We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time. Job Summary Serves as the senior technical leader and strategist for Exposure Management, setting the architectural direction for how the enterprise scopes, discovers, prioritizes, validates, and mobilizes remediation of vulnerabilities, misconfigurations, and other exploitable weaknesses across IT, cloud, SaaS, identity, and OT/medical-device estates. Leads the transformation of exposure management from batch-oriented, ticket-driven, human-mediated workflows with multi-week SLAs to a continuous, near real-time, threat-informed Continuous Threat Exposure Management (CTEM) capability. Owns the end-to-end data architecture that the program depends on — the canonical data model, asset and identity graph, ingestion and normalization patterns, data contracts, lineage, and quality/SLA controls that unify a complex set of telemetry and business-context sources. Designs and delivers automation, machine learning, and GenAI capabilities that accelerate exposure discovery, prioritization, validation, remediation, and incident response while materially reducing manual work and operating cost. Brings the attacker's perspective into prioritization and validation — integrating threat intelligence, attack surface management, and adversarial exposure validation — so the program acts on real, exploitable attack paths to critical business assets and PHI rather than solely on CVE lists. Collaborates with Cyber-defense and Vulnerability Management team members to develop strategic responses to emerging threat and vulnerability events (novel exploits, zero-days, supply-chain and third-party incidents), driving rapid, automated impact assessment and mobilization in hours rather than days or weeks. Contributes to design of outcome-based exposure metrics and reporting frameworks that translate technical exposure data into business-aligned risk outcomes for executive audiences and that meet evolving regulatory and disclosure expectations. Accountable for ensuring that metrics can be accurately computed and delivered within SLA. Operates as a trusted bridge between deeply technical security teams and business stakeholders, influencing strategy, investment, and execution across organizational boundaries without relying on direct authority.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior