Please mention DailyRemote when applying
Match your resume skills with our AI powered skill match!
The Distinguished Engineer serves as the senior technical leader for Application Security, defining the architectural strategy for securing software across web, mobile, and AI-native environments. They are responsible for integrating security controls into CI/CD pipelines and leading the enterprise adoption of AI-assisted development guardrails.
We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.
Position Summary
Serves as the senior technical leader and strategist for Application Security at CVS Health, setting the architectural direction for how the enterprise secures the software that it builds and integrates across web, mobile, API, microservice, and AI-native applications spanning cloud, on-prem, SaaS and hybrid environments. Partners with the AVP, Application Security to define and deliver an industry-leading application security program that shifts security responsibility left into design and development, enforces it consistently through CI/CD, and validates it continuously in production, replacing point-in-time scan-and-triage workflows with a developer-native, control-driven, threat-informed model.
Owns the technical strategy and end-to-end architecture of the application security tooling stack including SAST, DAST, SCA, IAST/RASP, secrets scanning, API security, IaC and container scanning, ASPM/ASOC and its integration into the Developer Experience platform and enterprise CI/CD pipelines, so that security controls are consumed as native platform capabilities by application teams rather than as separate bolt-on tools. Accountable for tool selection, evaluation, and integration planning across a rapidly evolving vendor landscape, including build-vs-buy decisions and consolidation into a coherent Application Security Posture Management (ASPM) view. Serves as the ultimately responsible architect for the components, tools, and services developed and operated by the Application Security team, including microservices that integrate AppSec tools into CI/CD, reusable components, setting design standards, leading design reviews, and contributing hands-on to critical components. Provides hands-on support to application teams adopting standards and tooling, ensuring that the secure path is also the easy and default path.
Charts the enterprise course through the rapidly evolving field of AI-assisted software development, establishing the technical strategy and guardrails for safe adoption of AI coding assistants, agentic coding tools, and AI-generated code across the engineering organization; evaluating and integrating AI-native application security tooling (AI-assisted triage, autofix, secure code review, threat modeling, and detection engineering); and helping the enterprise navigate emerging risks including insecure generated code, prompt injection in developer workflows, model and prompt supply-chain exposure, and IP/data leakage through AI tooling.
Partners with the Developer Experience team to design and deliver the developer-facing side of the program, secure-by-default paved paths, secure coding standards mapped to OWASP ASVS and NIST SSDF, and outcome-based metrics that translate application security posture into business risk. Partners closely with the Developer Experience team that manages the enterprise CI/CD pipelines, and with Security Engineering peers across Cloud Security, AI Security, Identity, Detection Engineering, and Exposure Management, to ensure application security controls are integrated end-to-end from developer laptop to production runtime. Operates as a trusted bridge between deeply technical engineering teams and business stakeholders, influencing strategy, investment, and execution across organizational boundaries without relying on direct authority.
This role can be remote anywhere in the continental USA.
Required Qualifications
Preferred Qualifications
Education
Bachelor's degree in Computer Science, Engineering, or a related field.
Pay Range
The typical pay range for this role is:
$175,100.00 - $334,750.00
This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company’s equity award program.
Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.
Great benefits for great people
We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.
Additional details about available benefits are provided during the application process and on Benefits Moments.
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Discover remote opportunities in Software Development
Answer easy questions
200,000+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”