Full-Time

Associate Vice President Platform Security

Updated on 9/14/2026

Deadline 9/28/26
CVS Health

CVS Health

10,001+ employees

Healthcare, insurance, PBM, and retail pharmacy

Compensation Overview

$185.4k - $375.9k/yr

+ Bonus + Commission + Short-term incentive + Equity award

Company Historically Provides H1B Sponsorship

Arizona, USA + 1 more

More locations: Scottsdale, AZ, USA

Remote

Master's

Category
Cybersecurity (1)
Required Skills
Kubernetes
Threat modeling
Vulnerability Analysis
Cryptography
HIPAA

Get referred to CVS Health

See people who can refer or advise you

Requirements
  • 12+ years of progressive experience in information security, cybersecurity engineering, cloud security, infrastructure security, platform security, or related technology leadership roles.
  • 5+ years of senior leadership experience building, leading, and scaling cross-functional security engineering teams in large, complex enterprise environments.
  • Deep technical expertise in cloud security architecture and operations across major cloud platforms, including cloud posture management, identity and access controls, network segmentation, encryption, logging, vulnerability management, and policy enforcement.
  • Strong understanding of container and Kubernetes security, including image scanning, workload protection, runtime controls, secrets management, cluster hardening, continuous integration and continuous delivery integration, and vulnerability remediation.
  • Demonstrated experience defining technical security standards, reference architectures, control frameworks, and engineering guardrails for enterprise-scale platforms.
  • Experience with artificial intelligence, generative artificial intelligence, or emerging technology security programs, including artificial intelligence governance, artificial intelligence platform security, model risk, agentic systems, prompt and response guardrails, model scanning, artificial intelligence threat modeling, or artificial intelligence runtime monitoring.
  • Strong knowledge of security posture management, vulnerability management, threat modeling, risk-based prioritization, and executive-level risk reporting.
  • Proven ability to influence engineering culture, platform governance, security control adoption, and strategic investment decisions across multiple leadership levels.
  • Experience operating in highly regulated environments and applying security requirements aligned to healthcare, privacy, financial, or critical infrastructure obligations.
  • Excellent communication and presentation skills, with the ability to translate complex cloud, container, infrastructure, and artificial intelligence security risks into clear decisions and executive narratives.
Responsibilities
  • Define and own the enterprise platform security strategy, roadmap, and policy framework for cloud, container, and artificial intelligence security, aligned with business objectives, technology strategy, and regulatory obligations.
  • Establish a unified technical standards and architecture approach across cloud, container, and artificial intelligence platforms, ensuring security controls are built into platform design and operational execution.
  • Stand up and mature the artificial intelligence security operating model as an enterprise capability supporting safe artificial intelligence and generative artificial intelligence adoption.
  • Serve as a subject matter expert and trusted advisor to senior technology, security, and business executives on emerging platform security risks, cloud-native attack trends, artificial intelligence threats, and industry best practices.
  • Drive continuous improvement across the platform security program through risk-based prioritization, measurable key performance indicators, executive reporting, benchmarking, and innovation.
  • Own the strategy, architecture, and operational standards for securing enterprise cloud environments, including cloud posture management, policy-as-code, identity and access guardrails, vulnerability exposure reduction, and automated remediation workflows.
  • Define and govern container and Kubernetes security across cloud and on-premises container platforms, including image scanning, workload protection, runtime controls, configuration standards, vulnerability management, and platform coverage objectives.
  • Promote preventive guardrails, policy enforcement, infrastructure-as-code controls, and self-service remediation patterns that reduce risk while preserving engineering velocity.
  • Influence the platform security tooling portfolio, including cloud security posture management, cloud-native application protection platforms, container security, posture management, artificial intelligence security, and related integrations; manage vendor strategy, platform health, roadmap alignment, and capability adoption.
  • Establish and scale a dedicated artificial intelligence security function with clear accountability, sustained governance, and defined responsibilities across artificial intelligence governance, platform security, model security, agentic security, incident readiness, and risk reporting.
  • Define and maintain enterprise artificial intelligence security standards, including requirements for artificial intelligence gateways, model gateways, prompt and response guardrails, model review, model inventory, artificial intelligence use-case risk classification, and controls for high-risk artificial intelligence use cases.
