gesundheitsunternehmen, das sich der Verbesserung des Zugangs zu Gesundheitsdiensten und deren Erschwinglichkeit verschrieben hat. Das Unternehmen verfolgt einen umfassenden Ansatz, der Gesundheitsdienstleistungen, Krankenversicherungen und das Management von Apothekenleistungen umfasst. Durch seine Tochtergesellschaften, wie Aetna und CVS Caremark, bietet CVS Health eine Vielzahl von Dienstleistungen an, die Wohlbefinden, Krankheitsmanagement und erschwinglichen Versicherungsschutz für verschreibungspflichtige Medikamente erleichtern. CVS Health betreibt Apotheken in der Nachbarschaft, bietet Versandapothekendienste an und verwaltet Programme für Spezialmedikamente, um Gesundheitsversorgung für jeden bequem und zugänglich zu machen. Angetrieben von der Mission, Menschen mit wesentlichen Pflegediensten zu verbinden, ist CVS Health bestrebt, gesündere Gemeinschaften zu fördern und das Wohlbefinden aller Menschen zu unterstützen.

Beschreibung

• Define and own the enterprise application security strategy, roadmap, and policy framework, aligned with CVS Health's business objectives and regulatory obligations. • Establish and enforce technical standards for secure software development, including code scanning, code vulnerability management, and secure-by-design principles. • Serve as a subject matter expert and trusted advisor to senior technology and business executives on emerging application security risks, attack trends, and industry best practices. • Drive continuous improvement across the application security program through metrics, benchmarking, and innovation. • Lead the integration of application security scanning, testing, and policy enforcement gates into CI/CD pipelines across the enterprise. • Define strategy, standards, and tooling for enterprise-wide SAST scanning. • Oversee DAST program covering pre-production and production environments. • Own the strategy, configuration, and operations of the enterprise WAF platform. • Implement and manage continuous scanning of source code repositories for secrets, misconfigurations, exposed credentials, and policy violations. • Manage the Software Composition Analysis (SCA) program to identify and remediate vulnerabilities in third-party libraries and open-source dependencies. • Oversee security configuration and policy enforcement for content delivery network infrastructure. • Own the full application security tooling portfolio. Manage vendor relationships, licensing, platform health, and roadmap alignment. • Define and maintain application security policies, standards, and operational procedures. • Ensure compliance with applicable regulatory frameworks and industry standards, including HIPAA, PCI-DSS, CCPA, NIST SSDF, and OWASP. • Build, lead, and develop a high-performing team of application security engineers, architects, and program managers. • Partner closely with Developer Experience leadership to align security tooling and practices with developer workflows, ensuring security is integrated seamlessly into agile and DevSecOps pipelines.

🎯 Anforderungen

• 12+ years of progressive experience in information security, with at least 5 years in application security leadership roles. • Deep technical background in software development, including hands-on coding experience in one or more modern programming languages (e.g., Java, Python, Go, JavaScript, or similar). • Candidates must bring developer-level fluency to credibly engage with engineering teams, evaluate code-level risks, and drive meaningful secure coding practices. • Demonstrated expertise in application security engineering and secure software development lifecycle (SDLC) practices, grounded in first-hand experience building or shipping software. • Strong understanding of software architecture patterns, CI/CD pipelines, containerization, and cloud-native development — with the ability to assess security implications at every layer of the stack. • Hands-on experience managing enterprise application security tooling, including SAST, DAST, SCA, WAF, and repository scanning platforms. • Deep knowledge of application security standards and frameworks, including OWASP Top 10, NIST SSDF, and relevant regulatory requirements (HIPAA, PCI-DSS, CCPA). • Proven ability to influence engineering culture and drive security adoption at scale within agile development environments. • Strong leadership skills with experience building and managing cross-functional technical teams and influencing senior stakeholders. • Excellent communication and presentation skills; ability to translate complex security concepts for both technical and non-technical audiences.

🏖️ Vorteile

• Medical, dental, and vision coverage • Paid time off • Retirement savings options • Wellness programs • Comprehensive benefits package

Jetzt Bewerben

Ähnliche Jobs

🕒 vor 9 Tagen

Allstate

10.000+ Mitarbeiter

💼 Beratung

📦 Logistik

🛡️ Versicherung

Product Manager responsible for defining and delivering cybersecurity products at Allstate. Collaborates with stakeholders to enhance security operations and compliance readiness.

🇺🇸 Vereinigte Staaten – Remote

💵 $120.000 - $193.725 / Jahr

💰 Post-IPO Equity im 2014-01

⏰ Vollzeit

🟠 Senior

🔴 Experte

👮‍♂️ IT-Sicherheitsingenieur

🦅 H1B-Visum-Sponsor

info

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 9 Tagen

SEI

1001 - 5000

💸 Finanzen

💳 Fintech

🏢 Unternehmen

AI Cybersecurity Engineer serving as a technical security lead for AI initiatives at SEI. Architecting secure platforms to protect organization against evolving AI-powered threats.

🇺🇸 Vereinigte Staaten – Remote

💵 $160.000 - $200.000 / Jahr

⏰ Vollzeit

🟠 Senior

🔴 Experte

👮‍♂️ IT-Sicherheitsingenieur

🦅 H1B-Visum-Sponsor

info

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 9 Tagen

van den Boom & Associates LLC

51 - 200

💸 Finanzen

📋 Compliance

Director leading managed security services managing Secure + MDR offering for life sciences clients in a build-phase leadership role. Overseeing security operations, compliance programs, and client engagement.

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🔴 Experte

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 10 Tagen

SmarterDx

11 - 50

🏥 Gesundheitswesen

💼 Beratung

⚖️ Rechtswesen

Senior Security Engineer focusing on AI and cloud security at SmarterDx. Leading detection strategies and mentoring engineers in a fully remote environment.

🇺🇸 Vereinigte Staaten – Remote

💵 $230.000 - $250.000 / Jahr

💰 €6.000.000 Seed Round im 2022-04

⏰ Vollzeit

🔴 Experte

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 10 Tagen

KBR, Inc.

10.000+ Mitarbeiter

💼 Beratung

🎖️ Verteidigung

📦 Logistik

Information System Security Officer providing critical support for DoD cybersecurity compliance and systems administration. Develops and maintains security policies while collaborating within distributed teams.

🇺🇸 Vereinigte Staaten – Remote

💵 $125.000 - $155.000 / Jahr

⏰ Vollzeit

🟠 Senior

🔴 Experte

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

Cyber Security

Linux

TypeScript

VMware