Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Distinguished Engineer - Application Security

$175.1k - $334.75k
Full-time

CVS Health

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.

Position Summary

Serves as the senior technical leader and strategist for Application Security at CVS Health, setting the architectural direction for how the enterprise secures the software that it builds and integrates across web, mobile, API, microservice, and AI-native applications spanning cloud, on-prem, SaaS and hybrid environments. Partners with the AVP, Application Security to define and deliver an industry-leading application security program that shifts security responsibility left into design and development, enforces it consistently through CI/CD, and validates it continuously in production, replacing point-in-time scan-and-triage workflows with a developer-native, control-driven, threat-informed model.

Owns the technical strategy and end-to-end architecture of the application security tooling stack including SAST, DAST, SCA, IAST/RASP, secrets scanning, API security, IaC and container scanning, ASPM/ASOC and its integration into the Developer Experience platform and enterprise CI/CD pipelines, so that security controls are consumed as native platform capabilities by application teams rather than as separate bolt-on tools. Accountable for tool selection, evaluation, and integration planning across a rapidly evolving vendor landscape, including build-vs-buy decisions and consolidation into a coherent Application Security Posture Management (ASPM) view. Serves as the ultimately responsible architect for the components, tools, and services developed and operated by the Application Security team, including microservices that integrate AppSec tools into CI/CD, reusable components, setting design standards, leading design reviews, and contributing hands-on to critical components. Provides hands-on support to application teams adopting standards and tooling, ensuring that the secure path is also the easy and default path.

Charts the enterprise course through the rapidly evolving field of AI-assisted software development, establishing the technical strategy and guardrails for safe adoption of AI coding assistants, agentic coding tools, and AI-generated code across the engineering organization; evaluating and integrating AI-native application security tooling (AI-assisted triage, autofix, secure code review, threat modeling, and detection engineering); and helping the enterprise navigate emerging risks including insecure generated code, prompt injection in developer workflows, model and prompt supply-chain exposure, and IP/data leakage through AI tooling.

Partners with the Developer Experience team to design and deliver the developer-facing side of the program, secure-by-default paved paths, secure coding standards mapped to OWASP ASVS and NIST SSDF, and outcome-based metrics that translate application security posture into business risk. Partners closely with the Developer Experience team that manages the enterprise CI/CD pipelines, and with Security Engineering peers across Cloud Security, AI Security, Identity, Detection Engineering, and Exposure Management, to ensure application security controls are integrated end-to-end from developer laptop to production runtime. Operates as a trusted bridge between deeply technical engineering teams and business stakeholders, influencing strategy, investment, and execution across organizational boundaries without relying on direct authority.

This role can be remote anywhere in the continental USA.

Required Qualifications
  • 15+ years of experience in technical roles, with demonstrated ability to influence without authority across technical and executive audiences
  • 10+ years of experience acting as a bridge between deep technical work and business strategy, translating between the two fluently
  • 10+ years of hands-on software engineering experience across multiple language ecosystems (e.g., Java, C#, JavaScript/TypeScript, Python, Go) — with recent, current coding proficiency, not solely architectural or advisory experience
  • 8+ years in application security or product security roles at enterprise scale, including hands-on experience with threat modeling, secure design review, secure code review, and vulnerability triage
  • 5+ years setting multi-year technical strategy and architectural roadmaps for enterprise-scale application security or DevSecOps programs
  • Deep working knowledge of the modern application security tooling landscape — SAST, DAST, SCA, IAST/RASP, secrets scanning, API security, container and IaC scanning, ASPM/ASOC — including hands-on experience selecting, integrating, tuning, and operating these tools at enterprise scale
  • Demonstrated experience integrating security controls into modern CI/CD pipelines and developer platforms (Git-based workflows, GitHub Actions / GitLab CI / Jenkins / Argo, container registries, artifact repositories, service catalogs) as native, low-friction platform capabilities
  • Strong working knowledge of software supply chain security — SBOMs (CycloneDX, SPDX), the SLSA framework, provenance and attestation, dependency and license governance, and build-system hardening
  • Deep familiarity with cloud-native architectures (Kubernetes, serverless, microservices), API design patterns (REST, GraphQL, gRPC, event-driven), and the security implications of each
  • Demonstrated experience leading the transformation of an application security program from centralized, gate-oriented, meeting-driven workflows to developer-native, control-driven, continuous operations — including measurable improvements in adoption, remediation velocity, and defect escape rate
  • Demonstrated experience partnering with platform engineering or developer experience teams to deliver security capabilities as native platform features rather than external gates
  • Strong written and verbal communication, including proven experience briefing executive leadership and the board


