Staff Application Security Engineer – AI & Agentic Systems
Job Description
CVS Health seeks a Staff Application Security Engineer to strengthen application and AI security across AI-enabled and agentic systems.
Responsibilities
- Develop and maintain application and AI security standards, best practices, and guardrails
- Drive secure-by-design principles across application and AI development lifecycles
- Establish secure design patterns for AI agents, prompt management, tool integrations, memory handling, and autonomous workflows
- Partner with engineering teams to identify and reduce AI-specific risks, including prompt injection, model abuse, data leakage, and unauthorized agent actions
- Act as a subject matter expert for the security of AI-enabled applications and agentic systems
- Review and advise architectures using large language models, retrieval augmented generation, AI agents, and AI-powered workflows
- Define and recommend controls for AI environments, including identity, authorization, data protection, observability, and governance
- Collaborate with AI platform, engineering, product, and data teams to support secure and responsible AI adoption
- Run threat modeling, architecture reviews, and security assessments for applications and AI-enabled systems
- Perform security analysis of AI workflows, model integrations, agent interactions, and data flows
- Partner with engineering teams to prioritize and remediate security findings
- Evaluate emerging AI security tools and technologies to strengthen organizational security posture
- Influence engineering teams to embed security controls into development processes and product roadmaps
- Coordinate with privacy, compliance, legal, and risk teams to align security controls with organizational requirements
- Provide guidance on AI security considerations, emerging threats, and industry best practices
- Support strategic initiatives for secure AI adoption across the enterprise
- Help investigate and respond to application and AI-related security events
- Assist in identifying root causes and implementing long-term security improvements
- Drive continuous improvement across security controls, processes, and engineering practices
- Mentor security engineers and development teams on secure coding, threat modeling, and AI security best practices
- Contribute to evaluating emerging AI security research, technologies, and industry standards
- Advance the organization’s application and AI security strategy through innovation and technical leadership
Requirements
- 7+ years experience designing, building, or securing enterprise-scale applications and platforms
- 5+ years application security experience, including threat modeling, secure design, code review, and vulnerability management
- 5+ years programming experience in one or more: Python, Java, JavaScript, C#, Go
- 3+ years experience developing or securing AI, machine learning, or generative AI solutions
- 3+ years experience with public cloud platforms such as AWS, Azure, or Google Cloud Platform
Preferred Qualifications
- Experience securing modern application architectures, including APIs, containers, microservices, and serverless
- Strong understanding of secure SDLC and application security testing methodologies
- Hands-on experience securing AI agents, RAG solutions, and LLM integrations
- Experience conducting threat modeling and security assessments for AI-enabled systems
- Familiarity with responsible AI principles, AI governance, and emerging AI security frameworks
- Experience integrating security controls into CI/CD pipelines
- Knowledge of compliance frameworks such as PCI DSS, HIPAA, NIST, HITRUST, and CSA
- Ability to influence technical decisions across multiple teams and organizations
- Experience contributing to security research, open-source projects, or industry communities
Technologies
- Python
- Java
- JavaScript
- C#
- Go
- AWS
- Azure
- Google Cloud Platform
Benefits
- Medical, dental, and vision coverage
- Paid time off
- Retirement savings options
- Wellness programs
- Other resources, based on eligibility
- CVS Health bonus, commission, or short-term incentive program (eligible in addition to the base pay range)
- Award target in the company’s equity award program
Location: New York, NY (onsite)
Pay range: $106,605.00 - $284,280.00 per year
Education: Bachelor’s degree from an accredited college or university (or equivalent combination of education and relevant work experience)
This full-time role is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well-being of colleagues and their families.