Full-Time

Associate Vice President of Application Security

Posted on 7/22/2026

Deadline 8/27/26
CVS Health

CVS Health

10,001+ employees

Healthcare, insurance, PBM, and retail pharmacy

Compensation Overview

$185.4k - $375.9k/yr

+ Bonus + Commission + Short-term incentive + Equity award

Company Historically Provides H1B Sponsorship

Arizona, USA + 2 more

More locations: Rhode Island, USA | New York, NY, USA

Remote

Bachelor's

Category
IT Operations
Cybersecurity
Required Skills
LLM
Python
JavaScript
Java
Docker
ISC2 CSSLP
Vulnerability Analysis
Go
DevOps
HIPAA

Get referred to CVS Health

See people who can refer or advise you

Requirements
  • The candidate must have 12 or more years of progressive experience in information security, including at least 5 years in application security leadership roles.
  • The candidate must have hands-on coding experience in one or more modern programming languages, such as Java, Python, Go, or JavaScript, with developer-level fluency.
  • The candidate must have first-hand expertise in application security engineering and secure software development lifecycle practices, including building or shipping software.
  • The candidate must understand software architecture patterns, continuous integration and continuous delivery pipelines, containerization, and cloud-native development, including their security implications.
  • The candidate must have hands-on experience managing enterprise application security tooling, including static application security testing, dynamic application security testing, software composition analysis, web application firewalls, and repository scanning platforms.
  • The candidate must have deep knowledge of application security standards and frameworks, including the OWASP Top 10 and NIST Secure Software Development Framework, as well as HIPAA, PCI-DSS, and CCPA requirements.
  • The candidate must be able to influence engineering culture and drive security adoption at scale within agile development environments.
  • The candidate must have experience building and managing cross-functional technical teams and influencing senior stakeholders.
  • The candidate must be able to communicate and present complex security concepts to technical and non-technical audiences.
  • The candidate must hold a Bachelor's Degree.
Responsibilities
  • Define and own the enterprise application security strategy, roadmap, and policy framework in alignment with business objectives and regulatory obligations.
  • Establish and enforce technical standards for secure software development, including code scanning, code vulnerability management, and secure-by-design principles.
  • Advise senior technology and business executives on emerging application security risks, attack trends, and industry best practices.
  • Drive continuous improvement across the application security program through metrics, benchmarking, and innovation.
  • Lead the integration of application security scanning, testing, and policy-enforcement gates into enterprise continuous integration and continuous delivery pipelines.
  • Partner with Developer Experience leadership to make security tooling developer-friendly and compatible with agile delivery practices.
  • Define strategy, standards, and tooling for enterprise-wide static application security testing, tune rulesets, reduce false positives, drive remediation workflows, and ensure coverage across critical code repositories.
  • Oversee the dynamic application security testing program across pre-production and production environments, including automated scanning schedules, triage processes, and integration with enterprise vulnerability management platforms.
  • Own the strategy, configuration, and operations of the enterprise web application firewall platform, including rule sets, emerging-threat monitoring, zero-trust alignment, and defense-in-depth.
  • Implement and manage continuous scanning of source code repositories for secrets, misconfigurations, exposed credentials, and policy violations, and establish automated guardrails to prevent insecure code from reaching production.
  • Develop policies and technical controls for security risks introduced by AI-assisted code-generation tools and implement scanning to detect vulnerabilities in AI-generated code.
  • Manage the software composition analysis program for third-party libraries and open-source dependencies, maintain software supply-chain visibility, and drive compliance with internal ingestion policies.
  • Oversee security configuration and policy enforcement for content delivery network infrastructure, including DDoS mitigation, bot management, and transport layer security standards.
  • Own the application security tooling portfolio, including vendor relationships, licensing, platform health, roadmap alignment, and evaluation of emerging technologies.
  • Define and maintain application security policies, standards, and operational procedures.
  • Ensure compliance with HIPAA, PCI-DSS, CCPA, NIST Secure Software Development Framework, and OWASP standards.
  • Provide executive-level reporting and governance dashboards covering program health, risk posture, and remediation progress.
  • Establish and maintain a risk-based vulnerability management process for software development vulnerabilities in code, dependencies, build pipelines, and deployment pipelines.
  • Build, lead, and develop a high-performing team of application security engineers, architects, and program managers.
  • Collaborate with Cyber Defense, Data Protection, Infrastructure Security, Legal, Compliance, and Technology leadership to deliver integrated security outcomes.
  • Partner with Chief Data and Technology Officers across business units to understand technology strategies, influence security outcomes, and embed application security priorities into roadmaps and investment decisions.
  • Foster a security-minded engineering culture through developer education, secure coding training, security champion programs, and engagement with engineering communities of practice.
Desired Qualifications
  • An advanced degree in Computer Science, Information Security, or a related field is preferred.
  • Certifications such as Certified Information Systems Security Professional, Certified Secure Software Lifecycle Professional, Certified Information Security Manager, GIAC Web Application Penetration Tester, or equivalent are preferred.
  • Experience in healthcare or other highly regulated industries is preferred.
  • Familiarity with artificial intelligence or machine-learning-driven security tooling and modern cloud-native application security architectures is preferred.
  • Experience implementing security programs within large-scale DevOps or platform engineering organizations is preferred.

CVS Health operates as a diversified health services company in the United States, organized into Health Care Benefits, Pharmacy & Consumer Wellness, and Health Services. Its offerings include medical insurance products, retail and mail-order prescription drugs, and pharmacy benefit management (PBM) services, all connected through its integrated platform. By combining insurance, retail pharmacy, PBM, and health solutions, CVS Health coordinates care and controls costs across touchpoints for individuals, employers, and government programs. The company aims to lower health care costs while improving access and health outcomes for customers.

