Senior Manager - Application Security Engineering

Posted Yesterday
Be an Early Applicant
4 Locations
In-Office or Remote
118K-261K Annually
Senior level
Fitness • Healthtech • Retail • Pharmaceutical
The Role
Lead and scale enterprise application security, vulnerability management, software supply chain security, and DevSecOps capabilities. Manage a team delivering secure software delivery, automation, developer enablement, and governance across cloud-native, hybrid, and legacy environments. Partner with engineering, product, risk, and compliance to reduce risk and operationalize security controls.
Summary Generated by Built In

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.

POSITION SUMMARY

CVS Health is seeking a Senior Manager, Application Security Engineering to lead enterprise application security, vulnerability management, secure software delivery, and security engineering capabilities across a complex technology environment.

Within the Cybersecurity organization, this leader will be responsible for managing and advancing application security programs that help protect CVS Health applications and technology platforms throughout the software development lifecycle. The role will partner closely with Engineering, Architecture, Infrastructure, Product, Risk, Compliance, and Cybersecurity teams to integrate security into development processes and support secure delivery of business solutions.

The Senior Manager will lead a team responsible for application security engineering, vulnerability management, software supply chain security, security automation, and developer security enablement. This role will oversee security standards, tooling, governance, risk reduction activities, and operational processes that support enterprise technology portfolios and strategic initiatives, including Health 100.

Additionally, this leader will help build and scale security capabilities that improve developer adoption, increase automation, strengthen secure software development practices, and support enterprise DevSecOps initiatives.

This is a U.S.-based remote position. Candidates must reside within the United States.

PRIMARY DUTIES AND RESPONSIBILITIES

Application Security & Secure Software Delivery

  • Lead the design, implementation, and governance of enterprise application security programs, secure development standards, and software supply chain security practices.
  • Establish security requirements, security definitions of done, launch readiness criteria, and automated controls that enable secure software delivery across cloud-native, hybrid, and legacy environments.
  • Drive adoption of secure coding practices and developer-focused security capabilities across enterprise engineering organizations.

Vulnerability Management & Security Operations

  • Oversee the end-to-end vulnerability management lifecycle, including identification, prioritization, remediation, exception management, validation, and reporting.
  • Establish operational metrics, service level objectives, governance processes, and executive reporting mechanisms that drive accountability and measurable risk reduction.
  • Lead enterprise response efforts for critical and zero-day vulnerabilities, including risk assessment, stakeholder communication, remediation coordination, and executive reporting.

Security Engineering, DevSecOps & Platform Innovation

  • Drive adoption of modern security technologies and DevSecOps capabilities, including SAST, SCA, container security, secrets management, software bill of materials (SBOM), and software supply chain security solutions.
  • Lead automation of security controls within CI/CD pipelines to improve operational efficiency, strengthen risk mitigation, and accelerate secure software delivery.
  • Evaluate, implement, and optimize application security, cloud security, and software supply chain security technologies across on-premises, cloud, and hybrid environments.
  • Assess and adopt emerging technologies, including AI-powered security and developer productivity solutions, that improve security outcomes and operational effectiveness.
Leadership, Strategy & Enterprise Partnership
  • Lead and develop a high-performing team of security professionals while fostering a culture of technical excellence, accountability, innovation, and continuous improvement.

  • Build and scale security programs that drive developer adoption, self-service security capabilities, and DevSecOps maturity across enterprise engineering teams.

  • Partner across Engineering, Product, Architecture, Infrastructure, Risk, Compliance, and Cybersecurity teams to define strategic roadmaps, enable secure engineering practices, and support enterprise transformation initiatives, including Health 100.

  • Drive workforce development, capacity planning, operational readiness, and execution of strategic security objectives.

REQUIRED QUALIFICATIONS
  • 7+ years of experience developing, implementing, and operating enterprise security technologies across Application Security, Container Security, Data Security, Infrastructure Security, or related cybersecurity domains.

  • 7+ years of experience leading security programs and initiatives from design and implementation through operationalization and continuous improvement within enterprise environments.

  • 5+ years of experience securing cloud-native and modern application environments leveraging AWS, Azure, or GCP, including containers, Kubernetes, Infrastructure-as-Code (IaC), and Security-as-Code practices.

  • 5+ years of experience supporting secure software development lifecycle (SDLC) programs, vulnerability management, security testing, regulatory compliance, and enterprise application portfolios.

  • 4+ years of experience with application security technologies including SAST, SCA, CVA, mobile application security testing, secrets scanning, software supply chain security, and developer enablement programs.

  • 2+ years of experience leading, mentoring, managing, and developing security engineering, application security, vulnerability management, or cybersecurity teams.

PREFERRED QUALIFICATIONS
  • Experience architecting, securing, and modernizing enterprise applications, CI/CD pipelines, and cloud-native platforms across multi-cloud, hybrid, and legacy environments, including containerized, serverless, microservices-based, monolithic, and mainframe architectures.

  • Experience with application security, software composition analysis (SCA), software bills of materials (SBOM), software supply chain security, developer enablement programs, and secure software delivery practices utilizing platforms such as JFrog, Snyk, Veracode, Wiz, GitGuardian, Prisma Cloud, or similar technologies.

