CVS Health Logo

CVS Health

Senior Manager - Application Security Engineering

Posted 3 Hours Ago
Be an Early Applicant
In-Office or Remote
3 Locations
118K-261K Annually
Senior level
In-Office or Remote
3 Locations
118K-261K Annually
Senior level
Lead and scale enterprise application security, vulnerability management, software supply chain security, and DevSecOps capabilities. Manage a team delivering secure software delivery, automation, developer enablement, and governance across cloud-native, hybrid, and legacy environments. Partner with engineering, product, risk, and compliance to reduce risk and operationalize security controls.
The summary above was generated by AI

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.

POSITION SUMMARY

CVS Health is seeking a Senior Manager, Application Security Engineering to lead enterprise application security, vulnerability management, secure software delivery, and security engineering capabilities across a complex technology environment.

Within the Cybersecurity organization, this leader will be responsible for managing and advancing application security programs that help protect CVS Health applications and technology platforms throughout the software development lifecycle. The role will partner closely with Engineering, Architecture, Infrastructure, Product, Risk, Compliance, and Cybersecurity teams to integrate security into development processes and support secure delivery of business solutions.

The Senior Manager will lead a team responsible for application security engineering, vulnerability management, software supply chain security, security automation, and developer security enablement. This role will oversee security standards, tooling, governance, risk reduction activities, and operational processes that support enterprise technology portfolios and strategic initiatives, including Health 100.

Additionally, this leader will help build and scale security capabilities that improve developer adoption, increase automation, strengthen secure software development practices, and support enterprise DevSecOps initiatives.

This is a U.S.-based remote position. Candidates must reside within the United States.

PRIMARY DUTIES AND RESPONSIBILITIES

Application Security & Secure Software Delivery

  • Lead the design, implementation, and governance of enterprise application security programs, secure development standards, and software supply chain security practices.
  • Establish security requirements, security definitions of done, launch readiness criteria, and automated controls that enable secure software delivery across cloud-native, hybrid, and legacy environments.
  • Drive adoption of secure coding practices and developer-focused security capabilities across enterprise engineering organizations.

Vulnerability Management & Security Operations

  • Oversee the end-to-end vulnerability management lifecycle, including identification, prioritization, remediation, exception management, validation, and reporting.
  • Establish operational metrics, service level objectives, governance processes, and executive reporting mechanisms that drive accountability and measurable risk reduction.
  • Lead enterprise response efforts for critical and zero-day vulnerabilities, including risk assessment, stakeholder communication, remediation coordination, and executive reporting.

Security Engineering, DevSecOps & Platform Innovation

  • Drive adoption of modern security technologies and DevSecOps capabilities, including SAST, SCA, container security, secrets management, software bill of materials (SBOM), and software supply chain security solutions.
  • Lead automation of security controls within CI/CD pipelines to improve operational efficiency, strengthen risk mitigation, and accelerate secure software delivery.
  • Evaluate, implement, and optimize application security, cloud security, and software supply chain security technologies across on-premises, cloud, and hybrid environments.
  • Assess and adopt emerging technologies, including AI-powered security and developer productivity solutions, that improve security outcomes and operational effectiveness.
Leadership, Strategy & Enterprise Partnership
  • Lead and develop a high-performing team of security professionals while fostering a culture of technical excellence, accountability, innovation, and continuous improvement.

  • Build and scale security programs that drive developer adoption, self-service security capabilities, and DevSecOps maturity across enterprise engineering teams.

  • Partner across Engineering, Product, Architecture, Infrastructure, Risk, Compliance, and Cybersecurity teams to define strategic roadmaps, enable secure engineering practices, and support enterprise transformation initiatives, including Health 100.

  • Drive workforce development, capacity planning, operational readiness, and execution of strategic security objectives.

REQUIRED QUALIFICATIONS
  • 7+ years of experience developing, implementing, and operating enterprise security technologies across Application Security, Container Security, Data Security, Infrastructure Security, or related cybersecurity domains.

  • 7+ years of experience leading security programs and initiatives from design and implementation through operationalization and continuous improvement within enterprise environments.

  • 5+ years of experience securing cloud-native and modern application environments leveraging AWS, Azure, or GCP, including containers, Kubernetes, Infrastructure-as-Code (IaC), and Security-as-Code practices.

  • 5+ years of experience supporting secure software development lifecycle (SDLC) programs, vulnerability management, security testing, regulatory compliance, and enterprise application portfolios.

  • 4+ years of experience with application security technologies including SAST, SCA, CVA, mobile application security testing, secrets scanning, software supply chain security, and developer enablement programs.

  • 2+ years of experience leading, mentoring, managing, and developing security engineering, application security, vulnerability management, or cybersecurity teams.

PREFERRED QUALIFICATIONS
  • Experience architecting, securing, and modernizing enterprise applications, CI/CD pipelines, and cloud-native platforms across multi-cloud, hybrid, and legacy environments, including containerized, serverless, microservices-based, monolithic, and mainframe architectures.

  • Experience with application security, software composition analysis (SCA), software bills of materials (SBOM), software supply chain security, developer enablement programs, and secure software delivery practices utilizing platforms such as JFrog, Snyk, Veracode, Wiz, GitGuardian, Prisma Cloud, or similar technologies.

