Distinguished Engineer - Application Security
$175.1k - $334.75kCVS Health
We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.
Position Summary
Position Summary:
This is a rare opportunity to help define the future of Application Security at CVS Health. As the technical counterpart to the AVP of Application Security, you will drive enterprise AppSec strategy, secure AI adoption, and the transformation of software security at one of the largest healthcare organizations in the world.
The Distinguished Engineer - Application Security serves as the senior technical leader and strategist for Application Security at CVS Health, setting the architectural direction for how the enterprise secures the software that it builds and integrates across web, mobile, API, microservice, and AI-native applications spanning cloud, on-prem, SaaS and hybrid environments. Partners with the AVP, Application Security to define and deliver an industry-leading application security program that shifts security responsibility left into design and development, enforces it consistently through CI/CD, and validates it continuously in production, replacing point-in-time scan-and-triage workflows with a developer-native, control-driven, threat-informed model.
Working across the engineering and security organizations, this leader owns the technical strategy and end-to-end architecture of the application security tooling stack including SAST, DAST, SCA, IAST/RASP, secrets scanning, API security, IaC and container scanning, ASPM/ASOC and its integration into the Developer Experience platform and enterprise CI/CD pipelines, so that security controls are consumed as native platform capabilities by application teams rather than as separate bolt-on tools. Accountable for tool selection, evaluation, and integration planning across a rapidly evolving vendor landscape, including build-vs-buy decisions and consolidation into a coherent Application Security Posture Management (ASPM) view. Serves as the ultimately responsible architect for the components, tools, and services developed and operated by the Application Security team, including microservices that integrate AppSec tools into CI/CD, reusable components, setting design standards, leading design reviews, and contributing hands-on to critical components. Provides hands-on support to application teams adopting standards and tooling, ensuring that the secure path is also the easy and default path.
Charts the enterprise course through the rapidly evolving field of AI-assisted software development, establishing the technical strategy and guardrails for safe adoption of AI coding assistants, agentic coding tools, and AI-generated code across the engineering organization; evaluating and integrating AI-native application security tooling (AI-assisted triage, autofix, secure code review, threat modeling, and detection engineering); and helping the enterprise navigate emerging risks including insecure generated code, prompt injection in developer workflows, model and prompt supply-chain exposure, and IP/data leakage through AI tooling.
Partners with the Developer Experience team to design and deliver the developer-facing side of the program, secure-by-default paved paths, secure coding standards mapped to OWASP ASVS and NIST SSDF, and outcome-based metrics that translate application security posture into business risk. Partners closely with the Developer Experience team that manages the enterprise CI/CD pipelines, and with Security Engineering peers across Cloud Security, AI Security, Identity, Detection Engineering, and Exposure Management, to ensure application security controls are integrated end-to-end from developer laptop to production runtime. Operates as a trusted bridge between deeply technical engineering teams and business stakeholders, influencing strategy, investment, and execution across organizational boundaries without relying on direct authority.
*This role can work remotely from anywhere in the continental USA.
