
Assistant Vice President – Security Risk Management
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in California.
• Develop and enhance CVS Health’s cybersecurity and technology risk management framework, which includes risk taxonomy, alignment of risk appetite, assessment methodologies, risk scoring, validation of controls, governance, issue management, and reporting to executives.
• Oversee the comprehensive process of third-party cybersecurity risk evaluations across vendors and business partners.
• Incorporate internal, third-party, supply chain, and M&A cyber and technology risk indicators into the overall enterprise risk profile.
• Direct cybersecurity initiatives for M&A onboarding, covering due diligence, evaluation of security architecture, integration requirements, remediation efforts, and secure onboarding procedures.
• Manage cybersecurity operations for M&A offboarding, divestitures, separations, and transitional services.
• Collaborate with security, privacy, legal, technology, procurement, corporate development, integration, enterprise risk, and business leadership teams.
• Provide guidance to internal stakeholders, vendors, suppliers, acquired or divested organizations, regulators, and client due diligence teams.
• Work closely with the CISO, Deputy CISO, and Chief Privacy Officer on risk strategies, regulatory compliance, control stance, escalation processes, and governance structures.
• Create and present cybersecurity and technology risk indicators, metrics, trends, and significant risk themes to senior management.
• Lead risk treatment initiatives, governance of remediation, issue management, compensating controls, exception handling, and risk acceptance procedures.
• Assess and implement cybersecurity risk management tools, GRC capabilities, security rating services, continuous monitoring systems, control assessment automation, and data analytics.
• Act as a representative of CVS Health during regulatory inspections, client due diligence assessments, transaction-related reviews, and audits.
• Adjust the program to address emerging cyber threats, regulatory demands, healthcare cyber risk developments, ransomware, cloud challenges, identity issues, software supply chain risks, AI/ML vendor risks, and transaction-related threats.
• Lead and cultivate a high-performing cybersecurity risk management team.
• Over 10 years of progressive experience in information security, cybersecurity risk management, technology risk, or IT auditing.
• A minimum of 5 years focused on third-party, vendor, supplier, supply chain, or M&A cyber risk management.
• Proven experience in designing, implementing, and advancing cybersecurity and technology risk management programs within a large, intricate organization.
• Familiarity with internal and external risk assessment methodologies, inherent and residual risk evaluations, validation of controls, issue management, risk acceptance, and executive reporting.
• Experience in assessing identity and access management, privileged access, vulnerability management, endpoint security, cloud security, network security, logging and monitoring, data protection, incident response readiness, application security, infrastructure, platform management, change management, business continuity, and disaster recovery controls.
• Background in supporting merger, acquisition, divestiture, separation, or transition services from a cybersecurity risk perspective.
• At least 3 years of experience in leading, managing, and developing high-performing security or risk teams.
• Strong leadership, collaboration, relationship-building, and partnership skills in a matrixed enterprise environment.
• Working knowledge of HIPAA, NIST CSF, NIST 800-53, ISO 27001, HITRUST, SOC 2, PCI DSS, and other relevant regulations.
• Proficiency with TPRM, GRC platforms, security ratings services, continuous monitoring, technology risk reporting, and cyber risk reporting tools.
• Capacity to influence senior stakeholders and manage cross-functional internal and external collaborations.
• Exceptional written and verbal communication skills, including the ability to communicate effectively with executives, governance committees, regulators, clients, and Board members.
• Bachelor’s degree in Computer Science, Information Security, Cybersecurity, Business, or a related field, or equivalent professional experience.
• Preferred: CISSP, CISM, CRISC, CTPRP, CCSP, CISA, or HCISPP certifications.
• Preferred: Experience in the healthcare, health insurance, pharmacy, or retail sectors.
• Preferred: A master’s degree or Juris Doctor.
• Preferred: Familiarity with cyber risk quantification, control maturity models, threat-informed assessments, continuous control monitoring, technology resilience, cloud security posture, fourth-party risk, AI/ML vendor risk, software supply chain risk, enterprise risk aggregation, and transaction-related cybersecurity risks.
• Preferred: Experience in supporting regulatory audits, client due diligence, transaction diligence, or related assessments.
• CVS Health bonus, commission, or short-term incentive program in addition to base salary.
• Target awards in the company’s equity award program.
• Medical coverage.
• Dental coverage.
• Vision coverage.
• Paid time off.
• Retirement savings options.
• Wellness programs.
• Additional resources supporting physical, emotional, and financial well-being, based on eligibility.
American Health Marketplace
ReSource Pro
Terac
Twoconnect
Get handpicked remote jobs straight to your inbox weekly.