Associate Security Product Manager
CVS Pharmacy - Alpharetta, GA
Apply NowJob Description
Job DescriptionWithin CVS Health Digital, the security of our customer data and the applications we develop for them is paramount to our success. Security becomes a burden when it comes too late in the development cycle. At CVS Health Digital, we strive to shift security left into the hands of our developers to build secure applications. We do this by integrating security controls into our existing CICD pipelines and by building foundational security components that abstract the complexity and simplify integration into the various application teams across Digital.A critical responsibility of an Associate Security Product Manager is to understand the common software security challenges within the organization, and to come up with operational procedures and security solutions the respective application teams can use to ensure we ship secure products. You will be responsible for identifying key metrics that measure success and that provide insights into to identify security areas the need focus. As a key security stakeholder within the Digital organization, the security product owner's primary objective is to make security easy for developers, engineers, product managers, and security teams alike while most importantly ensuring Digital applications are secure by design. Key Responsibilities include: Collaborate with stakeholders (including Scrum Teams & Values Streams) on feature requests around Security Compliance items to assess priority, value, and development cost Define and communicate the security backlog and strategy for SAFe teams and trains Understand internal customer needs to define short term and long-term product direction Decompose high-level requirements into user stories and tasks, manage and prioritize the product backlog, participate in scrums and meta-scrums, and validate delivered solution designs Understands, assesses and critiques the architecture proposed by the application architecture team and ensures the scrum team delivery is aligned to the solution's mission Communicate security backlog and vision effectively to colleagues and Digital leadership Perform industry research as necessary to support feature development Partner with engineering teams to define, track and test user stories in an agile software development life-cycle Provide security product subject matter expertise and leadership Work with product management to track schedule against the roadmap and escalate risks/issues Explore new market space developments, and evaluating / understanding competitive tools Collaborate with the engineering team to prioritize security features and scan related findings and facilitate determining the best technical solutions.Pay RangeThe typical pay range for this role is:Minimum: 70,000Maximum: 140,000Please keep in mind that this range represents the pay range for all positions in the job grade within which this position falls. The actual salary offer will take into account a wide range of factors, including location.Required Qualifications2+ years of experience in Security 2+ years of experience as a product owner/product manager1+ years of experience with security toolsProven experience building consumer facing products at scale Proven ability to deliver convincing business case recommendations to senior management Demonstrated collaborative style, with ability to lead and influence diverse teams Demonstrated experience driving agile product developmentPreferred QualificationsKnowledge of various security tools: SAST, DAST, Container scans, SCAKnowledge of security testing (pentests, API tests, Web Security Tests, BOT tests) Knowledge of DevSecOps concepts in agile environmentsProduct Manager / Owner certificationSANS GIAC, CISSP and related security certificationsBroad experience working in the security domainGood communication skillsApp security, cloud security and devsecops knowledge is a plusAbility to learn fast and develop knowledge regarding our organizational services, products and cultureAbility to gauge vast amount of information and provide clear business analyticsAbility to work independently and also as a team memberExperience in creating and delivering presentations to broader audience (Especially executive level)Experience working on or directly with software security developmentKnowledge of and experience with one or more information security domainsEducationBachelors Degree or equivalent work experienceBusiness OverviewBring your heart to CVS Health Every one of us at CVS Health shares a single, clear purpose: Bringing our heart to every moment of your health. This purpose guides our commitment to deliver enhanced human-centric health care for a rapidly changing world. Anchored in our brand - with heart at its center - our purpose sends a personal message that how we deliver our services is just as important as what we deliver. Our Heart At Work Behaviors support this purpose. We want everyone who works at CVS Health to feel empowered by the role they play in transforming our culture and accelerating our ability to innovate and deliver solutions to make health care more personal, convenient and affordable. We strive to promote and sustain a culture of diversity, inclusion and belonging every day. CVS Health is an affirmative action employer, and is an equal opportunity employer, as are the physician-owned businesses for which CVS Health provides management services. We do not discriminate in recruiting, hiring, promotion, or any other personnel action based on race, ethnicity, color, national origin, sex/gender, sexual orientation, gender identity or expression, religion, age, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law. We proudly support and encourage people with military experience (active, veterans, reservists and National Guard) as well as military spouses to apply for CVS Health job opportunities.
Created: 2024-11-02