• Skip to primary navigation
  • Skip to main content
  • Skip to footer

Side Hustles

Side Hustles

Side Hustles For All

  • Best Side Hustles
    • Woman sitting on a pile of coins and working on a laptop surrounded by icons representing different side hustle ideas

      31 Best Side Hustles to Earn Extra Money in 2026

    • Bicycle courier delivering food for their side hustle.

      What Is a Side Hustle?

    • Remote worker sitting at his desk making money from home

      18 Ways to Make Money from Home (Online and Offline Jobs)

    • By Category
      • Arts & Crafts
      • Business Services
      • Caregiving
      • Creative Services
      • Digital Freelance Services
      • View All
    • By Lifestyle
      • I’m introverted
      • I’m a man
      • I’m a woman
      • I’m a stay-at-home mom
      • I’m unique
      • View All
    • By Profession
      • Artists & Creatives
      • Musicians
      • Nurses
      • Physicians
      • Teachers
      • View All
    • By Age Group
      • College Students
      • Teens
      • Age 50+
      • Seniors
      • View All
    • By Skills & Interests
      • Get Paid to Lose Weight
      • Get Paid to Play Games
      • Get Paid to Read
      • Get Paid to Sleep
      • Get Paid to Travel
      • View All
  • Best Gig Apps
    • Freelance worker popping out of a phone screen and considering gig apps on the App Store and Google Play

      Top 6 Gig Apps to Make Real Cash in 2026

    • Smartphone surrounded by the icons of different money-making apps

      Top 10 Best Money-Making Apps to Try in 2026

    • two teenagers using job apps on a phone and laptop

      19 Job Apps for Teens to Find Jobs and Make Money

    • By Gig Type
      • Cashback
      • Data Entry
      • Delivery
      • Games
      • Product Testing
      • View All
    • By Payment Method
      • Bingo Games that Pay to Cash App
      • Games that Pay Real Money
      • Games that Pay to Cash App
      • Games that Pay via PayPal
      • Surveys that Pay to Cash App
      • View All
    • By Benefits
      • $20 Signup Bonuses
      • $25 Signup Bonuses
      • $50 Signup Bonuses
      • Best Signup Bonuses
      • Instant Signup Bonuses
      • View All
    • By Skills & Interests
      • Driving
      • Losing Weight
      • Playing Games
      • Product Testing
      • Watching Ads
      • View All
  • Job Hunting
    • Freelance worker browsing a job post on a freelance job board.

      23 Job Boards You Can Use to Find Remote Work

    • Freelance writer sitting at her laptop working on a project

      15 Best Remote Jobs That Require No Paid Work Experience

    • Teenager sitting at laptop working an online job

      14 Online Jobs for Teens (With No Experience)

    • Freelancing
      • Freelance Writing Sites
      • Freelance Writing Job Boards
      • Freelance Writing Platforms
      • View More
    • Gig & Shift Work
      • Gig Work Apps
      • On-Demand Work Apps
      • Shift Work Apps
      • View More
    • GPT (Get Paid To)
      • Microtasking
      • Product Testing
      • Survey Taking
      • View More
    • Remote Working
      • Best Remote Job Boards
      • Top 15 Remote Jobs
      • View More
  • Job Board
    • Work Schedule
      • Part-Time Jobs
      • Per-Diem Jobs
      • Go Search
    • Work Environment
      • Hybrid Jobs
      • Remote Jobs
      • Go Search
    • Employment Type
      • Contractor Jobs
      • Internship Jobs
      • Temporary Jobs
      • Go Search
    • Job Title
      • Accounting Jobs
      • Data Entry Jobs
      • Nursing Jobs
      • Online Teaching Jobs
      • Software Engineer Jobs
      • Go Search
    • State
      • California Jobs
      • Florida Jobs
      • New York Jobs
      • Pennsylvania Jobs
      • Texas Jobs
      • Go Search
    • City
      • Chicago, IL
      • Houston, TX
      • Los Angeles, CA
      • New York City, NY
      • Phoenix, AZ
      • Go Search

Home Flexible Job Board Distinguished Engineer - Application Security

$175,100–334,750/yr 23d ago

Distinguished Engineer - Application Security

Boost your chances before you apply.

  • ✨ Apply 10x Faster Free

    It takes 30+ tailored applications to land jobs like this one. We'll help you get that done in 1 hour.

    No Credit Card Required

  • Proceed to Application Go directly to the company's job page to apply.
Logo

CVS Health

AZ

Full-time Permanent Remote

✨ Apply 10x Faster

Analyze your resume for missing keywords, then one-click optimize it. Don't be anything less than a 100% match candidate.

