AVP, Application Security
Top focus
We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do.
Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time. Position Summary CVS Health is seeking a polished and experienced security leader to serve as Associate Vice President of Application Security, responsible for defining and executing the enterprise strategy for securing software across its full development lifecycle.
This role owns the policies, technical standards, and tooling that enable CVS Health's engineering teams to build and deploy secure applications at scale. The AVP will lead a high-performing team of application security engineers and architects, partner deeply with Developer Experience leadership to embed security seamlessly into agile development practices and serve as a trusted advisor to executive stakeholders on software security risk.
This leader will balance targeted security outcomes with developer productivity, ensuring that security is an enabler — not a barrier — to innovation
Key Responsibilities
- Strategic Leadership Define and own the enterprise application security strategy, roadmap, and policy framework, aligned with CVS Health's business objectives and regulatory obligations.
- Establish and enforce technical standards for secure software development, including code scanning, code vulnerability management, and secure-by-design principles.
- Serve as a subject matter expert and trusted advisor to senior technology and business executives on emerging application security risks, attack trends, and industry best practices.
- Drive continuous improvement across the application security program through metrics, benchmarking, and innovation.
- Application Security Engineering & Controls Secure Development Lifecycle (SDLC) Integration: Lead the integration of application security scanning, testing
- policy enforcement gates into CI/CD pipelines across the enterprise.
- Partner with Developer Experience leadership to ensure security tooling is frictionless, developer-friendly, and compatible with agile delivery practices.
- Static Application Security Testing (SAST): Define strategy, standards, and tooling for enterprise-wide SAST scanning.
- Manage tuning of rulesets to reduce false positives, drive remediation workflows, and ensure coverage across all critical code repositories.
- Dynamic Application Security Testing (DAST): Oversee DAST program covering pre-production and production environments.
- Establish automated scanning schedules, triage processes, and integration with enterprise vulnerability management platforms.
- Web Application Firewall (WAF) Management: Own the strategy, configuration, and operations of the enterprise WAF platform.
- Define and maintain rule sets, monitor for emerging threats, and ensure alignment with zero-trust and defense-in-depth principles.
- Code Repository Scanning: Implement and manage continuous scanning of source code repositories for secrets, misconfigurations, exposed credentials, and policy violations.
- Establish guardrails and automated enforcement to prevent insecure code from reaching production.
- AI-Assisted Code Generation Security: Develop policies and technical controls to assess and govern security risks introduced by AI-assisted code generation tools (e.g., GitHub Copilot, generative AI coding assistants).
- Define standards for safe use and implement scanning capabilities to detect AI-generated code vulnerabilities.
- Third-Party and Open-Source Software (SCA) Scanning: Manage the Software Composition Analysis (SCA) program to identify and remediate vulnerabilities in third-party libraries and open-source dependencies.
- Maintain visibility into the software supply chain and drive compliance with internal ingestion policies.
- Content Delivery Network (CDN) Security Management: Oversee security configuration and policy enforcement for content delivery network infrastructure.
- Ensure CDN-layer protections — including DDoS mitigation, bot management, and TLS standards — are aligned with enterprise security policy.
- Application Security Technology Stack: Own the full application security tooling portfolio.
- Manage vendor relationships, licensing, platform health, and roadmap alignment.
- Evaluate and introduce emerging technologies to improve coverage, automation, and developer experience.
- Governance & Compliance Define and maintain application security policies, standards, and operational procedures.
- Ensure compliance with applicable regulatory frameworks and industry standards, including HIPAA, PCI-DSS, CCPA, NIST SSDF, and OWASP.
- Provide executive-level reporting and governance dashboards that communicate program health, risk posture, and remediation progress.
- Establish and maintain a risk-based vulnerability management process focused specifically on software development vulnerabilities, including those introduced through code, dependencies
- the build and deployment pipeline, in partnership with peer security organizations.