Required Qualifications- 15+ years of experience in technical roles, with demonstrated ability to influence without authority across technical and executive audiences
- 10+ years of experience acting as a bridge between deep technical work and business strategy, translating between the two fluently
- 10+ years of hands-on software engineering experience across multiple language ecosystems (e.g., Java, C#, JavaScript/TypeScript, Python, Go) — with recent, current coding proficiency, not solely architectural or advisory experience
- 8+ years in application security or product security roles at enterprise scale, including hands-on experience with threat modeling, secure design review, secure code review, and vulnerability triage
- 5+ years setting multi-year technical strategy and architectural roadmaps for enterprise-scale application security or DevSecOps programs
- Deep working knowledge of the modern application security tooling landscape — SAST, DAST, SCA, IAST/RASP, secrets scanning, API security, container and IaC scanning, ASPM/ASOC — including hands-on experience selecting, integrating, tuning, and operating these tools at enterprise scale
- Demonstrated experience integrating security controls into modern CI/CD pipelines and developer platforms (Git-based workflows, GitHub Actions / GitLab CI / Jenkins / Argo, container registries, artifact repositories, service catalogs) as native, low-friction platform capabilities
- Strong working knowledge of software supply chain security — SBOMs (CycloneDX, SPDX), the SLSA framework, provenance and attestation, dependency and license governance, and build-system hardening
- Deep familiarity with cloud-native architectures (Kubernetes, serverless, microservices), API design patterns (REST, GraphQL, gRPC, event-driven), and the security implications of each
- Demonstrated experience leading the transformation of an application security program from centralized, gate-oriented, meeting-driven workflows to developer-native, control-driven, continuous operations — including measurable improvements in adoption, remediation velocity, and defect escape rate
- Demonstrated experience partnering with platform engineering or developer experience teams to deliver security capabilities as native platform features rather than external gates
- Strong written and verbal communication, including proven experience briefing executive leadership and the board
Preferred Qualifications
- Practical, current experience with AI-assisted software development — evaluating and governing AI coding assistants (e.g., Claude Code, GitHub Copilot, Cursor, Windsurf, Cody, Amazon Q Developer, and equivalents), agentic coding tools, and MCP-based developer integrations — including security guardrails and organizational rollout patterns
- Hands-on experience evaluating and integrating AI-native application security tooling — AI-assisted triage, autofix, secure code review, and AI threat modeling capabilities — with practical awareness of accuracy, false-positive, and prompt-injection concerns
- Deep working knowledge of OWASP LLM Top 10, OWASP AI Security & Privacy Guide, MITRE ATLAS, and NIST AI RMF as they apply to application security
- Experience with Application Security Posture Management (ASPM) platforms and unified security signal aggregation, correlation, and prioritization across the AppSec toolchain
- Healthcare-sector application security experience: PHI-handling clinical and pharmacy systems, HIPAA Security Rule, FDA pre-market and post-market cybersecurity guidance (including SPDF), retail pharmacy PCI-scoped applications, and clinical-system safety considerations
- Experience operating application security programs simultaneously against HIPAA, HITRUST CSF, PCI DSS 4.0, the SEC cyber-incident disclosure rule, and NIST CSF 2.0
- Experience with runtime application security capabilities — RASP, eBPF-based runtime protection, service mesh security, and WAF/API gateway integration — and with correlating runtime signals back to source code and design
- Experience partnering with product management, engineering leadership, and platform engineering to embed security into developer workflows without slowing delivery velocity
- Experience influencing standards bodies, open-source projects, or industry working groups relevant to application security or secure software development
- Industry certifications such as CISSP, CSSLP, OSWE, OSCP, GIAC (e.g., GWEB, GWAPT, GMOB, GCSA), or equivalent
- Advanced degree in Computer Science, Software Engineering, or related technical field
- Open-source, publication, or community contribution in application security, DevSecOps, secure software development, or AI-assisted development
- Advanced degree in Computer Science
Education
Bachelor's degree in Computer Science, Engineering, or a related field or related experience.
Pay Range
The typical pay range for this role is:
$175,100.00 - $334,750.00
This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company’s equity award program.
Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.
Great benefits for great people
We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.
This full‑time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well‑being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.
Additional details about available benefits are provided during the application process and on Benefits Moments .
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.
