Staff DevSecOps Engineer

CVS Health

Confirmed live yesterday High trust
Remote

Quick summary

Work type
Remote
Location
MassachusettsConnecticutNew YorkRhode Island
Salary
$130,295–$260,590 / yr
Employment
Full-time
Posted
14 days ago
Freshness
Confirmed live yesterday
Closes
Oct 30, 2026

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $173k
This role $195k
$112k most similar roles pay here $277k

This role pays more than 65% of similar roles. Most pay $129,200–$216,000 — the shaded band above. At the midpoint, this role pays about $195k versus about $173k for comparable roles.

Based on 240 similar postings.

Employer

About CVS Health

CVS Health is a leading American healthcare company operating retail pharmacies, pharmacy benefit management services, and a health insurance segment through Aetna, one of the nation''s largest health insurers. Industry: Healthcare & Pharmacy

CVS Health currently has 81 open roles on FindRole.

Listed pay typically runs $106,605–$260,590 across 80 roles with salary data.

Most-posted roles

View all roles at CVS Health

At a glance

TL;DR · Staff DevSecOps Engineer

Staff DevSecOps Engineer (Health 100) The Staff DevSecOps Engineer leads technical implementation, migration, automation, mobile application security, and standardization across the Health 100 portfolio. This role translates security strategy into scalable engineering solutions to improve release readiness, vulnerability remediation, and secure-by-default delivery. Responsibilities include designing CI/CD security controls, managing tool migrations from Checkmarx to Snyk, automating secret detection with Gitleaks, and ensuring SBOM coverage for software supply chain security. The engineer manages risks across public cloud platforms like AWS, Azure, or GCP, while securing containerized environments using Docker and Kubernetes. Key technical requirements include proficiency in Python, Java, JavaScript, Go, Shell, or PowerShell, alongside expertise in Infrastructure-as-Code and Security-as-Code. This role addresses the challenge of balancing security enforcement with developer efficiency by providing automated tools and clear remediation guidance for high-risk vulnerabilities across a complex application ecosystem.

What you'll do

  • Lead technical implementation of DevSecOps initiatives, including security tool migrations and infrastructure automation across the Health 100 portfolio.
  • Design and implement automated CI/CD security controls, secret detection workflows, and self-service tools to reduce manual effort.
  • Standardize security tooling configurations and pipeline requirements across multiple development teams to ensure consistent policy alignment.
  • Drive the remediation of high-risk vulnerabilities and manage software supply chain risks through SBOM coverage and dependency management.
  • Engineer security controls for cloud environments, including Kubernetes, container security, and Infrastructure-as-Code (IaC) implementations.
  • Perform mobile application security testing and provide specific remediation guidance for iOS and Android platforms.
  • Track and report key metrics regarding scan coverage, vulnerability aging, and SLA compliance to senior leadership.
  • Serve as a technical authority by mentoring engineers and creating reusable patterns to foster developer self-service.

What we're looking for

  • Bachelor's degree in Computer Science, Software Development, Software Engineering, or a related field, or equivalent practical experience.
  • 7+ years of experience in DevSecOps, application security engineering, platform security, or software engineering.
  • Experience integrating SAST, SCA, secrets detection, container scanning, IaC scanning, or comparable controls into CI/CD pipelines.
  • Experience leading security implementations or tool migrations in large or complex engineering environments.
  • Proficiency in public cloud platforms (AWS, Azure, or GCP) and experience with Docker, Kubernetes, Security-as-Code, and Infrastructure-as-Code.
  • Hands-on scripting or programming experience in languages such as Python, Java, JavaScript, Go, Shell, or PowerShell.
  • Experience with application vulnerability management, open-source risk, software supply chain security, and mobile application security testing for iOS and Android.
  • Demonstrated ability to use metrics to drive adoption, remediation, and measurable technical outcomes.
  • Experience with specific tools like Snyk, Checkmarx, Gitleaks, or SBOM tooling (preferred).
  • Experience with mobile security platforms such as Data Theorem or MobSF (preferred).
  • Expertise in architecting public cloud security solutions and understanding of networking/SDN principles (preferred).
  • Familiarity with regulated environments such as HIPAA, HITRUST, PCI, NIST, GDPR, or CCPA (preferred).

More like this

Similar roles

Staff DevSecOps Engineer

Okta Inc

Washington, DC 18 days ago $161,000–$221,000
Python Terraform Bash Go AWS GCP Azure CI/CD Infrastructure-as-Code ETL ELT SaaS CSPM CNAPP Qualys TenableSC Prisma Cloud Wiz Orca Lacework Jira ServiceNow
10+ yrs exp

DevSecOps Security Engineer

Leidos

Remote (Gaithersburg, MD) +2 1 day ago $87,100–$157,450
Kubernetes CI/CD SAST DAST Python Bash Go Terraform CloudFormation HashiCorp Vault OPA Rego Kyverno Istio ArgoCD Flux Nessus Trivy Grype Qualys AWS Azure GitLab CI GitHub Actions Jenkins mTLS SBOM CycloneDX SPDX
4+ yrs exp Remote

Lead InfoSec Engineer, DevSecOps

S&P Global

New York, NY +1 15 days ago $100,000–$130,000
DevSecOps CI/CD SAST DAST SCA AWS Azure Cloud Platform Kubernetes Docker OpenShift Terraform CloudFormation Pulumi Python Go Git HashiCorp Vault CSPM CNAPP
8+ yrs exp

Staff Security Engineer, Strategy & Operations

CVS Health

Remote (New York, NY) +3 14 days ago $130,295–$284,280
Power BI Microsoft Fabric SharePoint Microsoft Excel Microsoft 365 Cybersecurity Infrastructure Management KPI Frameworks Risk Management Compliance Data Visualization Strategic Planning Lean Six Sigma CISSP CISM PMP Security+
7+ yrs exp Remote

DevSecOps Engineer

Booz Allen Hamilton

Washington, DC 46 days ago $77,600–$176,000
DevSecOps CI/CD AWS Azure GCP Terraform CloudFormation CDK Docker Kubernetes Python Bash Go GitLab CI GitHub Actions PostgreSQL MySQL MongoDB Oracle Ansible Prometheus Grafana ELK Helmfile Flux Argo CD IaC SAST SCA
8+ yrs exp

DevSecOps Engineer

General Dynamics

Sudbury, MA 38 days ago $142,696–$158,303
Azure AKS Terraform Ansible GitLab CI CI/CD SAST DAST Model Context Protocol Microsoft Entra ID OAuth 2.0 OpenID Connect RAG LLM Azure App Service Container Apps
8+ yrs exp Hybrid