CrawlJobs Logo

Senior Security Risk Assessor

https://www.cvshealth.com/ Logo

CVS Health

Location Icon

Location:
United States, Work At Home

Category Icon
Category:
IT - Administration

Job Type Icon

Contract Type:
Not provided

Salary Icon

Salary:

92700.00 - 185400.00 USD / Year
Save Job
Save Icon
Job offer has expired

Job Description:

At CVS Health, we’re building a world of health around every consumer and surrounding ourselves with dedicated colleagues who are passionate about transforming health care. As the nation’s leading health solutions company, we reach millions of Americans through our local presence, digital channels and more than 300,000 purpose-driven colleagues – caring for people where, when and how they choose in a way that is uniquely more connected, more convenient and more compassionate. And we do it all with heart, each and every day.

Job Responsibility:

  • Conducts thorough security risk assessments for new technologies before deployment and technologies post-deployment in the production environment
  • Identifies, assesses, analyzes security risks, scrutinizes potential vulnerabilities, and provides risk mitigation strategies to ensure compliance and adherence to information security standards for a seamless and secure integration
  • Engages project managers, project management team members including developers, architects, infrastructure engineers, and EIS stakeholders as applicable
  • Describes technical issues to business partners or senior leaders in risk terms that are clear and understandable while still having some subject matter expertise
  • Leads small teams, mentors junior team members, oversees third party contractors, and responds to critical requests

Requirements:

  • 5+ years of information security or related experience
  • 5+ years working knowledge of common security frameworks and regulations, including but not limited to NIST 800-53, ISO 27001/2, HIPAA/HITECH, HITRUST and PCI-DSS
  • 5+ years working knowledge of Information Technology including Cloud, access management, architecture, infrastructure, operating systems, application/software development, and endpoint security

Nice to have:

  • Industry related certification such as CISSP, CISM, CRISC, etc.
  • Ability to comprehend implications of security risk (inherent risk, residual risks), compensating controls, etc.
  • Solid written and verbal communication skills
  • Ability to demonstrate critical thinking and knowledge of risk management basic processes, tools, and techniques
  • Experience operating in applications including Archer, Qualys, Checkmarx, and Prisma
  • Solid knowledge of Information Security policies and procedures
  • Solid knowledge of regulatory (including Audit frameworks) standards, including but not limited to NIST 800-53, SOX, SOC1/SOC2 Type II audits, HIPPA/HITECH, HITRUST, and PCI-DSS
  • Knowledge of current security threat and vulnerability trends
  • Understanding of cloud Security best practices and frameworks
What we offer:
  • Affordable medical plan options
  • 401(k) plan (including matching company contributions)
  • Employee stock purchase plan
  • No-cost programs for all colleagues including wellness screenings, tobacco cessation and weight management programs, confidential counseling and financial coaching
  • Paid time off
  • Flexible work schedules
  • Family leave
  • Dependent care resources
  • Colleague assistance programs
  • Tuition assistance
  • Retiree medical access

Additional Information:

Job Posted:
August 14, 2025

Expiration:
August 18, 2025

Employment Type:
Fulltime
Work Type:
Remote work
Job Link Share:
Welcome to CrawlJobs.com
Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.