- Hi, we're Oscar. We're hiring a Senior Product Security Engineer 1 to join our Security Team.Oscar is the first health insurance company built... .... You will work at the intersection of traditional application security and modern AI-driven engineering, ensuring that our...ApplicationFull timeWork experience placementWork at officeFlexible hours
- ...protection solutions at the heart of digital security. Business and governments rely on us to... ...Jose, HybridThales is looking for a Sr Engineer, Advanced Security Response Team (ASRT),... ...on the operational aspects of web application security: analyzing threats, suggesting...ApplicationFull timeLocal areaRemote workDay shiftAfternoon shift
- Security Engineer - Application Security Locations: Charlotte NC, Chandler AZ, Westlake TX (Hybrid), (3 days onsite) Duration: 12+ Months Contract W2 Contract Only Required Qualifications: 5+ years of Application Security Engineering experience, or equivalent demonstrated...ApplicationContract workWork experience placement
- Opportunity OverviewTeam Overview:Join our team as a Security Engineer IV and contribute to the safeguarding of our information system resources... ..., and support API security controls across enterprise applications, cloud services, and third-party integrationsLead...ApplicationTemporary workWork at officeHome officeFlexible hours3 days per week
$78k - $97.45k
...Job Profile: Applications Developer 3 Job Family: IT Applications... ...Job Description Engineering Technical Services (ETS) at... ...to ensure reliability, security, and long-term sustainability... ...framework of values designed to distinguish our practice and guide daily...ApplicationFull timePart timeCasual workInternshipWork at officeLocal areaRelocation packageAfternoon shift$91k - $185.9k
...contribute to the company’s success. As a Security Specialist within PNC's Technology... ...Denver, CO, Phoenix, AZ. As a Security Engineer on PNC's Cloud Security team, you will... ...configurations, and architectures, for applications, platforms, and infrastructure o Assist...ApplicationFull timeTemporary workPart timeWork experience placementWork at officeShift work- Physical Security Support Engineer (Security Integrations Group), Security Integrations Group (SIG) Tempe, United States | Posted on 09/08/202... ...) is seeking a detail-oriented individual for the role of Application Support Engineer within the GSO Security Integrations Group...ApplicationFlexible hoursNight shiftWeekend work
$155.6k - $306.8k
...and proactively manage their security posture.Recruiting for this... ...As a Cyber Forward Deployed Engineer (FDE) Manager, you will lead... ...-enabled capabilities where applicable), and deploy them for clients... ...or platform improvements, distinguishing reusable enhancements from client...ApplicationLocal areaVisa sponsorship$123k - $215.25k
..., and a commitment to back the broader engineering community through open source, our mission... ...of this mission is our Information Security organization, enabling exceptional experiences... ...and control effectiveness.Partner with application, engineering, and architecture teams to...Application- ...Phoenix, AZ 85027 Category: Information Security Shift: Day Department: Information Security... ...: JOB SUMMARY The Cyber Security Cloud Engineer is a key member of the Information... ...Collaborate with IT, Enterprise Architecture and application teams to ensure cloud environments meet...ApplicationMonday to FridayShift work
- ...expertise and innovation abilities, we distinguish new business and innovation slants and... ...innovation, ERP and CRM counselling, Product Engineering, Business Intelligence, Data Management... ...support and maintenance of the HRMS application in addition to other systems supported...ApplicationContract workWorldwide
$250.6k - $362.6k
...The application window is expected to close on: 09/21/2026Job posting may be removed earlier... ...States.Meet the Team You will join Cisco’s Security and Policy Platform Group, a... ...comprehensive security outcomes, as a Principal Engineer. The team delivers secure, scalable capabilities...ApplicationFull timeTemporary workLocal areaRemote workFlexible hours$122k - $240.5k
Position Summary As a Full Stack Engineer Senior Consultant in Deloitte Cyber’s... ...communicate effectively with business, security, privacy, legal, and compliance stakeholders... ...capabilities where applicableBuilding application programming interfaces (APIs), automations...ApplicationLocal areaVisa sponsorship$293.9k - $406.8k
The application window is expected to close on: 10/19/2026Job posting may be removed earlier... ....Meet the TeamYou will join Cisco’s Security and Policy Platform Group, a... ...comprehensive security outcomes, as a Distinguished Engineer. The team delivers secure, scalable capabilities...ApplicationFull timeTemporary workLocal areaRemote workFlexible hours$61.4k - $76.7k
...operating systems, and software applications. Responsibilities include... ...teams to ensure reliable, secure, and effective technology services... ...Ira A. Fulton Schools of Engineering with locations on the Tempe,... ...of values designed to distinguish our practice and guide daily...ApplicationFull timePart timeInternshipSecond jobWork at officeRelocation package- ...Threat Intelligence Analyst to join our team on a highly visible cyber security single-award IDIQ vehicle that provides Network Operations Security Operations (NOSC) support, cyber analysis, and application development.Department of Homeland Security (DHS), NOSC Support...ApplicationFull timeShift work
