EngineerJobs.io
← Back to all jobs

Job Description

Defend cloud and application environments at scale with CVS Health. In this onsite role in Sacramento, you will design and run defensive application and cloud security controls, strengthen security governance, and improve incident readiness through automation, playbooks, and continuous operational improvements.

What you’ll do

  • Design, implement, and maintain defensive security controls across applications, cloud platforms, data systems, and network environments.
  • Develop and enforce enterprise-wide application and data security standards, policies, and best practices.
  • Embed security controls into SDLC processes, CI/CD pipelines, and deployment automation frameworks.
  • Lead security architecture reviews and help ensure alignment with organizational security objectives.
  • Establish security governance frameworks that improve confidentiality, integrity, availability, and resiliency.
  • Partner with Engineering, Infrastructure, Architecture, and Business teams to support secure-by-design practices.
  • Monitor, detect, investigate, and respond to security events, vulnerabilities, threats, and incidents.
  • Lead vulnerability assessments, remediation planning, risk prioritization, and validation across application and data platforms.
  • Design, evaluate, and optimize defensive controls across cloud-native, hybrid, and on-premises environments.
  • Conduct security assessments, perform threat modeling, and run architecture reviews to identify and mitigate risks.
  • Implement advanced security solutions across multi-cloud, colocation, and enterprise environments.
  • Support a rotational on-call schedule, including off-hours, nights, weekends, and holidays for a 24x7 operational environment.
  • Lead security incident response activities including investigation, containment, eradication, recovery, and post-incident reviews.
  • Develop and continuously improve incident response, detection, escalation, and recovery playbooks to strengthen readiness and cyber resilience.
  • Mentor and coach engineers on secure coding practices, security engineering principles, and defensive operations.
  • Research emerging threats, vulnerabilities, and security technologies; evaluate and recommend new defensive tools and platforms.
  • Automate security operations using code and Security-as-Code principles to improve efficiency and scalability.
  • Contribute to long-term security strategy, architecture roadmaps, and technology planning; define security objectives and KPIs.
  • Partner with leadership to prioritize security investments and risk reduction activities, including cyber resilience, redundancy, business continuity, and recovery capabilities.

Required qualifications

  • 7+ years of experience in security engineering, application security, cloud security, or defensive security operations.
  • 3+ years securing modern cloud platforms including AWS, Azure, and GCP.
  • 3+ years with Docker, Kubernetes, Infrastructure-as-Code, and Security-as-Code methodologies.
  • 3+ years experience with one or more programming or scripting languages: Python, Java, C#, JavaScript, Shell, or PowerShell.
  • 3+ years experience in networking, identity management, authentication, authorization, and threat mitigation techniques.

Technologies you’ll work with

  • AWS, Azure, GCP
  • Docker, Kubernetes
  • Infrastructure-as-Code, Security-as-Code
  • Python, Java, C#, JavaScript, Shell, PowerShell

Benefits

  • Medical, dental, and vision coverage
  • Paid time off
  • Retirement savings options
  • Wellness programs
  • Comprehensive benefits package designed to support the physical, emotional, and financial well-being of colleagues and their families

Pay range and incentives

USD 130,295 - 260,590 per year. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to base pay, and includes an award target in the company’s equity award program.

Education

Bachelor’s degree from an accredited college or university, or equivalent combination of education and relevant work experience (High School Diploma/GED plus 4 years of related experience).

Other details

  • Application window closes on: 09/22/2026
  • Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.

Similar Jobs