DevSecops Engineer
CVS Health
- Location
- NY New York
- Work model
- On-Site
- Level
- Mid
- Posted
- 19h ago
Skills
About this role
We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.
POSITION
SUMMARY CVS Health is seeking a DevSecOps Engineer to help build, secure, and scale modern technology platforms that power critical healthcare services. This is a unique opportunity to join a high-impact engineering organization where security is embedded into everything we build, from cloud infrastructure and applications to data platforms and deployment pipelines. As a DevSecOps Engineer, you will partner closely with software engineers, cloud architects, and platform teams to design and implement secure-by-default solutions across multi-cloud environments. You'll leverage automation, software development, and modern security practices to reduce risk, increase engineering velocity, and improve platform reliability at enterprise scale. This role is ideal for an engineer who enjoys solving complex security challenges through code, automation, and collaboration. You'll have the opportunity to influence engineering standards, shape enterprise security strategy, drive DevSecOps adoption, and help protect healthcare data that impacts millions of customers. As a DevSecOps Engineer, you'll work across application security, cloud security, data protection, infrastructure security, and security automation while gaining exposure to cutting-edge technologies including Kubernetes, Infrastructure-as-Code, CI/CD platforms, cloud-native architectures, and AI-enabled engineering solutions.V You'll join a culture that values innovation, continuous learning, engineering excellence, and career growth. Whether you're building security automation, improving developer experience, securing cloud-native applications, or maturing enterprise DevSecOps capabilities, your work will have visible impact across the organization.
PRIMARY RESPONSIBILITIES
Partner with engineering, platform, and business teams to embed secure-by-design practices throughout the software development lifecycle and DevSecOps processes. Develop, implement, and govern application, infrastructure, and data security standards across cloud, on-premises, and hybrid environments. Serve as the Application Security SME, leading security assessments, vulnerability management, remediation strategies, and security testing initiatives. Design, implement, and automate security controls, policies, and guardrails to improve security posture, operational efficiency, and compliance. Develop security metrics, dashboards, and executive reporting using platforms such as Power BI, Grafana, Tableau, or similar analytics tools. Lead incident response planning, security investigations, and recovery efforts while contributing to enterprise-wide resiliency initiatives. Participate in operational support and on-call activities, driving continuous improvement through automation, collaboration, and Agile/Kanban practices.
REQUIRED QUALIFICATIONS
3+ years designing, implementing, and supporting enterprise security solutions and secure engineering practices across cloud-native and distributed environments. 3+ years working within modern SDLC and DevSecOps ecosystems, including CI/CD pipelines, deployment automation, and remediation of findings from SAST, SCA, API, and Mobile security testing. 2+ years securing AWS, Azure, and/or GCP environments, including identity, network, container, and workload security, utilizing Infrastructure-as-Code and Security-as-Code methodologies. 2+ years developing security automation, integrations, and tooling using Python, Java, JavaScript, C#, PowerShell, Bash, or similar languages. 1+ years implementing