AVP, Platform Security
9025 CVS Shared Services Resources LLC · AZ - Scottsdale, United States
About The Role
We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.
Position Summary
CVS Health is seeking a polished and experienced security leader to serve as Associate Vice President of Platform Security, responsible for defining and executing the enterprise strategy for securing cloud, container, and AI platforms across CVS Health's technology estate. This role owns the technical security standards, architecture, controls, and operating model that enable secure, scalable adoption of cloud-native infrastructure, containerized workloads, and enterprise AI and GenAI capabilities. The AVP will lead a high-performing team of platform security engineers, architects, and domain leaders across Cloud Security, Container Security, and AI Security, while partnering deeply with technology, infrastructure, application, IAM, Cyber Defense, Data Protection, Legal, Compliance, and business leadership. This leader will balance risk reduction, engineering velocity, and enterprise adoption, ensuring security is embedded into platform design, deployment, runtime governance, and ongoing operations.
Key Responsibilities
Strategic Leadership
- Define and own the enterprise platform security strategy, roadmap, and policy framework for cloud, container, and AI security, aligned with CVS Health's business objectives, technology strategy, and regulatory obligations.
- Establish a unified technical standards and architecture approach across cloud, container, and AI platforms, ensuring security controls are built into platform design and operational execution.
- Stand up and mature the AI Security operating model as a first-class enterprise capability supporting safe AI and GenAI adoption across the enterprise.
- Serve as a subject matter expert and trusted advisor to senior technology, security, and business executives on emerging platform security risks, cloud-native attack trends, AI threats, and industry best practices.
- Drive continuous improvement across the platform security program through risk-based prioritization, measurable KPIs, executive reporting, benchmarking, and innovation.
Cloud, Container & Platform Security Engineering
- Cloud Security Services: Own the strategy, architecture, and operational standards for securing enterprise cloud environments, including cloud posture management, policy-as-code, identity and access guardrails, vulnerability exposure reduction, and automated remediation workflows.
- Container Security: Define and govern container and Kubernetes security across cloud and on-premises container platforms, including image scanning, workload protection, runtime controls, configuration standards, vulnerability management, and platform coverage objectives.
- Automation & Enforcement: Promote preventive guardrails, policy enforcement, infrastructure-as-code controls, and self-service remediation patterns that reduce risk while preserving engineering velocity.
- Technology Stack Ownership: Influence the platform security tooling portfolio, including CSPM, CNAPP, container security, posture management, AI security, and related integrations. Manage vendor strategy, platform health, roadmap alignment, and capability adoption in partnership with procurement and peer technology leaders.
AI Security Strategy, Architecture & Controls
- AI Security Operating Model: Establish and scale a dedicated AI Security function with clear accountability, sustained governance, and defined responsibilities across AI governance, platform security, model security, agentic security, incident readiness, and risk reporting.
- AI Security Standards: Define and maintain enterprise AI security standards, including requirements for AI gateways, model gateways, prompt and response guardrails, model review, model inventory, AI use case risk classification, and controls for high-risk AI use cases.
- AI Gateway & Guardrails: Own security requirements for AI/Agent Gateway capabilities, including identity propagation, tool and service brokering, prompt-injection defenses, default-deny mediation, data protection, auditability, traffic and cost controls, runtime governance, and agentic runtime protections.
- Agentic Security: Drive controls for agent identity, authentication, authorization, registry, tool governance, long-running agent activity, non-human identity exposure, session revocation, kill switches, human-in-the-loop gates, and runtime behavioral monitoring.
- Model & Platform Protection: Lead security architecture for AI models and AI platforms, including model scanning, model provenance, unauthorized model detection, AI visibility, adversarial testing, red teaming, and alignment to relevant AI management and threat frameworks.
- AI Detection & Response: Partner with Cyber Defense to develop AI-specific monitoring, detection use cases, incident response playbooks, audit logging, and operational telemetry needed to respond to model abuse, data leakage, tool misuse, and adversarial behavior.
Governance & Compliance
- Define and maintain platform security policies, standards, reference architectures, and operational procedures for cloud, container, infrastructure, and AI security domains.
- Ensure security controls align with applicable regulatory frameworks and industry standards, including HIPAA, PCI-DSS, ISO/IEC 42001, NIST AI RMF, NIST CSF, MITRE ATLAS, OWASP LLM/Agentic guidance, and cloud security best practices.
- Provide executive-level reporting and governance dashboards that communicate program health, control coverage, security posture, remediation progress, residual risk, and decisions requiring leadership sponsorship.
- Establish a risk-based vulnerability and misconfiguration management process for cloud, container, and AI platforms, including defined ownership, remediation SLAs, escalation paths, and executive transparency.
- Partner with Legal, Compliance, Privacy, TPRM, Data Protection, and AI Governance teams to ensure AI tools, connectors, model platforms, SaaS AI services, and third-party capabilities meet enterprise control and contractual requirements before production use.
Leadership & Collaboration
- Build, lead, and develop a high-performing organization of cloud security, container security, infrastructure security, AI security, and distinguished engineering leaders.
- Lead through direct and matrixed influence across Cloud Security Services, Infrastructure Security, AI Security, Application Security, IAM, Cyber Delivery, Cyber Defense, Data Protection, Developer Experience, Enterprise Architecture, and business technology teams.