  • Own security requirements for artificial intelligence and agent gateways, including identity propagation, tool and service brokering, prompt-injection defenses, default-deny mediation, data protection, auditability, traffic and cost controls, runtime governance, and agentic runtime protections.
  • Drive controls for agent identity, authentication, authorization, registry, tool governance, long-running agent activity, non-human identity exposure, session revocation, kill switches, human-in-the-loop gates, and runtime behavioral monitoring.
  • Lead security architecture for artificial intelligence models and platforms, including model scanning, model provenance, unauthorized model detection, artificial intelligence visibility, adversarial testing, red teaming, and alignment to relevant artificial intelligence management and threat frameworks.
  • Partner with Cyber Defense to develop artificial-intelligence-specific monitoring, detection use cases, incident response playbooks, audit logging, and operational telemetry for model abuse, data leakage, tool misuse, and adversarial behavior.
  • Define and maintain platform security policies, standards, reference architectures, and operational procedures for cloud, container, infrastructure, and artificial intelligence security domains.
  • Ensure security controls align with applicable regulatory frameworks and industry standards, including HIPAA, PCI-DSS, ISO/IEC 42001, NIST AI RMF, NIST CSF, MITRE ATLAS, OWASP LLM and agentic guidance, and cloud security best practices.
  • Provide executive-level reporting and governance dashboards covering program health, control coverage, security posture, remediation progress, residual risk, and decisions requiring leadership sponsorship.
  • Establish a risk-based vulnerability and misconfiguration management process for cloud, container, and artificial intelligence platforms, including ownership, remediation service-level agreements, escalation paths, and executive transparency.
  • Partner with Legal, Compliance, Privacy, third-party risk management, Data Protection, and AI Governance teams to ensure artificial intelligence tools, connectors, model platforms, software-as-a-service artificial intelligence services, and third-party capabilities meet enterprise control and contractual requirements before production use.
  • Build, lead, and develop a high-performing organization of cloud security, container security, infrastructure security, artificial intelligence security, and distinguished engineering leaders.
  • Lead through direct and matrixed influence across Cloud Security Services, Infrastructure Security, AI Security, Application Security, identity and access management, Cyber Delivery, Cyber Defense, Data Protection, Developer Experience, Enterprise Architecture, and business technology teams.
  • Partner with the Vice President of Security Engineering and Platforms, peer Associate Vice Presidents, Executive Directors, and enterprise technology leaders to align platform security priorities with broader security engineering strategy, objectives and key results, investment decisions, and enterprise delivery commitments.
  • Engage regularly with cloud providers, security tooling vendors, artificial intelligence platform providers, and industry standards groups to inform architecture decisions, capability roadmaps, and evolving technical standards.
  • Foster a culture of secure-by-default platform engineering, risk-based decision-making, operational accountability, automation, and measured business enablement.
Desired Qualifications
  • An advanced degree in Computer Science, Information Security, Cybersecurity, Engineering, Artificial Intelligence/Machine Learning, or a related field.
  • Certifications such as Certified Information Systems Security Professional, Certified Information Security Manager, Certified Cloud Security Professional, AWS Security Specialty, Azure Security Engineer, Google Professional Cloud Security Engineer, Kubernetes Security Specialist, or equivalent.
  • Experience establishing or scaling an artificial intelligence security function, artificial intelligence governance control model, artificial intelligence gateway strategy, model security program, agentic security capability, or artificial intelligence red-teaming function.
  • Familiarity with ISO/IEC 42001, NIST AI RMF, MITRE ATLAS, OWASP Top 10 for Large Language Model Applications, OWASP agentic guidance, NIST CSF, and cloud security best-practice frameworks.
  • Experience with cloud-native application protection platforms, cloud security posture management, cloud workload protection platforms, container security, application programming interface gateways, model gateways, artificial intelligence guardrails, software-as-a-service security posture management, artificial intelligence security posture management, and security data platform technologies.
  • Experience in healthcare, pharmacy, insurance, financial services, or another highly regulated industry.
  • Demonstrated success partnering with cloud providers, artificial intelligence platform providers, enterprise architecture, procurement, third-party risk, privacy, legal, compliance, and business technology leaders.

