EngineerJobs.io
← Back to all jobs

Job Description

CVS Health is hiring a Staff Application Security Engineer – Threat Research to help secure healthcare technology through the combined lens of application security engineering, threat research, and secure development practices. This onsite role in New York, NY brings a focus on partnering with engineering teams to reduce risk, strengthen defenses, and build security into the delivery lifecycle across cloud and enterprise environments.

What you’ll do

  • Implement and support application security standards, policies, and best practices.
  • Collaborate with engineering teams to embed security into design, development, testing, and deployment workflows.
  • Promote secure coding practices and support teams with remediation of security findings.
  • Drive security automation initiatives to improve efficiency and scalability.
  • Research emerging threats, vulnerabilities, attack techniques, and security trends.
  • Conduct application security assessments, threat modeling, and vulnerability analysis.
  • Evaluate risks and deliver actionable recommendations to engineering teams.
  • Use threat intelligence to improve application security controls and detection capabilities.
  • Design, configure, and support security technologies across cloud and enterprise environments.
  • Help implement and manage security controls that protect applications, APIs, and data.
  • Support vulnerability management and remediation programs.
  • Contribute to scalable and resilient security architecture.
  • Participate in design reviews to ensure security requirements are considered early.
  • Communicate technical security findings to both technical and non-technical audiences.
  • Support security investigations and incident response activities as needed.
  • Support operational security functions across cloud and enterprise environments.
  • Assist in identifying root causes and implementing longer-term remediation strategies.
  • Serve as a technical mentor for engineers and application security practitioners.
  • Share knowledge through training sessions, presentations, and documentation.
  • Contribute to building a culture of security awareness and continuous learning.
  • Evaluate emerging security tools and technologies, including security research and proof-of-concept efforts.
  • Recommend process improvements to strengthen the effectiveness of application security programs.

Minimum qualifications

  • 7+ years of experience in application security, information security, software engineering, or related roles.
  • 5+ years of experience with one or more programming or scripting languages including Java, Python, JavaScript, C#, C/C++, PowerShell, or Shell scripting.
  • 3+ years of experience securing public cloud environments such as AWS, Azure, or Google Cloud Platform.
  • 3+ years of experience with container technologies including Docker and Kubernetes.
  • 3+ years of experience with Infrastructure as Code or Security as Code practices.
  • 3+ years of experience performing application security assessments, vulnerability analysis, and threat modeling.

Technologies you may work with

  • Java, Python, JavaScript, C#, C/C++, PowerShell, Shell scripting
  • AWS, Azure, Google Cloud Platform
  • Docker, Kubernetes
  • Infrastructure as Code, Security as Code
  • Web Application Firewalls, API security solutions
  • DevSecOps platforms, CI/CD pipelines
  • HIPAA, HITRUST, PCI DSS, NIST, CSA
  • Snowflake, plus data protection controls

Compensation and benefits

The typical pay range for this role is USD 106,605 - 284,280 per year. This range represents the base hourly rate or base annual full-time salary for positions in the job grade where this role falls. The position is eligible for a CVS Health bonus, commission, or short-term incentive program in addition to base pay, and includes an award target in the company’s equity award program.

  • Medical, dental, and vision coverage
  • Paid time off
  • Retirement savings options
  • Wellness programs
  • Other resources (based on eligibility)

Other information

  • Location: New York, NY (onsite)
  • Application window anticipated to close on 08/24/2026
  • Qualified applicants with arrest or conviction records will be considered in accordance with federal, state, and local laws.

The Health100 platform integrates participating health plan, PBM, pharmacy (retail and specialty), provider, digital health point solution provider, and employer, and addresses top health care challenges for the consumer.

Similar Jobs