At CVS Health, we’re building a world of health around every consumer and surrounding ourselves with dedicated colleagues who are passionate about transforming health care.
As the nation’s leading health solutions company, we reach millions of Americans through our local presence, digital channels and more than 300,000 purpose-driven colleagues – caring for people where, when and how they choose in a way that is uniquely more connected, more convenient and more compassionate. And we do it all with heart, each and every day.
Position Summary
The Vulnerability Analysis Staff Engineer is responsible for performing an analysis of vulnerabilities leveraging additional risk telemetry data and compensating security tools in the organization’s systems, applications, and networks to perform contextual risk identification. This role plays a crucial part in strengthening the organization’s cybersecurity posture by proactively analyzing vulnerabilities, collaborating with various teams, and recommending effective remediation strategies. The ideal candidate has strong technical skills, a deep understanding of security frameworks, and a proactive mindset.
Key Responsibilities
Vulnerability Assessment
-
Analyze vulnerability scan results and additional risk telemetry to determine the severity, impact, and risk of identified vulnerabilities.
-
Research emerging threats and vulnerabilities to stay ahead of potential risks.
-
Identify the appropriate risk severity and corresponding remediation service level agreement (SLA) after vulnerability analysis.
Remediation and Mitigation
-
Collaborate with IT, DevOps, and application teams to develop appropriate remediation strategies.
-
Provide technical guidance on patch management, security policy configuration changes, and other mitigation measures.
-
Track and validate the effectiveness of remediation efforts to ensure vulnerabilities are resolved.
Threat Analysis and Reporting
-
Perform in-depth analysis of vulnerabilities to determine potential exploit scenarios and business impact.
-
Create detailed reports and dashboards for stakeholders, highlighting key findings, risks, and mitigation status.
-
Present vulnerability assessment findings to leadership, providing clear recommendations for risk reduction.
Collaboration and Cross-Functional Partnership
-
Partner closely with IT, infrastructure, business units, and other stakeholders to ensure remediation strategies effectively integrated and aligned with enterprise architecture.
-
Partner with compliance and risk management teams to ensure remediation strategies meet regulatory requirements.
Policy and Compliance
-
Ensure vulnerability management practices align with security frameworks (e.g., NIST, CIS, ISO 27001) and regulatory requirements (e.g., PCI DSS, HIPAA).
-
Support audit and compliance efforts by providing necessary data and documentation on vulnerability management activities.
Continuous Improvement
-
Identify opportunities to enhance vulnerability management processes and tools.
-
Assist with the automation of routine tasks, such as scanning, reporting, and remediation tracking, to improve efficiency.
-
Contribute to the development and refinement of security policies, procedures, and best practices.
Required Qualifications
-
7+ years of experience in vulnerability management, cybersecurity, or a related field.
-
5+ hands-on experience with vulnerability risk detection tools (e.g., Qualys, Crowdstrike, Tanium, Microsoft Defender, Wiz).
-
5+ years of experience with cybersecurity frameworks (CIS, NIST, ISO 27001) and regulatory requirements (GDPR, HIPAA, etc.)
Preferred Qualifications
-
Knowledge of common vulnerabilities and exploitation techniques (e.g., OWASP Top 10, CVSS).
-
Proficiency in operating systems (Windows, Linux) and network protocols.
-
Understanding of cloud security (AWS, Azure, GCP) and container security (e.g., Kubernetes, Docker).
-
Familiarity with scripting and automation tools (e.g., Python, Bash, PowerShell).
-
Strong analytical and problem-solving abilities.
-
Excellent communication skills, with the ability to convey technical information to both technical and non-technical audiences.
-
Attention to detail and a proactive approach to identifying and resolving vulnerabilities.
-
CEH (Certified Ethical Hacker)
-
CISSP (Certified Information Systems Security Professional)
-
GIAC certifications (e.g., GSEC, GCIA, GPEN)
-
CCFA (Crowdstrike Certified Falcon Administrator)
-
QFIM (Qualys File Integrity Monitoring)
-
QPolicy (Qualys Policy Compliance)
Education
Bachelor’s degree, or equivalent experience (HS diploma + 4 years relevant experience)
Business Overview
Bring your heart to CVS Health Every one of us at CVS Health shares a single, clear purpose: Bringing our heart to every moment of your health. This purpose guides our commitment to deliver enhanced human-centric health care for a rapidly changing world. Anchored in our brand — with heart at its center — our purpose sends a personal message that how we deliver our services is just as important as what we deliver. Our Heart At Work Behaviors™ support this purpose. We want everyone who works at CVS Health to feel empowered by the role they play in transforming our culture and accelerating our ability to innovate and deliver solutions to make health care more personal, convenient and affordable. We strive to promote and sustain a culture of diversity, inclusion and belonging every day. CVS Health is an affirmative action employer, and is an equal opportunity employer, as are the physician-owned businesses for which CVS Health provides management services. We do not discriminate in recruiting, hiring, promotion, or any other personnel action based on race, ethnicity, color, national origin, sex/gender, sexual orientation, gender identity or expression, religion, age, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law. We proudly support and encourage people with military experience (active, veterans, reservists and National Guard) as well as military spouses to apply for CVS Health job opportunities.
Pay Range
The typical pay range for this role is:
$118,450.00 - $284,280.00
This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company’s equity award program.
Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.
Great benefits for great people
We take pride in our comprehensive and competitive mix of pay and benefits – investing in the physical, emotional and financial wellness of our colleagues and their families to help them be the healthiest they can be. In addition to our competitive wages, our great benefits include:
-
Affordable medical plan options, a 401(k) plan (including matching company contributions), and an employee stock purchase plan .
-
No-cost programs for all colleagues including wellness screenings, tobacco cessation and weight management programs, confidential counseling and financial coaching.
-
Benefit solutions that address the different needs and preferences of our colleagues including paid time off, flexible work schedules, family leave, dependent care resources, colleague assistance programs, tuition assistance, retiree medical access and many other benefits depending on eligibility.
For more information, visit https://jobs.cvshealth.com/us/en/benefits
We anticipate the application window for this opening will close on: 03/27/2025
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.
We are an equal opportunity and affirmative action employer. We do not discriminate in recruiting, hiring, promotion, or any other personnel action based on race, ethnicity, color, national origin, sex/gender, sexual orientation, gender identity or expression, religion, age, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law.