Job Information
CVS Health Staff Operational Security Engineer in Austin, Texas
Bring your heart to CVS Health. Every one of us at CVS Health shares a single, clear purpose: Bringing our heart to every moment of your health. This purpose guides our commitment to deliver enhanced human-centric health care for a rapidly changing world. Anchored in our brand — with heart at its center — our purpose sends a personal message that how we deliver our services is just as important as what we deliver.
Our Heart At Work Behaviors™ support this purpose. We want everyone who works at CVS Health to feel empowered by the role they play in transforming our culture and accelerating our ability to innovate and deliver solutions to make health care more personal, convenient and affordable.
Who You Are
Strong technical expertise in building and operating secure, resilient infrastructure, with a deep understanding of modern operational security challenges in observability, cloud security, and security control effectiveness.
Strong technical expertise in automating security operations through engineered solutions, improving the efficiency and security posture of complex, distributed systems.
Proven ability to contribute to security operations, collaborating with senior engineers and cross-functional teams to ensure secure and reliable infrastructure.
Technical expertise in observability, anomaly detection, and incident response in distributed environments, utilizing metrics like KPIs and KRIs to drive security improvements.
Experience working with multi-cloud environments, including container/serverless and other microservice architectures.
Experience with implementing Zero Trust Security principles, focusing on access controls, identity management, and network segmentation across hybrid environments.
Experience with automating security workflows, such as patch management, security monitoring, and incident response, ensuring operational efficiency.
Experience with security monitoring tools, Web Application Firewalls (WAF), and API security management to protect critical systems from external threats.
Role Responsibilities
Development & Enforcement
Contribute to the development and enforcement of security engineering policies and standards focused on infrastructure, observability, and cloud environments, ensuring alignment with operational security goals.
Implement security operational automation, ensuring integration with systems such as SIEM, monitoring, and notification tools to improve operational efficiency and ensure security controls are functioning as intended.
Regularly evaluate and improve operational security policies and automation systems to address evolving threats, contributing to the security team's overall objectives.
Collaboration & Expertise
Collaborate with cross-functional teams, including infrastructure, development, and operations, to ensure security is integrated into operational processes and system monitoring.
Provide hands-on expertise in implementing secure operational engineering practices, ensuring security controls are effective and aligned with business goals.
Assist in the implementation and management of observability and anomaly detection systems to ensure prompt detection of security incidents and effective response through automation.
Analysis & Configuration
Analyze and configure operational security systems across cloud and on-prem environments, ensuring data integrity, confidentiality, and availability.
Support the deployment of operational security technologies, focusing on automation, scalability, and adaptability to defend against evolving threats.
Act as a technical contributor in operational security, maintaining security controls, monitoring, and helping manage dynamic, cloud-native, and distributed environments.
Operational Support
Participate in operational security support, assisting with monitoring and maintaining the health of security controls, and responding to security incidents in cloud and on-premises environments.
Utilize a metrics-driven approach to security operations, contributing to the evaluation of KPIs and KRIs to measure the organization’s security posture and improve response times.
Assist with managing Web Application Firewalls (WAF) and other security tools to protect critical systems from potential vulnerabilities and attacks.
Mentorship and Training
- Assist in knowledge sharing and collaboration within the security team, fostering a culture of continuous learning and technical excellence.
Innovation and Research
- Contribute to security research and innovation by exploring next-generation tools and practices, staying current with industry trends, and encouraging team contributions to open-source and security communities.
Strategic Planning
- Contribute to the development of the organization’s operational security roadmap, assisting in long-term security strategies that align with business goals and ensuring security is a priority across engineering teams.
Qualifications
Basic Qualifications
7+ years of experience in developing and deploying operational security technologies.
A minimum of a Bachelor’s degree in Computer Science, Information Security, Software Development, Software Engineering, or a related field, or equivalent alternative education, skills, and/or practical experience is required.
Technical expertise with cloud security (AWS/Azure/GCP), security control automation, and Zero Trust Security principles.
Experience with Docker, Kubernetes, Security-as-Code, and Infrastructure-as-Code.
Experience with one or more general-purpose programming/script languages including but not limited to: Java, C/C++, C#, Python, JavaScript, Shell Script, PowerShell.
Experience in designing and implementing security measures in multi-cloud and hybrid environments, with a focus on automation and scalability.
Proven experience working in security operations, showcasing hands-on project contributions and collaboration with cross-functional teams.
Preferred Qualifications
Technical expertise in observability and anomaly detection tools, Infrastructure-as-Code (IaC), and cloud-native security solutions.
Experience with cloud and container security practices, including Kubernetes and microservices architectures.
Experience with implementing Zero Trust Security practices, ensuring continuous verification and access control across cloud and on-prem environments.
Experience with implementing security automation programs, leveraging tools to ensure comprehensive and continuous security coverage.
Ability to collaborate in a team environment, contributing to cross-functional teamwork and problem-solving within security operations.
Experience in contributing to operational security initiatives, helping to drive improvements in security culture across the organization.
Pay Range
The typical pay range for this role is:
$118,450.00 - $260,590.00
This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company’s equity award program.
In addition to your compensation, enjoy the rewards of an organization that puts our heart into caring for our colleagues and our communities. The Company offers a full range of medical, dental, and vision benefits. Eligible employees may enroll in the Company’s 401(k) retirement savings plan, and an Employee Stock Purchase Plan is also available for eligible employees. The Company provides a fully-paid term life insurance plan to eligible employees, and short-term and long term disability benefits. CVS Health also offers numerous well-being programs, education assistance, free development courses, a CVS store discount, and discount programs with participating partners. As for time off, Company employees enjoy Paid Time Off (“PTO”) or vacation pay, as well as paid holidays throughout the calendar year. Number of paid holidays, sick time and other time off are provided consistent with relevant state law and Company policies.
For more detailed information on available benefits, please visit Benefits | CVS Health (https://jobs.cvshealth.com/us/en/benefits)
We anticipate the application window for this opening will close on: 02/21/2025
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.
We are an equal opportunity and affirmative action employer. We do not discriminate in recruiting, hiring, promotion, or any other personnel action based on race, ethnicity, color, national origin, sex/gender, sexual orientation, gender identity or expression, religion, age, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law.