Talent.com
Oak St. Health
AVP, Application SecurityOak St. Health • Providence, RI, United States
AVP, Application Security

AVP, Application Security

Oak St. Health • Providence, RI, United States
24 days ago
Job type
  • Full-time
Job description

Associate Vice President Of Application Security

We're building a world of health around every individual shaping a more connected, convenient and compassionate health experience. At CVS Health, you'll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger helping to simplify health care one person, one family and one community at a time.

CVS Health is seeking a polished and experienced security leader to serve as Associate Vice President of Application Security, responsible for defining and executing the enterprise strategy for securing software across its full development lifecycle. This role owns the policies, technical standards, and tooling that enable CVS Health's engineering teams to build and deploy secure applications at scale. The AVP will lead a high-performing team of application security engineers and architects, partner deeply with Developer Experience leadership to embed security seamlessly into agile development practices and serve as a trusted advisor to executive stakeholders on software security risk. This leader will balance targeted security outcomes with developer productivity, ensuring that security is an enabler not a barrier to innovation.

Key Responsibilities

Strategic Leadership

  • Define and own the enterprise application security strategy, roadmap, and policy framework, aligned with CVS Health's business objectives and regulatory obligations.
  • Establish and enforce technical standards for secure software development, including code scanning, code vulnerability management, and secure-by-design principles.
  • Serve as a subject matter expert and trusted advisor to senior technology and business executives on emerging application security risks, attack trends, and industry best practices.
  • Drive continuous improvement across the application security program through metrics, benchmarking, and innovation.

Application Security Engineering & Controls

  • Secure Development Lifecycle (SDLC) Integration: Lead the integration of application security scanning, testing, and policy enforcement gates into CI/CD pipelines across the enterprise. Partner with Developer Experience leadership to ensure security tooling is frictionless, developer-friendly, and compatible with agile delivery practices.
  • Static Application Security Testing (SAST): Define strategy, standards, and tooling for enterprise-wide SAST scanning. Manage tuning of rulesets to reduce false positives, drive remediation workflows, and ensure coverage across all critical code repositories.
  • Dynamic Application Security Testing (DAST): Oversee DAST program covering pre-production and production environments. Establish automated scanning schedules, triage processes, and integration with enterprise vulnerability management platforms.
  • Web Application Firewall (WAF) Management: Own the strategy, configuration, and operations of the enterprise WAF platform. Define and maintain rule sets, monitor for emerging threats, and ensure alignment with zero-trust and defense-in-depth principles.
  • Code Repository Scanning: Implement and manage continuous scanning of source code repositories for secrets, misconfigurations, exposed credentials, and policy violations. Establish guardrails and automated enforcement to prevent insecure code from reaching production.
  • AI-Assisted Code Generation Security: Develop policies and technical controls to assess and govern security risks introduced by AI-assisted code generation tools (e.g., GitHub Copilot, generative AI coding assistants). Define standards for safe use and implement scanning capabilities to detect AI-generated code vulnerabilities.
  • Third-Party and Open-Source Software (SCA) Scanning: Manage the Software Composition Analysis (SCA) program to identify and remediate vulnerabilities in third-party libraries and open-source dependencies. Maintain visibility into the software supply chain and drive compliance with internal ingestion policies.
  • Content Delivery Network (CDN) Security Management: Oversee security configuration and policy enforcement for content delivery network infrastructure. Ensure CDN-layer protections including DDoS mitigation, bot management, and TLS standards are aligned with enterprise security policy.
  • Application Security Technology Stack: Own the full application security tooling portfolio. Manage vendor relationships, licensing, platform health, and roadmap alignment. Evaluate and introduce emerging technologies to improve coverage, automation, and developer experience.

Governance & Compliance

  • Define and maintain application security policies, standards, and operational procedures.
  • Ensure compliance with applicable regulatory frameworks and industry standards, including HIPAA, PCI-DSS, CCPA, NIST SSDF, and OWASP.
  • Provide executive-level reporting and governance dashboards that communicate program health, risk posture, and remediation progress.
  • Establish and maintain a risk-based vulnerability management process focused specifically on software development vulnerabilities, including those introduced through code, dependencies, and the build and deployment pipeline, in partnership with peer security organizations.

