CVS Health

Staff DevSecOps Engineer (Health 100)

CVS Health
Apply
2 days ago
Remote, United States or New York, NY, USAStaff+
H1B sponsor

Base Salary

$130k - $261k/yr

Responsibilities

  • Lead Health 100 application security enablement, including release-readiness patterns, mobile security testing, secure configuration validation, and remediation guidance.
  • Own technical planning, architecture, delivery, issue resolution, and outcomes for DevSecOps implementations and security-tool migrations.
  • Design and improve CI/CD security controls, pipeline enforcement, automated scanning, secret detection, and self-service security solutions.
  • Lead migrations such as Checkmarx to Snyk, validate post-migration scan results, and standardize security tooling configurations.
  • Drive remediation of critical and high-risk vulnerabilities, monitor SLA performance, and prioritize open-source and software-supply-chain risks.
  • Engineer security controls for public cloud, containers, Kubernetes, Security-as-Code, and Infrastructure-as-Code environments.
  • Assess iOS and Android application risks, validate mobile-security testing results, and guide remediation of mobile-specific findings.
  • Track scan coverage, mobile testing coverage, vulnerability aging, SLA adherence, automation adoption, tool coverage, and pipeline compliance.
  • Mentor engineers, establish reusable engineering patterns, create implementation guidance, and provide executive-ready security updates.

Requirements

  • 7+ years of experience in DevSecOps, application security engineering, platform security, or software engineering.
  • Experience integrating SAST, SCA, secrets detection, container scanning, IaC scanning, or comparable security controls into CI/CD pipelines.
  • Experience leading security implementations or tool migrations in large or complex engineering environments.
  • Proficiency with public cloud platforms such as AWS, Azure, or GCP, along with cloud and network security concepts.
  • Experience with Docker, Kubernetes, Security-as-Code, and Infrastructure-as-Code.
  • Hands-on scripting or programming experience with Python, Java, JavaScript, Go, Shell, or PowerShell.
  • Experience with application vulnerability management, open-source risk, and software supply-chain security.
  • Experience with mobile application security testing, mobile threat modeling, or remediation of iOS and Android security findings.
  • Demonstrated ability to use metrics to drive adoption, remediation, and measurable technical outcomes.
  • Preferred: experience with portfolio-based initiatives, Snyk, Checkmarx, Gitleaks, SBOM tooling, Data Theorem, MobSF, public-cloud security architecture, networking, Software-Defined Networking, Snowflake, HIPAA, HITRUST, PCI, NIST, GDPR, CCPA, and communicating risk posture to senior leadership.
  • Bachelor’s degree in Computer Science, Software Development, Software Engineering, or a related field, or equivalent practical experience.

Benefits

  • Full-time position with medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources based on eligibility.
  • Eligible for CVS Health bonus, commission, or short-term incentive programs and an equity award target; compensation details excluded from this benefits summary.
  • Application window is anticipated to close on 10/30/2026.
CVS Health

About CVS Health

10,000+ employees

CVS Health is a U.S. health care company that operates thousands of retail pharmacies, runs the CVS Caremark pharmacy benefits manager, and owns the Aetna health insurance business. It sells prescriptions, retail health goods, and insurance plans, and provides primary and urgent care through MinuteClinic and other services for consumers, employers, and government programs. Founded in 1963 and headquartered in Woonsocket, Rhode Island, it is a public company traded on the NYSE.

Contact me