Full-Time

Executive Director

Threat Engineering & Adversary Operations

Posted on 1/17/2025

CVS Health

CVS Health

10,001+ employees

Comprehensive pharmacy and healthcare services

Healthcare
Consumer Goods

Compensation Overview

$175.1k - $334.8kAnnually

+ Bonus + Commission + Equity Award Program

Senior, Expert

Company Historically Provides H1B Sponsorship

Remote in USA + 1 more

More locations: New York, NY, USA

Hybrid role with New York as a required in-office location.

Category
Cybersecurity
IT & Security
Required Skills
PowerShell
Microsoft Azure
Python
JavaScript
Machine Learning
Java
C#
AWS
C/C++
Google Cloud Platform
Requirements
  • 12+ years of experience in cybersecurity leadership roles, with proven success in both offensive (red team) and defensive (blue team) domains.
  • Industry certifications such as OSCP, OSCE, OSEP, GPEN, GXPN, CISSP, GCIH, GCIA, CEH, or CISM are highly preferred. Cloud-specific certifications such as GCP Cloud Security Engineer, AWS Certified Security, or Azure Security Engineer are a plus but not required.
  • Strong expertise in adversary simulation, red teaming, penetration testing, and detection frameworks, with deep knowledge of exploit development, attack methodologies, and advanced detection techniques.
  • Proven ability to leverage automation, AI, and machine learning to enhance offensive security testing, vulnerability exploitation, threat detection, and remediation processes across diverse environments.
  • Extensive experience with offensive and defensive security tools, including Metasploit, Cobalt Strike, Burp Suite, custom scripting, threat intelligence platforms, SIEM solutions, and endpoint detection and response (EDR) systems.
  • Strong technical expertise in testing and detection techniques across cloud, on-prem, and hybrid environments, with a focus on scalability and resilience.
  • Proficient in one or more general-purpose programming or scripting languages, such as Java, C/C++, C#, Python, JavaScript, Shell Script, and PowerShell, with an emphasis on automation for security operations.
  • Demonstrated ability to build and lead high-performing global teams, cultivate talent, and foster a collaborative culture that drives innovation and operational excellence in both offensive and defensive security practices.
  • Demonstrated success in leading large-scale, global security initiatives, with a deep understanding of diverse regulatory environments and the ability to navigate complex international data protection laws.
Responsibilities
  • Lead the development and execution of advanced, proactive threat-hunting strategies, leveraging cutting-edge technologies such as AI, machine learning, and advanced analytics to detect, respond, and mitigate complex threats at scale.
  • Build and oversee robust threat-hunting frameworks that integrate MITRE ATT&CK, Cyber Kill Chain, and the Diamond Model of Intrusion Analysis, alongside state-of-the-art tools such as SIEM platforms, endpoint detection, and threat intelligence solutions, to continuously identify and eliminate security threats.
  • Continuously assess and enhance detection and defense strategies based on evolving threat landscapes, ensuring the organization remains resilient against sophisticated and emerging attack vectors.
  • Oversee the adoption of detection and mitigation strategies for advanced AI and LLM-based threats, including adversarial attacks, model exploitation, and abuse, ensuring early identification and elimination of complex vulnerabilities.
  • Drive the development and execution of offensive security and adversary simulation strategies, employing cutting-edge techniques to identify, test, and exploit vulnerabilities across all organizational systems.
  • Oversee and enhance red teaming frameworks that leverage MITRE ATT&CK, Cyber Kill Chain, and OWASP frameworks, alongside tools such as Metasploit, Cobalt Strike, and custom-built solutions, to rigorously evaluate security defenses.
  • Continuously evaluate and refine offensive strategies based on the evolving threat landscape, ensuring readiness against sophisticated attack vectors and proactive identification of weaknesses.
  • Champion the implementation of advanced simulation techniques, including AI and machine learning-based attack methods, adversarial AI exploitation, and model abuse, to identify potential system weaknesses and enhance the organization's defensive posture.
  • Direct the implementation of both incident detection and adversary simulation capabilities, ensuring readiness to identify, exploit, contain, and remediate potential threats.
  • Guide the development of playbooks, automated workflows, and resilience strategies to ensure rapid and effective response to both simulated and real incidents.
  • Collaborate with external stakeholders, including threat intelligence providers and law enforcement, to enhance incident response and ensure a cohesive approach to high-impact threats.
  • Leverage AI, machine learning, and automation to enhance detection, adversary emulation, and remediation processes, improving scalability and effectiveness across teams.
  • Oversee strategies for defending against AI/LLM-based threats, including adversarial attacks, model exploitation, and abuse, ensuring proactive protection against emerging risks.
  • Drive innovation in leveraging AI/LLM technologies for enhanced detection, response, and simulation capabilities, including the use of generative AI for adversary emulation and detection engineering.
  • Adopt advanced technologies such as SOAR platforms, deception technologies, adversarial AI exploitation frameworks, and behavioral analytics to simulate and counteract evolving threats.
  • Develop and implement key security metrics (KPIs/KRIs) to track the effectiveness of threat-hunting strategies and overall cyber resilience efforts.
  • Establish a metrics-driven approach to threat detection and incident response, continuously evaluating and improving the organization’s defense posture.
  • Leverage incident data, threat intelligence, and predictive analysis to continuously enhance threat-hunting techniques and improve defensive controls.
  • Drive team research into emerging threat trends, advanced detection techniques, and AI-based predictive models, fostering a culture of innovation and continuous improvement.
  • Allocate resources to security research and experimentation, encouraging the exploration of next-generation detection tools, frameworks, and methodologies.
  • Stay well-informed on the latest advancements in threat detection, cyber resilience, and AI-based defense mechanisms, integrating them into the team’s practices.
  • Build and lead a high-performing threat-hunting team, cultivating leadership talent and fostering an environment of continuous learning and professional development.
  • Develop leadership programs to ensure team members grow in both technical expertise and leadership competencies, preparing future leaders for the next generation of cyber defense challenges.
  • Foster a collaborative and inclusive team environment that values cross-functional teamwork and knowledge sharing to tackle complex security challenges.
Desired Qualifications
  • Experience working with advanced security platforms, including offensive tools like Cobalt Strike, Brute Ratel, Sliver, Metasploit, and custom-developed solutions, as well as defensive platforms such as CrowdStrike Falcon Complete, Carbon Black, SentinelOne, and XDR systems, to enhance simulation, detection, and response capabilities.
  • Strong expertise in implementing AI and machine learning-driven tools to enhance both offensive and defensive capabilities, including advanced attack simulations, threat hunting, and vulnerability modeling.
  • Strong technical expertise in advanced techniques, including adversary emulation, exploit development, behavioral analytics, deception technologies, and bypassing defenses across multi-cloud, hybrid, and on-prem environments.
  • Familiarity with generative AI and adversarial machine learning techniques to craft realistic attack simulations, enhance detection strategies, and identify novel vulnerabilities.
  • Proven ability to lead global security teams, fostering a collaborative environment focused on cross-functional teamwork, continuous improvement, process automation, and operational excellence.
  • Experience in driving transformational security initiatives—offensive and defensive—that align with organizational goals and elevate the overall security posture.

