About The Position

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time. Position Summary The Staff Engineer, Regulatory Technology Engineering is responsible for the development and delivery of technology solutions that support the strategic direction of technology compliance and audit management for CVS Health’s Digital, Data, Analytics & Technology (DDAT) Compliance organization. This role applies deep technical expertise to design, modernize, and operationalize technology solutions that support SOX, SOC 1, SOC 2, PCI, HITRUST, NIST 800‑53, NYDFS, and other cybersecurity and regulatory frameworks. The role partners closely with engineering teams, process and control owners, and security architects to develop robust, audit‑ready control environments and automate evidence collection for complex, modern technology stacks, including cloud‑native platforms, distributed systems, AI/ML solutions, and DevSecOps implementations. This role requires an engineering mindset and the ability to translate regulatory requirements into scalable technical controls, automated testing approaches, and measurable compliance indicators. You will contribute to the development and continuous improvement of compliance tooling, control processes, dashboards, and metrics. Additionally, you will collaborate with IT, business partners, Learning and Development, Internal Audit, Legal, and external assessors to ensure alignment, transparency, and consistent execution of the technology compliance program.

Requirements

  • 7+ years of software engineering or software development experience with modern architectures and engineering practices.
  • 7+ years of technical project leadership experience supporting engineering initiatives on cross-functional teams.
  • 5+ years of experience in internal audit, external assessments, risk management, regulatory compliance, or information security within a corporate environment.
  • 5+ years of experience with audit methodologies, internal control frameworks, risk assessments, and control testing techniques, applied to cloud and modern technology environments.
  • 3+ years of hands-on experience with cloud security engineering, architecture, and/or automation, including technical controls in cloud-native platforms (AWS, Azure, GCP).

Nice To Haves

  • Strong understanding of the software development lifecycle (SDLC) and secure development practices.
  • Experience with AI/ML platforms, tools, and related risk considerations.
  • Understanding of regulatory frameworks and security standards (NIST, ISO, HITRUST, HIPAA, PCI, SOC 1/SOC 2, SOX) and ability to translate requirements into technical solutions.
  • Experience with DevOps/DevSecOps, CI/CD pipelines, infrastructure-as-code, and modern cloud infrastructure and cybersecurity patterns.
  • Ability to document and translate complex technical requirements for development team consumption.
  • Strong attention to detail with exceptional analytical and problem-solving skills.
  • Demonstrated ability to influence across engineering, security, and business teams.
  • Excellent written and verbal communication skills.
  • Experience working with risk management frameworks and identifying cybersecurity risks in modern technology environments.
  • Strong program management skills, including strategic planning, road-mapping, and technical project execution.
  • Industry experience in Healthcare, Insurance, or Retail is a plus.
  • Relevant certifications such as CCSK, CCSP, CISSP, CRISC, or similar credentials.

Responsibilities

  • Development and delivery of technology solutions supporting technology compliance and audit management.
  • Design, modernize, and operationalize technology solutions for regulatory frameworks (SOX, SOC 1, SOC 2, PCI, HITRUST, NIST 800‑53, NYDFS, etc.).
  • Partner with engineering teams, control owners, and security architects to develop audit-ready control environments.
  • Automate evidence collection for complex technology stacks (cloud-native, distributed systems, AI/ML, DevSecOps).
  • Translate regulatory requirements into scalable technical controls, automated testing, and compliance indicators.
  • Contribute to the development and continuous improvement of compliance tooling, control processes, dashboards, and metrics.
  • Collaborate with IT, business partners, L&D, Internal Audit, Legal, and external assessors for alignment and consistent execution.

Benefits

  • Medical coverage
  • Dental coverage
  • Vision coverage
  • Paid time off
  • Retirement savings options
  • Wellness programs
  • CVS Health bonus, commission or short-term incentive program
  • Award target in the company’s equity award program

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Senior

Education Level

Associate degree

Number of Employees

5,001-10,000 employees

© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service