  • Experience supporting highly regulated environments and compliance frameworks including HIPAA, HITRUST, PCI-DSS, NIST, CSA, and related security and risk management standards.

  • Experience leading enterprise-scale transformation, application modernization, DevSecOps, and security automation initiatives, including building and scaling security programs, developer enablement capabilities, self-service security platforms, executive reporting, KPIs, KRIs, security scorecards, portfolio governance, and risk management programs.

  • Experience leveraging AI-powered technologies such as Claude, Claude Code, GitHub Copilot, Microsoft Copilot, and similar platforms to automate vulnerability remediation, integrate MCP-based security scanning, implement security controls within CI/CD pipelines, enhance developer enablement, and improve secure software delivery at enterprise scale.

EDUCATION

Bachelor’s degree from an accredited college or university, or equivalent combination of education and relevant work experience (High School Diploma/GED plus 4 years of related experience).

BUSINESS OVERVIEW

Bring your heart to CVS Health. Every one of us at CVS Health shares a single, clear purpose: Bringing our heart to every moment of your health. This purpose guides our commitment to deliver enhanced human-centric healthcare for a rapidly changing world. Anchored in our brand — with heart at its center — our purpose sends a personal message that how we deliver our services is just as important as what we deliver. Our Heart At Work Behaviors™ support this purpose. We want everyone who works at CVS Health to feel empowered by the role they play in transforming our culture and accelerating our ability to innovate and deliver solutions that make healthcare more personal, convenient, and affordable. CVS Health is an affirmative action employer and an equal opportunity employer. We are committed to fostering a diverse, inclusive, and equitable workplace and encourage candidates from all backgrounds to apply, including veterans, reservists, National Guard members, military spouses, and individuals with disabilities.

Pay Range

The typical pay range for this role is:

$118,450.00 - $260,590.00


This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls.  The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors.  This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above.  This position also includes an award target in the company’s equity award program. 
 

Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.

Great benefits for great people

We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.

This full‑time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well‑being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.


Additional details about available benefits are provided during the application process and on
Benefits Moments.

We anticipate the application window for this opening will close on: 08/31/2026

Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.

CVS Health Edison, New Jersey, USA Office

Edison, United States

CVS Health Elizabeth, New Jersey, USA Office

Elizabeth, United States

CVS Health Florham Park, New Jersey, USA Office

Florham Park, United States

CVS Health Hoboken, New Jersey, USA Office

Hoboken, United States

CVS Health Jersey City, New Jersey, USA Office

Jersey City, United States

CVS Health Montclair, New Jersey, USA Office

Montclair, United States

CVS Health New Brunswick, New Jersey, USA Office

New Brunswick, United States

CVS Health New Rochelle, New York, USA Office

New Rochelle, United States

CVS Health New York, New York, USA Office

New York, United States

CVS Health New York, New York, USA Office

New York, United States

CVS Health New York, New York, USA Office

New York, United States

CVS Health New York, New York, USA Office

New York, United States

CVS Health Newark, New Jersey, USA Office

Newark, United States

CVS Health North Brunswick, New Jersey, USA Office

North Brunswick, United States

CVS Health Paterson, New Jersey, USA Office

Paterson, United States

CVS Health Teaneck, New Jersey, USA Office

Teaneck, United States

CVS Health Yonkers, New York, USA Office

Yonkers, United States

Similar Jobs

2 Hours Ago
Remote
United States
185K-251K Annually
Expert/Leader
185K-251K Annually
Expert/Leader
Artificial Intelligence • Cloud • Consumer Web • Productivity • Software • App development • Data Privacy
Lead and scale Dropbox's enterprise competitive intelligence across multiple products. Build an operating model to collect and analyze competitor activity, win/loss, market shifts, and field signals. Deliver executive briefings, battlecards, alerts, and decision-ready recommendations to Sales, Product, and GTM teams. Own and modernize the win/loss program, partner cross-functionally to improve differentiation and enablement, and use AI and automation to measure and scale program impact.
Top Skills: AIAlphasenseAutomationClozdCrayon
2 Hours Ago
Remote
United States
Senior level
Senior level
Blockchain • Legal Tech • Other • Professional Services • Consulting • Financial Services • Cryptocurrency
Provide tax preparation, planning, and advisory services for individuals and businesses holding bitcoin and digital assets. Prepare and file tax returns, calculate cost basis and gains/losses, advise on mining/staking/airdrop income, collaborate with advisors and estate planners, maintain compliance documentation, and contribute thought leadership through articles and webinars.
Top Skills: BitcoinCryptocurrency ExchangesDigital AssetsTax Preparation SoftwareWallets
2 Hours Ago
Easy Apply
Remote
United States
Easy Apply
Mid level
Mid level
Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
Lead and coach a team of Enterprise Account Executives on prospecting, account planning, forecasting, and closing Fortune-level accounts. Develop territory and strategic account plans, track KPIs, hire and enable talent, collaborate cross-functionally, and directly engage high-priority prospects to drive ACV and revenue goals while ensuring CRM and sales processes are followed.
Top Skills: CRMSalesforce

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account