Leadership & Collaboration

  • Build, lead, and develop a high-performing team of application security engineers, architects, and program managers.
  • Partner closely with Developer Experience leadership to align security tooling and practices with developer workflows, ensuring security is integrated seamlessly into agile and DevSecOps pipelines.
  • Collaborate with Cyber Defense, Data Protection, Infrastructure Security, Legal, Compliance, and Technology leadership to deliver integrated security outcomes.
  • Partner with Chief Data and Technology Officers (CDTOs) across CVS Health business units to understand technology strategies, influence security-targeted outcomes, and ensure application security priorities are embedded within divisional roadmaps and investment decisions.
  • Foster a security-minded engineering culture through developer education, secure coding training, security champion programs, and engagement with engineering communities of practice.

Key Performance Indicators (KPIs)

  • Pipeline Coverage: Percentage of active software development pipelines with integrated SAST, DAST, and SCA scanning controls.
  • Vulnerability Remediation SLA: Mean time to remediate (MTTR) critical and high application security vulnerabilities, tracked against defined SLAs.
  • Secrets & Policy Violations: Reduction in secrets exposed in code repositories and policy violations detected year-over-year.
  • WAF Effectiveness: Percentage of malicious web traffic blocked; reduction in application-layer incidents attributed to WAF-protected assets.
  • Third-Party Risk Coverage: Percentage of production applications with up-to-date SCA coverage and no unaddressed critical open-source vulnerabilities.
  • AI Code Security: Coverage rate of AI-assisted code generation under security policy and scanning controls.
  • Developer Experience Satisfaction: Developer NPS and feedback scores related to security tooling and friction within the SDLC.
  • Regulatory Compliance: Audit findings related to application security controls, targeting zero critical findings.
  • Program Adoption: Number of development teams operating under the secure SDLC framework and security champion program.
  • Roadmap Delivery: On-time completion of strategic application security initiatives and tooling milestones.

Required Qualifications

  • 12+ years of progressive experience in information security, with at least 5 years in application security leadership roles.
  • Deep technical background in software development, including hands-on coding experience in one or more modern programming languages (e.g., Java, Python, Go, JavaScript, or similar). Candidates must bring developer-level fluency to credibly engage with engineering teams, evaluate code-level risks, and drive meaningful secure coding practices.
  • Demonstrated expertise in application security engineering and secure software development lifecycle (SDLC) practices, grounded in first-hand experience building or shipping software.
  • Strong understanding of software architecture patterns, CI/CD pipelines, containerization, and cloud-native development with the ability to assess security implications at every layer of the stack.
  • Hands-on experience managing enterprise application security tooling, including SAST, DAST, SCA, WAF, and repository scanning platforms.
  • Deep knowledge of application security standards and frameworks, including OWASP Top 10, NIST SSDF, and relevant regulatory requirements (HIPAA, PCI-DSS, CCPA).
  • Proven ability to influence engineering culture and drive security adoption at scale within agile development environments.
  • Strong leadership skills with experience building and managing cross-functional technical teams and influencing senior stakeholders.
  • Excellent communication and presentation skills; ability to translate complex security concepts for both technical and non-technical audiences.

Preferred Qualifications

  • Advanced degree in Computer Science, Information Security, or a related field.
  • Certifications such as CISSP
Create a job alert for this search

AVP, Application Security • Providence, RI, United States

Similar jobs

Security- Xfinity Center

Live Nation EntertainmentMansfield, MA, United States
Full-time

Job Summary:WHO ARE WE?Live Nation Entertainment is the world's leading live entertainment company, comprised of global market leaders: Ticketmaster, Live Nation Concerts, and Live Nation Media &am... Show more

 • Promoted

PT Security - Providence Marriott Downtown

Meyer Jabara HotelsProvidence, RI, United States
Full-time

Marriott Providence DowntownProtect the hotel guests, associates and hotel property.Respond to emergency situations and use good judgment, serving the best interest of the Providence Marriott Downt... Show more

 • Promoted

Remote Building Code Compliance Expert

Micro1Newport, Rhode Island, US
$50.00 hourly
Remote
Full-time

Building Code Compliance Expert.Plan review and blueprint reading.AI data lab for training frontier models and evaluating AI agents.Experts contribute their diverse subject matter knowledge across ... Show more