- Partner with the Vice President of Security Engineering and Platforms, peer AVPs, Executive Directors, and enterprise technology leaders to align platform security priorities with broader SecEng strategy, OKRs, investment decisions, and enterprise delivery commitments.
- Engage regularly with cloud providers, security tooling vendors, AI platform providers, and industry standards groups to inform architecture decisions, capability roadmaps, and evolving technical standards.
- Foster a culture of secure-by-default platform engineering, risk-based decision-making, operational accountability, automation, and measured business enablement.
Key Performance Indicators (KPIs)
- Cloud Security Posture: Reduction in critical, high, and medium cloud risks; percentage of cloud environments covered by posture management and policy enforcement controls.
- Container Security Coverage: Percentage of cloud and on-premises container platforms covered by container security tooling, image scanning, runtime protection, and vulnerability remediation workflows.
- Remediation SLA Performance: Mean time to remediate critical and high platform security findings, including cloud misconfigurations, container vulnerabilities, exposed workloads, and AI platform risks.
- AI Security Operating Model Maturity: Progress against the AI Security operating model, dedicated staffing plan, governance cadence, standards publication, and sustained control ownership.
- AI Gateway & Guardrail Adoption: Coverage of enterprise AI and agentic traffic through approved AI gateways, model gateways, prompt/response guardrails, content filtering, logging, and runtime governance controls.
- AI Visibility & Inventory: Percentage of AI platforms, models, agents, endpoints, and SaaS AI usage visible through approved inventory, monitoring, and reporting capabilities.
- Unauthorized Model & Tool Use: Reduction in unauthorized AI models, unapproved connectors, unmanaged MCP/tool usage, and AI services operating outside approved governance and security controls.
- Compliance & Audit Readiness: Conformance to ISO/IEC 42001, NIST AI RMF, HIPAA, PCI-DSS, and internal security standards, targeting zero critical audit findings related to platform and AI security controls.
- Executive Risk Transparency: Timely delivery of executive reporting, decision requests, risk trends, and escalations for cloud, container, and AI security posture.
- Roadmap Delivery: On-time delivery of strategic platform security initiatives, including cloud and container posture improvements, AI Security capability buildout, AI gateway deployment, and risk-based automation milestones.
Reporting Structure
This role reports directly to the Vice President of Security Engineering and Platforms at CVS Health.
Required Qualifications
- 12+ years of progressive experience in information security, cybersecurity engineering, cloud security, infrastructure security, platform security, or related technology leadership roles.
- 5+ years of senior leadership experience building, leading, and scaling cross-functional security engineering teams in large, complex enterprise environments.
- Deep technical expertise in cloud security architecture and operations across major cloud platforms, including cloud posture management, identity and access controls, network segmentation, encryption, logging, vulnerability management, and policy enforcement.
- Strong understanding of container and Kubernetes security, including image scanning, workload protection, runtime controls, secrets management, cluster hardening, CI/CD integration, and vulnerability remediation.
- Demonstrated experience defining technical security standards, reference architectures, control frameworks, and engineering guardrails for enterprise-scale platforms.
- Experience with AI, GenAI, or emerging technology security programs, including AI governance, AI platform security, model risk, agentic systems, prompt/response guardrails, model scanning, AI threat modeling, or AI runtime monitoring.
- Strong knowledge of security posture management, vulnerability management, threat modeling, risk-based prioritization, and executive-level risk reporting.
- Proven ability to influence engineering culture, platform governance, security control adoption, and strategic investment decisions across multiple leadership levels.
- Experience operating in highly regulated environments and applying security requirements aligned to healthcare, privacy, financial, or critical infrastructure obligations.
- Excellent communication and presentation skills; ability to translate complex cloud, container, infrastructure, and AI security risks into clear decisions and executive narratives.
Preferred Qualifications
- Advanced degree in Computer Science, Information Security, Cybersecurity, Engineering, AI/ML, or a related field.
- Certifications such as CISSP, CISM, CCSP, AWS Security Specialty, Azure Security Engineer, Google Professional Cloud Security Engineer, Kubernetes Security Specialist, or equivalent.
- Experience establishing or scaling an AI Security function, AI governance control model, AI gateway strategy, model security program, agentic security capability, or AI red teaming function.
- Familiarity with ISO/IEC 42001, NIST AI RMF, MITRE ATLAS, OWASP Top 10 for LLM Applications, OWASP Agentic guidance, NIST CSF, and cloud security best-practice frameworks.
- Experience with CNAPP, CSPM, CWPP, container security, API gateway, model gateway, AI guardrail, SSPM/AISPM, and security data platform technologies.
- Experience in healthcare, pharmacy, insurance, financial services, or another highly regulated industry.
- Demonstrated success partnering with cloud providers, AI platform providers, enterprise architecture, procurement, third-party risk, privacy, legal, compliance, and business technology leaders.
Pay Range
The typical pay range for this role is
$185,400.00 - $375,950.00
This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company’s equity award program.
Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.
Great benefits for great people
We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.
This full‑time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well‑being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.
Additional details about available benefits are provided during the application process and on Benefits Moments .
We anticipate the application window for this opening will close on: 09/08/2026
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
