All jobs

DevSecops Engineer

CVS Health21h ago
United StatesHybridFull-time

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do.

Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time. POSITION SUMMARY CVS Health is seeking a DevSecOps Engineer to help build, secure, and scale modern technology platforms that power critical healthcare services.

This is a unique opportunity to join a high-impact engineering organization where security is embedded into everything we build, from cloud infrastructure and applications to data platforms and deployment pipelines. As a DevSecOps Engineer, you will partner closely with software engineers, cloud architects, and platform teams to design and implement secure-by-default solutions across multi-cloud environments.

You'll leverage automation, software development, and modern security practices to reduce risk, increase engineering velocity, and improve platform reliability at enterprise scale. This role is ideal for an engineer who enjoys solving complex security challenges through code, automation, and collaboration.

You'll have the opportunity to influence engineering standards, shape enterprise security strategy, drive DevSecOps adoption, and help protect healthcare data that impacts millions of customers. As a DevSecOps Engineer, you'll work across application security, cloud security, data protection, infrastructure security, and security automation while gaining exposure to cutting-edge technologies including Kubernetes, Infrastructure-as-Code, CI/CD platforms, cloud-native architectures, and AI-enabled engineering solutions.V You'll join a culture that values innovation, continuous learning, engineering excellence, and career growth.

Whether you're building security automation, improving developer experience, securing cloud-native applications, or maturing enterprise DevSecOps capabilities, your work will have visible impact across the organization. PRIMARY RESPONSIBILITIES Partner with engineering, platform, and business teams to embed secure-by-design practices throughout the software development lifecycle and DevSecOps processes.

Develop, implement, and govern application, infrastructure, and data security standards across cloud, on-premises, and hybrid environments. Serve as the Application Security SME, leading security assessments, vulnerability management, remediation strategies, and security testing initiatives.

Design, implement, and automate security controls, policies, and guardrails to improve security posture, operational efficiency, and compliance. Develop security metrics, dashboards, and executive reporting using platforms such as Power BI, Grafana, Tableau, or similar analytics tools.

Lead incident response planning, security investigations, and recovery efforts while contributing to enterprise-wide resiliency initiatives. Participate in operational support and on-call activities, driving continuous improvement through automation, collaboration, and Agile/Kanban practices.

REQUIRED QUALIFICATIONS 3+ years designing, implementing, and supporting enterprise security solutions and secure engineering practices across cloud-native and distributed environments. 3+ years working within modern SDLC and DevSecOps ecosystems, including CI/CD pipelines, deployment automation, and remediation of findings from SAST, SCA, API, and Mobile security testing. 2+ years securing AWS, Azure, and/or GCP environments, including identity, network, container, and workload security, utilizing Infrastructure-as-Code and Security-as-Code methodologies. 2+ years developing security automation, integrations, and tooling using Python, Java, JavaScript, C#, PowerShell, Bash, or similar languages. 1+ years implementing and governing data protection, compliance, and security controls aligned to frameworks and regulations such as HIPAA, PCI-DSS, GDPR, CCPA, NIST, or equivalent standards.

PREFERRED QUALIFICATIONS Familiarity with OWASP ASVS and secure application development best practices. Knowledge of security and compliance frameworks such as HIPAA, HITRUST, PCI-DSS, NIST, CSA, or similar industry standards. Hands-on experience with application security and software supply chain platforms such as GitHub Advanced Security, Snyk, Veracode, or comparable solutions.

Experience developing security automation, cyber resilience capabilities, and operational controls across cloud-native, distributed, and hybrid environments. Strong analytical and communication skills, including the ability to leverage Power BI, Grafana, Tableau, or similar platforms to develop metrics, identify trends, and deliver actionable insights to technical and business stakeholders.

Experience working within Agile/Kanban teams, driving continuous improvement through automation, metrics, and cross-functional collaboration. EDUCATION Bachelor’s degree from accredited university or equivalent work experience (HS diploma + 4 years relevant experience).

BUSINESS OVERVIEW Bring your heart to CVS Health Every one of us at CVS Health shares a single, clear purpose: Bringing our heart to every moment of your health. This purpose guides our commitment to deliver enhanced human-centric health care for a rapidly changing world.

Anchored in our brand — with heart at its center — our purpose sends a personal message that how we deliver our services is just as important as what we deliver. Our Heart At Work Behaviors™ support this purpose. We want everyone who works at CVS Health to feel empowered by the role they play in transforming our culture and accelerating our ability to innovate and deliver solutions to make health care more personal, convenient and affordable.

We strive to promote and sustain a culture of diversity, inclusion and belonging every day. CVS Health is an affirmative action employer, and is an equal opportunity employer, as are the physician-owned businesses for which CVS Health provides management services.

We do not discriminate in recruiting, hiring, promotion, or any other personnel action based on race, ethnicity, color, national origin, sex/gender, sexual orientation, gender identity or expression, religion, age, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law.

We proudly support and encourage people with military experience (active, veterans, reservists and National Guard) as well as military spouses to apply for CVS Health job opportunities. Anticipated Weekly Hours 40 Time Type Full time Pay Range The typical pay range for this role is: $72,100.00 - $173,040.00 This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls.

The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above.

Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong. Great benefits for great people We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.

This full‑time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well‑being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.

Additional details about available benefits are provided during the application process and on Benefits Moments . We anticipate the application window for this opening will close on: 08/31/2026 Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.

Required skills

PythonJavaScriptJavaAWSGCPAzureKubernetesCI/CDGrafanaAgileSecurity
Posted on JobRush — the end-to-end AI job-search platform.