Preferred Qualifications

  • Practical, current experience with AI-assisted software development — evaluating and governing AI coding assistants (e.g., Claude Code, GitHub Copilot, Cursor, Windsurf, Cody, Amazon Q Developer, and equivalents), agentic coding tools, and MCP-based developer integrations — including security guardrails and organizational rollout patterns
  • Hands-on experience evaluating and integrating AI-native application security tooling — AI-assisted triage, autofix, secure code review, and AI threat modeling capabilities — with practical awareness of accuracy, false-positive, and prompt-injection concerns
  • Deep working knowledge of OWASP LLM Top 10, OWASP AI Security & Privacy Guide, MITRE ATLAS, and NIST AI RMF as they apply to application security
  • Experience with Application Security Posture Management (ASPM) platforms and unified security signal aggregation, correlation, and prioritization across the AppSec toolchain
  • Healthcare-sector application security experience: PHI-handling clinical and pharmacy systems, HIPAA Security Rule, FDA pre-market and post-market cybersecurity guidance (including SPDF), retail pharmacy PCI-scoped applications, and clinical-system safety considerations
  • Experience operating application security programs simultaneously against HIPAA, HITRUST CSF, PCI DSS 4.0, the SEC cyber-incident disclosure rule, and NIST CSF 2.0
  • Experience with runtime application security capabilities — RASP, eBPF-based runtime protection, service mesh security, and WAF/API gateway integration — and with correlating runtime signals back to source code and design
  • Experience partnering with product management, engineering leadership, and platform engineering to embed security into developer workflows without slowing delivery velocity
  • Experience influencing standards bodies, open-source projects, or industry working groups relevant to application security or secure software development
  • Industry certifications such as CISSP, CSSLP, OSWE, OSCP, GIAC (e.g., GWEB, GWAPT, GMOB, GCSA), or equivalent
  • Advanced degree in Computer Science, Software Engineering, or related technical field
  • Open-source, publication, or community contribution in application security, DevSecOps, secure software development, or AI-assisted development
  • Advanced degree in Computer Science

Education

Bachelor's degree in Computer Science, Engineering, or a related field.

Pay Range

The typical pay range for this role is:

$175,100.00 - $334,750.00


This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company’s equity award program.

Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.

Great benefits for great people

We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.

This full‑time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well‑being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.


Additional details about available benefits are provided during the application process and on Benefits Moments .

We anticipate the application window for this opening will close on: 12/31/2026

Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.

Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Distinguished Engineer - Application Security in Remote vacancy
  • $320k

     ...NVIDIA is seeking a Distinguished Engineer to serve as the founding technical leader for our AI Safety & Security Engineering team. Rooted in the firm belief that open-weight...  ...also be eligible for equity and benefits.Applications for this job will be accepted at least... 
    Application
    Full time
    Remote work

    Nvidia

    Santa Clara, CA
    1 day ago
  •  ...this job’s a big deal:As the Distinguished Enterprise Architect for...  ...building reliable, scalable, secure, and cost-effective foundations...  .... You’ll unify platform engineering, SRE, networking, and multi-...  ...create an account to save/view applications.SummaryLocation: New York; Norwalk... 
    Application
    Full time
    Interim role
    Work at office
    Remote work
    Flexible hours

    Priceline.com

    New York, NY
    4 days ago
  •  ...Job Description Fragomen is seeking a Security Engineer - Application Security to join our talented Cyber Security team in our Technology...  ...a small team of Security Engineers who make security a distinguishing factor in our technological offerings. A successful candidate... 
    Application
    Local area
    Remote work

    Fragomen, Del Rey, Bernsen & Loewy, LLP

    United States
    3 days ago
  •  ...Job Description About Index Engines At Index Engines, we’re...  ...are seeking an experienced Distinguished Software Engineer to join our...  ...the Index Engines’ Linux applications. In this role, you will act...  ...teams create highly scalable, secure solutions. Write clean, maintainable... 
    Application
    Work from home
    Monday to Friday

    Index Engines

    Holmdel, NJ
    12 days ago
  • $176.1k - $308.2k

     ...DescriptionIt all started when engineer Fred Luddy wrote code that...  ...DescriptionThe ServiceNow Security Organization (SSO) The ServiceNow...  .... Role Summary As an Staff Application Security Engineer in GSSC...  ...are a contributing factor. Distinguish between product vulnerabilities... 
    Application
    Work at office
    Immediate start
    Remote work
    Relocation
    Flexible hours

    ServiceNow

    Santa Clara, CA
    3 days ago
  • $99k - $206k

     ...Incident Response Team (HIRT) secures the Nation’s cyber and...  ..., and misuse activities and distinguish these incidents and events from...  ...traffic using metadata- Identify applications and operating systems of a...  ..., Cyber Security, Computer Engineering, or related degree; or HS... 
    Application
    Full time
    For contractors
    Immediate start
    Remote work

