×
Register Here to Apply for Jobs or Post Jobs. X

Security and Compliance Analyst

Job in Buffalo Grove, Lake County, Illinois, 60089, USA
Listing for: CVS Health
Full Time position
Listed on 2026-04-17
Job specializations:
  • IT/Tech
    Cybersecurity, IT Consultant
Salary/Wage Range or Industry Benchmark: 60000 - 80000 USD Yearly USD 60000.00 80000.00 YEAR
Job Description & How to Apply Below

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.

Position Overview

The Security and Compliance Analyst (VP Point of Contact) is a highly visible role within the CVS Caremark organization responsible for ensuring effective governance of application security and compliance requirements. This position serves as a critical liaison between CVS Enterprise security and audit teams, business stakeholders, and application development teams to strengthen CVS Health s cybersecurity posture and compliance framework.

Position Summary

The VP Point of Contact (VP POC) will collaborate with peers across CVS Enterprise security and audit teams to provide expert guidance on integrating security best practices throughout the Software Development Lifecycle (SDLC). The role focuses on vulnerability management, scanning and remediation, strategic infrastructure security implementation, and risk assessment. The analyst will evaluate enterprise risks based on identified vulnerabilities and threats, recommend mitigation strategies, provide regular updates to IT management, and support audit response activities.

Key Responsibilities Vulnerability Management & Remediation
  • Participate in daily and weekly meetings with vulnerability management teams, lines of business, towers, and application owners to track status and progress of assigned vulnerabilities
  • Ensure proper alignment of vulnerability assignments across lines of business, towers, and application groups
  • Drive the creation, tracking, and timely closure of vulnerability remediation plans in accordance with CVS Health security timelines
  • Monitor remediation of critical vulnerabilities within required time frames (Critical: 7 days, High: 90 days, Medium: 180 days, Low: 365 days)
  • Ci security requirements
Security Strategy & Advisory
  • Advise business stakeholders and development teams on proper security practices throughout the Software Development Lifecycle
  • Evaluate user needs and system functionality to help develop comprehensive IT security strategies for security scanning and detection
  • Provide strategic guidance on infrastructure technologies to implement layered defense mechanisms
  • Assess and communicate enterprise risks based on vulnerability findings and emerging threats
  • Recommend appropriate mitigation strategies aligned with business objectives
Compliance & Governance
  • Partner with internal and external auditors during compliance and regulatory reviews
  • Contribute to and influence application security policies across Pharmacy Services IT and the broader CVS enterprise
  • Ensure adherence to CVS Health cybersecurity compliance requirements and industry standards
Enterprise cybersecurity compliance policy
  • Support continuous monitoring and assessment initiatives
  • Continuous monitoring
Communication & Stakeholder Management
  • Provide appropriate updates and security status reporting to IT management
  • Facilitate meetings with both technical and business audiences across multiple functional departments
  • Document and track security remediation plans and exceptions
  • Communicate complex security topics effectively to diverse stakeholder groups
Required Qualifications
  • 3+ years of experience in application security, monitoring/management, vulnerability management, or risk and compliance
  • 3+ years of experience working across all phases of SDLC and CI/CD pipelines
  • 1+ years of experience managing or coordinating large-scale projects
  • Strong understanding of security principles and secure coding practices
  • Secure coding
Preferred Qualifications Technical Knowledge
  • Background and understanding of networking and network security technologies, including:
  • Azure Cloud security policy adherence
  • TCP/IP networking knowledge (networking architecture, firewall configuration, DMZ layout)
  • Advanced web technology knowledge (HTTP, HTML, SQL)
  • Advanced…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary