Skip to content
← Back to job listings

Staff DevSecOps Engineer (Health 100)

9025 CVS Shared Services Resources LLC · Work At Home-Massachusetts, Austria

CybersecurityImported listingfull-timeabout 13 hours ago

About The Role

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.

Staff Engineer, DevSecOps Security Engineering

Health 100 Focus | Security Implementation, Migration and Automation Leadership

Role Overview

The Staff Engineer, DevSecOps Security Engineering, isresponsible for leadingtechnicalimplementation, migration, automation, mobile application security and standardizationacross the Health 100 portfolio. This roletranslates applicationsecuritystrategy into scalable engineering solutions that strengthen release readiness, improvevulnerability remediation,expand security and mobile testing coverage, and enable secure-by-default deliveryacross engineering teams.

Who You Are

  • -
  • A seniortechnical employeewith deepexpertise inapplication security, DevSecOps, automation and secure deliverypractices.
  • -
  • Experiencedtranslatingsecuritystrategy into implementations that development teams can adopt consistently.
  • -
  • Strong inautomation, tooling integrationandprocess improvementthat reduce manualeffortand improveengineering outcomes.
  • -
  • Comfortable using metrics to communicate technical risk, delivery progress and measurable outcomes.
  • -
  • Able to balance hands-on engineering depth with cross-functional influence acrossapplication,platform,cloudand security teams.

Role Responsibilities

  1. Health 100 Security Enablement
  • -
  • Support application onboarding andsecurityenablementforHealth 100 initiatives.
  • -
  • Help development teams meet security requirements throughstandardtooling, pipelineintegration and repeatable implementation patterns.
  • -
  • Translate release-readiness expectations into repeatable technical patterns and evidence.
  • -
  • Ensuremobile applicationsare included in Health 100 security enablementthrough mobile application security testing,secureconfigurationvalidationandclear remediation guidance.
  1. Security Implementation & Major Initiatives
  • -
  • LeadDevSecOpsimplementationinitiatives aligned to security goals and engineering priorities.
  • -
  • Own technicalplanning, architecture, delivery,issueresolutionand implementation outcomes.
  • -
  • Coordinate across application,platformand security teams to remove blockers and sustain adoption.
  1. Pipeline Enforcement & Automation
  • -
  • Design, implementandimproveCI/CD security controls,pipeline enforcement and automated scanning workflows.
  • -
  • Partner with developmentandplatform teams to embed security controlswithoutcreating unnecessary delivery friction.
  • -
  • Build self-service security solutions and reusable automation that reduce manual intervention and improve engineering efficiency.
  • -
  • Automatesecret-detectionand CI/CD security workflows, including Gitleaks or comparable capabilities.
  1. Security Tool Migration & Standardization
  • -
  • Lead security-tool migrations, including transitions such as Checkmarx to Snyk, from design through stable productionoperation.
  • -
  • Produce and validate initial post-migration scan results to demonstrate successful implementation and integration.
  • -
  • Standardize tooling configurations across development teams to improve consistency, ease ofuseand policy alignment.
  • -
  • Partner with platform teams to reduce legacy pipeline risk, fragmentedconfigurationsand duplicated manual processes.
  1. Vulnerability Reduction & SLA Compliance
  • -
  • Drive remediation of critical and high-risk vulnerabilities across Health 100 applications with clear technical ownership and follow-through.
  • -
  • Monitor remediation against established SLAs andidentifyaging,recurrenceand systemic issues.
  • -
  • Lead technical prioritization of high-impact open-source and software supply chain exposures affecting multiple applications.
  • -
  • Provide remediation guidance and scalable fixes that teams can adopt consistently.
  1. Supply Chain, Cloud & Container Security
  • -
  • Improve open-source visibility through SBOM coverage and related software supply chain practices.
  • -
  • Drive secure-by-default dependency usage and remediation of high-risk third-party components.
  • -
  • Engineer controls for public cloud, container, Kubernetes, Security-as-Codeand Infrastructure-as-Code environments.
  • -
  • Applynetwork-securityandcloud-architectureexpertiseto design practical, resilient solutions.
  • -
  • Applymobile securityexpertise to assessiOS and Android applicationrisk, validatemobile security testing results and guideremediationof mobile-specific findings.
  1. Metrics, Reporting & Continuous Improvement
  • -
  • Trackand reportscan coverage, mobile testing coverage, vulnerability aging, SLA adherence, remediation effectiveness, automation adoption,tool coverage andpipeline compliance.
  • -
  • Use metrics toidentifycontrol gaps, adoptionbarriersand opportunities for continuous improvement.
  • -
  • Provide concise, executive-ready updates on implementation progress, deliveryriskand measurable security outcomes.
  1. Technical Leadership & Knowledge Enablement
  • -
  • Serve as a senior technical authority for DevSecOps implementation,migrationand automation decisions.
  • -
  • Mentorengineers,establishreusable engineering patterns and strengthen technical consistency across teams.
  • -
  • Create clear implementation guidance and education that foster developer self-service and security awareness.
  • -
  • Build resilient ownership and support models that reduce single points of failure.