    Nightwing

    Sterling, VA
    1 day ago
  • $159.3k - $212.8k

    The AWS Security Hub team is looking for a passionate and innovative security engineer with a focus on compliance and security best practices for AWS, Azure, and GCP services...  ...accommodation or adjustment during the application and hiring process, including support for... 
    Application
    Internship
    Flexible hours

    Amazon

    New York, NY
    4 days ago
  • $165k - $242k

     ...more at .What You’ll Do:The Enterprise Security team at CoreWeave is responsible for securing...  ..., contractors, and critical business applications protected in a modern, cloud-native...  ...join.About the Role:As a Senior Security Engineer, Enterprise Security, you’ll design and... 
    Application
    Permanent employment
    Full time
    Temporary work
    For contractors
    Casual work
    Work at office
    Remote work
    Flexible hours

    CoreWeave

    New York, NY
    4 days ago
  • $286.2k - $326.7k

     ...Senior. Distinguished AI Engineer - Agentic AI Platform (Remote Eligible) At Capital One, we are...  ...answering their questions in real time, our applications of AI & ML are bringing humanity and...  ...kits that let AI engineers spin up secure, observable agentic workflows in... 
    Application
    Full time
    Part time
    Work at office
    Local area
    Remote work

    Capital One

    United States
    4 days ago
  • $269.1k - $307.2k

     ...Distinguished AI Engineer - Agentic AI Platform (Remote Eligible) At Capital One, we are creating responsible...  ...their questions in real time, our applications of AI & ML are bringing humanity and...  ...kits that let AI engineers spin up secure, observable agentic workflows in... 
    Application
    Full time
    Part time
    Work at office
    Local area
    Remote work

    Capital One

    United States
    20 hours ago
  • $244.7k - $279.2k

    Distinguished AI Engineer (Remote) Job Description Overview: At Capital One, we are creating responsible and...  ...charges to answering their questions in real time, our applications of AI & ML are bringing humanity and simplicity to banking... 
    Application
    Full time
    Part time
    Local area
    Remote work

    Capital One Financial Corporation

    McLean, VA
    20 hours ago
  •  ...will provide more details.Director, Distinguished Engineer, Enterprise AI PlatformsPosition SummaryMUFG...  ..., evaluation frameworks, security guardrails, FinOps, and reusable engineering...  ...architecture patterns for AI applications, RAG pipelines, agentic workflows, AI... 
    Application
    Full time
    Work at office
    Local area
    Remote work
    1 day per week

    MUFG

    Jersey City, NJ
    4 days ago
  • $100k - $125k

     ...Position Summary You are the kind of engineer who stays curious when no one is watching...  ...likely seen what happens when strong security talent gets trapped in slow, rigid organizations...  ...you! Duties & Responsibilities Application Security & Secure SDLC: Lead... 
    Application
    Remote job
    Full time
    Work experience placement

    Delta Defense, Llc

    Remote
    20 hours ago
  • $178.4k - $226.7k

     ...production systems and customer environments. As the Senior Security Engineer embedded with an AHAS software development team, you own the...  ...and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding... 
    Application
    Internship
    Remote work
    Flexible hours

    Amazon

    Arlington, VA
    20 hours ago
  • $320k

     ...motivated and energetic senior technologist for the role of Distinguished Engineer, Wireless Infrastructure.What you will be doing:Lead the...  ...technology with AI Native approaches.Drive development of new applications in Integrated Sensing and Communications (ISAC), Semantic... 
    Application
    Full time
    Remote work

    Nvidia

    Santa Clara, CA
    3 days ago
  • $103.62k - $172.63k

     ...financial goals. Job Overview:LPL is seeking an AVP Tech Network Engineer, Security who will be responsible for the design, engineering, and...  ...offer work authorization sponsorship now or in the future. Applicants must have valid U.S. work authorization that does not require... 
    Application
    Full time
    Remote work
    Work from home

    LPL Financial

    Austin, TX
    4 days ago
  • $110k - $190k

     .... Role Overview: We are seeking a Cybersecurity Engineer focused on Product Security to help design, assess, and secure our next-generation...  ...experience in cybersecurity engineering, product security, application security, or related engineering roles   ~ Experience... 
    Application
    Full time
    Contract work
    Work experience placement
    Casual work
    Relocation package

    Chaos Industries

    Remote
    20 hours ago
  • Washington DCTechnology - Security /RemoteThe Senior Security Engineer II will be responsible for designing, implementing, and maintaining security services...  ...6+ years of experience in securing and deploying applications within Cloud Native environments3+ years of... 
    Application
    Temporary work
    Work at office
    Remote work
    Work from home
    Flexible hours