CVS Health operates a large network of retail pharmacies and walk-in medical clinics across the United States, providing a variety of health-related products and services. The company serves individual consumers, businesses, and communities, offering prescription medications, over-the-counter health products, beauty items, and general merchandise. CVS Health also functions as a pharmacy benefits manager, managing health plans for over 75 million members, and provides specialized care for seniors and patients requiring specialty pharmacy services. This integrated approach allows CVS Health to deliver affordable health management solutions, improve access to quality care, and enhance health outcomes while aiming to reduce overall healthcare costs. The company's goal is to support individuals in achieving better health through its comprehensive services.

Company Stage

Debt Financing

Total Funding

N/A

Headquarters

Woonsocket, Rhode Island

Founded

1963

Simplify Jobs

Simplify's Take

What believers are saying

  • Expansion of telehealth services allows CVS to reach more patients remotely.
  • Increased consumer interest in wellness boosts demand for CVS's health-related products.
  • The trend towards value-based care aligns with CVS's integrated healthcare approach.

What critics are saying

  • Legal challenges related to opioid prescriptions could harm CVS's reputation and finances.
  • The DOJ's intervention in a whistleblower lawsuit may increase legal costs for CVS.
  • The Horizon Organic Milk recall exposes potential vulnerabilities in CVS's supply chain.

What makes CVS Health unique

  • CVS Health operates over 9,600 retail pharmacies and 1,100 walk-in clinics nationwide.
  • The company integrates pharmacy benefits management with specialty pharmacy services for comprehensive care.
  • CVS Health offers tailored medication plans through personalized medicine and pharmacogenomics.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Disability Insurance

401(k) Retirement Plan

Company Equity

Wellness Program

Professional Development Budget

Paid Vacation

Paid Holidays