Staff Application Security Engineer - Blue Team
CVS Health
- Location
- CA - Work from home
- Work model
- Remote
- Level
- Staff
- Posted
- Sep 15, 2026
Skills
About this role
We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time. Staff Application Security Engineer – Blue Team Who Are You A senior defensive security practitioner with deep engineering expertise and the ability to design, develop, and influence security solutions across the enterprise. Highly experienced in protecting applications, cloud platforms, data assets, and infrastructure through proactive detection, prevention, response, and resilience strategies. Passionate about building secure and scalable systems while driving continuous security improvements through automation and innovation. A recognized subject matter expert in application security, cloud security, data security, and network security from a Blue Team / defensive operations perspective. Comfortable leading security initiatives in complex environments including cloud-native architectures, distributed systems, hybrid infrastructures, and legacy platforms. Able to provide technical leadership during security incidents while remaining calm and effective in high-pressure situations. Skilled at influencing engineering teams, mentoring peers, and driving organization-wide adoption of secure-by-design principles.
Role
Responsibilities: Development & Enforcement Design, implement, and maintain defensive security controls across applications, cloud platforms, data systems, and network environments. Develop and enforce enterprise-wide application and data security standards, policies, and best practices. Embed security controls into SDLC processes, CI/CD pipelines, and deployment automation frameworks. Lead security architecture reviews and ensure alignment with organizational security objectives. Establish security governance frameworks that improve confidentiality, integrity, availability, and resiliency. Collaboration & Expertise Partner with Engineering, Infrastructure, Architecture, and Business teams to embed secure-by-design practices across products and services. Serve as a trusted advisor and technical leader for Application Security, Cloud Security, and Secure Development practices. Influence technical decision-making and security strategy across multiple teams and business units. Drive organization-wide security awareness and operational readiness initiatives. Analysis & Configuration Monitor, detect, investigate, and respond to security events, vulnerabilities, threats, and incidents. Lead vulnerability assessments, remediation planning, risk prioritization, and validation efforts across application and data platforms. Design, evaluate, and optimize defensive controls across cloud-native, hybrid, and on-premises environments. Conduct security assessments, threat modeling exercises, and architecture reviews to identify and mitigate risks. Implement advanced security solutions across multi-cloud, colocation, and enterprise environments. Operational Support Participate in a rotational on-call schedule, including off-hours, nights, weekends, and holidays, supporting a 24x7 operational environment. Lead security incident response activities including investigation, containment, eradication, recovery, and post-incident reviews. Develop, maintain, and continuously improve incident response, detection, escalation, and recovery playbooks. Drive operational improvements that strengthen incident readiness and cyber resilience. Mentorship & Training Mentor and coach engineers on secure coding practices, security engineering principles, and defensive operations. Provide guidance to development and operational teams on security best practices and emerging threats. Support training