    Aledade

    Washington DC
    4 days ago
  •  ...the company’s global operations through secure, scalable solutions that enable innovation...  ...Security Enablement, we partner with application teams to integrate enterprise applications...  ...:We are seeking a Senior Cybersecurity Engineer to lead security enablement and automation... 
    Application
    Full time
    Local area
    Work from home
    Relocation package

    General Motors

    Austin, TX
    1 day ago
  •  ...expertise, capable of driving enterprise security initiatives and influencing...  ...a highly skilled Senior Cybersecurity Engineer with deep expertise in systems development...  ...practices to safeguard infrastructure and applications.Infrastructure & CloudArchitect and manage... 
    Application
    Full time
    Local area
    Work from home
    Relocation package

    General Motors

    Warren, MI
    3 days ago
  •  ...We are looking for software engineers first: strong full-stack or...  ...platform problems end to end. Security experience is helpful, and...  ...Codex Security more useful for application security teams, systems that...  ...and remediation flows that distinguish real issues from noisy or... 
    Application
    Full time

    OpenAI

    Remote
    more than 2 months ago
  • Senior Security Engineer- Product SecurityAugusta, GaWork Location & ScheduleThis is a hybrid position based in our Augusta, GA office. Team...  .... This role is responsible for identifying and mitigating application security risks, conducting security assessments, managing TaxSlayer... 
    Application
    Full time
    Temporary work
    For contractors
    Fixed term contract
    Work at office
    Remote work
    Flexible hours
    2 days per week
    3 days per week

    TaxSlayer

    Augusta, GA
    2 days ago
  • $210k - $260k

     ...toward becoming the world's top retail-focused trading platform in the world. What you'll do:We're looking for aStaff Security Engineer, Application Security to help scale and mature our security program. You'll own key security domains and initiatives end-to-end, working... 
    Application
    Work at office
    Remote work
    Worldwide
    Monday to Friday
    Flexible hours

    NinjaTrader Group

    Chicago, IL
    1 day ago
  • $221.2k - $387.1k

    Company DescriptionIt all started when engineer Fred Luddy wrote code that automated a tedious...  ....Job DescriptionAbout SSOThe ServiceNow Security Organization (SSO) delivers world-class,...  ...$221,200 - $387,100, plus equity (when applicable), variable/incentive compensation and... 
    Application
    Permanent employment
    Work at office
    Immediate start
    Remote work
    Flexible hours
    Shift work

    ServiceNow

    Kirkland, WA
    3 days ago
  • $200k - $210k

     ...Investment Platforms group is seeking a Distinguished Engineer to architect and guide our technical...  ...and private credit front office applications. This is a senior technical leadership...  ...mentor team members on software, infra, security, data, and AI engineering... 
    Application
    Full time
    Work at office
    Local area
    Remote work
    1 day per week

    HarbourVest Partners

    Boston, MA
    4 days ago
  • Hi, we're Oscar. We're hiring a Senior Product Security Engineer 1 to join our Security Team.Oscar is the first health insurance company built...  .... You will work at the intersection of traditional application security and modern AI-driven engineering, ensuring that our... 
    Application
    Full time
    Work experience placement
    Work at office
    Remote work

    Oscar Health Insurance

    San Francisco, CA
    2 days ago
  • The GCS - Security Architecture function secures Carnival Corp’s adoption of AI by protecting...  ...layer. This position is a hands-on engineering role centered on scripting, programming...  ...large language model and agentic applications against prompt injection, jailbreaks, and... 
    Application
    Full time
    Part time
    Work at office
    Local area
    Work from home
    Relocation
    Monday to Thursday

    Carnival Cruise Line

    Miami, FL
    2 days ago
  • $150k - $200k

     ...unique viewpoint matter. Learn about the Danaher Business System which makes everything possible.At Danaher, the Senior Engineer, Application Security embeds security into the SDLC and product engineering. Enterprise AppSec strategy and standards are set by leadership/... 
    Application
    Full time
    Remote work
    Work from home
    Flexible hours
    Night shift

    Danaher Corporation

    New York, NY
    3 days ago
  • $300k - $320k

     ...human access to all of an organization's applications, data, and business processes....  ...recognized as the leader in identity security, with solutions that protect and empower...  ...tenant applications cannot reach. As Distinguished Engineer, Data Platform, you will own the end-... 
    Application
    Full time

    Saviynt

    Remote
    20 hours ago
  • $266k

     ...artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We...  ...a robust security culture. About the RoleAs a Security Engineer, Application Security you will be responsible for identifying and mitigating... 
    Application
    Work at office
    Remote work
    Relocation package
    Flexible hours

    OpenAI

    San Francisco, CA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Distinguished Engineer - Application Security. Be the first to apply!