Senior Application Security Engineer — Blue Team

CVS Health

Sacramento (CA)

On-site

USD 130,000 - 261,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medical coverage
Dental coverage
Vision coverage
Retirement plan
Paid time off
Wellness programs

Job summary

CVS Health is seeking a Staff Application Security Engineer - Blue Team to design, implement, and enforce security controls across cloud and on-prem environments. You will lead vulnerability management, threat modeling, and security automation while guiding secure development across teams.

The ideal candidate has 7+ years in security engineering, extensive experience with AWS/Azure/GCP, Docker and Kubernetes, and a track record of mentoring engineers in secure coding practices.

Qualifications

  • 7+ years of experience in security engineering, application security, cloud security, or defensive security operations.
  • 3+ years of experience securing modern cloud platforms including AWS, Azure, and GCP.
  • 3+ years of experience with Docker, Kubernetes, Infrastructure-as-Code, and Security-as-Code methodologies.
  • 3+ years of experience in one or more programming or scripting languages such as Python, Java, C#, JavaScript, Shell, or PowerShell.
  • 3+ years of experience in networking, identity management, authentication, authorization, and threat mitigation techniques.

Responsibilities

  • Design, implement, and maintain defensive security controls across applications, cloud platforms, data systems, and network environments.
  • Develop and enforce enterprise-wide application and data security standards, policies, and best practices.
  • Embed security controls into SDLC processes, CI/CD pipelines, and deployment automation frameworks.
  • Lead security architecture reviews and ensure alignment with organizational security objectives.
  • Establish security governance frameworks that improve confidentiality, integrity, availability, and resiliency.
  • Partner with Engineering, Infrastructure, Architecture, and Business teams to embed secure-by-design practices.
  • Serve as a trusted advisor and technical leader for Application Security, Cloud Security, and Secure Development practices.
  • Influence technical decision-making and security strategy across multiple teams and business units.
  • Drive organization-wide security awareness and operational readiness initiatives.
  • Monitor, detect, investigate, and respond to security events, vulnerabilities, threats, and incidents.
  • Lead vulnerability assessments, remediation planning, risk prioritization, and validation efforts across application and data platforms.
  • Design, evaluate, and optimize defensive controls across cloud-native, hybrid, and on-premises environments.
  • Conduct security assessments, threat modeling exercises, and architecture reviews to identify and mitigate risks.
  • Implement advanced security solutions across multi-cloud, colocation, and enterprise environments.
  • Participate in a rotational on-call schedule, including off-hours, nights, weekends, and holidays, supporting a 24x7 operational environment.
  • Lead security incident response activities including investigation, containment, eradication, recovery, and post-incident reviews.
  • Develop, maintain, and continuously improve incident response, detection, escalation, and recovery playbooks.
  • Drive operational improvements that strengthen incident readiness and cyber resilience.
  • Mentor and coach engineers on secure coding practices, security engineering principles, and defensive operations.
  • Provide guidance to development and operational teams on security best practices and emerging threats.
  • Support training initiatives that improve security maturity across the organization.
  • Foster a culture of shared responsibility for security and operational excellence.
  • Research emerging threats, vulnerabilities, attack techniques, and security technologies.
  • Evaluate and recommend new security tools, platforms, and defensive capabilities.
  • Automate security operations using code and Security-as-Code principles to improve efficiency and scalability.
  • Improve threat detection, monitoring, alerting, and response capabilities through innovation and continuous improvement.
  • Contribute to long-term security strategy, architecture roadmaps, and technology planning initiatives.
  • Define and drive enterprise security objectives and key performance indicators.
  • Partner with leadership to prioritize security investments and risk reduction activities.
  • Develop standards and practices that improve cyber resilience, redundancy, business continuity, and recovery capabilities.

Skills

Defensive security
Security leadership
Cloud security
Application security
Threat modeling
Security automation

Education

Bachelor's degree

Tools

Docker
Kubernetes
Infrastructure-as-Code
Security-as-Code

Job description

CVS Health is seeking a Staff Application Security Engineer - Blue Team to design, implement, and enforce security controls across cloud and on-prem environments. You will lead vulnerability management, threat modeling, and security automation while guiding secure development across teams.

The ideal candidate has 7+ years in security engineering, extensive experience with AWS/Azure/GCP, Docker and Kubernetes, and a track record of mentoring engineers in secure coding practices.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer - Blue Team
Senior Application Security Engineer - Blue Team

9025 CVS Shared Services Resources LLC • California (MO)

Hybrid
USD 130,000 - 261,000
Comprehensive benefits
Performance bonus
Staff AppSec Engineer: Secure, Scalable Cloud + Equity
Staff AppSec Engineer: Secure, Scalable Cloud + Equity

Koitecc Solutions • Sacramento (CA), Northern (KY)

Hybrid
USD 130,000 - 261,000
Senior Application Security Engineer - Threat Research
Senior Application Security Engineer - Threat Research

Partners in Digital Health • Indianapolis (IN)

Hybrid
USD 144,000 - 288,000
Lead Application Security Threat Research Engineer
Lead Application Security Threat Research Engineer

Partners in Digital Health • Lansing (MI)

On-site
USD 144,000 - 288,000
Comprehensive benefits package
Bonus program and equity awards
Senior Application Security Engineer: Threat Research Lead
Senior Application Security Engineer: Threat Research Lead

Partners in Digital Health • Augusta (ME)

Hybrid
USD 144,000 - 288,000
Senior Application Security Engineer: Threat Research
Senior Application Security Engineer: Threat Research

Sacbar • Sacramento (CA), Northern (KY)

Hybrid
USD 144,000 - 288,000
Comprehensive benefits package
Bonus/ incentive program
Equity award program
+1
Senior Application Security Engineer - Threat Research
Senior Application Security Engineer - Threat Research

Koitecc Solutions • Jackson (MS)

On-site
USD 144,000 - 288,000
Medical, dental, vision coverage
Retirement savings options
Paid time off
+1
Senior App Security & Threat Research Engineer
Senior App Security & Threat Research Engineer

Partners in Digital Health • Jackson (MS)

On-site
USD 144,000 - 288,000
Medical, dental, vision coverage
Paid time off
Retirement savings options
+1
Lead Application Security Engineer - Threat Research
Lead Application Security Engineer - Threat Research

Koitecc Solutions • Columbus (OH)

On-site
USD 144,000 - 288,000
Comprehensive benefits
Bonus eligible
Equity program
Senior Threat Research & Application Security Engineer
Senior Threat Research & Application Security Engineer

ISHE • Boise (ID), Northern (KY)

Hybrid
USD 144,000 - 288,000