$80k
Description SOFTWARE ENGINEER | ENTERPRISE TECHNOLOGY & SECURITY DEVELOPMENT PROGRAM Get ready to make your mark! Jumpstart your career through hands... ...modern engineering practices and contributing to applications, components, and tools that support strategic business...ApplicationPermanent employmentInternshipLocal areaFlexible hours$75k - $85k
.... Position Summary The Senior Cyber Security Specialist will be responsible for protecting... ..., firewalls) as a tool administrator or engineer strongly desired. Analytical Skills:... ...and Sick Leave provided as required by applicable state law Other Benefits: Life insurance...ApplicationFull timeContract workTemporary workWork at officeFlexible hours$134.5k - $265.1k
...how they relate to the deployment of technology in line with applicable laws and regulations.General knowledge of integrating technologies... ...:Bachelor’s degree in Computer Science, Computer Engineering, Information Technology, or similar Engineering disciplines7+...ApplicationLocal area$105.4k - $207.8k
...could be the place for you. Traditional security programs have often been unsuccessful... ...Design and implement Secure-by-Design and Application Security processes across the software... ...Cybersecurity, Information Technology, Engineering, Information Systems, or a related...ApplicationWorldwideVisa sponsorship$102.17k
...Job Description Join the Trinnex Security Team as a Senior Cyber Security Analyst... ...identifying vulnerabilities, and ensuring that applications deployed in water environments are... ...threats. You will work closely with engineering and development teams to safeguard systems...ApplicationWork experience placementH1b- ...Cisco enterprise networking and network security and helps clients translate business... ...leaders, security leaders, architects, and engineering teams on Cisco strategy, modernization... ...work remotely/from home (where applicable)EEO StatementOptiv is an equal opportunity...ApplicationFull timeLocal areaRemote workWork from home
$134.5k - $265.1k
...Summary As a Cyber Forward Deployed Engineer (FDE), you will work at the intersection... ...AI/GenAI-enabled capabilities where applicable, and deploying them in alignment with client... ...concepts (e.g., application security, cloud security, identity, detection engineering...ApplicationLocal areaVisa sponsorship$61.56k - $146.64k
...RoleMainframe Infrastructure Engineers at Kyndryl are project-based... ...& Product Support (MF Application-Adjacent)Support and administer... ...test execution.Reliability, Security & ComplianceImplement and maintain... ...either an Architect or Distinguished Engineer, and there are opportunities...ApplicationMinimum wageFull timePart timeLive inLocal areaRelocation3 days per week- ...Details: Must Have Skills Cyber security consultant 7 years delivering Application security SIEM, Incident Response , AWS Security... ...Response , AWS Security and GCP Security. GCP Cloud engineer. Python script programmer. Database Minimum...Application
- ...requirements and technological functionalities Promotion of shared applications and infrastructure to cut expenditures and enhance the flow of... ...of risks related to IT assets by means of proper security policies and standards Direct/indirect participation in developing...ApplicationFlexible hours
$25.77 - $30.93 per hour
...Information Systems - Phoenix, Arizona Open in Google Maps Cyber Security Analyst Washington Elementary School District 6 Management... ...Phoenix, Arizona Open in Google Maps Job Details Job ID: 5462551 Application Deadline: Posted until filled Posted: Dec 08, 2025 7:00 AM (...ApplicationHourly payFull timeLocal areaImmediate startWork visa- Job Title: Cyber Security Remediation Analyst Location: Phoenix, AZ (Remote) Job Type: Contract (Long Term) Experience... ...Intelligence, Incident Response, Red Team, Security Engineering, Technology Risk, application teams, infrastructure teams, and ServiceNow...ApplicationLong term contractContract workImmediate startRemote work
- A leading cybersecurity company in Scottsdale, Arizona, is looking for a skilled developer to contribute to exciting SaaS web applications. The role involves collaborating on feature designs, coding enhancements, and making improvements across platforms. Candidates should...Application
- ...design, implementation, and/or support of highly distributed applications (i.e. having an architectural sense for ensuring availability,... ...WAN & LAN technologies Storage/SAN/NAS system technologies OS Security Experience with large Database systems Experience with scripting...ApplicationFull time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Distinguished Engineer - Application Security. Be the first to apply!
- cyber security analyst Arizona
- information security consultant Arizona
- application scientist Arizona
- director enterprise applications Arizona
- now accepting applications Arizona
- cash application clerk Arizona
- application security lead Arizona
- applications consultant Arizona
- cash app Arizona
- cash application representative Arizona



