
Staff DevSecOps Engineer, Health
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Connecticut, +3 more states.
• Oversee the technical implementation, migration, automation, mobile application security, and standardization across the Health 100 portfolio.
• Assist in the application onboarding process and enable security for Health 100 initiatives.
• Support development teams in fulfilling security requirements through standardized tools, pipeline integration, and consistent implementation patterns.
• Convert release-readiness expectations into reusable technical patterns and supporting evidence.
• Facilitate mobile application security testing, secure configuration validation, and guidance for remediation.
• Spearhead DevSecOps implementation initiatives, including technical planning, architecture, delivery, issue resolution, and implementation results.
• Collaborate across application, platform, and security teams to eliminate obstacles and promote adoption.
• Design, execute, and enhance CI/CD security controls, pipeline enforcement, and automated scanning workflows.
• Develop self-service security solutions and reusable automation processes.
• Automate secret-detection and CI/CD security workflows, utilizing tools like Gitleaks or similar capabilities.
• Direct security tool migrations, such as from Checkmarx to Snyk, ensuring stable production operations.
• Generate and validate scan results post-migration.
• Standardize tool configurations across development teams.
• Propel the remediation of critical and high-risk vulnerabilities while monitoring remediation efforts against SLAs.
• Lead the prioritization of open-source and software supply chain vulnerabilities.
• Enhance SBOM coverage and promote secure-by-default dependency practices.
• Design controls for public cloud, containers, Kubernetes, Security-as-Code, and Infrastructure-as-Code environments.
• Utilize expertise in network security, cloud architecture, and mobile security to evaluate risks and guide remediation efforts.
• Monitor and report on scan coverage, mobile testing coverage, vulnerability aging, SLA adherence, remediation effectiveness, automation adoption, tool coverage, and pipeline compliance.
• Provide executive-ready updates on implementation progress, delivery risks, and measurable security results.
• Mentor engineers, establish reusable engineering patterns, and create implementation guidance and educational resources.
• 7+ years of experience in DevSecOps, application security engineering, platform security, or software engineering.
• Proficient in integrating SAST, SCA, secrets detection, container scanning, IaC scanning, or similar security controls into CI/CD pipelines.
• Experienced in leading security implementations or tool migrations in large or complex engineering settings.
• Strong proficiency in public cloud platforms such as AWS, Azure, or GCP, along with cloud and network security concepts.
• Familiarity with Docker, Kubernetes, Security-as-Code, and Infrastructure-as-Code.
• Hands-on experience in scripting or programming with Python, Java, JavaScript, Go, Shell, or PowerShell.
• Experience in managing application vulnerabilities, open-source risks, and software supply chain security.
• Knowledgeable in mobile application security testing, mobile threat modeling, or the remediation of security findings in iOS and Android applications.
• Demonstrated ability to utilize metrics to drive adoption, remediation, and measurable technical outcomes.
• A Bachelor's degree in Computer Science, Software Development, Software Engineering, or a related field, or equivalent practical experience.
• Preferred: experience with portfolio-based initiatives or prioritized application sets like Health 100.
• Preferred: hands-on experience with Snyk, Checkmarx, Gitleaks, SBOM tooling, or similar platforms.
• Preferred: hands-on experience with Data Theorem, MobSF, or similar mobile testing tools.
• Preferred: expertise in architecting public cloud security solutions and scalable engineering processes.
• Preferred: strong understanding of networking and Software-Defined Networking principles.
• Preferred: experience with security solutions for data warehouses or big-data platforms, including Snowflake.
• Preferred: familiarity with HIPAA, HITRUST, PCI, NIST, GDPR, or CCPA.
• Preferred: experience in communicating technical security outcomes and risk posture to senior leadership.
• CVS Health bonus, commission, or short-term incentive program in addition to base salary.
• Equity award program.
• Medical coverage.
• Dental coverage.
• Vision coverage.
• Paid time off.
• Retirement savings options.
• Wellness programs.
• Additional resources supporting physical, emotional, and financial well-being.
In All Media
Verity Group
Fingerprint
Endava
Get handpicked remote jobs straight to your inbox weekly.