Staff DevSecOps Engineer, Health

Posted 1 day ago

This is a fully remote position, open to applicants in Connecticut, +3 more states.

📋 Description

• Oversee the technical implementation, migration, automation, mobile application security, and standardization across the Health 100 portfolio.

• Assist in the application onboarding process and enable security for Health 100 initiatives.

• Support development teams in fulfilling security requirements through standardized tools, pipeline integration, and consistent implementation patterns.

• Convert release-readiness expectations into reusable technical patterns and supporting evidence.

• Facilitate mobile application security testing, secure configuration validation, and guidance for remediation.

• Spearhead DevSecOps implementation initiatives, including technical planning, architecture, delivery, issue resolution, and implementation results.

• Collaborate across application, platform, and security teams to eliminate obstacles and promote adoption.

• Design, execute, and enhance CI/CD security controls, pipeline enforcement, and automated scanning workflows.

• Develop self-service security solutions and reusable automation processes.

• Automate secret-detection and CI/CD security workflows, utilizing tools like Gitleaks or similar capabilities.

• Direct security tool migrations, such as from Checkmarx to Snyk, ensuring stable production operations.

• Generate and validate scan results post-migration.

• Standardize tool configurations across development teams.

• Propel the remediation of critical and high-risk vulnerabilities while monitoring remediation efforts against SLAs.

• Lead the prioritization of open-source and software supply chain vulnerabilities.

• Enhance SBOM coverage and promote secure-by-default dependency practices.

• Design controls for public cloud, containers, Kubernetes, Security-as-Code, and Infrastructure-as-Code environments.

• Utilize expertise in network security, cloud architecture, and mobile security to evaluate risks and guide remediation efforts.

• Monitor and report on scan coverage, mobile testing coverage, vulnerability aging, SLA adherence, remediation effectiveness, automation adoption, tool coverage, and pipeline compliance.

• Provide executive-ready updates on implementation progress, delivery risks, and measurable security results.

• Mentor engineers, establish reusable engineering patterns, and create implementation guidance and educational resources.


⛳️ Requirements

• 7+ years of experience in DevSecOps, application security engineering, platform security, or software engineering.

• Proficient in integrating SAST, SCA, secrets detection, container scanning, IaC scanning, or similar security controls into CI/CD pipelines.

• Experienced in leading security implementations or tool migrations in large or complex engineering settings.

• Strong proficiency in public cloud platforms such as AWS, Azure, or GCP, along with cloud and network security concepts.

• Familiarity with Docker, Kubernetes, Security-as-Code, and Infrastructure-as-Code.

• Hands-on experience in scripting or programming with Python, Java, JavaScript, Go, Shell, or PowerShell.

• Experience in managing application vulnerabilities, open-source risks, and software supply chain security.

• Knowledgeable in mobile application security testing, mobile threat modeling, or the remediation of security findings in iOS and Android applications.

• Demonstrated ability to utilize metrics to drive adoption, remediation, and measurable technical outcomes.

• A Bachelor's degree in Computer Science, Software Development, Software Engineering, or a related field, or equivalent practical experience.

• Preferred: experience with portfolio-based initiatives or prioritized application sets like Health 100.

• Preferred: hands-on experience with Snyk, Checkmarx, Gitleaks, SBOM tooling, or similar platforms.

• Preferred: hands-on experience with Data Theorem, MobSF, or similar mobile testing tools.

• Preferred: expertise in architecting public cloud security solutions and scalable engineering processes.

• Preferred: strong understanding of networking and Software-Defined Networking principles.

• Preferred: experience with security solutions for data warehouses or big-data platforms, including Snowflake.

• Preferred: familiarity with HIPAA, HITRUST, PCI, NIST, GDPR, or CCPA.

• Preferred: experience in communicating technical security outcomes and risk posture to senior leadership.


🏝️ Benefits

• CVS Health bonus, commission, or short-term incentive program in addition to base salary.

• Equity award program.

• Medical coverage.

• Dental coverage.

• Vision coverage.

• Paid time off.

• Retirement savings options.

• Wellness programs.

• Additional resources supporting physical, emotional, and financial well-being.

People also viewed

In All Media18 hours ago

DevOps Engineer – Cloud

BR flagBrazil, +5 more countriesFull-timeDevOps & Site Reliability Engineer (SRE)
ApplyView job
Verity Group18 hours ago

SRE Engineer

BR flagBrazil OnlyFull-timeDevOps & Site Reliability Engineer (SRE)
ApplyView job
Fingerprint21 hours ago

Senior Site Reliability Engineer

US flagUnited States OnlyFull-timeDevOps & Site Reliability Engineer (SRE)$152k – $205k/year
ApplyView job
Endava23 hours ago

Senior DevOps Engineer, Terraform

IN flagIndia OnlyFull-timeDevOps & Site Reliability Engineer (SRE)
ApplyView job
GoFasti1 day ago

Senior DevOps Engineer

Latin AmericaFull-timeDevOps & Site Reliability Engineer (SRE)$5,000 – $6,000/month
ApplyView job
Hitss Brasil1 day ago

DevOps Architect

BR flagBrazil OnlyFull-timeDevOps & Site Reliability Engineer (SRE)
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers