Lead Threat Research & Application Security Engineer

Partners in Digital Health

Oklahoma City (OK)

On-site

USD 144,000 - 288,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical benefits
Dental benefits
Vision benefits
Paid time off

Job summary

CVS Health is seeking a Principal Application Security Engineer - Threat Research to secure healthcare software across multi-cloud and on-prem environments. You will lead secure engineering practices, mentor engineers, and drive strategic security initiatives in a 24/7 infrastructure landscape.

You will oversee policy enforcement, risk assessment, and the deployment of cutting-edge security tools, balancing performance with strong protection.

Qualifications

  • 10+ years of experience in developing and deploying security technologies.
  • 7+ years of experience with one or more general-purpose programming/script languages including but not limited to: Java, C/C++, C#, Python, JavaScript, Shell Script, PowerShell.
  • 5+ years of with Public Cloud (AWS/Azure/GCP) & Network Security.
  • 5+ years of experience with Docker, Kubernetes, Security-as-Code, and Infrastructure-as-Code.
  • 5+ years of experience with implementing and managing data protection measures and compliance with data protection regulations (e.g., GDPR, CCPA).
  • 5+ years of experience designing, implementing, and managing Web Application Firewall (WAF) and Layer 7 security solutions.
  • 5+ years of experience performing vulnerability analysis and risk prioritization using industry-standard tools, with the ability to provide clear, actionable remediation guidance to engineering and development teams.
  • 3+ years of experience leading security initiatives from inception through to successful deployment, demonstrating exceptional project management skills and the ability to navigate complex stakeholder landscapes.

Responsibilities

  • Develop and enforce engineering security policies and standards.
  • Develop and enforce data security policies and standards.
  • Drive security awareness across the organization.
  • Lead the development and enforcement of comprehensive security policies and standards, integrating advanced security practices throughout the software development lifecycle to mitigate risks and align with industry-leading security protocols.
  • Collaborate with Engineering and Business teams to develop secure engineering practices.
  • Act as a pivotal security leader, driving the integration of secure engineering practices across the organization while liaising with senior management to ensure a cohesive security strategy that aligns with business objectives.
  • Analyze, develop, and configure security solutions across multi-cloud, on-premises, and colocation environments, ensuring application security, integrity, confidentiality, and availability of data.
  • Lead security testing, vulnerability analysis, and documentation.
  • Spearhead the evaluation and strategic deployment of cutting-edge security solutions, emphasizing scalability, performance, and adaptability, to fortify the organization's defense against evolving threats.
  • Participate in operational on-call duties to support a 24/7 infrastructure across multiple regions and environments (cloud, on-premises, colocation).
  • Lead by example in incident response situations, orchestrating rapid and effective responses while leveraging these experiences to bolster future resilience and response strategies.
  • Demonstrated leadership skills with developing a comprehensive mentorship program for junior engineers, including organizing regular training sessions to elevate the team's technical and security skills.
  • Proven track record with participation in security research and the exploration of next-generation security tools and practices. This includes encouraging the team to engage with the wider security community, contributing to open‑source projects, and staying well-informed of emerging threats and innovative defense mechanisms.
  • Play a key role in the strategic planning of the organization's security roadmap, including conducting thorough risk assessments, allocating budgets for security initiatives, and aligning long‑term security strategies with overarching business goals. This responsibility includes advocating for security within the company and ensuring that security considerations are paramount in all technology decisions.

Skills

Security engineering
Threat research
Security policy enforcement
Cloud security
Vulnerability analysis
Team leadership
Mentorship
Incident response
DevSecOps
Security automation

Education

Bachelor's degree or equivalent experience

Tools

Docker
Kubernetes
Security-as-Code
Infrastructure-as-Code
Web Application Firewall
Threat intel tools

Job description

CVS Health is seeking a Principal Application Security Engineer - Threat Research to secure healthcare software across multi-cloud and on-prem environments. You will lead secure engineering practices, mentor engineers, and drive strategic security initiatives in a 24/7 infrastructure landscape.

You will oversee policy enforcement, risk assessment, and the deployment of cutting-edge security tools, balancing performance with strong protection.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Threat Research & Application Security Engineer
Lead Threat Research & Application Security Engineer

Koitecc Solutions • Lansing (MI)

On-site
USD 144,000 - 288,000
Medical benefits
Dental benefits
Vision coverage
+2
Lead Threat Research & Application Security
Lead Threat Research & Application Security

Partners in Digital Health • Olympia (WA)

On-site
USD 144,000 - 288,000
Bonus eligibility
Equity award program
Comprehensive benefits
Lead Application Security Threat Research Engineer
Lead Application Security Threat Research Engineer

Partners in Digital Health • Lansing (MI)

On-site
USD 144,000 - 288,000
Comprehensive benefits package
Bonus program and equity awards
Senior Application Security Engineer: Threat Research Lead
Senior Application Security Engineer: Threat Research Lead

Partners in Digital Health • Augusta (ME)

Hybrid
USD 144,000 - 288,000
Senior Threat Research & Application Security Engineer
Senior Threat Research & Application Security Engineer

ISHE • Boise (ID), Northern (KY)

Hybrid
USD 144,000 - 288,000
Lead, Application Security & Threat Research
Lead, Application Security & Threat Research

Partners in Digital Health • Frankfort (KY)

On-site
USD 144,000 - 288,000
Medical, dental and vision coverage
Retirement savings options
Wellness programs
+1
Lead Threat Research & App Security Engineer
Lead Threat Research & App Security Engineer

Partners in Digital Health • Lincoln (NE)

On-site
USD 144,000 - 288,000
Comprehensive benefits
Principal Threat Research & App Security Engineer
Principal Threat Research & App Security Engineer

Koitecc Solutions • Tallahassee (FL)

On-site
USD 144,000 - 288,000
Bonus eligibility
Equity awards
Comprehensive benefits package
Senior Threat Research & Application Security Lead
Senior Threat Research & Application Security Lead

Partners in Digital Health • Tallahassee (FL)

On-site
USD 144,000 - 288,000
Senior Threat Research Engineer — Application Security Lead
Senior Threat Research Engineer — Application Security Lead

Idaho Society of Professional Engineers • Boise (ID), Northern (KY)

Hybrid
USD 144,000 - 288,000