About The Position

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time. Position Summary As a member of the Infrastructure Controls Enablement team within the Infrastructure Engineering organization, you will be focused on activities relating to the controls that provide secure IT infrastructure. The Infrastructure Engineering (IE) organization at CVS Health delivers public and private cloud capabilities to the enterprise. You will bring your knowledge of security issue remediation processes and real-world experience in an enterprise infrastructure engineering ecosystem to help our colleagues meet the highest levels of compliance with the CVS IT control standards. You will be responsible for driving the execution of work relating to closing security issues and coordinating remediation activities to maintain a secure and compliant IT environment. You will apply a project management skillset to assemble a robust plan on an urgent timeline to reduce risk in the infrastructure environment. You will directly interact with members of engineering, application and cloud security teams to assemble the remediation tasks, timeline, named contributors and measurable outcomes. You will leverage your experience working with cloud engineers to assemble detailed remediation guides to remediate issues and implement infrastructure controls within a hybrid cloud technology ecosystem. Your excellent organizational, collaboration and communication skills will enable you to facilitate progress to strengthen our overall security posture. Your demonstrated bias for action coupled with a strong sense of ownership will reduce risk on an aggressive timeline. Candidates will primarily work remotely or in a hybrid office model, and will be required to join in-person meetings in our Hartford office regularly. This role will lead some activities that may be outside of regular working hours.

Requirements

  • 8+ years of project/program management experience including leading large enterprise-wide cross-functional programs
  • 5+ years of experience leading efforts to achieve IT compliance

Nice To Haves

  • Experience working in a highly regulated company
  • Excellent analytical and problem-solving skills
  • Strong organizational skills that enable you to assemble and execute viable plans
  • Experience working with integrated risk management platforms for risk assessment, threat detection, compliance monitoring, and systems that enable the management of security posture, vulnerabilities, audits and policies
  • Ability to influence and collaborate with stakeholders at all levels
  • Excellent communications skills and proven ability to communicate effectively with senior management and business leaders
  • Experience evaluating and recommending new solutions to meet enterprise control standards requirements
  • Demonstrated teamwork, positive attitude and good rapport with peers and customers
  • Ability to multitask in a fast paced and continually changing environment
  • Bachelor's degree or equivalent experience (HS diploma + 4 years relevant experience)

Responsibilities

  • Leading remediation campaigns that require cross-functional coordination to reduce risk on an aggressive timeline
  • Analyzing data from integrated risk management platforms to enable the development of robust, actionable remediation guides and plans
  • Assembling plans with timelines, resource assignments and milestones to remediate issues and risks on an enterprise-wide scale
  • Facilitating remediation efforts by assembling engineers, application testers and other key contributors to complete the remediation activities
  • Managing the engineering deliverables for audit and compliance related requests, ensuring engineers prioritize the work for a timely delivery
  • Ensuring that all necessary audit evidence is collected, organized, and presented effectively, while minimizing disruptions to core engineering and product development activities
  • Collaborating with teams across the company (e.g., Network, Security, Operations) as needed to ensure compliance with required security and control frameworks
  • Educating and guiding engineers and leaders across Cloud and Platform Engineering teams, providing information and advice on control compliance related activities, including rationale, recommended practices, and implementation strategies
  • Stay up-to-date with the latest developments in Cloud technology and broader technology trends and applicability to infrastructure control responsibilities, sharing valuable insights with your team
  • Prepare reports for senior leaders to summarize campaign status and initiatives

Benefits

  • Affordable medical plan options, a 401(k) plan (including matching company contributions), and an employee stock purchase plan.
  • No-cost programs for all colleagues including wellness screenings, tobacco cessation and weight management programs, confidential counseling and financial coaching.
  • Benefit solutions that address the different needs and preferences of our colleagues including paid time off, flexible work schedules, family leave, dependent care resources, colleague assistance programs, tuition assistance, retiree medical access and many other benefits depending on eligibility.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service