Assistant Vice President, Technology Assurance
Listed on 2026-09-04
-
IT/Tech
Cybersecurity, IT Consultant, IT Project Manager, IT Business Analyst
We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.
The AVP, Technology Assurance leads Internal Audit’s technology audit and assurance coverage across CVS Health. The role brings together three areas of coverage under a single leader: established technology and cybersecurity audit, emerging risk assurance, and Internal Audit’s advisory presence on the company’s largest enterprise system implementations. The AVP provides independent, third-line assurance and advisory support across the technology landscape.
Technology risk ownership, technology and AI strategy, and decisions about how solutions are designed, built, and deployed remain with technology, digital, and business leadership; this role evaluates and advises on them independently. Consistent with how the Emerging Risk Assurance function operates, the AVP adds value early and surfaces gaps without assuming management responsibility for decisions that belong to the business, preserving the independence that makes the assurance credible.
The AVP sets direction and quality standards for their teams and represents Internal Audit with senior technology, digital, and business leadership on cross‑cutting matters. Because both the established IT/cybersecurity audit and emerging risk assurance pillars report to this role, the AVP owns coordination across them directly - ensuring coverage is complete and efficient, with clear ownership of where the two disciplines meet.
The AVP also serves as Internal Audit’s embedded advisory presence on governance and steering forums for large‑scale ERP implementations. This is an advisory role that surfaces control and risk considerations to program leadership ahead of go‑live, and is distinct from any formal testing the program may later require.
- Technology and Cybersecurity Audit Leadership Set strategy and audit plan coverage for IT corporate audit and cybersecurity, aligned to enterprise risk appetite. Oversee the Executive Director, DDAT/IT Audit in execution of the IT and cyber audit plan, including cybersecurity controls, incident response, and regulatory compliance reviews. Hold the primary Internal Audit relationship with technology leadership, providing independent perspective on control effectiveness, IT governance, and risk management maturity.
Report technology audit results, themes, and emerging risks to the CAE and Audit Committee. - Emerging Risk Assurance Oversight Oversee the Executive Director, Emerging Risk Assurance and the third‑line assurance function over AI, machine learning, intelligent automation, and other algorithmic or autonomous decision‑making risk. Ensure emerging risk assurance work stays positioned as independent evaluation of governance and controls, distinct from strategy‑setting or management of how AI and emerging solutions are built and deployed. Coordinate emerging risk coverage against established technology audit coverage owned by the DDAT/IT Audit team, so the two pillars stay aligned without duplicating work.
Maintain the human‑in‑the‑loop versus human‑over‑the‑loop distinction across audit approach and reporting, including for AI‑related changes to the SOX control environment. Support the Emerging Risk Assurance team's advisory role with the AI Governance Council and technology teams during design of new AI use cases and governance structures. - ERP Program Advisory Serve as Internal Audit's embedded advisory presence on governance and steering forums for large‑scale ERP implementations. Surface control and risk considerations to program leadership ahead of go‑live in an advisory capacity. Define the boundary between this advisory role and any downstream formal audit or SOX testing the program later requires. Keep the CAE informed on ERP program risk and readiness at…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).