Assistant Vice President (AVP) Security Risk Management
CVS Health
- Location
- CA - Work from home
- Work model
- Remote
- Level
- Staff
- Posted
- Aug 12, 2026
Skills
About this role
We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.
Position
Summary The AVP Security Risk Management is responsible for reducing enterprise cybersecurity and technology risk by identifying, measuring, prioritizing, and driving treatment of material cyber and technology risks across enterprise technology environments, business processes, third-party relationships, supply chain dependencies, and merger, acquisition, and divestiture activity. This leader defines the cyber and technology risk strategy, governance, assessment methods, control validation, and operating routines used to evaluate control effectiveness, threat exposure, technology, data, identity, resilience, third-party, and regulatory risk across internal and external stakeholders. Reporting to the Deputy CISO, this collaborative leader partners with senior security, privacy, risk, legal, technology, procurement, corporate development, integration, and business leaders . T he AVP converts internal and external cybersecurity and technology risk intelligence — including enterprise control gaps, technology control deficiencies, emerging threats, third-party exposure , supply chain dependencies , and M&A risk — into measurable risk decisions, remediation priorities, control requirements, and executive reporting that help protect CVS Health’s members, colleagues, protected health information, confidential data, critical systems, operations, and brand.
Key Responsibilities
Evolve CVS Health’s cybersecurity and technology risk management program as a core component of the enterprise cyber and technology risk strategy, including risk taxonomy, risk appetite alignment, assessment methodology, internal and external risk identification, inherent and residual risk scoring, technology and security control validation, governance routines, issue management, and executive risk reporting. Lead the end-to-end lifecycle of third-party cybersecurity risk assessments — including pre-contract due diligence, security architecture review, onboarding, periodic reassessment, continuous monitoring, offboarding, and risk acceptance — across thousands of vendors and business associates, ensuring decisions are transparent, evidence-based, and aligned to enterprise risk appetite. Integrate internal enterprise risk signals and external third-party, supply chain, and M&A cyber and technology risk signals into CVS Health’s enterprise risk posture by identifying systemic exposure, technology concentration risk, control gaps, ransomware exposure, data protection risk, identity and access risk, cloud and infrastructure risk, application and platform risk, software supply chain risk, technology resilience risk, and emerging threat trends. Lead M&A Security onboarding activities by partnering with Corporate Development, Integration Management, Legal, Privacy, Technology, and cybersecurity teams to assess cyber risk during due diligence; evaluate security architecture, identity, data, endpoint, network, vulnerability, cloud, and third-party exposures; define integration security requirements; prioritize remediation; and support secure onboarding of acquired entities, assets, applications, users, suppliers, and data into CVS Health’s security control environment. Lead M&A Security offboarding activities for divestitures, separations, and transition services by defining cybersecurity exit requirements; coordinating secure separation of data, identities,