Skip to main contentA logo with &quat;the muse&quat; in dark blue text.

Senior Analyst

AT CVS Health
CVS Health

Senior Analyst

Phoenix, AZ

At CVS Health, we're building a world of health around every consumer and surrounding ourselves with dedicated colleagues who are passionate about transforming health care.As the nation's leading health solutions company, we reach millions of Americans through our local presence, digital channels and more than 300,000 purpose-driven colleagues - caring for people where, when and how they choose in a way that is uniquely more connected, more convenient and more compassionate. And we do it all with heart, each and every day.Position Summary

The Senior Security Analyst is responsible for ensuring CVS data remains secure and all risks, vulnerabilities and defects are managed, tracked, and remediated according to policy and/or best practices.

Want more jobs like this?

Get jobs in Phoenix, AZ delivered to your inbox every week.

By signing up, you agree to our Terms of Service & Privacy Policy.

The Sr Security Analyst selected for this role must have experience with risk management con-cepts and processes and a background in Information technology and/or Cyber Security. The Sr Security Analyst will execute the TPS program and serve as a contact to participants across the enterprise that put vendors through the program.
The incumbent will be responsible for ensuring that the proper due diligence is performed over our third parties with access to CVS data and/or our environment.
The Sr Security Analyst will be responsible for but not limited to:
- Develop reports and evaluate the results of the vendor assessment
- Identify and document control gaps
- Review and interpret results of vulnerability assessments and penetration testing
- Communicate with auditors and regulators during compliance and regulatory reviews
- Participate in information security assessments ensuring technical compliance with security re-lated regulatory requirements (PCI, SOX, PII, PHI, etc)
- Collaboratively work with peers to ensure operational excellence
- Contribute to or help lead current state risk assessments, continual risk assessments, risk met-rics and visualization and integrated operational risk management
- Identify and prioritize risk based on impact and likelihood
- Work directly with key business leaders to facilitate information risk analysis and risk manage-ment processes, identify acceptable levels of risk, and establish roles and responsibilities with re-gards to information risk management
- Assist in Policy/Standard development and security awareness and training
- Ensure security programs are in compliance with applicable laws, regulations and policies to minimize risk and audit fi ndings
The ideal candidate for this role will have:
- Knowledge of risk assessment methodologies, IT/IS Policies and Standards, IT risk standards and industry best practices (ISO 27001, HITRUST, etc).
- Experience or understanding of managing third party assessments
- Experience with development and administration of risk assessments and reviews
- Experience with assessment processes and disciplines
- Experience with more than one major IT discipline (distributed computing, networks, application design and development, IT security, cloud, AI, and business recovery)
- Knowledge of risk assessment methodologies, IT policies and standards
- Strong client relationship management experience and skills
- Familiarity with relevant regional regulatory requirementsPrimary Job Duties & Responsibilities
Conducts complex risk assessments to identify and assess potential security risks and vulnerabilities across the organization's systems, networks, and technology infrastructure.
Under limited supervision, monitors and analyzes threat intelligence sources to stay informed about current and emerging security threats and trends that may impact the organization.
Assists in development and implements risk mitigation strategies, controls, and countermeasures to reduce the organization's exposure to identified risks.
Configures incident response plans, including defining roles, responsibilities, and procedures to effectively respond to and recover from security incidents.
Monitors security risk management metrics, reporting frameworks, and dashboards to provide regular updates to management and stakeholders.
Examines the security posture of third-party vendors and partners, evaluating their potential im-pact on the organization and providing risk mitigation recommendations.
Coordinates incident response activities, including incident detection, containment, analysis, and resolution, working closely with cross-functional teams.
Applies in-depth knowledge of risk management principles to administer training programs that aim to educate employees about security risks, best practices, and their roles in mitigating risks.
Identifies opportunities for enhancing security risk management processes, procedures, and tools, while contributing to the organization's continuous improvement efforts.

Education
Bachelor's degree preferred/specialized training/relevant professional qualification.Prior Relevant Work Experience
3-5 yearsRequired Qualifications
- 2+ years of experience in an IT Security/IT Risk environment with a large regulated organizationEssential Qualifications
Working knowledge of problem solving and decision making skills
Certified in Risk and Information Systems Control (CRISC) preferred.Preferred Qualifications
- Previous cyber security risk assessment within Healthcare, or other highly regulated environment with
CISSP, CISA, CIPP, CISM, PCIP, ISA, CTPRA
- Experience with regulatory requirements, including Sarbanes Oxley, HIPAA, and the PCI-DSS
- Knowledge and working experience with Information Security frameworks, including ISO27001 and the NIST CSF
- Strong interpersonal and oral/written communication skills, able to build relationships at all levels
- Knowledge of IT risk standards and industry best practice approaches such as ISO 27001, HITRUST
- Knowledge of web application security testing and vulnerability testing tools.
- Knowledge of network-level penetration testing
- Knowledge of source code reviews using automated tool Anticipated Weekly Hours
40Time Type
Full timePay Range

The typical pay range for this role is:$72,100.00 - $144,200.00This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above.Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.Great benefits for great peopleWe take pride in our comprehensive and competitive mix of pay and benefits - investing in the physical, emotional and financial wellness of our colleagues and their families to help them be the healthiest they can be. In addition to our competitive wages, our great benefits include:
  • Affordable medical plan options, a 401(k) plan (including matching company contributions), and an employee stock purchase plan.
  • No-cost programs for all colleagues including wellness screenings, tobacco cessation and weight management programs, confidential counseling and financial coaching.
  • Benefit solutions that address the different needs and preferences of our colleagues including paid time off, flexible work schedules, family leave, dependent care resources, colleague assistance programs, tuition assistance, retiree medical access and many other benefits depending on eligibility.
For more information, visit https://jobs.cvshealth.com/us/en/benefitsWe anticipate the application window for this opening will close on: 07/18/2025Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.

Client-provided location(s): Phoenix, AZ, USA
Job ID: CVS-R0643593
Employment Type: Other

Perks and Benefits

  • Health and Wellness

    • Health Insurance
    • Dental Insurance
    • Vision Insurance
    • Life Insurance
    • HSA
    • HSA With Employer Contribution
    • Pet Insurance
    • Mental Health Benefits
  • Parental Benefits

    • Fertility Benefits
    • Adoption Assistance Program
    • Family Support Resources
  • Work Flexibility

    • Flexible Work Hours
    • Remote Work Opportunities
    • Hybrid Work Opportunities
  • Vacation and Time Off

    • Paid Vacation
    • Paid Holidays
    • Personal/Sick Days
  • Financial and Retirement

    • 401(K) With Company Matching
  • Professional Development

    • Tuition Reimbursement
  • Diversity and Inclusion

    • Employee Resource Groups (ERG)
    • Diversity, Equity, and Inclusion Program