Principal Application Security Engineer – AI & Agentic Systems

CVS Health

Helena (MT)

On-site

USD 144,200 - 288,400

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Affordable medical plan options
401(k) plan with company matching
Employee stock purchase plan
Tuition assistance
Flexible work schedules

Job summary

A leading health organization is looking for an experienced candidate to lead AI security efforts, ensuring application security and compliance. The ideal candidate will have over 10 years of experience in application security, along with deep knowledge of AI, programming, and cloud platforms. This role offers a competitive compensation range from $144,200 to $288,400, along with comprehensive health benefits, including medical plans and a 401(k). The position is based in Helena, Montana.

Qualifications

  • 10+ years of experience designing and securing applications.
  • 7+ years in application security, threat modeling, and vulnerability management.
  • 5+ years developing and securing AI/ML workloads.
  • 3+ years with containerized and microservice architectures.

Responsibilities

  • Lead enforcement of application and AI security policies.
  • Architect secure designs for AI-enabled applications.
  • Influence teams to integrate secure engineering practices.
  • Conduct advanced security testing for AI systems.

Skills

Application security
Threat modeling
Programming (Python, Java, etc.)
Cloud platforms (AWS, Azure, GCP)
Secure design practices

Education

Bachelor's degree or equivalent experience

Tools

CI/CD pipelines
RAG pipelines

Job description

We're building a world of health around every individual - shaping a more connected, convenient and compassionate health experience. At CVS Health®, you'll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger - helping to simplify health care one person, one family and one community at a time.

Position Summary
Development, Standards & Secure Design
  • Lead development and enforcement of application and AI security policies, standards, and guardrails, embedding security-by-design across both traditional and AI-driven systems.
  • Establish secure design patterns for AI agent frameworks, covering prompt management, tool invocation, memory handling, autonomy boundaries, and escalation controls.
  • Promote organization-wide awareness of AI-specific risks such as model misuse, prompt injection, data leakage, and unsafe agent behavior.
AI & Agentic Security Architecture
  • Serve as the principal SME for securing AI-enabled applications and agentic system architectures.
  • Architect and review secure designs for systems leveraging LLMs/foundation models, autonomous and semi-autonomous agents, RAG pipelines, and tool‑using or decision‑making workflows.
  • Define identity, authorization, data access, and observability controls specific to agentic environments while partnering closely with AI platform, product, and data teams to ensure responsible AI delivery.
Collaboration, Leadership & Influence
  • Influence engineering and product teams to integrate secure engineering practices and align security with compliance, privacy, and responsible AI initiatives.
  • Advise senior leadership on AI security implications, architectural decisions, and long-term strategy while shaping roadmaps that anticipate emerging AI threats and regulatory requirements.
Testing, Analysis & Risk Management
  • Lead advanced security testing and risk assessments for AI-enabled systems, including threat modeling of agent workflows, abuse/misuse analysis, and secure design reviews of AI pipelines.
  • Evaluate and guide adoption of new AI security tools, ensuring protections maintain confidentiality, integrity, availability, and responsible data use.
Operational Response & Continuous Improvement
  • Provide senior technical leadership during incidents involving application or AI systems, guiding response strategies for misuse, data exposure, and autonomous failures.
  • Translate operational learnings into improved security architecture, controls, and system resilience.
Mentorship, Innovation & Strategy
  • Mentor senior and principal engineers to elevate security maturity across the organization.
  • Contribute to research and evaluation of emerging AI security practices and play a key role in shaping the long-term application and AI security roadmap, advocating for security as a strategic accelerator for AI adoption.
Required Qualifications
  • 10+ years of experience designing, building, and securing large-scale applications and platforms.
  • 7+ years of expertise in application security, including threat modeling, secure design, and vulnerability management.
  • 7+ years of programming experience in one or more languages such as Python, Java, JavaScript, C#, or Go.
  • 5+ years of experience developing and securing AI and ML workloads, with recent experience in generative AI and agentic workloads.
  • 5+ years of experience public cloud platforms (AWS, Azure, and/or GCP) and modern application architectures.
  • 3+ years of experience with containerized, serverless, and microservice-based architectures.
Preferred Qualifications
  • Hands-on experience securing AI agents, RAG pipelines, and tool-using LLM systems.
  • Proven ability to lead complex security initiatives from concept through enterprise-scale adoption.
  • Familiarity with AI governance, responsible AI principles, and emerging AI security standards.
  • Experience integrating security controls into CI/CD pipelines for AI and application workloads.
  • Strong understanding of compliance frameworks (PCI, HIPAA, NIST, HITRUST, CSA).
  • Experience influencing security strategy beyond a single team, including enterprise or platform-level impact.
  • Contributions to security research, open-source projects, or industry communities.
Education
  • Bachelor's degree or equivalent experience (High School Diploma and 4 years relevant experience)
Pay Range

The typical pay range for this role is:

$144,200.00 - $288,400.00

This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company's equity award program.

