CVS Health

AVP, Application Security

CVS Health$185K — $375K *
US-Anywhere
+ 3 other locationsRemote
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • 12+ years of experience in information security, with 5 years in application security leadership.
  • Strong technical background with hands-on coding in modern programming languages (Java, Python, Go, etc.).
  • Expertise in application security engineering and secure software development lifecycle practices.
  • Solid understanding of software architecture patterns and cloud-native development security.
  • Experience with enterprise application security tools (SAST, DAST, SCA, WAF, etc.).
  • Familiarity with application security standards like OWASP Top 10 and regulatory requirements (HIPAA, PCI-DSS).
  • Proven ability to drive security culture within agile environments.

Responsibilities

  • Define and execute the enterprise application security strategy and policies.
  • Establish technical standards for secure software development processes.
  • Advise senior executives on application security risks and best practices.
  • Integrate application security checks into CI/CD pipelines.
  • Oversee dynamic and static application security testing programs.
  • Manage application security tooling and vendor relationships.
  • Lead a high-performing team of application security professionals.

Benefits

  • Comprehensive medical, dental, and vision coverage.
  • Paid time off for work-life balance.
  • Retirement savings options to secure your future.
  • Wellness programs supporting overall health and wellbeing.
  • Additional resources based on individual eligibility.
Full Job Description
Position Summary

CVS Health is seeking a polished and experienced security leader to serve as Associate Vice President of Application Security, responsible for defining and executing the enterprise strategy for securing software across its full development lifecycle. This role owns the policies, technical standards, and tooling that enable CVS Health's engineering teams to build and deploy secure applications at scale. The AVP will lead a high-performing team of application security engineers and architects, partner deeply with Developer Experience leadership to embed security seamlessly into agile development practices and serve as a trusted advisor to executive stakeholders on software security risk. This leader will balance targeted security outcomes with developer productivity, ensuring that security is an enabler - not a barrier - to innovation.

Key Responsibilities:
Strategic Leadership
  • Define and own the enterprise application security strategy, roadmap, and policy framework, aligned with CVS Health's business objectives and regulatory obligations.
  • Establish and enforce technical standards for secure software development, including code scanning, code vulnerability management, and secure-by-design principles.
  • Serve as a subject matter expert and trusted advisor to senior technology and business executives on emerging application security risks, attack trends, and industry best practices.
  • Drive continuous improvement across the application security program through metrics, benchmarking, and innovation.

Application Security Engineering & Controls
  • Secure Development Lifecycle (SDLC) Integration: Lead the integration of application security scanning, testing, and policy enforcement gates into CI/CD pipelines across the enterprise. Partner with Developer Experience leadership to ensure security tooling is frictionless, developer-friendly, and compatible with agile delivery practices.
  • Static Application Security Testing (SAST): Define strategy, standards, and tooling for enterprise-wide SAST scanning. Manage tuning of rulesets to reduce false positives, drive remediation workflows, and ensure coverage across all critical code repositories.
  • Dynamic Application Security Testing (DAST): Oversee DAST program covering pre-production and production environments. Establish automated scanning schedules, triage processes, and integration with enterprise vulnerability management platforms.
  • Web Application Firewall (WAF) Management: Own the strategy, configuration, and operations of the enterprise WAF platform. Define and maintain rule sets, monitor for emerging threats, and ensure alignment with zero-trust and defense-in-depth principles.
  • Code Repository Scanning: Implement and manage continuous scanning of source code repositories for secrets, misconfigurations, exposed credentials, and policy violations. Establish guardrails and automated enforcement to prevent insecure code from reaching production.
  • AI-Assisted Code Generation Security: Develop policies and technical controls to assess and govern security risks introduced by AI-assisted code generation tools (e.g., GitHub Copilot, generative AI coding assistants). Define standards for safe use and implement scanning capabilities to detect AI-generated code vulnerabilities.
  • Third-Party and Open-Source Software (SCA) Scanning: Manage the Software Composition Analysis (SCA) program to identify and remediate vulnerabilities in third-party libraries and open-source dependencies. Maintain visibility into the software supply chain and drive compliance with internal ingestion policies.
  • Content Delivery Network (CDN) Security Management: Oversee security configuration and policy enforcement for content delivery network infrastructure. Ensure CDN-layer protections - including DDoS mitigation, bot management, and TLS standards - are aligned with enterprise security policy.
  • Application Security Technology Stack: Own the full application security tooling portfolio. Manage vendor relationships, licensing, platform health, and roadmap alignment. Evaluate and introduce emerging technologies to improve coverage, automation, and developer experience.

