Principal Application Security Engineer - Threat Research
Listed on 2026-06-08
-
IT/Tech
Cybersecurity, Security Manager
Overview
We re building a world of health around every individual - shaping a more connected, convenient and compassionate health experience. At CVS Health®, you ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger - helping to simplify health care one person, one family and one community at a time.
Position Summary
As the Principal Application Security Engineer - Threat Research, you will sit at the forefront of securing modern healthcare technology, combining deep engineering expertise with advanced threat research to protect applications and sensitive data position drives the design, implementation, and continuous improvement of security across complex environments. By embedding security directly into development pipelines and leveraging automation, this role ensures resilience, scalability, and integrity across the full software lifecycle.
Equally critical, this role contributes to the broader mission of transforming how healthcare data is secured, owned, and trusted. It plays a key part in advancing security practices through research, innovation, and mentorship-elevating engineering teams while shaping how secure systems are built across the enterprise. The impact extends beyond technology, helping enable a future where healthcare innovation is delivered with confidence, accountability, and a strong foundation of security.
ResponsibilitiesDevelopment & Enforcement
- Develop and enforce engineering security policies and standards.
- Develop and enforce data security policies and standards.
- Drive security awareness across the organization.
- Lead the development and enforcement of comprehensive security policies and standards, integrating advanced security practices throughout the software development lifecycle to mitigate risks and align with industry-leading security protocols.
- Collaborate with Engineering and Business teams to develop secure engineering practices.
- Act as a pivotal security leader, driving the integration of secure engineering practices across the organization while liaising with senior management to ensure a cohesive security strategy that aligns with business objectives.
- Analyze, develop, and configure security solutions across multi-cloud, on-premises, and colocation environments, ensuring application security, integrity, confidentiality, and availability of data.
- Lead security testing, vulnerability analysis, and documentation.
- Spearhead the evaluation and strategic deployment of cutting-edge security solutions, emphasizing scalability, performance, and adaptability, to fortify the organization s defense against evolving threats.
- Participate in operational on-call duties to support a 24/7 infrastructure across multiple regions and environments (cloud, on-premises, colocation).
- Lead by example in incident response situations, orchestrating rapid and effective responses while leveraging these experiences to bolster future resilience and response strategies.
- Demonstrated leadership skills with developing a comprehensive mentorship program for junior engineers, including organizing regular training sessions to elevate the team s technical and security skills. This role requires a commitment to fostering a culture of continuous improvement and knowledge sharing.
- Proven track record with participation in security research and the exploration of next-generation security tools and practices. This includes encouraging the team to engage with the wider security community, contributing to open-source projects, and staying well-informed of emerging threats and innovative defense mechanisms.
- Play a key role in the strategic planning of the organization s security roadmap, including conducting thorough risk assessments, allocating budgets for security initiatives, and aligning long-term security strategies with overarching business goals. This responsibility includes advocating for security within the company and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).