AVP, Application Security

Job not on LinkedIn

🔥 3 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of CVS Health

CVS Health

10,000+ employees

Founded 1963

⚕️ Healthcare Insurance

🛒 Retail

🧘 Wellness

Healthcare Insurance • Retail • Wellness

CVS Health is a leading American healthcare company dedicated to improving health access and affordability. The company focuses on a comprehensive approach that includes health services, health insurance, and pharmacy benefits management. Through its subsidiaries, such as Aetna and CVS Caremark, CVS Health offers a range of services that facilitate wellness, condition management, and affordable prescription drug coverage. CVS Health operates neighborhood pharmacies, provides mail-order pharmacy services, and manages specialty medication programs, aiming to make healthcare convenient and accessible for everyone. Driven by a mission to connect people with essential care services, CVS Health is committed to fostering healthier communities and supporting the wellbeing of all individuals.

📋 Description

• Define and own the enterprise application security strategy, roadmap, and policy framework, aligned with CVS Health's business objectives and regulatory obligations. • Establish and enforce technical standards for secure software development, including code scanning, code vulnerability management, and secure-by-design principles. • Serve as a subject matter expert and trusted advisor to senior technology and business executives on emerging application security risks, attack trends, and industry best practices. • Drive continuous improvement across the application security program through metrics, benchmarking, and innovation. • Lead the integration of application security scanning, testing, and policy enforcement gates into CI/CD pipelines across the enterprise. • Define strategy, standards, and tooling for enterprise-wide SAST scanning. • Oversee DAST program covering pre-production and production environments. • Own the strategy, configuration, and operations of the enterprise WAF platform. • Implement and manage continuous scanning of source code repositories for secrets, misconfigurations, exposed credentials, and policy violations. • Manage the Software Composition Analysis (SCA) program to identify and remediate vulnerabilities in third-party libraries and open-source dependencies. • Oversee security configuration and policy enforcement for content delivery network infrastructure. • Own the full application security tooling portfolio. Manage vendor relationships, licensing, platform health, and roadmap alignment. • Define and maintain application security policies, standards, and operational procedures. • Ensure compliance with applicable regulatory frameworks and industry standards, including HIPAA, PCI-DSS, CCPA, NIST SSDF, and OWASP. • Build, lead, and develop a high-performing team of application security engineers, architects, and program managers. • Partner closely with Developer Experience leadership to align security tooling and practices with developer workflows, ensuring security is integrated seamlessly into agile and DevSecOps pipelines.

🎯 Requirements

• 12+ years of progressive experience in information security, with at least 5 years in application security leadership roles. • Deep technical background in software development, including hands-on coding experience in one or more modern programming languages (e.g., Java, Python, Go, JavaScript, or similar). • Candidates must bring developer-level fluency to credibly engage with engineering teams, evaluate code-level risks, and drive meaningful secure coding practices. • Demonstrated expertise in application security engineering and secure software development lifecycle (SDLC) practices, grounded in first-hand experience building or shipping software. • Strong understanding of software architecture patterns, CI/CD pipelines, containerization, and cloud-native development — with the ability to assess security implications at every layer of the stack. • Hands-on experience managing enterprise application security tooling, including SAST, DAST, SCA, WAF, and repository scanning platforms. • Deep knowledge of application security standards and frameworks, including OWASP Top 10, NIST SSDF, and relevant regulatory requirements (HIPAA, PCI-DSS, CCPA). • Proven ability to influence engineering culture and drive security adoption at scale within agile development environments. • Strong leadership skills with experience building and managing cross-functional technical teams and influencing senior stakeholders. • Excellent communication and presentation skills; ability to translate complex security concepts for both technical and non-technical audiences.

🏖️ Benefits

• Medical, dental, and vision coverage • Paid time off • Retirement savings options • Wellness programs • Comprehensive benefits package

Apply Now

Similar Jobs

🔥 21 minutes ago

Allstate

10,000+ employees

💸 Finance

Product Manager responsible for defining and delivering cybersecurity products at Allstate. Collaborates with stakeholders to enhance security operations and compliance readiness.

🔥 31 minutes ago

SEI

1001 - 5000

💸 Finance

💳 Fintech

🏢 Enterprise

AI Cybersecurity Engineer serving as a technical security lead for AI initiatives at SEI. Architecting secure platforms to protect organization against evolving AI-powered threats.

🔥 1 hour ago

van den Boom & Associates LLC

51 - 200

💸 Finance

📋 Compliance

Director leading managed security services managing Secure + MDR offering for life sciences clients in a build-phase leadership role. Overseeing security operations, compliance programs, and client engagement.

🔥 23 hours ago

Ford Motor Company

10,000+ employees

🚗 Transport

Cyber Security Engineer focusing on engineering practical vulnerability risk solutions at Ford. Collaborating with teams to implement security controls across cloud and enterprise environments.

🕒 Yesterday

Lyric - Clarity in motion.

201 - 500

⚕️ Healthcare Insurance

💳 Fintech

☁️ SaaS

Staff Security Engineer designing, implementing, and operating security technologies at Lyric. Collaborating on security controls in cloud ecosystems and corporate infrastructure.