DevSecOps Engineer; Health
Listed on 2026-09-25
-
IT/Tech
Cybersecurity, Cloud Computing: Infrastructure & Operations
We're building a world of health around every individual - shaping a more connected, convenient and compassionate health experience. At CVS Health®, you'll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger - helping to simplify health care one person, one family and one community at a time.
StaffEngineer, Dev Sec Ops Security Engineering
Health 100 Focus | Security Implementation, Migration and Automation Leadership
Role OverviewThe Staff Engineer, Dev Sec Ops Security Engineering, is responsible for leading technical implementation, migration, automation, mobile application security and standardization across the Health 100 portfolio. This role translates application security strategy into scalable engineering solutions that strengthen release readiness, improve vulnerability remediation, expand security and mobile testing coverage, and enable secure-by-default delivery across engineering teams.
Who You AreA senior technical employee with deep expertise in application security, Dev Sec Ops , automation and secure delivery practices.
Experiencedtranslatingsecuritystrategy into implementations that development teams can adopt consistently.
Strong in automation, tooling integrationandprocess improvement that reduce manualeffortand improve engineering outcomes.
Comfortable using metrics to communicate technical risk, delivery progress and measurable outcomes.
Able to balance hands-on engineering depth with cross-functional influence across application,platform,cloudand security teams.
1. Health 100 Security Enablement
Support application onboarding and security enablement for Health 100 initiatives.
Help development teams meet security requirements through standard tooling, pipeline integration and repeatable implementation patterns.
Translate release-readiness expectations into repeatable technical patterns and evidence.
Ensure mobile applications are included in Health 100 security enablement through mobile application security testing, secure configuration validation and clear remediation guidance.
Lead Dev Sec Ops implementation initiatives aligned to security goals and engineering priorities.
Own technical planning, architecture, delivery, issue resolution and implementation outcomes.
Coordinate across application, platform and security teams to remove blockers and sustain adoption.
Design, implement and improve CI/CD security controls, pipeline enforcement and automated scanning workflows.
Partner with development and platform teams to embed security controls without creating unnecessary delivery friction.
Build self-service security solutions and reusable automation that reduce manual intervention and improve engineering efficiency.
Automate secret-detection and CI/CD security workflows, including Gitleaks or comparable capabilities.
Lead security-tool migrations, including transitions such as Checkmarx to Snyk, from design through stable production operation.
Produce and validate initial post-migration scan results to demonstrate successful implementation and integration.
Standardize tooling configurations across development teams to improve consistency, ease of use and policy alignment.
Partner with platform teams to reduce legacy pipeline risk, fragmented configurations and duplicated manual processes.
Drive remediation of critical and high-risk vulnerabilities across Health 100 applications with clear technical ownership and follow-through.
Monitor remediation against established SLAs and identify aging, recurrence and systemic issues.
Lead technical prioritization of high-impact open-source and software supply chain exposures affecting multiple applications.
Provide remediation guidance and scalable fixes that teams can adopt consistently.
Improve open-source visibility through SBOM coverage and related software supply chain practices.
Drive secure-by-default dependency usage and remediation of high-risk third-party components.
Engineer controls for public cloud, container, Kubernetes, Security-as-Code and Infrastructure-as-Code environments.
Apply network-security and cloud-architecture expertise to design practical, resilient solutions.
Apply mobile security…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).