CVS Health→
Analyst, Information Security at CVS Health in Remote
Entry LevelRemoteFull-timeRemote$62k–$124k/yr
Skills
security technologiessoftware development practicesci/cd pipelinesvulnerability scanning toolssastscamobile scanningapi scanningpublic cloud platformsawsazuregcpnetwork security conceptsdockerkubernetessecurity-as-codeinfrastructure-as-codeprogramming languagesjavapythonc#javascriptshell scriptingpowershelldata protectionencryptionprivacy regulationsgdprccpa
Job Description
Summary: CVS Health is dedicated to building a more connected and compassionate health experience. They are looking for a Junior Security Engineer to help develop secure systems, support engineering teams, and participate in security practices across various domains.
Responsibilities:
- Help develop and maintain engineering and data security policies and standards
- Contribute to security awareness efforts across the organization
- Support Engineering and Business teams in applying secure engineering practices
- Assist with application security reviews and participate in security discussions
- Learn how to integrate security into each stage of the software development lifecycle
- Assist in configuring and analyzing security tools across cloud and on‑prem environments
- Support security testing, vulnerability analysis, and documentation
- Participate in an on‑call rotation with guidance and mentorship
- Help develop incident response procedures and learn recovery strategies
Required Qualifications:
- 1–2 years of experience developing or deploying security technologies (internships and academic projects count)
- Familiarity with modern software development practices and CI/CD pipelines
- Experience using vulnerability scanning tools (SAST, SCA, mobile scanning, API scanning) and handling basic remediation
- Foundational understanding of public cloud platforms (AWS, Azure, or GCP) and core network security concepts
- Exposure to Docker, Kubernetes, Security‑as‑Code, or Infrastructure‑as‑Code tools
- Experience with at least one programming or scripting language (Java, Python, C#, JavaScript, Shell, PowerShell, etc.)
- Interest in data protection, encryption, and privacy regulations (GDPR, CCPA)
- A Bachelor's degree in Computer Science, Software Development, Software Engineering, or a related field, or equivalent alternative education, skills, and/or practical experience is required
Preferred Qualifications:
- Familiarity with cloud architecture concepts
- Understanding of networking fundamentals and software‑defined networking (SDN)
- Ability to read or create basic network, sequence, or data flow diagrams
- Awareness of the OWASP Application Security Verification Standard (ASVS)
- Experience collaborating with remote or distributed teams
- Knowledge of compliance frameworks such as HIPAA, HITRUST, PCI, NIST, or CSA
- Exposure to security tools like GitHub Advanced Security, CodeQL, Checkmarx, or Snyk
- Interest in building resilient, fault‑tolerant systems in cloud environments
Required Skills: Security technologies, Software development practices, CI/CD pipelines, Vulnerability scanning tools, SAST, SCA, Mobile scanning, API scanning, Public cloud platforms, AWS, Azure, GCP, Network security concepts, Docker, Kubernetes, Security-as-Code, Infrastructure-as-Code, Programming languages, Java, Python, C#, JavaScript, Shell scripting, PowerShell, Data protection, Encryption, Privacy regulations, GDPR, CCPA
Benefits: Medical, dental, and vision coverage, Paid time off, Retirement savings options, Wellness programs, Other resources
Benefits
Medical, dental, and vision coverage
Paid time off
Retirement savings options
Wellness programs
Other resources