FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Staff DevSecOps Engineer, Health
CVS Health. Lead technical implementation, migration, automation, mobile application security and standardization across the Health 100 portfolio .
Posted 9/18/2026full-timeRemote • Connecticut • United StatesLead💰 $130,295 - $260,590 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in DevSecOps, application security, and cloud security, with a strong focus on implementing security controls within CI/CD pipelines. Proven ability to lead technical initiatives, mentor teams, and drive measurable security outcomes across complex engineering environments.
Highest-signal resume keywords
DevSecOps ImplementationCI/CD Security ControlsApplication Security EngineeringCloud Security ExpertiseMobile Application Security Testing
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
PythonJavaJavaScriptGoShellPowerShellSASTSCAContainer ScanningInfrastructure-as-Code
Soft Skills
MentoringCommunicationProblem-SolvingCollaborationLeadership
Tools & Technologies
AWSAzureGCPDockerKubernetesSnykCheckmarxGitleaksData TheoremMobSF
Industry Keywords
HIPAAHITRUSTPCINISTGDPRCCPASoftware Supply Chain SecurityOpen-Source RiskMobile Threat ModelingSecurity-as-Code
Tech Stack
Tools & technologiesAndroidAWSAzureCloudDockerGoogle Cloud PlatformiOSJavaJavaScriptKubernetesPythonGo
About the role
Key responsibilities & impact- Lead technical implementation, migration, automation, mobile application security and standardization across the Health 100 portfolio
- Support application onboarding and security enablement for Health 100 initiatives
- Help development teams meet security requirements through standard tooling, pipeline integration and repeatable implementation patterns
- Translate release-readiness expectations into repeatable technical patterns and evidence
- Enable mobile application security testing, secure configuration validation and remediation guidance
- Lead DevSecOps implementation initiatives, including technical planning, architecture, delivery, issue resolution and implementation outcomes
- Coordinate across application, platform and security teams to remove blockers and sustain adoption
- Design, implement and improve CI/CD security controls, pipeline enforcement and automated scanning workflows
- Build self-service security solutions and reusable automation
- Automate secret-detection and CI/CD security workflows, including Gitleaks or comparable capabilities
- Lead security-tool migrations such as Checkmarx to Snyk through stable production operation
- Produce and validate post-migration scan results
- Standardize tooling configurations across development teams
- Drive remediation of critical and high-risk vulnerabilities and monitor remediation against SLAs
- Lead prioritization of open-source and software supply chain exposures
- Improve SBOM coverage and secure-by-default dependency usage
- Engineer controls for public cloud, containers, Kubernetes, Security-as-Code and Infrastructure-as-Code environments
- Apply network-security, cloud-architecture and mobile-security expertise to assess risks and guide remediation
- Track and report scan coverage, mobile testing coverage, vulnerability aging, SLA adherence, remediation effectiveness, automation adoption, tool coverage and pipeline compliance
- Provide executive-ready updates on implementation progress, delivery risk and measurable security outcomes
- Mentor engineers, establish reusable engineering patterns and create implementation guidance and education
Requirements
What you’ll need- 7+ years of experience in DevSecOps, application security engineering, platform security or software engineering
- Experience integrating SAST, SCA, secrets detection, container scanning, IaC scanning or comparable security controls into CI/CD pipelines
- Experience leading security implementations or tool migrations in large or complex engineering environments
- Proficiency in public cloud platforms such as AWS, Azure or GCP, plus cloud and network security concepts
- Experience with Docker, Kubernetes, Security-as-Code and Infrastructure-as-Code
- Hands-on scripting or programming experience in Python, Java, JavaScript, Go, Shell or PowerShell
- Experience with application vulnerability management, open-source risk and software supply chain security
- Experience with mobile application security testing, mobile threat modeling, or remediation of iOS and Android application security findings
- Demonstrated ability to use metrics to drive adoption, remediation and measurable technical outcomes
- Bachelor's degree in Computer Science, Software Development, Software Engineering or a related field, or equivalent practical experience
- Preferred: experience with portfolio-based initiatives or prioritized application sets such as Health 100
- Preferred: hands-on experience with Snyk, Checkmarx, Gitleaks, SBOM tooling or comparable platforms
- Preferred: hands-on experience with Data Theorem, MobSF or comparable mobile testing tools
- Preferred: expertise architecting public cloud security solutions and scalable engineering processes
- Preferred: strong understanding of networking and Software-Defined Networking principles
- Preferred: experience with security solutions for data warehouses or big-data platforms, including Snowflake
- Preferred: familiarity with HIPAA, HITRUST, PCI, NIST, GDPR or CCPA
- Preferred: experience communicating technical security outcomes and risk posture to senior leadership
Benefits
Comp & perks- CVS Health bonus, commission or short-term incentive program in addition to base pay
- Equity award program
- Medical coverage
- Dental coverage
- Vision coverage
- Paid time off
- Retirement savings options
- Wellness programs
- Other resources supporting physical, emotional, and financial well-being