×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

AVP, Application Security

Job in North Providence, Providence County, Rhode Island, 02911, USA
Listing for: 9025 CVS Shared Services Resources LLC
Full Time position
Listed on 2026-07-26
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 185400 - 375950 USD Yearly USD 185400.00 375950.00 YEAR
Job Description & How to Apply Below

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.

Position Summary

CVS Health is seeking a polished and experienced security leader to serve as Associate Vice President of Application Security, responsible for defining and executing the enterprise strategy for securing software across its full development lifecycle. This role owns the policies, technical standards, and tooling that enable CVS Health's engineering teams to build and deploy secure applications  AVP will lead a high-performing team of application security engineers and architects, partner deeply with Developer Experience leadership to embed security seamlessly into agile development practices and serve as a trusted advisor to executive stakeholders on software security risk.

This leader will balance targeted security outcomes with developer productivity, ensuring that security is an enabler — not a barrier — to innovation.

Key Responsibilities:
Strategic Leadership
  • Define and own the enterprise application security strategy, roadmap, and policy framework, aligned with CVS Health's business objectives and regulatory obligations.
  • Establish and enforce technical standards for secure software development, including code scanning, code vulnerability management, and secure-by-design principles.
  • Serve as a subject matter expert and trusted advisor to senior technology and business executives on emerging application security risks, attack trends, and industry best practices.
  • Drive continuous improvement across the application security program through metrics, benchmarking, and innovation.
Application Security Engineering & Controls
  • Secure Development Lifecycle (SDLC) Integration: Lead the integration of application security scanning, testing, and policy enforcement gates into CI/CD pipelines across the enterprise. Partner with Developer Experience leadership to ensure security tooling is frictionless, developer-friendly, and compatible with agile delivery practices.
  • Static Application Security Testing (SAST): Define strategy, standards, and tooling for enterprise-wide SAST scanning. Manage tuning of rulesets to reduce false positives, drive remediation workflows, and ensure coverage across all critical code repositories.
  • Dynamic Application Security Testing (DAST): Oversee DAST program covering pre-production and production environments. Establish automated scanning schedules, triage processes, and integration with enterprise vulnerability management platforms.
  • Web Application Firewall (WAF) Management: Own the strategy, configuration, and operations of the enterprise WAF platform. Define and maintain rule sets, monitor for emerging threats, and ensure alignment with zero-trust and defense-in-depth principles.
  • Code Repository Scanning: Implement and manage continuous scanning of source code repositories for secrets, misconfigurations, exposed credentials, and policy violations. Establish guardrails and automated enforcement to prevent insecure code from reaching production.
  • AI-Assisted Code Generation Security: Develop policies and technical controls to assess and govern security risks introduced by AI-assisted code generation tools (e.g., Git Hub Copilot, generative AI coding assistants). Define standards for safe use and implement scanning capabilities to detect AI-generated code vulnerabilities.
  • Third-Party and Open-Source Software (SCA) Scanning: Manage the Software Composition Analysis (SCA) program to identify and remediate vulnerabilities in third-party libraries and open-source dependencies. Maintain visibility into the software supply chain and drive compliance with internal ingestion policies.
  • Content Delivery Network (CDN) Security Management: Oversee security configuration and policy enforcement for content delivery network infrastructure. Ensure…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary