Senior Manager Application Security Engineering

CVS HealthNew York, NY
$142,140 - $284,280Remote

About The Position

CVS Health is seeking a Senior Manager, Application Security Engineering to lead the strategy, execution, and continuous improvement of application security capabilities across enterprise platforms, digital products, and cloud-native environments. The Senior Manager, Application Security Engineering will be responsible for advancing secure software development practices, driving security-by-design principles, and ensuring security controls are embedded throughout the software development lifecycle. As a key security leader, the Senior Manager, Application Security Engineering will partner closely with Engineering, Product, Architecture, Infrastructure, Risk, Compliance, and Cyber Defense teams to strengthen the organization's security posture while enabling innovation and accelerating delivery. This role will oversee application security programs, vulnerability management, DevSecOps enablement, software supply chain security, and security governance initiatives supporting CVS Health's most critical business priorities. The Senior Manager, Application Security Engineering will lead a team of security engineers responsible for securing modern cloud-native applications, APIs, containers, and enterprise platforms. This leader will establish security standards, drive automation, implement scalable security controls, and partner with development teams to identify and reduce risk across the application portfolio. The ideal Senior Manager, Application Security Engineering combines deep technical expertise in application security with proven leadership experience, strong business acumen, and a passion for enabling secure, resilient, and high-performing technology solutions at enterprise scale. This is a U.S.-based remote position. Candidates must reside within the United States.

Requirements

  • 7+ years of experience designing, implementing, and supporting enterprise security capabilities across application security, mobile application security, cloud security, vulnerability management, DevSecOps, or security engineering environments.
  • 5+ years securing cloud platforms such as AWS, Azure, and/or GCP, including network security, Infrastructure-as-Code, Security-as-Code, containers, Kubernetes, Android and iOS application security, and modern application architectures.
  • 3+ years leading enterprise security initiatives from strategy through implementation, including application security testing, mobile application security testing, MAST, vulnerability management, data protection, regulatory compliance, and secure software delivery.
  • 3+ years in mobile application security scanning, including tools such as Data Theorem or similar solutions, with the ability to assess, prioritize, and drive remediation of findings across Android and iOS environments.
  • 3+ years developing and delivering security reporting and dashboards using Power BI, Grafana, or similar platforms to communicate risk, vulnerabilities, KPIs, and remediation progress to technical and leadership stakeholders.
  • 3+ years integrating security into the SDLC and CI/CD pipelines using languages such as Python, Java, JavaScript, Go, PowerShell, or similar, with a focus on automation and scalable security controls.
  • 2+ years of people leadership managing, mentoring, and developing high-performing engineering teams while driving measurable security outcomes across large-scale application portfolios, mobile and digital products, or enterprise transformation programs.

Nice To Haves

  • Strong technical expertise in designing and securing public cloud environments (AWS, Azure, and/or GCP), including distributed, resilient, and cloud-native architectures.
  • Experience with network security, software-defined networking (SDN), threat modeling, and development of architectural artifacts such as network, sequence, and data flow diagrams.
  • Understanding healthcare and industry compliance frameworks, including HIPAA, HITRUST, PCI-DSS, NIST, and CSA, as well as data platform security solutions such as Snowflake.
  • Experience implementing or managing application security platforms (e.g., Snyk, Veracode, Checkmarx, or similar), software supply chain security controls, SBOM programs, dependency risk management, and cyber resilience initiatives.
  • Proven ability to influence cross-functional stakeholders, collaborate effectively within distributed organizations, support enterprise transformation programs and strategic portfolios, and contribute to the advancement of security engineering practices and standards.

Responsibilities

  • Lead the development, implementation, enforcement, and continuous improvement of application, engineering, and data security policies, standards, governance controls, and secure software development practices; define and maintain Health 100 security baselines, launch readiness requirements, and audit/compliance expectations while adapting controls to evolving threats and business priorities.
  • Partner closely with Product, Engineering, Architecture, DevSecOps, Threat Modeling, GRC, and business stakeholders to embed secure engineering practices across the organization, drive onboarding to security tooling and pipelines, establish clear risk acceptance and escalation processes, and ensure alignment on security priorities, launch readiness, and governance requirements.
  • Oversee application security engineering and testing programs across cloud, on-premises, and hybrid environments, including security architecture, SAST, SCA, secrets detection, container scanning, vulnerability analysis, pipeline integrations, scanning and gating controls, security tooling strategy, and vulnerability data quality, ownership, tagging, and reporting governance.
  • Own end-to-end vulnerability management and operational security processes, including triage, prioritization, remediation, validation, reporting, SLA management, KPI/KRI tracking, incident response, zero-day vulnerability coordination, risk exceptions, ServiceNow workflows, ticket governance, operational excellence, and Health 100 vulnerability posture management.
  • Build, mentor, and develop a high-performing security engineering team by establishing leadership development programs, cross-training models, operational documentation, knowledge-sharing practices, and targeted security enablement programs that strengthen secure development, remediation effectiveness, and software supply chain risk management.
  • Drive innovation, automation, and continuous improvement through security research, evaluation of emerging technologies, workflow automation, tooling optimization, software supply chain security enhancements, SBOM governance, dependency risk reduction, and scalable security operations.
  • Own the application security strategy and roadmap, including budgeting, workforce planning, capacity management, risk management, executive reporting, KPIs/KRIs, security investments, tooling prioritization, and Health 100 security initiatives, ensuring alignment with business objectives, accelerated delivery timelines, and enterprise risk tolerance.

Benefits

  • medical
  • dental
  • vision coverage
  • paid time off
  • retirement savings options
  • wellness programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service