The AVP Security Risk Management is responsible for reducing enterprise cybersecurity and technology risk by identifying, measuring, prioritizing, and driving treatment of material cyber and technology risks across enterprise technology environments, business processes, third-party relationships, supply chain dependencies, and merger, acquisition, and divestiture activity. This leader defines the cyber and technology risk strategy, governance, assessment methods, control validation, and operating routines used to evaluate control effectiveness, threat exposure, technology, data, identity, resilience, third-party, and regulatory risk across internal and external stakeholders. Reporting to the Deputy CISO, this collaborative leader partners with senior security, privacy, risk, legal, technology, procurement, corporate development, integration, and business leaders. The AVP converts internal and external cybersecurity and technology risk intelligence—including enterprise control gaps, technology control deficiencies, emerging threats, third-party exposure, supply chain dependencies, and M&A risk—into measurable risk decisions, remediation priorities, control requirements, and executive reporting that help protect CVS Health’s members, colleagues, protected health information, confidential data, critical systems, operations, and brand.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Executive