Senior Manager - Application Security, Ecosystem and Threat Management

March 13

Apply Now
Logo of CVS Health

CVS Health

CVS Health is a leading American healthcare company dedicated to improving health access and affordability. The company focuses on a comprehensive approach that includes health services, health insurance, and pharmacy benefits management. Through its subsidiaries, such as Aetna and CVS Caremark, CVS Health offers a range of services that facilitate wellness, condition management, and affordable prescription drug coverage. CVS Health operates neighborhood pharmacies, provides mail-order pharmacy services, and manages specialty medication programs, aiming to make healthcare convenient and accessible for everyone. Driven by a mission to connect people with essential care services, CVS Health is committed to fostering healthier communities and supporting the wellbeing of all individuals.

Retail • Pharmacy Benefits Management • Health Insurance • Health Care • Pharmacy

📋 Description

• Manage a team of application security operations engineers in efforts related to code scanning, CDN, metrics, presentations, interfacing with technical and business partners to drive results. • Develop and enforce engineering security policies and standards. • Drive security awareness across the organization. • Oversee the development and enforcement of comprehensive security policies and standards, ensuring advanced security practices are integrated throughout the software development lifecycle to mitigate risks and maintain alignment with industry-leading security protocols. • Facilitate collaboration between security, development, and operations teams to foster a unified approach to secure software development. • Regularly review and update security policies and standards to reflect evolving threat landscapes and technological advancements, embedding a culture of continuous improvement within the team. • Build and maintain strong relationships with product management, engineering leaders, and other key stakeholders to seamlessly integrate security considerations into product development lifecycles and operational processes. • Serve as a key security figure, orchestrating the integration of secure engineering practices across the organization and ensuring alignment with business objectives through strategic communication with senior management and other stakeholders. • Analyze, develop, and configure security solutions across multi-cloud, on-premises, and colocation environments, ensuring application security, integrity, confidentiality, and availability of data. • Lead security testing, vulnerability analysis, and documentation. • Spearhead the evaluation and strategic deployment of cutting-edge security solutions, emphasizing scalability, performance, and adaptability, to fortify the organization's defense against evolving threats. • Enhance and maintain a dynamic security architecture framework that empowers project teams to develop secure solutions, fostering agility and innovation within secure boundaries, thus aligning security measures with business objectives. • Participate in operational on-call duties to support a 24/7 infrastructure across multiple regions and environments (cloud, on-premises, colocation). • Manage the security incident response team, ensuring rapid and effective handling of all security incidents, and leverage these experiences to develop and refine a resilient incident response strategy. • Implement a metrics-driven approach to security operations, using key performance indicators (KPIs) and key risk indicators (KRIs) to effectively measure and report on the security posture, incident response efficacy, and continuous improvement of security practices. • Demonstrated leadership skills with developing a comprehensive mentorship program for junior engineers, including organizing regular training sessions to elevate the team's technical and security skills. • Establish a targeted leadership development program within the security team to cultivate future leaders by enhancing specific competencies and experiences, emphasizing the development of both technical skills and leadership qualities. • Proven track record with participation in security research and the exploration of next-generation security tools and practices. This includes encouraging the team to engage with the wider security community, contributing to open-source projects, and staying well-informed of emerging threats and innovative defense mechanisms. • Encourage a culture of innovation within the team by allocating resources for research into emerging security technologies and practices, and by recognizing and rewarding innovative ideas and solutions. • Lead the strategic planning of the organization's security roadmap, including conducting comprehensive risk assessments, managing budgets for security initiatives, and aligning the security strategy with overarching business goals. • Champion security within the organization to ensure it is a key consideration in all business decisions and technology investments. • Advocate for the necessary resources and investments in security initiatives, demonstrating the ability to communicate the value and necessity of security to both technical and non-technical stakeholders effectively.

🎯 Requirements

• 7+ years of experience in developing and deploying security technologies. • 7+ years of managing a team • Proficiency in Active Directory • Proficiency in Public Cloud (AWS/Azure/GCP) & Network Security. • Experience with Docker, Kubernetes, Security-as-Code, and Infrastructure-as-Code. • Experience with one or more general-purpose programming/script languages including but not limited to: Java, C/C++, C#, Python, JavaScript, Shell Script, PowerShell. • Strong experience with implementing and managing data protection measures and compliance with data protection regulations (e.g., GDPR, CCPA). • Proven track record in leading security initiatives from inception through to successful deployment, demonstrating exceptional project management skills and the ability to navigate complex stakeholder landscapes. • Demonstrated experience in managing and leading high-performance security teams, showcasing strong organizational navigation skills and the ability to inspire, challenge, and support team members towards achieving personal and organizational goals.

🏖️ Benefits

• Affordable medical plan options • 401(k) plan (including matching company contributions) • Employee stock purchase plan • No-cost programs for all colleagues including wellness screenings, tobacco cessation and weight management programs, confidential counseling and financial coaching. • Benefit solutions that address the different needs and preferences of our colleagues including paid time off, flexible work schedules, family leave, dependent care resources, colleague assistance programs, tuition assistance, retiree medical access and many other benefits depending on eligibility.

Apply Now

March 13

Cobalt seeks a Senior Security Researcher to drive security research and advance their methodologies, focusing on penetration testing.

March 12

Join Dealer Tire as a Senior HRIS Administrator, focused on Workday security and operations.

Discover 100,000+ Remote Jobs!

Join now to unlock all jobs

Discover hidden jobs

We scan the internet everyday and find jobs not posted on LinkedIn or other job boards.

Head start against the competition

We find jobs as soon as they're posted, so you can apply before everyone else.

Be the first to know

Daily emails with new job openings straight to your inbox.

Choose your membership

Loved by 10,000+ remote workers
🎉$6 / week

Cancel anytime

MOST POPULAR
🥳$18 / month
$24
Save 25% vs weekly

Cancel anytime

BEST VALUE
🥰$54 / year
$216
Save 75% vs monthly

Cancel anytime

Wall of Love

Frequently asked questions

We use powerful scraping tech to scan the internet for thousands of remote jobs daily. It operates 24/7 and costs us to operate, so we charge for access to keep the site running.

Of course! You can cancel your subscription at any time with no hidden fees or penalties. Once canceled, you’ll still have access until the end of your current billing period.

Other job boards only have jobs from companies that pay to post. This means that you miss out on jobs from companies that don't want to pay. On the other hand, Remote Rocketship scrapes the internet for jobs and doesn't accept payments from companies. This means we have thousands more jobs!

New jobs are constantly being posted. We check each company website every day to ensure we have the most up-to-date job listings.

Yes! We’re always looking to expand our listings and appreciate any suggestions from our community. Just send an email to Lior@remoterocketship.com. I read every request.

Remote Rocketship is a solo project by me, Lior Neu-ner. I built this website for my wife when she was looking for a job! She was having a hard time finding remote jobs, so I decided to build her a tool that would search the internet for her.

Why I created Remote Rocketship

Choose your membership

Loved by 10,000+ remote workers
🎉$6 / week

Cancel anytime

MOST POPULAR
🥳$18 / month
$24
Save 25% vs weekly

Cancel anytime

BEST VALUE
🥰$54 / year
$216
Save 75% vs monthly

Cancel anytime

Built by Lior Neu-ner. I'd love to hear your feedback — Get in touch via DM or lior@remoterocketship.com