Staff Security Engineer
Position Summary
We're building a world of health around every individual - shaping a more connected, convenient and compassionate health experience. At CVS Health you will be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do.
We are hiring a Staff Security Engineer in Woonsocket, RI to conduct application and infrastructure penetration tests and red teaming engagements in order to strengthen the security of perimeter and internal-facing assets. The engineer will perform advanced penetration tests on web applications, mobile applications, network infrastructure, and cloud environments; perform regular risk-based and intelligence-led penetration tests on public-facing and perimeter assets; collaborate with SOC, vulnerability management and other stakeholder teams to uncover and verify security weaknesses; develop, plan and execute detailed Red Teaming engagements; assist in scoping, executing and peer reviewing prospective change and operational assurance penetration testing engagements; safely use various penetration testing tools and emulate hacker tactics, techniques and procedures; participate and contribute on risk assessment and threat modeling sessions; develop scripts, tools or methodologies to enhance CVS's penetration testing processes; produce comprehensive and accurate reports and presentations; stay current on cyber threats, vulnerabilities and trends; and mentor and train junior team members.
Requirements
Bachelor's degree (or foreign equivalent) in Computer Science, Computer Engineering, Information Technology, Engineering, or a related field and five (5) years of progressive, postbaccalaureate experience in the job offered or related occupation.
Minimum three (3) years of experience in each of the following areas:
IT information security services, including application penetration testing
Mobile application security assessment
Infrastructure penetration testing
Vulnerability assessment and network/?server hardening
Performing security assessments and review of applications, including documenting technical issues
Defining baseline security configuration for operating systems across multiple platforms
Management, construction and maintenance of security tools and infrastructure to support the security testing team; source code review
Wireless penetration testing
Database security assessment
Product security review
Position also requires completion of a university-level course research project or internship involving the following:
Data structures and algorithms
Computer architecture
Software testing and system programming
Data warehousing and mining
Mobile computing
Pay Range
$137,654.00 per year to $213,210.00 per year. The base salary will depend on experience, education, geography and other factors. The position is eligible for a bonus, commission or short-term incentive program, and an equity award program.
Benefits
The company offers a full range of medical, dental and vision benefits, eligibility for a 401(k) retirement savings plan, an employee stock purchase plan, a fully-paid term life insurance plan, short-term and long-term disability benefits, well-being programs, education assistance, free development courses, a CVS store discount and partner discounts. Paid time off, vacation pay and paid holidays are also provided.
Equal Employment Opportunity
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.
Application Information
This job does not have an application deadline; applications are accepted on an ongoing basis.
J-18808-Ljbffr