  • Experience supporting highly regulated environments and compliance frameworks including HIPAA, HITRUST, PCI-DSS, NIST, CSA, and related security and risk management standards.

  • Experience leading enterprise-scale transformation, application modernization, DevSecOps, and security automation initiatives, including building and scaling security programs, developer enablement capabilities, self-service security platforms, executive reporting, KPIs, KRIs, security scorecards, portfolio governance, and risk management programs.

  • Experience leveraging AI-powered technologies such as Claude, Claude Code, GitHub Copilot, Microsoft Copilot, and similar platforms to automate vulnerability remediation, integrate MCP-based security scanning, implement security controls within CI/CD pipelines, enhance developer enablement, and improve secure software delivery at enterprise scale.

EDUCATION

Bachelor’s degree from an accredited college or university, or equivalent combination of education and relevant work experience (High School Diploma/GED plus 4 years of related experience).

BUSINESS OVERVIEW

Bring your heart to CVS Health. Every one of us at CVS Health shares a single, clear purpose: Bringing our heart to every moment of your health. This purpose guides our commitment to deliver enhanced human-centric healthcare for a rapidly changing world. Anchored in our brand — with heart at its center — our purpose sends a personal message that how we deliver our services is just as important as what we deliver. Our Heart At Work Behaviors™ support this purpose. We want everyone who works at CVS Health to feel empowered by the role they play in transforming our culture and accelerating our ability to innovate and deliver solutions that make healthcare more personal, convenient, and affordable. CVS Health is an affirmative action employer and an equal opportunity employer. We are committed to fostering a diverse, inclusive, and equitable workplace and encourage candidates from all backgrounds to apply, including veterans, reservists, National Guard members, military spouses, and individuals with disabilities.

Pay Range

The typical pay range for this role is:

$118,450.00 - $260,590.00


This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls.  The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors.  This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above.  This position also includes an award target in the company’s equity award program. 
 

Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.

Great benefits for great people

We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.

This full‑time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well‑being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.


Additional details about available benefits are provided during the application process and on
Benefits Moments.

We anticipate the application window for this opening will close on: 08/31/2026

Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.

Skills Required

  • 7+ years developing, implementing, and operating enterprise security technologies across application, container, data, or infrastructure security.
  • 7+ years leading security programs from design through operationalization and continuous improvement.
  • 5+ years securing cloud-native and modern application environments using AWS, Azure, or GCP, including containers, Kubernetes, IaC, and Security-as-Code.
  • 5+ years supporting secure SDLC programs, vulnerability management, security testing, regulatory compliance, and enterprise application portfolios.
  • 4+ years with application security technologies (SAST, SCA, CVA), mobile app security testing, secrets scanning, software supply chain security, and developer enablement.
  • 2+ years leading, mentoring, managing, and developing security engineering or application security teams.
  • Bachelor's degree or equivalent combination of education and experience.
  • Experience architecting and modernizing enterprise applications, CI/CD pipelines, and cloud-native platforms across multi-cloud, hybrid, and legacy environments.
  • Experience with SCA, SBOM, software supply chain security, and developer enablement using platforms such as JFrog, Snyk, Veracode, Wiz, GitGuardian, or Prisma Cloud.
  • Experience supporting regulated environments and compliance frameworks (HIPAA, HITRUST, PCI-DSS, NIST, CSA).
  • Experience leading enterprise-scale transformation, DevSecOps, security automation, and building self-service security platforms, KPIs, and governance.
  • Experience leveraging AI-powered tools (Claude, Claude Code, GitHub Copilot, Microsoft Copilot) to automate vulnerability remediation and improve secure software delivery.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Woonsocket, RI
119,959 Employees
Year Founded: 1963

What We Do

CVS Health is the leading health solutions company that delivers care in ways no one else can. We reach people in more ways and improve the health of communities across America through our local presence, digital channels and our nearly 300,000 dedicated colleagues – including more than 40,000 physicians, pharmacists, nurses and nurse practitioners. Wherever and whenever people need us, we help them with their health – whether that’s managing chronic diseases, staying compliant with their medications, or accessing affordable health and wellness services in the most convenient ways. We help people navigate the health care system – and their personal health care – by improving access, lowering costs and being a trusted partner for every meaningful moment of health. And we do it all with heart, each and every day.

Similar Jobs

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Associate Claims Adjuster, Workers Compensation

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Remote or Hybrid
4 Locations
40000 Employees
50K-94K Annually

Identity Digital Logo Identity Digital

Staff Devops Engineer

Consumer Web • eCommerce • Internet of Things
Remote or Hybrid
United States
240 Employees
175K-220K Annually

Zscaler Logo Zscaler

Senior Manager, Sales Engineering - Majors, NY/NJ

Cloud • Information Technology • Security • Software • Cybersecurity
Easy Apply
Remote or Hybrid
3 Locations
8697 Employees
176K-251K Annually

MetLife Logo MetLife

Senior Consultant

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
121K-149K Annually

Similar Companies Hiring

Scotch Thumbnail
Artificial Intelligence • eCommerce • Fintech • Payments • Retail • Software • Analytics
US
35 Employees
OneImaging Thumbnail
Healthtech
Miami, FL
62 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account