FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Staff Application Security Engineer – Blue Team
CVS Health. Design, implement, and maintain defensive security controls across applications, cloud platforms, data systems, and network environments .
Posted 9/15/2026full-timeRemote • California • United StatesLead💰 $130,295 - $260,590 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in security engineering, application security, and cloud security, with a strong focus on implementing and maintaining defensive security controls across various environments. Proficient in developing security standards, conducting assessments, and leading incident response activities while mentoring teams on secure practices.
Highest-signal resume keywords
Security EngineeringCloud Security (AWS, Azure, GCP)Defensive Security OperationsIncident Response LeadershipSecurity Compliance Frameworks (NIST, PCI DSS, HIPAA)
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Security Architecture ReviewsThreat ModelingVulnerability AssessmentSecure CodingAutomation SolutionsData Protection ControlsInfrastructure-as-CodeSecurity-as-CodeNetwork Architecture DiagramsCyber Resilience Strategies
Soft Skills
MentoringCollaborationTechnical Leadership
Tools & Technologies
DockerKubernetesPythonJavaC#JavaScriptShellPowerShellSnowflakeCI/CD Pipelines
Certifications & Qualifications
CISSPCCSPGSECGIACAWS Security SpecialtyAzure Security Engineer Associate
Industry Keywords
GDPRCCPAISO 27001SOC 2HITRUSTZero-Trust ArchitecturesCloud Security ModelsData WarehousingBusiness ContinuityRegulatory Compliance
Tech Stack
Tools & technologiesAWSAzureCloudDockerGoogle Cloud PlatformJavaJavaScriptKubernetesPythonSDLC
About the role
Key responsibilities & impact- Design, implement, and maintain defensive security controls across applications, cloud platforms, data systems, and network environments
- Develop and enforce enterprise-wide application and data security standards, policies, and best practices
- Embed security controls into SDLC processes, CI/CD pipelines, and deployment automation frameworks
- Lead security architecture reviews and establish security governance frameworks
- Partner with Engineering, Infrastructure, Architecture, and Business teams on secure-by-design practices
- Serve as a trusted advisor and technical leader for Application Security, Cloud Security, and Secure Development
- Monitor, detect, investigate, and respond to security events, vulnerabilities, threats, and incidents
- Lead vulnerability assessments, remediation planning, risk prioritization, and validation
- Conduct security assessments, threat modeling, and architecture reviews
- Implement advanced security solutions across multi-cloud, colocation, and enterprise environments
- Participate in a rotational 24x7 on-call schedule, including off-hours, nights, weekends, and holidays
- Lead incident response activities including investigation, containment, eradication, recovery, and post-incident reviews
- Develop and improve incident response, detection, escalation, and recovery playbooks
- Mentor and coach engineers on secure coding, security engineering, and defensive operations
- Research emerging threats, vulnerabilities, attack techniques, and security technologies
- Evaluate and recommend security tools, platforms, and defensive capabilities
- Automate security operations using code and Security-as-Code principles
- Contribute to long-term security strategy, architecture roadmaps, technology planning, and enterprise security objectives
- Partner with leadership to prioritize security investments and risk reduction activities
Requirements
What you’ll need- 7+ years of experience in security engineering, application security, cloud security, or defensive security operations
- 3+ years of experience securing AWS, Azure, and GCP cloud platforms
- 3+ years of experience with Docker, Kubernetes, Infrastructure-as-Code, and Security-as-Code methodologies
- 3+ years of experience with programming or scripting languages such as Python, Java, C#, JavaScript, Shell, or PowerShell
- 3+ years of experience in networking, identity management, authentication, authorization, and threat mitigation techniques
- Experience designing and operating defensive security controls in cloud-native, containerized, and distributed application environments
- Experience with data protection controls and regulatory/compliance requirements including GDPR, CCPA, or similar frameworks
- Experience designing and implementing enterprise-scale security controls and automation solutions
- Understanding of networking, SDN, zero-trust architectures, and cloud security models
- Experience with threat modeling, security architecture reviews, and secure design assessments
- Ability to develop and interpret network, sequence, application architecture, and data flow diagrams
- Experience with security and compliance frameworks such as NIST, PCI DSS, HIPAA, HITRUST, ISO 27001, SOC 2, or CSA
- Experience securing enterprise data platforms, analytics environments, and data warehouses including Snowflake or similar technologies
- Experience defining and implementing cyber resilience, business continuity, backup, redundancy, and recovery strategies
- Relevant industry certifications such as CISSP, CCSP, GSEC, GIAC, AWS Security Specialty, Azure Security Engineer Associate, or equivalent
- Bachelor’s degree from an accredited college or university, or equivalent combination of education and relevant work experience (High School Diploma/GED plus 4 years of related experience)
Benefits
Comp & perks- Medical coverage
- Dental coverage
- Vision coverage
- Paid time off
- Retirement savings options
- Wellness programs
- Other resources supporting physical, emotional, and financial well-being
- CVS Health bonus, commission or short-term incentive program
- Equity award program