Company Size

10,001+

Company Stage

IPO

Headquarters

Woonsocket, Rhode Island

Founded

1963

Get referred to CVS Health

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Q2 2026 revenue hit $106.1 billion, up 7.3%, with adjusted EPS $2.58.
  • CVS raised 2026 adjusted EPS guidance to $7.90-$8.10 and cash flow to $11.5 billion.
  • Walgreens' 1,200-store closures through 2027 funnel prescriptions toward CVS locations.

What critics are saying

  • FTC settlement on Caremark insulin practices forces transparency changes through 2036.
  • CVS expects 340B pressure and Caremark membership declines in 2027.
  • $175 billion liabilities and $3.12 billion annual interest burden constrain strategic flexibility.

What makes CVS Health unique

  • Caremark, Aetna, and 9,000 stores create unmatched U.S. pharmacy-insurance integration.
  • CVS handled 87 million PBM members and 37 million insured people in June 2026.
  • CVS app now prices Eli Lilly Zepbound and Mounjaro for same-day pickup.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Disability Insurance

401(k) Retirement Plan

Company Equity

Wellness Program

Professional Development Budget

Paid Vacation

Paid Holidays

Company News

Yahoo Finance
Sep 12th, 2026
CVS quietly gains market share as Walgreens closes 1,200 US stores following $10B private equity sale

Walgreens is closing roughly 1,200 of its approximately 8,500 US locations through 2027, with many customers being redirected to nearby CVS pharmacies. The pattern is reshaping suburban pharmacy markets without direct competition. In August 2025, Walgreens completed a $10 billion sale to private equity firm Sycamore Partners, taking the 124-year-old chain private for the first time. Mike Motz was named chief executive, replacing Tim Wentworth. CVS is gaining market share without active expansion efforts. Federal and state rules require orderly prescription transfers when pharmacies close, often directing patients to the nearest CVS location. CVS and Walgreens together now handle nearly 40% of all US retail prescription sales. CVS benefits from owning Caremark, a dominant pharmacy benefit manager, providing vertical integration advantages.

Yahoo Finance
Aug 28th, 2026
CVS stock down 12% in a month despite 34% annual gain, faces 2027 headwinds

CVS Health stock has declined 12.3% over the past month, sitting about 15% below its 52-week high, though it remains up 34% over the trailing twelve months. The company's revenue reached approximately $415 billion, up 7.4% year-over-year. Management raised its full-year 2026 adjusted earnings per share guidance by $0.60 to a range of $7.90 to $8.10. For 2027, the company anticipates membership declines at Caremark and continued 340B programme pressure, offset by Aetna's recovery, which added over $2 billion in adjusted operating income in the first half of 2026. Management considers a 2027 adjusted EPS outlook of at least $8.44 reasonable. Historically, CVS has experienced varied recovery periods following market downturns, with some rebounds taking years rather than months.

Yahoo Finance
Aug 25th, 2026
CVS and Roche stocks could benefit from expanding GLP-1 drug market

CVS Health and Roche could benefit from the growing GLP-1 drug market, alongside current leaders Eli Lilly and Novo Nordisk. CVS Health has improved its financial performance, with second-quarter revenue rising 7.3% year-over-year to $106.1 billion and adjusted earnings per share increasing 42.5% to $2.58. The pharmacy chain offers all approved GLP-1 medicines in the US, including Eli Lilly's Zepbound and Foundayo, plus Novo Nordisk's Wegovy. CVS also provides low-cost online consultations at $29 to assess patient eligibility for GLP-1 drugs. Beyond GLP-1 initiatives, CVS is addressing previous business challenges and is positioned to capitalise on rising healthcare spending in the US over the next decade.

Yahoo Finance
Aug 19th, 2026
CVS Health appoints JPMorgan data executive to board as focus shifts to digital healthcare

CVS Health has appointed Teresa Heitsenrether, a senior executive from JPMorgan Chase with extensive data and analytics experience, to its board of directors. The move follows the resignation of board member Larry M. Robbins. The appointment signals CVS Health's focus on technology and data-driven healthcare at the governance level. The company, valued at approximately $120bn, operates an integrated healthcare model spanning insurance, pharmacy benefits, and retail services. Heitsenrether's data expertise aligns with CVS Health's strategy to leverage digital capabilities and operational efficiency across its businesses, including Aetna and Caremark. The company faces challenges including high debt levels and reimbursement pressures in a competitive market alongside UnitedHealth Group and Cigna.

Yahoo Finance
Aug 14th, 2026
CVS Health beats Q2 revenue and profit estimates but faces questions on sustainability

CVS Health reported second quarter revenue of $106.1 billion, beating analyst estimates of $99.41 billion by 6.7%. Adjusted earnings per share came in at $2.58, surpassing expectations of $1.85 by 39.4%. Management attributed strong performance to specialty pharmacy and Medicare Advantage, with CEO David Joyner noting improvements from actions taken in Aetna and Caremark. The company raised its full-year adjusted EPS guidance to $8 at the midpoint. However, analysts raised concerns about sustainability. Management acknowledged ongoing challenges in the 340B program and normalisation of script share gains from Rite Aid. To offset these headwinds, executives pointed to biosimilars and investments in service technology. The company has committed $20 billion over a decade to AI and technology investments, with operational savings already being realised.

INACTIVE