Free

No Credit Card Required

Summary

The Distinguished Engineer serves as the senior technical leader for Application Security, defining the architectural strategy for securing software across web, mobile, and AI-native environments. They are responsible for integrating security controls into CI/CD pipelines and leading the enterprise adoption of AI-assisted development guardrails.

Job Description

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.

Position Summary

Serves as the senior technical leader and strategist for Application Security at CVS Health, setting the architectural direction for how the enterprise secures the software that it builds and integrates across web, mobile, API, microservice, and AI-native applications spanning cloud, on-prem, SaaS and hybrid environments. Partners with the AVP, Application Security to define and deliver an industry-leading application security program that shifts security responsibility left into design and development, enforces it consistently through CI/CD, and validates it continuously in production, replacing point-in-time scan-and-triage workflows with a developer-native, control-driven, threat-informed model.

Owns the technical strategy and end-to-end architecture of the application security tooling stack including SAST, DAST, SCA, IAST/RASP, secrets scanning, API security, IaC and container scanning, ASPM/ASOC and its integration into the Developer Experience platform and enterprise CI/CD pipelines, so that security controls are consumed as native platform capabilities by application teams rather than as separate bolt-on tools. Accountable for tool selection, evaluation, and integration planning across a rapidly evolving vendor landscape, including build-vs-buy decisions and consolidation into a coherent Application Security Posture Management (ASPM) view. Serves as the ultimately responsible architect for the components, tools, and services developed and operated by the Application Security team, including microservices that integrate AppSec tools into CI/CD, reusable components, setting design standards, leading design reviews, and contributing hands-on to critical components. Provides hands-on support to application teams adopting standards and tooling, ensuring that the secure path is also the easy and default path.

Charts the enterprise course through the rapidly evolving field of AI-assisted software development, establishing the technical strategy and guardrails for safe adoption of AI coding assistants, agentic coding tools, and AI-generated code across the engineering organization; evaluating and integrating AI-native application security tooling (AI-assisted triage, autofix, secure code review, threat modeling, and detection engineering); and helping the enterprise navigate emerging risks including insecure generated code, prompt injection in developer workflows, model and prompt supply-chain exposure, and IP/data leakage through AI tooling.

Partners with the Developer Experience team to design and deliver the developer-facing side of the program, secure-by-default paved paths, secure coding standards mapped to OWASP ASVS and NIST SSDF, and outcome-based metrics that translate application security posture into business risk. Partners closely with the Developer Experience team that manages the enterprise CI/CD pipelines, and with Security Engineering peers across Cloud Security, AI Security, Identity, Detection Engineering, and Exposure Management, to ensure application security controls are integrated end-to-end from developer laptop to production runtime. Operates as a trusted bridge between deeply technical engineering teams and business stakeholders, influencing strategy, investment, and execution across organizational boundaries without relying on direct authority.

This role can be remote anywhere in the continental USA.

Required Qualifications

  • 15+ years of experience in technical roles, with demonstrated ability to influence without authority across technical and executive audiences
  • 10+ years of experience acting as a bridge between deep technical work and business strategy, translating between the two fluently
  • 10+ years of hands-on software engineering experience across multiple language ecosystems (e.g., Java, C#, JavaScript/TypeScript, Python, Go) — with recent, current coding proficiency, not solely architectural or advisory experience
  • 8+ years in application security or product security roles at enterprise scale, including hands-on experience with threat modeling, secure design review, secure code review, and vulnerability triage
  • 5+ years setting multi-year technical strategy and architectural roadmaps for enterprise-scale application security or DevSecOps programs
  • Deep working knowledge of the modern application security tooling landscape — SAST, DAST, SCA, IAST/RASP, secrets scanning, API security, container and IaC scanning, ASPM/ASOC — including hands-on experience selecting, integrating, tuning, and operating these tools at enterprise scale
  • Demonstrated experience integrating security controls into modern CI/CD pipelines and developer platforms (Git-based workflows, GitHub Actions / GitLab CI / Jenkins / Argo, container registries, artifact repositories, service catalogs) as native, low-friction platform capabilities
  • Strong working knowledge of software supply chain security — SBOMs (CycloneDX, SPDX), the SLSA framework, provenance and attestation, dependency and license governance, and build-system hardening
  • Deep familiarity with cloud-native architectures (Kubernetes, serverless, microservices), API design patterns (REST, GraphQL, gRPC, event-driven), and the security implications of each
  • Demonstrated experience leading the transformation of an application security program from centralized, gate-oriented, meeting-driven workflows to developer-native, control-driven, continuous operations — including measurable improvements in adoption, remediation velocity, and defect escape rate
  • Demonstrated experience partnering with platform engineering or developer experience teams to deliver security capabilities as native platform features rather than external gates
  • Strong written and verbal communication, including proven experience briefing executive leadership and the board

