CybersecurityJobs.io
← Back to all jobs

Job Description

CVS Health is hiring a Staff Application Security Engineer (Blue Team) to strengthen defensive security across applications, cloud platforms, data systems, and network environments. In this role, you will help monitor and respond to security events, improve incident readiness through repeatable playbooks, and advance security through automation, governance, and secure development practices.

What you’ll do

  • Design, implement, and maintain defensive security controls across applications, cloud platforms, data systems, and network environments.
  • Develop and enforce enterprise-wide application and data security standards, policies, and best practices.
  • Embed security controls into SDLC processes, CI/CD pipelines, and deployment automation frameworks.
  • Lead security architecture reviews and ensure alignment with organizational security objectives.
  • Establish security governance frameworks that improve confidentiality, integrity, availability, and resiliency.
  • Partner with Engineering, Infrastructure, Architecture, and Business teams to apply secure-by-design practices across products and services.
  • Act as a trusted advisor and technical leader for Application Security, Cloud Security, and Secure Development practices.
  • Influence technical decision-making and security strategy across multiple teams and business units.
  • Monitor, detect, investigate, and respond to security events, vulnerabilities, threats, and incidents.
  • Lead vulnerability assessments, remediation planning, risk prioritization, and validation across application and data platforms.
  • Design, evaluate, and optimize defensive controls across cloud-native, hybrid, and on-premises environments.
  • Conduct security assessments, threat modeling exercises, and architecture reviews to identify and mitigate risks.
  • Implement advanced security solutions across multi-cloud, colocation, and enterprise environments.
  • Participate in a rotational on-call schedule, including off-hours, nights, weekends, and holidays, supporting a 24x7 operational environment.
  • Lead security incident response activities including investigation, containment, eradication, recovery, and post-incident reviews.
  • Develop, maintain, and continuously improve incident response, detection, escalation, and recovery playbooks.
  • Drive operational improvements that strengthen incident readiness and cyber resilience.
  • Mentor and coach engineers on secure coding practices, security engineering principles, and defensive operations.
  • Provide guidance to development and operational teams on security best practices and emerging threats.
  • Support training initiatives that improve security maturity across the organization.
  • Research emerging threats, vulnerabilities, attack techniques, and security technologies.
  • Evaluate and recommend new security tools, platforms, and defensive capabilities.
  • Automate security operations using code and Security-as-Code principles to improve efficiency and scalability.
  • Improve threat detection, monitoring, alerting, and response capabilities through innovation and continuous improvement.
  • Contribute to long-term security strategy, architecture roadmaps, and technology planning initiatives.
  • Define and drive enterprise security objectives and key performance indicators, partnering with leadership to prioritize security investments and risk reduction activities.
  • Develop standards and practices that improve cyber resilience, redundancy, business continuity, and recovery capabilities.

Required qualifications

  • 7+ years of experience in security engineering, application security, cloud security, or defensive security operations.
  • 3+ years of experience securing modern cloud platforms including AWS, Azure, and GCP.
  • 3+ years of experience with Docker, Kubernetes, Infrastructure-as-Code, and Security-as-Code methodologies.
  • 3+ years of experience in one or more programming or scripting languages including Python, Java, C#, JavaScript, Shell, or PowerShell.
  • 3+ years of experience in networking, identity management, authentication, authorization, and threat mitigation techniques.

Technologies

  • AWS, Azure, GCP
  • Docker, Kubernetes
  • Infrastructure-as-Code, Security-as-Code
  • Python, Java, C#, JavaScript, Shell, PowerShell

Benefits

  • Medical, dental, and vision coverage
  • Paid time off
  • Retirement savings options
  • Wellness programs
  • Comprehensive benefits package designed to support the physical, emotional, and financial well-being of colleagues and their families

Preferred qualifications

  • Experience designing and operating defensive security controls within cloud-native, containerized, and distributed application environments.
  • Experience implementing data protection controls and supporting regulatory and compliance requirements including GDPR, CCPA, or similar frameworks.
  • Demonstrated experience designing and implementing enterprise-scale security controls and security automation solutions.
  • Deep understanding of networking, software-defined networking (SDN), zero-trust architectures, and cloud security models.
  • Experience performing threat modeling, security architecture reviews, and secure design assessments.
  • Ability to develop and interpret network, sequence, application architecture, and data flow diagrams.
  • Experience with compliance and security frameworks such as NIST, PCI DSS, HIPAA, HITRUST, ISO 27001, SOC 2, or CSA.
  • Experience securing enterprise data platforms, analytics environments, and data warehouses including Snowflake and similar technologies.
  • Experience defining and implementing cyber resilience, business continuity, backup, redundancy, and recovery strategies.
  • Relevant industry certifications such as CISSP, CCSP, GSEC, GIAC, AWS Security Specialty, Azure Security Engineer Associate, or equivalent.

Compensation and location

  • Location: Sacramento, CA (onsite)
  • Salary range: USD 130,295 - 260,590 per year
  • Eligible for a CVS Health bonus, commission, or short-term incentive program in addition to the base pay range listed above
  • Equity award program includes an award target

Education

  • Bachelor’s degree from an accredited college or university, or equivalent combination of education and relevant work experience (High School Diploma/GED plus 4 years of related experience)

Additional information

  • Application window closes on: 09/22/2026
  • Qualified applicants with arrest or conviction records will be considered in accordance with federal, state, and local laws

Similar Jobs