Success Measures

  • -
  • Migration delivery:Tooling and process migrationsaredeliveredwith validated results and minimal operational disruption.
  • -
  • Automation enablement:Secret detection and CI/CD security workflows are automated, reducing manual effort and improving consistency.
  • -
  • Standardization:Security tooling and pipeline configurations are standardized across participating development teams.
  • -
  • Risk reduction:Critical and high-risk vulnerabilities are reduced, with remediation performance measured against established SLAs.
  • -
  • Coverage and adoption:Scan coverage, mobileapplication security testingcoverage, tool adoption, pipeline compliance and self-service usageshow measurable improvement.
  • -
  • Release readiness:Health 100 applications have consistent, enforceable security controls and clear evidence supporting launch decisions.

Qualifications

Basic Qualifications

  • -
  • 7+ years of experience in DevSecOps, application security engineering, platform security or software engineering.
  • -
  • Experienceintegrating SAST, SCA, secrets detection, container scanning, IaC scanning or comparablesecurity controlsinto CI/CD pipelines.
  • -
  • ​Experience leading security implementations or tool migrations in large or complex engineering environments.​
  • -
  • Proficiencyin public cloud platforms such as AWS,Azureor GCP, plus cloud and network security concepts.
  • -
  • Experience with Docker, Kubernetes, Security-as-Codeand Infrastructure-as-Code.
  • -
  • Hands-onscripting orprogrammingexperience inlanguages such as Python, Java, JavaScript, Go, Shell or PowerShell.
  • -
  • Experience with application vulnerability management, open-sourceriskand software supply chain security.
  • -
  • Experience with mobile application security testing, mobile threat modeling, or remediation of iOS and Android application security findings.
  • -
  • Demonstrated ability to use metrics to drive adoption,remediationand measurable technical outcomes.

Preferred Qualifications

  • -
  • Experience supporting portfolio-based initiatives or prioritized application sets such as Health 100.
  • -
  • Hands-on experience withapplicationsecuritytoolssuch as Snyk, Checkmarx, Gitleaks, SBOM tooling or comparableplatforms.
  • -
  • Hands-on experience with mobile application security platforms such as Data Theorem, MobSF, or comparable mobiletestingtools.
  • -
  • Expertisearchitecting public cloud security solutions and scalable engineering processes.
  • -
  • Strong understanding of networking and Software-Defined Networking principles.
  • -
  • Experience with security solutions for data warehouses orbig-dataplatforms, including Snowflake.
  • -
  • Familiarity with regulated environments and frameworks such as HIPAA, HITRUST, PCI, NIST,GDPRor CCPA.
  • -
  • Experience communicating technical security outcomes and risk posture to senior leadership.

Education

  • -
  • Bachelor's degree in Computer Science, Software Development, Software Engineering or a related field, or equivalent practical experience.

Why Join Us

  • -
  • Lead high-impact security engineering work for a priority application portfolio.
  • -
  • Shape scalable DevSecOps patterns thatimprove bothrisk reduction and developer efficiency.
  • -
  • Work acrossapplication,platform,cloudand security teams to deliver measurable enterprise outcomes.
  • -
  • Contribute to a collaborative environment that values innovation, technicalleadershipand professional growth.

Pay Range

The typical pay range for this role is

$130,295.00 - $260,590.00

This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company’s equity award program.

Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.

Great benefits for great people

We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.

This full‑time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well‑being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.

Additional details about available benefits are provided during the application process and on Benefits Moments.

We anticipate the application window for this opening will close on: 10/30/2026

Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.

This is an external listing. JobSpring does not represent or verify the employer. Report this listing