
Distinguished Engineer – Application Security
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Arizona.
• Act as the senior technical leader and strategist for Application Security at CVS Health.
• Establish the architectural framework for securing enterprise web, mobile, API, microservice, and AI-native applications across various environments including cloud, on-prem, SaaS, and hybrid.
• Design and implement an application security program that promotes early responsibility in design and development.
• Oversee the technical strategy and comprehensive architecture of the application security tooling stack.
• Choose, assess, integrate, optimize, and consolidate application security tools to create an ASPM view.
• Serve as the lead architect for Application Security components, tools, services, and CI/CD-integrated microservices.
• Establish design standards, conduct design reviews, and provide hands-on contributions to critical components.
• Assist application teams in adopting security standards and tools.
• Formulate strategies and guidelines for AI coding assistants, agentic coding tools, and AI-generated code.
• Assess and integrate AI-native application security tools.
• Collaborate with Developer Experience and Security Engineering teams to offer secure-by-default developer paths and embed controls from development through to production.
• Develop secure coding standards aligned with OWASP ASVS and NIST SSDF.
• Create outcome-based metrics that relate application security posture to business risk.
• Drive strategy, investment, and execution across organizational boundaries.
• Over 15 years of experience in technical roles.
• More than 10 years of experience connecting deep technical work with business strategy.
• At least 10 years of hands-on software engineering experience across various programming languages, with current coding skills.
• A minimum of 8 years in enterprise-scale application security or product security positions.
• Practical experience in threat modeling, secure design review, secure code review, and vulnerability triage.
• Over 5 years of experience in developing multi-year technical strategies and architectural roadmaps for enterprise-scale application security or DevSecOps initiatives.
• Extensive knowledge of SAST, DAST, SCA, IAST/RASP, secrets scanning, API security, container and IaC scanning, ASPM/ASOC.
• Experience in embedding security controls into modern CI/CD pipelines and developer platforms.
• Strong familiarity with SBOMs, CycloneDX, SPDX, SLSA, provenance and attestation, dependency and license governance, and build-system hardening.
• Deep understanding of Kubernetes, serverless, microservices, REST, GraphQL, gRPC, and event-driven architectures.
• Proven experience in transforming application security programs to be developer-native, control-driven, and continuous operations.
• Experience collaborating with platform engineering or developer experience teams.
• Excellent written and verbal communication skills, including the ability to brief executive leadership and the board.
• Bachelor's degree in Computer Science, Engineering, or a related field.
• CVS Health bonus, commission, or short-term incentive program.
• Award target in the company’s equity award program.
• Medical coverage.
• Dental coverage.
• Vision coverage.
• Paid time off.
• Retirement savings options.
• Wellness programs.
• Additional resources supporting physical, emotional, and financial well-being.
Eos Energy Enterprises, Inc.
Lightserve Corp
Agilent Technologies
Koniag Government Services
Get handpicked remote jobs straight to your inbox weekly.