CVS Health operates as a diversified health services company in the United States, organized into Health Care Benefits, Pharmacy & Consumer Wellness, and Health Services. Its offerings include medical insurance products, retail and mail-order prescription drugs, and pharmacy benefit management (PBM) services, all connected through its integrated platform. By combining insurance, retail pharmacy, PBM, and health solutions, CVS Health coordinates care and controls costs across touchpoints for individuals, employers, and government programs. The company aims to lower health care costs while improving access and health outcomes for customers.

Company Size

10,001+

Company Stage

IPO

Headquarters

Woonsocket, Rhode Island

Founded

1963

Get referred to CVS Health

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • August 5, 2026 CVS raised adjusted EPS guidance to $7.90-$8.10 and revenue to $414 billion.
  • Walgreens plans roughly 1,200 U.S. store closures through 2027, sending prescription volume to CVS.
  • Teresa Heitsenrether joined the board September 2026, strengthening CVS’s data and digital execution focus.

What critics are saying

  • May 2026 340B lawsuits from Mount Sinai, Michigan, and Kansas attack Caremark’s remittance model.
  • CVS disclosed 2027 Caremark membership declines and continued 340B pressure on August 5, 2026.
  • If courts restrict 340B spreads or rebate flows, CVS loses a core profit engine.

What makes CVS Health unique

  • CVS Health combines Aetna, Caremark, and 9,000 pharmacies across one U.S. customer funnel.
  • August 5, 2026 results showed integrated pricing, insurance, and pharmacy scale outperformed standalone peers.
  • The August 2026 Eli Lilly collaboration embeds Zepbound and Foundayo access inside CVS channels.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Disability Insurance

401(k) Retirement Plan

Company Equity

Wellness Program

Professional Development Budget

Paid Vacation

Paid Holidays

Company News

Yahoo Finance
Sep 14th, 2026
CVS Health up 32% in a year: is it time to buy the stock?

CVS Health shares have declined 2.1% over the past three months, prompting investors to consider whether now is an opportune time to buy. The healthcare giant, which operates approximately 9,000 retail pharmacy locations and serves more than 35 million people through its health insurance business, reported second-quarter revenue of $106 billion, up 7.3% year-over-year. Adjusted earnings per share rose 43% in the same period. The company offers a dividend yield of 2.8%, with its annual payout increasing from $2 in 2021 to $2.66 per share recently. Shares currently trade at $95, with one analyst setting a price target of $120. The stock's forward price-to-earnings ratio of 11 sits slightly above its five-year average of 10.

Yahoo Finance
Sep 13th, 2026
US health insurers rebound as medical costs stabilise, analysts predict 16% earnings growth through 2030

The health insurance industry may have recovered from high medical costs, with analysts predicting strong growth through 2030. Morningstar forecasts 16% annual earnings per share growth for major insurers, above the industry's typical low-double-digit target. Health insurers are improving profitability by raising rates to cover increased medical utilisation. UnitedHealth Group reported over $5 billion in second-quarter net income, with its medical care ratio falling to 86.7% from 89.4% year-over-year. The outlook also improved for pharmacy benefit management operations at companies like UnitedHealth, CVS Health, and Cigna. Despite increased regulatory scrutiny, the "big three" PBMs maintain strong competitive positions. Third-quarter earnings reports next month should provide further clarity on the industry's financial health.

Yahoo Finance
Sep 12th, 2026
CVS quietly gains market share as Walgreens closes 1,200 US stores following $10B private equity sale

Walgreens is closing roughly 1,200 of its approximately 8,500 US locations through 2027, with many customers being redirected to nearby CVS pharmacies. The pattern is reshaping suburban pharmacy markets without direct competition. In August 2025, Walgreens completed a $10 billion sale to private equity firm Sycamore Partners, taking the 124-year-old chain private for the first time. Mike Motz was named chief executive, replacing Tim Wentworth. CVS is gaining market share without active expansion efforts. Federal and state rules require orderly prescription transfers when pharmacies close, often directing patients to the nearest CVS location. CVS and Walgreens together now handle nearly 40% of all US retail prescription sales. CVS benefits from owning Caremark, a dominant pharmacy benefit manager, providing vertical integration advantages.

Yahoo Finance
Aug 28th, 2026
CVS stock down 12% in a month despite 34% annual gain, faces 2027 headwinds

CVS Health stock has declined 12.3% over the past month, sitting about 15% below its 52-week high, though it remains up 34% over the trailing twelve months. The company's revenue reached approximately $415 billion, up 7.4% year-over-year. Management raised its full-year 2026 adjusted earnings per share guidance by $0.60 to a range of $7.90 to $8.10. For 2027, the company anticipates membership declines at Caremark and continued 340B programme pressure, offset by Aetna's recovery, which added over $2 billion in adjusted operating income in the first half of 2026. Management considers a 2027 adjusted EPS outlook of at least $8.44 reasonable. Historically, CVS has experienced varied recovery periods following market downturns, with some rebounds taking years rather than months.

Yahoo Finance
Aug 25th, 2026
CVS and Roche stocks could benefit from expanding GLP-1 drug market

CVS Health and Roche could benefit from the growing GLP-1 drug market, alongside current leaders Eli Lilly and Novo Nordisk. CVS Health has improved its financial performance, with second-quarter revenue rising 7.3% year-over-year to $106.1 billion and adjusted earnings per share increasing 42.5% to $2.58. The pharmacy chain offers all approved GLP-1 medicines in the US, including Eli Lilly's Zepbound and Foundayo, plus Novo Nordisk's Wegovy. CVS also provides low-cost online consultations at $29 to assess patient eligibility for GLP-1 drugs. Beyond GLP-1 initiatives, CVS is addressing previous business challenges and is positioned to capitalise on rising healthcare spending in the US over the next decade.