Great benefits for great people

We take pride in our comprehensive and competitive mix of pay and benefits - investing in the physical, emotional and financial wellness of our colleagues and their families to help them be the healthiest they can be. In addition to our competitive wages, our great benefits include:

  • Affordable medical plan options, a 401(k) plan (including matching company contributions), and an employee stock purchase plan.
  • No-cost programs for all colleagues including wellness screenings, tobacco cessation and weight management programs, confidential counseling and financial coaching.
  • Benefit solutions that address the different needs and preferences of our colleagues including paid time off, flexible work schedules, family leave, dependent care resources, colleague assistance programs, tuition assistance, retiree medical access and many other benefits depending on eligibility.

For more information, visit https://jobs.cvshealth.com/us/en/benefits

We anticipate the application window for this opening will close on: 03/23/2026

Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Application Security Engineer – AI & Agentic Systems
Principal Application Security Engineer – AI & Agentic Systems

CVS Health • Pierre (SD)

On-site
USD 144,000 - 289,000
Comprehensive medical plans
401(k) plan with matching contributions
Employee stock purchase plan
+2
Principal Application Security Engineer – AI & Agentic Systems
Principal Application Security Engineer – AI & Agentic Systems

CVS Health • Topeka (KS)

On-site
USD 144,000 - 289,000
Affordable medical plan options
401(k) plan with matching contributions
Employee stock purchase plan
+2
Principal Application Security Engineer – AI & Agentic Systems
Principal Application Security Engineer – AI & Agentic Systems

CVS Health • City of Albany (NY)

On-site
USD 144,000 - 289,000
Affordable medical plan options
401(k) plan with matching contributions
Employee stock purchase plan
+2
Principal Application Security Engineer - AI & Agentic Systems
Principal Application Security Engineer - AI & Agentic Systems

CVS Health • Augusta (ME)

On-site
USD 144,000 - 289,000
Affordable medical plan options
401(k) with company matching
Employee stock purchase plan
+1
Principal Application Security Engineer - AI & Agentic Systems
Principal Application Security Engineer - AI & Agentic Systems

CVS Health • Baton Rouge (LA)

On-site
USD 144,000 - 289,000
401(k) plan with matching contributions
Affordable medical plan options
Employee stock purchase plan
+2
Principal Application Security Engineer - AI & Agentic Systems
Principal Application Security Engineer - AI & Agentic Systems

CVS Health • Saint Paul (MN)

On-site
USD 144,000 - 289,000
Affordable medical plan options
401(k) plan with matching contributions
Employee stock purchase plan
+2
Principal Application Security Engineer – AI & Agentic Systems
Principal Application Security Engineer – AI & Agentic Systems

CVS Health • Salem (OR)

On-site
USD 144,200 - 288,400
401(k) plan with company matching
Employee stock purchase plan
Flexible work schedules
Principal Application Security Engineer - AI & Agentic Systems
Principal Application Security Engineer - AI & Agentic Systems

CVS Health • Raleigh (NC)

On-site
USD 144,200 - 288,400
Affordable medical plan options
401(k) plan with company matching
Employee stock purchase plan
+3
Principal Application Security Engineer - AI & Agentic Systems
Principal Application Security Engineer - AI & Agentic Systems

CVS Health • Jefferson City (MO)

On-site
USD 144,000 - 289,000
Affordable medical plan options
401(k) plan with matching contributions
Employee stock purchase plan
+2
Principal Application Security Engineer – AI & Agentic Systems
Principal Application Security Engineer – AI & Agentic Systems

CVS Health • Austin (TX)

On-site
USD 144,000 - 289,000
Affordable medical plan options
401(k) plan with matching contributions
Tuition assistance