All jobs

Senior Manager Application Security Engineering

CVS Health19h ago
United StatesHybridFull-timeManager Level5+ yrs exp

Top focus

Senior Engineering ManagerEngineering ManagerVp EngineeringSecurity EngineerSecurity Architect

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do.

Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time. POSITION SUMMARY CVS Health is seeking a Senior Manager, Application Security Engineering to lead the strategy, execution, and continuous improvement of application security capabilities across enterprise platforms, digital products, and cloud-native environments.

The Senior Manager, Application Security Engineering will be responsible for advancing secure software development practices, driving security-by-design principles, and ensuring security controls are embedded throughout the software development lifecycle.

As a key security leader, the Senior Manager, Application Security Engineering will partner closely with Engineering, Product, Architecture, Infrastructure, Risk, Compliance, and Cyber Defense teams to strengthen the organization's security posture while enabling innovation and accelerating delivery.

This role will oversee application security programs, vulnerability management, DevSecOps enablement, software supply chain security, and security governance initiatives supporting CVS Health's most critical business priorities. The Senior Manager, Application Security Engineering will lead a team of security engineers responsible for securing modern cloud-native applications, APIs, containers, and enterprise platforms.

This leader will establish security standards, drive automation, implement scalable security controls, and partner with development teams to identify and reduce risk across the application portfolio. The ideal Senior Manager, Application Security Engineering combines deep technical expertise in application security with proven leadership experience, strong business acumen, and a passion for enabling secure, resilient, and high-performing technology solutions at enterprise scale.

This is a U.S.-based remote position. Candidates must reside within the United States. PRIMARY DUTIES AND RESPONSIBILITIES Lead the development, implementation, enforcement, and continuous improvement of application, engineering, and data security policies, standards, governance controls, and secure software development practices; define and maintain Health 100 security baselines, launch readiness requirements, and audit/compliance expectations while adapting controls to evolving threats and business priorities.

Partner closely with Product, Engineering, Architecture, DevSecOps, Threat Modeling, GRC, and business stakeholders to embed secure engineering practices across the organization, drive onboarding to security tooling and pipelines, establish clear risk acceptance and escalation processes, and ensure alignment on security priorities, launch readiness, and governance requirements.

Oversee application security engineering and testing programs across cloud, on-premises, and hybrid environments, including security architecture, SAST, SCA, secrets detection, container scanning, vulnerability analysis, pipeline integrations, scanning and gating controls, security tooling strategy, and vulnerability data quality, ownership, tagging, and reporting governance.

Own end-to-end vulnerability management and operational security processes, including triage, prioritization, remediation, validation, reporting, SLA management, KPI/KRI tracking, incident response, zero-day vulnerability coordination, risk exceptions, ServiceNow workflows, ticket governance, operational excellence, and Health 100 vulnerability posture management.

Build, mentor, and develop a high-performing security engineering team by establishing leadership development programs, cross-training models, operational documentation, knowledge-sharing practices, and targeted security enablement programs that strengthen secure development, remediation effectiveness, and software supply chain risk management.

Drive innovation, automation, and continuous improvement through security research, evaluation of emerging technologies, workflow automation, tooling optimization, software supply chain security enhancements, SBOM governance, dependency risk reduction, and scalable security operations.

Own the application security strategy and roadmap, including budgeting, workforce planning, capacity management, risk management, executive reporting, KPIs/KRIs, security investments, tooling prioritization, and Health 100 security initiatives, ensuring alignment with business objectives, accelerated delivery timelines, and enterprise risk tolerance.

REQUIRED QUALIFICATIONS 7+ years of experience designing, implementing, and supporting enterprise security capabilities across application security, mobile application security, cloud security, vulnerability management, DevSecOps, or security engineering environments. 5+ years securing cloud platforms such as AWS, Azure, and/or GCP, including network security, Infrastructure-as-Code, Security-as-Code, containers, Kubernetes, Android and iOS application security, and modern application architectures. 3+ years leading enterprise security initiatives from strategy through implementation, including application security testing, mobile application security testing, MAST, vulnerability management, data protection, regulatory compliance, and secure software delivery. 3+ years in mobile application security scanning, including tools such as Data Theorem or similar solutions, with the ability to assess, prioritize, and drive remediation of findings across Android and iOS environments. 3+ years developing and delivering security reporting and dashboards using Power BI, Grafana, or similar platforms to communicate risk, vulnerabilities, KPIs, and remediation progress to technical and leadership stakeholders. 3+ years integrating security into the SDLC and CI/CD pipelines using languages such as Python, Java, JavaScript, Go, PowerShell, or similar, with a focus on automation and scalable security controls. 2+ years of people leadership managing, mentoring, and developing high-performing engineering teams while driving measurable security outcomes across large-scale application portfolios, mobile and digital products, or enterprise transformation programs.

PREFERRED QUALIFICATIONS Strong technical expertise in designing and securing public cloud environments (AWS, Azure, and/or GCP), including distributed, resilient, and cloud-native architectures. Experience with network security, software-defined networking (SDN), threat modeling, and development of architectural artifacts such as network, sequence, and data flow diagrams.

Understanding healthcare and industry compliance frameworks, including HIPAA, HITRUST, PCI-DSS, NIST, and CSA, as well as data platform security solutions such as Snowflake. Experience implementing or managing application security platforms (e.g., Snyk, Veracode, Checkmarx, or similar), software supply chain security controls, SBOM programs, dependency risk management, and cyber resilience initiatives.

Proven ability to influence cross-functional stakeholders, collaborate effectively within distributed organizations, support enterprise transformation programs and strategic portfolios, and contribute to the advancement of security engineering practices and standards.

EDUCATION Bachelor’s degree from an accredited college or university, or equivalent combination of education and relevant work experience (High School Diploma/GED plus 4 years of related experience). BUSINESS OVERVIEW Bring your heart to CVS Health.

Every one of us at CVS Health shares a single, clear purpose: Bringing our heart to every moment of your health. This purpose guides our commitment to deliver enhanced human-centric healthcare for a rapidly changing world. Anchored in our brand — with heart at its center — our purpose sends a personal message that how we deliver our services is just as important as what we deliver.

Our Heart At Work Behaviors™ support this purpose. We want everyone who works at CVS Health to feel empowered by the role they play in transforming our culture and accelerating our ability to innovate and deliver solutions that make healthcare more personal, convenient, and affordable.

CVS Health is an affirmative action employer and an equal opportunity employer. We are committed to fostering a diverse, inclusive, and equitable workplace and encourage candidates from all backgrounds to apply, including veterans, reservists, National Guard members, military spouses, and individuals with disabilities.

Pay Range The typical pay range for this role is: $142,140.00 - $284,280.00 This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors.

This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company’s equity award program. Our people fuel our future.

Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong. Great benefits for great people We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.

This full‑time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well‑being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.

Additional details about available benefits are provided during the application process and on Benefits Moments . We anticipate the application window for this opening will close on: 09/30/2026 Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.

Required skills

PythonJavaScriptGoJavaSnowflakeAWSGCPAzureKubernetesCI/CDGrafanaSecurityiOSAndroid
Posted on JobRush — the end-to-end AI job-search platform.