 • Promoted

Remote Consumer Insights Participant

GL IncNewport, Rhode Island
$15.00 hourly
Remote
Part-time +1

Product Testers are wanted to work from home nationwide in the US to fulfill upcoming contracts with national and international companies.We guarantee 15-25 hours per week with an hourly pay of bet... Show more

 • Promoted

Project Manager

Software Technology, Inc.Providence, RI, United States
Full-time

The Project Manager (PM) is responsible for day-to-day management and execution of multiple medium projects and large or extra-large projects through the project lifecycle.The PM will be expected t... Show more

 • Promoted

Customer Security Assurance Specialist

DatavantProvidence, RI, United States
Full-time

Join Datavant, the data collaboration platform that is revolutionizing healthcare! Our mission is to secure, access, and utilize the world's health data effectively.We offer vital data solutions th... Show more

 • Promoted

Advanced Management Partner

CintasPawtucket, RI, United States
Full-time

Cintas is seeking an Advanced Management Partner to be trained and prepped for Senior Leadership roles.Each assignment prior to the role of General Manager will be hands-on and designed to teach th... Show more

 • Promoted

Senior Offensive Security Consultant

SHI GmbHProvidence, RI, United States
Full-time

About UsAt Stratascale, we are a dynamic digital and cybersecurity services company dedicated to empowering Fortune 1000 companies to effectively harness technology, drive business growth, and swif... Show more

 • Promoted

Security Officers

USentra SecurityNewport, RI, United States
Part-time

USENTRA Security Services - Looking for a few good security professionals to join our team and fill part time positions.These positions are at an upscale residential property in Newport, RI.Duties ... Show more

 • Promoted

Security & Law Enforcement

U.S. NavyMiddletown, RI, United States
Full-time

Job Title :Security & Law Enforcement (Master-at-Arms) Category / Component :Enlisted Active Overview Master-at-Arms (MA) Sailors provide the Navy's core security, antiterrorism, and law enforc... Show more

 • Promoted

Security Specialist II (INFOSEC & Visitor and Access Control)

ArmadaNewport, RI, United States
Full-time

Type: Full TimeLocation: Newport, RIOvertime Exempt: YesReports To: ARMADA HQSecurity Clearance Required: Active Top SecretThe Security Specialist II (INFOSEC & Visitor and Access Control) shal... Show more

 • Promoted

3rd Shift Security

The Dunes ClubNarragansett, RI, United States
Full-time

Seasonal Beach/Tennis Club(May through October) looking for 3rd shift security personnel.As part of our Security personnel, you would be responsible for ensuring the safety of guests and employees ... Show more

 • Promoted

Security Director

Aya HealthcareAttleboro, MA, United States
Temporary

Director Of Safety, Security, Emergency Management, And Hazardous Materials.The Director provides enterprise leadership for Safety, Security, Emergency Management, and Hazardous Materials programs ... Show more

 • Promoted

Unarmed Security Officer for Banking Sector

Inter-Con SecurityProvidence, RI, United States
Full-time

Join Our Team at Inter-Con Security Systems, Inc.Founded in 1973, Inter-Con Security Systems, Inc.US-owned security firm delivering customized security solutions across the globe.As a family-owned ... Show more

 • Promoted

Consumer Insights Analyst

Earn HausPeace Dale, Rhode Island, United States
Full-time +1

We are urgently seeking people interested in taking market research studies for well known brands.If you are a self-starter, looking for flexible hours throughout the week, this may be for you! Ear... Show more

 • Promoted

Mgr Security

Brown University HealthNewport, RI, United States
Full-time

Reports to the Newport Hospital Director of Operations.Provides a safe and secure environment for patients, employees, and visitors.Manages day-to-day operations of the Security Department.Develops... Show more

 • Promoted

Analyst

TradeJobsWorkforce02915 East Providence, RI, US
Full-time

ESSENTIAL JOB FUNCTIONS Analyzes global markets for IT Services, servers, storage, backup, IT security, productivity software, remote monitoring services, hyperconvergence and IoT.Studies SMB and m... Show more

 • Promoted

Earn up to $400 per Day by Playing Games and TakingSurveys

Freecash.comNewport, Rhode Island, United States
Full-time

Since its launch 6 years ago, over 60MN users have earned and withdrawn over $250MN! The platform is rated 4.TrustPilot with over 230k+ reviews, establishing Freecash as one of the highest-rated op... Show more