Distinguished Engineer, Application Security

CVS Health

Confirmed live 2 days ago High trust
Remote

Quick summary

Work type
Remote
Location
AZ
Salary
$175,100–$334,750 / yr
Posted
9 days ago
Freshness
Confirmed live 2 days ago
Closes
Dec 31, 2026

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $184k
This role $255k
$111k most similar roles pay here $359k

This role pays more than 91% of similar roles. Most pay $151,493–$216,571 — the shaded band above. At the midpoint, this role pays about $255k versus about $184k for comparable roles.

Based on 240 similar postings.

Employer

About CVS Health

CVS Health is a leading American healthcare company operating retail pharmacies, pharmacy benefit management services, and a health insurance segment through Aetna, one of the nation''s largest health insurers. Industry: Healthcare & Pharmacy

CVS Health currently has 88 open roles on FindRole.

Listed pay typically runs $118,450–$284,280 across 84 roles with salary data.

Most-posted roles

View all roles at CVS Health

At a glance

TL;DR · Distinguished Engineer, Application Security

Distinguished Engineer - Application Security serves as a senior technical leader and strategist responsible for the architectural direction of application security across web, mobile, API, microservice, and AI-native applications. This role involves building an industry-leading program that shifts security left into design and development while integrating tools like SAST, DAST, SCA, IAST/RASP, and secrets scanning into CI/CD pipelines. The position requires hands-on expertise in multiple languages including Java, C#, JavaScript, TypeScript, Python, and Go. Key responsibilities include establishing guardrails for AI-assisted software development, managing security posture through ASPM platforms, and ensuring compliance with standards like OWASP ASVS and NIST SSDF. The role addresses complex challenges in the healthcare sector, specifically securing systems involving PHI, HIPAA regulations, and PCI-scoped applications while navigating risks like prompt injection and insecure generated code.

What does a Engineer earn in Remote?

Median $189520 from 49 postings across 15 companies.

See salary data

What you'll do

  • Define the architectural direction and technical strategy for enterprise application security across web, mobile, API, and AI-native platforms.
  • Manage the end-to-end architecture of the application security tooling stack including SAST, DAST, SCA, IAST/RASP, and container scanning.
  • Integrate security controls into CI/CD pipelines to provide developer-native, control-driven, and continuous security capabilities.
  • Establish technical guardrails and strategies for the safe adoption of AI coding assistants and AI-generated code across the organization.
  • Lead the selection, evaluation, and integration of third-party security tools while managing build-vs-buy decisions.
  • Provide hands-on engineering support to application teams to ensure secure development is the default path.
  • Translate complex technical security requirements into actionable business risk metrics for executive leadership and stakeholders.
  • Oversee the design and operation of microservices and components that integrate security tools into developer platforms.

What we're looking for

  • 15+ years of experience in technical roles with an ability to influence without authority across technical and executive audiences.
  • 10+ years of experience acting as a bridge between deep technical work and business strategy.
  • 10+ years of hands-on software engineering experience across multiple language ecosystems including Java, C#, JavaScript/TypeScript, Python, and Go.
  • 8+ years in application security or product security roles at enterprise scale involving threat modeling, secure design review, and vulnerability triage.
  • 5+ years setting multi-year technical strategy and architectural roadmaps for enterprise-scale application security or DevSecOps programs.
  • Deep knowledge of the modern application security tooling landscape including SAST, DAST, SCA, IAST/RASP, secrets scanning, API security, and container/IaC scanning.
  • Experience integrating security controls into modern CI/CD pipelines and developer platforms as native, low-friction capabilities.
  • A Bachelor's degree in Computer Science, Engineering, or a related technical field is required.

More like this

Similar roles

Senior Application Security Engineer

AbbVie

Irvine, CA 42 days ago $109,500$208,500
SAST DAST IAST SCA ASPM CI/CD DevSecOps Java Node.js Python AWS Azure Terraform CloudFormation CSPM Snyk Endor Labs OWASP Top 10 CWE
7+ yrs exp

Senior Application Security Engineer

AbbVie

Chicago, IL 42 days ago $109,500$208,500
SAST DAST IAST SCA ASPM CI/CD DevSecOps Java Node.js Python AWS Azure Terraform CloudFormation OWASP Top 10 CWE CSPM Snyk Endor Labs
7+ yrs exp

Junior Application Security Engineer

AbbVie

Chicago, IL 9 days ago $84,500$162,000
Application Security SAST DAST IAST SCA ASPM CI/CD DevSecOps Java Node.js Python Snyk Endor Labs CSPM OWASP Top 10 CWE Containerization
5+ yrs exp

Application Security Engineer

AbbVie

Chicago, IL 9 days ago $84,500$162,000
Application Security SAST DAST IAST SCA ASPM CI/CD DevSecOps Java Node.js Python Snyk Endor Labs CSPM OWASP Top 10 CWE Containerization
5+ yrs exp

Application Security Engineer

Opendoor

Toronto, Canada 86 days ago
Go Python TypeScript Ruby Terraform AWS GCP Azure Kubernetes GraphQL Apollo GitHub Advanced Security CodeQL Semgrep HackerOne Burp Suite Cloudflare WAF Claude OpenAI REST gRPC Threat Modeling
5+ yrs exp Hybrid

Application Security Engineer

Opendoor

Miami, FL 86 days ago
Go Python TypeScript Ruby Terraform AWS GCP Azure Kubernetes GraphQL Apollo GitHub Advanced Security CodeQL Semgrep HackerOne Burp Suite Cloudflare WAF Claude OpenAI REST gRPC Threat Modeling
5+ yrs exp Hybrid