Governance & Compliance
  • Define and maintain application security policies, standards, and operational procedures.
  • Ensure compliance with applicable regulatory frameworks and industry standards, including HIPAA, PCI-DSS, CCPA, NIST SSDF, and OWASP.
  • Provide executive-level reporting and governance dashboards that communicate program health, risk posture, and remediation progress.
  • Establish and maintain a risk-based vulnerability management process focused specifically on software development vulnerabilities, including those introduced through code, dependencies, and the build and deployment pipeline, in partnership with peer security organizations.

Leadership & Collaboration
  • Build, lead, and develop a high-performing team of application security engineers, architects, and program managers.
  • Partner closely with Developer Experience leadership to align security tooling and practices with developer workflows, ensuring security is integrated seamlessly into agile and DevSecOps pipelines.
  • Collaborate with Cyber Defense, Data Protection, Infrastructure Security, Legal, Compliance, and Technology leadership to deliver integrated security outcomes.
  • Partner with Chief Data and Technology Officers (CDTOs) across CVS Health business units to understand technology strategies, influence security-targeted outcomes, and ensure application security priorities are embedded within divisional roadmaps and investment decisions.
  • Foster a security-minded engineering culture through developer education, secure coding training, security champion programs, and engagement with engineering communities of practice.


Key Performance Indicators (KPIs):
  • Pipeline Coverage: Percentage of active software development pipelines with integrated SAST, DAST, and SCA scanning controls.
  • Vulnerability Remediation SLA: Mean time to remediate (MTTR) critical and high application security vulnerabilities, tracked against defined SLAs.
  • Secrets & Policy Violations: Reduction in secrets exposed in code repositories and policy violations detected year-over-year.
  • WAF Effectiveness: Percentage of malicious web traffic blocked; reduction in application-layer incidents attributed to WAF-protected assets.
  • Third-Party Risk Coverage: Percentage of production applications with up-to-date SCA coverage and no unaddressed critical open-source vulnerabilities.
  • AI Code Security: Coverage rate of AI-assisted code generation under security policy and scanning controls.
  • Developer Experience Satisfaction: Developer NPS and feedback scores related to security tooling and friction within the SDLC.
  • Regulatory Compliance: Audit findings related to application security controls, targeting zero critical findings.
  • Program Adoption: Number of development teams operating under the secure SDLC framework and security champion program.
  • Roadmap Delivery: On-time completion of strategic application security initiatives and tooling milestones.


Required Qualifications
  • 12+ years of progressive experience in information security, with at least 5 years in application security leadership roles.
  • Deep technical background in software development, including hands-on coding experience in one or more modern programming languages (e.g., Java, Python, Go, JavaScript, or similar). Candidates must bring developer-level fluency to credibly engage with engineering teams, evaluate code-level risks, and drive meaningful secure coding practices.
  • Demonstrated expertise in application security engineering and secure software development lifecycle (SDLC) practices, grounded in first-hand experience building or shipping software.
  • Strong understanding of software architecture patterns, CI/CD pipelines, containerization, and cloud-native development - with the ability to assess security implications at every layer of the stack.
  • Hands-on experience managing enterprise application security tooling, including SAST, DAST, SCA, WAF, and repository scanning platforms.
  • Deep knowledge of application security standards and frameworks, including OWASP Top 10, NIST SSDF, and relevant regulatory requirements (HIPAA, PCI-DSS, CCPA).
  • Proven ability to influence engineering culture and drive security adoption at scale within agile development environments.
  • Strong leadership skills with experience building and managing cross-functional technical teams and influencing senior stakeholders.
  • Excellent communication and presentation skills; ability to translate complex security concepts for both technical and non-technical audiences.


