Senior Application Security Engineer: Threat Research Lead

Partners in Digital Health

Augusta (ME)

Hybrid

USD 144,000 - 288,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

CVS Health is seeking a Principal Application Security Engineer - Threat Research to secure healthcare technology, embed security into development pipelines, and drive threat research across multi-cloud and on-prem environments.

You will mentor engineers, lead security testing, and influence security practices enterprise-wide, shaping how secure systems are built with a strong emphasis on governance and resilience.

Qualifications

  • 10+ years of experience developing and deploying security technologies.
  • 7+ years with one or more general-purpose programming/script languages including but not limited to: Java, C/C++, C#, Python, JavaScript, Shell Script, PowerShell.
  • 5+ years with Public Cloud (AWS/Azure/GCP) & Network Security.
  • 5+ years with Docker, Kubernetes, Security-as-Code, and Infrastructure-as-Code.
  • 5+ years with implementing and managing data protection measures and compliance with data protection regulations (e.g., GDPR, CCPA).
  • 5+ years with designing, implementing, and managing Web Application Firewall (WAF) and Layer 7 security solutions.
  • 5+ years of experience performing vulnerability analysis and risk prioritization using industry-standard tools, with the ability to provide clear, actionable remediation guidance to engineering and development teams.
  • 3+ years of experience leading security initiatives from inception through to successful deployment, demonstrating exceptional project management skills and the ability to navigate complex stakeholder landscapes.

Responsibilities

  • Develop and enforce engineering security policies and standards.
  • Develop and enforce data security policies and standards.
  • Drive security awareness across the organization.
  • Lead the development and enforcement of comprehensive security policies and standards, integrating advanced security practices throughout the software development lifecycle to mitigate risks and align with industry-leading security protocols.
  • Collaborate with Engineering and Business teams to develop secure engineering practices.
  • Act as a pivotal security leader, driving the integration of secure engineering practices across the organization while liaising with senior management to ensure a cohesive security strategy that aligns with business objectives.
  • Analyze, develop, and configure security solutions across multi-cloud, on-premises, and colocation environments, ensuring application security, integrity, confidentiality, and availability of data.
  • Lead security testing, vulnerability analysis, and documentation.
  • Spearhead the evaluation and strategic deployment of cutting-edge security solutions, emphasizing scalability, performance, and adaptability, to fortify the organization's defense against evolving threats.
  • Participate in operational on-call duties to support a 24/7 infrastructure across multiple regions and environments (cloud, on-premises, colocation).
  • Lead by example in incident response situations, orchestrating rapid and effective responses while leveraging these experiences to bolster future resilience and response strategies.
  • Demonstrated leadership skills with developing a comprehensive mentorship program for junior engineers, including organizing regular training sessions to elevate the team's technical and security skills.
  • Proven track record with participation in security research and the exploration of next-generation security tools and practices. This includes encouraging the team to engage with the wider security community, contributing to open‑source projects, and staying well-informed of emerging threats and innovative defense mechanisms.
  • Play a key role in the strategic planning of the organization's security roadmap, including conducting thorough risk assessments, allocating budgets for security initiatives, and aligning long‑term security strategies with overarching business goals. This responsibility includes advocating for security within the company and ensuring that security considerations are paramount in all technology decisions.

Skills

Java
C/C++
C#
Python
JavaScript
Shell Script
PowerShell
Docker
Kubernetes
Security-as-Code
Infrastructure-as-Code
Data protection
WAF & L7 security
Vulnerability analysis
Incident response
Leadership / Mentorship

Education

Bachelor's degree or equivalent experience

Tools

Snowflake
Terraform

Job description

CVS Health is seeking a Principal Application Security Engineer - Threat Research to secure healthcare technology, embed security into development pipelines, and drive threat research across multi-cloud and on-prem environments.

You will mentor engineers, lead security testing, and influence security practices enterprise-wide, shaping how secure systems are built with a strong emphasis on governance and resilience.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer: Threat Research
Senior Application Security Engineer: Threat Research

Sacbar • Sacramento (CA), Northern (KY)

Hybrid
USD 144,000 - 288,000
Comprehensive benefits package
Bonus/ incentive program
Equity award program
+1
Senior Application Security Engineer - Threat Research
Senior Application Security Engineer - Threat Research

Koitecc Solutions • Jackson (MS)

On-site
USD 144,000 - 288,000
Medical, dental, vision coverage
Retirement savings options
Paid time off
+1
Senior Application Security Engineer - Threat Research
Senior Application Security Engineer - Threat Research

Partners in Digital Health • Indianapolis (IN)

Hybrid
USD 144,000 - 288,000
Senior Threat Research Engineer — Application Security Lead
Senior Threat Research Engineer — Application Security Lead

Idaho Society of Professional Engineers • Boise (ID), Northern (KY)

Hybrid
USD 144,000 - 288,000
Senior Threat Research & Application Security Lead
Senior Threat Research & Application Security Lead

Partners in Digital Health • Tallahassee (FL)

On-site
USD 144,000 - 288,000
Senior Threat Research & Application Security Engineer
Senior Threat Research & Application Security Engineer

ISHE • Boise (ID), Northern (KY)

Hybrid
USD 144,000 - 288,000
Senior Threat Research Engineer - App Security
Senior Threat Research Engineer - App Security

Partners in Digital Health • Concord (NH)

On-site
USD 144,000 - 288,000
Medical, dental, vision coverage
Paid time off
Retirement savings options
+1
Lead Application Security Threat Research Engineer
Lead Application Security Threat Research Engineer

Partners in Digital Health • Lansing (MI)

On-site
USD 144,000 - 288,000
Comprehensive benefits package
Bonus program and equity awards
Senior Application Security Engineer - Threat Research Lead
Senior Application Security Engineer - Threat Research Lead

Koitecc Solutions • Harrisburg, Northern (KY)

Hybrid
USD 144,000 - 288,000
Bonus potential
Equity awards
Comprehensive benefits
Senior Threat Research Security Engineer – App Security
Senior Threat Research Security Engineer – App Security

Colorado Psychiatric • Denver (CO), Northern (KY)

Hybrid
USD 144,000 - 288,000
Comprehensive benefits
Performance bonus
Equity