Senior Application Security Engineer: Threat Research

Sacbar

Sacramento, Northern (CA, KY)

Hybrid

USD 144,000 - 288,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Comprehensive benefits package
Bonus/ incentive program
Equity award program
Wellness programs

Job summary

CVS Health is seeking a Principal Application Security Engineer - Threat Research to lead security across healthcare applications, combining engineering depth with advanced threat research to protect data at scale.

You will embed security into development lifecycles, guide policy development, and mentor engineers while collaborating with multiple teams across cloud and on-prem environments to strengthen resilience and detection.

Qualifications

  • 10+ years of experience developing and deploying security technologies.
  • 7+ years of experience with one or more general-purpose programming languages including Java, C/C++, C#, Python, JavaScript, Shell Script, PowerShell.
  • 5+ years of experience with Public Cloud (AWS/Azure/GCP) & network security.
  • 5+ years of experience with Docker, Kubernetes, Security-as-Code, and Infrastructure-as-Code.
  • 5+ years of experience implementing and managing data protection measures and compliance with data protection regulations (e.g., GDPR, CCPA).
  • 5+ years of experience designing, implementing, and managing Web Application Firewall (WAF) and Layer 7 security solutions.
  • 3+ years of experience leading security initiatives from inception through to successful deployment.

Responsibilities

  • Develop and enforce engineering security policies and standards.
  • Develop and enforce data security policies and standards.
  • Drive security awareness across the organization.
  • Lead the development and enforcement of comprehensive security policies and standards, integrating advanced security practices throughout the software development lifecycle to mitigate risks and align with industry-leading security protocols.
  • Collaborate with Engineering and Business teams to develop secure engineering practices.
  • Act as a pivotal security leader, driving the integration of secure engineering practices across the organization while liaising with senior management to ensure a cohesive security strategy that aligns with business objectives.
  • Analyze, develop, and configure security solutions across multi-cloud, on-premises, and colocation environments, ensuring application security, integrity, confidentiality, and availability of data.
  • Lead security testing, vulnerability analysis, and documentation.
  • Spearhead the evaluation and strategic deployment of cutting-edge security solutions, emphasizing scalability, performance, and adaptability, to fortify the organization's defense against evolving threats.
  • Participate in operational on-call duties to support a 24/7 infrastructure across multiple regions and environments (cloud, on-premises, colocation).
  • Lead by example in incident response situations, orchestrating rapid and effective responses while leveraging these experiences to bolster future resilience and response strategies.
  • Demonstrated leadership skills with developing a comprehensive mentorship program for junior engineers, including organizing regular training sessions to elevate the team's technical and security skills.
  • Proven track record with participation in security research and the exploration of next-generation security tools and practices.
  • Play a key role in the strategic planning of the organization's security roadmap, including conducting thorough risk assessments, allocating budgets for security initiatives, and aligning long‑term security strategies with overarching business goals.

Skills

Java
C/C++
C#
Python
JavaScript
Shell Script
PowerShell
Security Architecture

Education

Bachelor's degree or equivalent experience

Tools

Docker
Kubernetes
Security-as-Code
Infrastructure-as-Code
Snowflake

Job description

CVS Health is seeking a Principal Application Security Engineer - Threat Research to lead security across healthcare applications, combining engineering depth with advanced threat research to protect data at scale.

You will embed security into development lifecycles, guide policy development, and mentor engineers while collaborating with multiple teams across cloud and on-prem environments to strengthen resilience and detection.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer: Threat Research Lead
Senior Application Security Engineer: Threat Research Lead

Partners in Digital Health • Augusta (ME)

Hybrid
USD 144,000 - 288,000
Senior Application Security Engineer - Threat Research
Senior Application Security Engineer - Threat Research

Koitecc Solutions • Jackson (MS)

On-site
USD 144,000 - 288,000
Medical, dental, vision coverage
Retirement savings options
Paid time off
+1
Senior Application Security Engineer - Threat Research
Senior Application Security Engineer - Threat Research

Partners in Digital Health • Indianapolis (IN)

Hybrid
USD 144,000 - 288,000
Senior Threat Research & Application Security Engineer
Senior Threat Research & Application Security Engineer

ISHE • Boise (ID), Northern (KY)

Hybrid
USD 144,000 - 288,000
Senior Threat Research & App Security Engineer
Senior Threat Research & App Security Engineer

Koitecc Solutions • Lincoln (NE)

On-site
USD 144,000 - 288,000
Senior Threat Research Engineer — Application Security Lead
Senior Threat Research Engineer — Application Security Lead

Idaho Society of Professional Engineers • Boise (ID), Northern (KY)

Hybrid
USD 144,000 - 288,000
Senior Threat Research Engineer - App Security
Senior Threat Research Engineer - App Security

Partners in Digital Health • Concord (NH)

On-site
USD 144,000 - 288,000
Medical, dental, vision coverage
Paid time off
Retirement savings options
+1
Senior Threat Research & Application Security Engineer
Senior Threat Research & Application Security Engineer

9025 CVS Shared Services Resources LLC • New York (NY)

Hybrid
USD 144,000 - 288,000
Medical, dental, and vision coverage
Paid time off
Retirement savings options
+2
Principal Threat Research Engineer, Application Security
Principal Threat Research Engineer, Application Security

Partners in Digital Health • Little Rock (AR)

On-site
USD 144,000 - 288,000
Medical, dental, and vision coverage
Paid time off
Retirement savings options
+1
Senior Threat Research & Application Security Engineer
Senior Threat Research & Application Security Engineer

Koitecc Solutions • Hartford (CT)

On-site
USD 144,000 - 288,000