Preferred Qualifications

  • Practical, current experience with AI-assisted software development — evaluating and governing AI coding assistants (e.g., Claude Code, GitHub Copilot, Cursor, Windsurf, Cody, Amazon Q Developer, and equivalents), agentic coding tools, and MCP-based developer integrations — including security guardrails and organizational rollout patterns
  • Hands-on experience evaluating and integrating AI-native application security tooling — AI-assisted triage, autofix, secure code review, and AI threat modeling capabilities — with practical awareness of accuracy, false-positive, and prompt-injection concerns
  • Deep working knowledge of OWASP LLM Top 10, OWASP AI Security & Privacy Guide, MITRE ATLAS, and NIST AI RMF as they apply to application security
  • Experience with Application Security Posture Management (ASPM) platforms and unified security signal aggregation, correlation, and prioritization across the AppSec toolchain
  • Healthcare-sector application security experience: PHI-handling clinical and pharmacy systems, HIPAA Security Rule, FDA pre-market and post-market cybersecurity guidance (including SPDF), retail pharmacy PCI-scoped applications, and clinical-system safety considerations
  • Experience operating application security programs simultaneously against HIPAA, HITRUST CSF, PCI DSS 4.0, the SEC cyber-incident disclosure rule, and NIST CSF 2.0
  • Experience with runtime application security capabilities — RASP, eBPF-based runtime protection, service mesh security, and WAF/API gateway integration — and with correlating runtime signals back to source code and design
  • Experience partnering with product management, engineering leadership, and platform engineering to embed security into developer workflows without slowing delivery velocity
  • Experience influencing standards bodies, open-source projects, or industry working groups relevant to application security or secure software development
  • Industry certifications such as CISSP, CSSLP, OSWE, OSCP, GIAC (e.g., GWEB, GWAPT, GMOB, GCSA), or equivalent
  • Advanced degree in Computer Science, Software Engineering, or related technical field
  • Open-source, publication, or community contribution in application security, DevSecOps, secure software development, or AI-assisted development
  • Advanced degree in Computer Science

Education

Bachelor's degree in Computer Science, Engineering, or a related field.
 

Pay Range

The typical pay range for this role is:

$175,100.00 - $334,750.00

This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls.  The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors.  This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above.  This position also includes an award target in the company’s equity award program. 
 

Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.

Great benefits for great people

We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.

This full‑time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well‑being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.

Additional details about available benefits are provided during the application process and on Benefits Moments.

We anticipate the application window for this opening will close on: 12/31/2026

Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.

About the company

CVS Health

CVS Health is the leading health solutions company, delivering care like no one else can. We reach more people and improve the health of communities across America through our local presence, digital channels and over 300,000 dedicated colleagues.

Wherever and whenever people need us, we help them with their health – whether that’s managing chronic diseases, staying compliant with their medications or accessing affordable health and wellness services in the most convenient ways. We help people navigate the health care system – and their personal health care – by simplifying health care one person, one family and one community at a time. Follow @CVSHealth on social media.

Founded

1963

Company size

10,001+ employees

Industry

Hospitals and Health Care

Org type

Public Company

Headquarters

Woonsocket, RI

Apply Now

About the company

CVS Health

CVS Health is the leading health solutions company, delivering care like no one else can. We reach more people and improve the health of communities across America through our local presence, digital channels and over 300,000 dedicated colleagues.

Wherever and whenever people need us, we help them with their health – whether that’s managing chronic diseases, staying compliant with their medications or accessing affordable health and wellness services in the most convenient ways. We help people navigate the health care system – and their personal health care – by simplifying health care one person, one family and one community at a time. Follow @CVSHealth on social media.

Founded

1963

Company size

10,001+ employees

Industry

Hospitals and Health Care

Org type

Public Company

Headquarters

Woonsocket, RI

Footer

sidehustles.com
Facebook Twitter Instagram LinkedIn Reddit TikTok YouTube

Show Me The Money

  • Side Hustle Basics
  • Side Hustle Job Board (Remote & Part-Time Jobs)
  • Gig App Reviews
  • Job Hunting
  • Manage Your Money
  • The Gig Apple: News & Events

Company

  • About Us
  • Contact Us
  • Become a Contributor
  • Advertising & Sponsorships
  • Partner With Us
  • Editorial Guidelines

Side Hustles © All rights reserved

  • Privacy Policy
  • Terms of Service

Thanks for using our free job board

Your review would mean a lot to us.

If you love that we're just giving away remote jobs for free with no paywall, please spread the word. (You will need to create an account on Trustpilot, for which we'll be eternally grateful.) Good luck out there!

Leave a Review Not yet. Send me to the job post.