- Leadership & Collaboration Build, lead, and develop a high-performing team of application security engineers, architects, and program managers.
- Partner closely with Developer Experience leadership to align security tooling and practices with developer workflows, ensuring security is integrated seamlessly into agile and DevSecOps pipelines.
- Collaborate with Cyber Defense, Data Protection, Infrastructure Security, Legal, Compliance, and Technology leadership to deliver integrated security outcomes.
- Partner with Chief Data and Technology Officers (CDTOs) across CVS Health business units to understand technology strategies, influence security-targeted outcomes
- ensure application security priorities are embedded within divisional roadmaps and investment decisions.
- Foster a security-minded engineering culture through developer education, secure coding training, security champion programs, and engagement with engineering communities of practice.
- Key Performance Indicators (KPIs): Pipeline Coverage: Percentage of active software development pipelines with integrated SAST, DAST, and SCA scanning controls.
- Vulnerability Remediation SLA: Mean time to remediate (MTTR) critical and high application security vulnerabilities, tracked against defined SLAs.
- Secrets & Policy Violations: Reduction in secrets exposed in code repositories and policy violations detected year-over-year.
- WAF Effectiveness: Percentage of malicious web traffic blocked; reduction in application-layer incidents attributed to WAF-protected assets.
- Third-Party Risk Coverage: Percentage of production applications with up-to-date SCA coverage and no unaddressed critical open-source vulnerabilities.
- AI Code Security: Coverage rate of AI-assisted code generation under security policy and scanning controls.
- Developer Experience Satisfaction: Developer NPS and feedback scores related to security tooling and friction within the SDLC.
- Regulatory Compliance: Audit findings related to application security controls, targeting zero critical findings.
- Program Adoption: Number of development teams operating under the secure SDLC framework and security champion program.
- Roadmap Delivery: On-time completion of strategic application security initiatives and tooling milestones.
- Required Qualifications 12+ years of progressive experience in information security, with at least 5 years in application security leadership roles.
- Deep technical background in software development, including hands-on coding experience in one or more modern programming languages (e.g., Java, Python, Go, JavaScript, or similar).
- Candidates must bring developer-level fluency to credibly engage with engineering teams, evaluate code-level risks, and drive meaningful secure coding practices.
- Demonstrated expertise in application security engineering and secure software development lifecycle (SDLC) practices, grounded in first-hand experience building or shipping software.
- Strong understanding of software architecture patterns, CI/CD pipelines, containerization, and cloud-native development — with the ability to assess security implications at every layer of the stack.
- Hands-on experience managing enterprise application security tooling, including SAST, DAST, SCA, WAF, and repository scanning platforms.
- Deep knowledge of application security standards and frameworks, including OWASP Top 10, NIST SSDF, and relevant regulatory requirements (HIPAA, PCI-DSS, CCPA).
- Proven ability to influence engineering culture and drive security adoption at scale within agile development environments.
- Strong leadership skills with experience building and managing cross-functional technical teams and influencing senior stakeholders.
- Excellent communication and presentation skills; ability to translate complex security concepts for both technical and non-technical audiences.
- Preferred Qualifications Advanced degree in Computer Science, Information Security, or a related field.
- Certifications such as CISSP, CSSLP, CISM, GWEB, or equivalent.
- Experience in healthcare or other highly regulated industries.
- Familiarity with AI/ML-driven security tooling and modern cloud-native application security architectures.
- Experience implementing security programs within large-scale DevOps or platform engineering organizations.
- Education Bachelor's Degree Pay Range The typical pay range for this role is: $185,400.00 - $375,950.00 This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls.
- The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors.
- This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above.
- This position also includes an award target in the company’s equity award program.
- Our people fuel our future.
- Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.
- Great benefits for great people We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.
- This full‑time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well‑being of colleagues and their families.
- The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.
- Additional details about available benefits are provided during the application process and on Benefits Moments .
- We anticipate the application window for this opening will close on: 08/13/2026 Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.