Preferred Qualifications
  • Advanced degree in Computer Science, Information Security, or a related field.
  • Certifications such as CISSP, CSSLP, CISM, GWEB, or equivalent.
  • Experience in healthcare or other highly regulated industries.
  • Familiarity with AI/ML-driven security tooling and modern cloud-native application security architectures.
  • Experience implementing security programs within large-scale DevOps or platform engineering organizations.


Education
Bachelor's Degree

Pay Range

The typical pay range for this role is:

$185,400.00 - $375,950.00

This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company's equity award program.

Great benefits for great people

We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.

This full-time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well-being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.

Additional details about available benefits are provided during the application process and on Benefits Moments.

We anticipate the application window for this opening will close on: 08/13/2026

About CVS Health

Omnicare provides comprehensive pharmaceutical services to patients and providers across the United States. As the market-leader in professional pharmacy, related consulting and data management services for skilled nursing, assisted living and other chronic care settings, Omnicare leverages its unparalleled clinical insight into the geriatric market along with some of the industry's most innovative technological capabilities to the benefit of its long-term care customers. Omnicare also provides key commercialization services for the bio-pharmaceutical industry through its Specialty Care Group.

CVS Health Careers

Joining CVS Health presents a unique opportunity to advance your career in a company where innovation, leadership, and growth go hand in hand. As a leader in the healthcare industry, CVS Health is more than just a pharmacy. We are a team of professionals dedicated to improving lives and optimizing health outcomes.

Work You’ll Do

At CVS Health, you will be part of a culture that values diversity and inclusivity, fostering an environment where every team member’s contribution is valued. Engage in meaningful work that directly impacts lives, driving innovation in healthcare services and solutions.

Explore Job Opportunities

Whether you’re looking for a position in pharmacy services, corporate leadership, or in-store management, CVS Health offers a variety of employment opportunities that will help you harness your skills and thrive professionally. Our job opportunities span across a wide range of professional fields and geographic locations, ensuring that your career at CVS Health aligns with your professional goals and lifestyle.

Internship Programs

Kickstart your career with CVS Health through our internship programs. These opportunities are designed for ambitious students eager to develop their skills in a real-world setting. Internships at CVS Health are not only about gaining work experience but also about making meaningful contributions to our ongoing projects.

Professional Growth and Development

CVS Health is committed to the professional growth of our employees. With access to cutting-edge technology, industry-leading experts, and comprehensive diversity training, our team members are equipped to lead and innovate. We support career advancement through professional development programs, leadership training, and opportunities for networking and internal mobility.

Benefits and Culture

Our employees enjoy a range of benefits that reflect our commitment to their well-being and success. From health and wellness benefits to professional development programs, CVS Health is dedicated to ensuring our team members have the resources they need. Our inclusive culture encourages collaboration and continuous learning, making CVS Health a place where you can grow and succeed.

Join Our Team

Ready to take the next step in your career? Explore the open positions at CVS Health that match your skills and interests. We are continuously hiring and looking for passionate, curious, and solution-driven team players.

Stay Connected

Keep up to date with the latest news, career tips, and industry insights from CVS Health. Personalize your experience by subscribing to job alert emails, tailored to your preferences and professional interests. Discover the rewarding opportunities that await at CVS Health, where your career development is always a priority.

Search CVS Health Jobs

Don’t just look for a job. Look for a place where you can be a part of something bigger. Visit our careers page to find the position that’s right for you and join a team that values innovation and leadership in healthcare.

READ CAREERS BLOG

Stay ahead in your career with insights from those who know CVS Health best – our team. Learn from their experiences and get insider tips that can help you succeed in your next interview, craft a standout resume, and build a career you’re proud of at CVS Health.
Learn more about CVS Health
Size
300,000 employees
Market Cap
$122 billion
Industry
Net Income
$7.1 billion
Founded
1963
5 Year Trend
+10.5%
Revenue
$268.7 billion
NASDAQ

Similar Jobs

More Jobs at CVS Health

More Information Technology Jobs

Find similar AVP, Application Security jobs: