FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Assistant Vice President – Security Risk Management
CVS HealthAVP leading cybersecurity and technology risk management for CVS Health’s healthcare enterprise. Overseeing third-party risk, M&A security, control governance, remediation, and executive reporting.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive experience in cybersecurity risk management, including third-party risk assessments, M&A cybersecurity activities, and the development of risk management programs. Proficient in regulatory compliance, risk assessment methodologies, and leading high-performing teams in a complex enterprise environment.
Highest-signal resume keywords
Cybersecurity Risk ManagementThird-Party Risk ManagementM&A Cybersecurity ActivitiesRegulatory ComplianceTeam Leadership
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Risk Assessment MethodologyControl ValidationVulnerability ManagementCloud SecurityIncident Response ReadinessData ProtectionApplication SecurityBusiness ContinuityDisaster RecoveryCyber Risk Reporting
Soft Skills
LeadershipCollaborationRelationship-BuildingCommunication
Tools & Technologies
GRC PlatformsContinuous Monitoring ToolsSecurity Ratings ServicesCyber Risk Reporting Tools
Certifications & Qualifications
CISSPCISMCRISCCTPRPCCSPCISAHCISPP
Industry Keywords
HIPAANIST CSFISO 27001HITRUSTSOC 2PCI DSSHealthcareHealth InsurancePharmacyRetail
Tech Stack
Tools & technologiesCloudCyber Security
About the role
Key responsibilities & impact- Evolve CVS Health’s cybersecurity and technology risk management program, including risk taxonomy, risk appetite alignment, assessment methodology, risk scoring, control validation, governance, issue management, and executive reporting
- Lead the end-to-end lifecycle of third-party cybersecurity risk assessments across vendors and business associates
- Integrate internal, third-party, supply chain, and M&A cyber and technology risk signals into the enterprise risk posture
- Lead cybersecurity activities for M&A onboarding, including due diligence, security architecture evaluation, integration requirements, remediation, and secure onboarding
- Lead cybersecurity activities for M&A offboarding, divestitures, separations, and transition services
- Partner with security, privacy, legal, technology, procurement, corporate development, integration, enterprise risk, and business leaders
- Advise internal stakeholders, vendors, suppliers, acquired or divested entities, regulators, and client due diligence teams
- Collaborate with the CISO, Deputy CISO, and Chief Privacy Officer on risk strategy, regulatory readiness, control posture, escalation, and governance
- Establish and report cybersecurity and technology risk indicators, metrics, trends, and material risk themes to senior leadership
- Drive risk treatment, remediation governance, issue management, compensating controls, exception management, and risk acceptance
- Evaluate and implement cybersecurity risk management tools, GRC capabilities, security ratings services, continuous monitoring platforms, control assessment automation, and data analytics
- Represent CVS Health in regulatory examinations, client due diligence reviews, transaction-related reviews, and audits
- Adapt the program to emerging cyber threats, regulatory expectations, healthcare cyber risk trends, ransomware, cloud, identity, software supply chain, AI/ML vendor, and transaction-related risks
- Lead and develop a high-performing cybersecurity risk management team
Requirements
What you’ll need- 10+ years of progressive experience in information security, cybersecurity risk management, technology risk, or IT audit
- 5+ years focused on third-party, vendor, supplier, supply chain, or M&A cyber risk management
- Experience designing, operating, and maturing cybersecurity and technology risk management programs across a large, complex enterprise
- Experience with internal and external risk assessment methodology, inherent and residual risk scoring, control validation, issue management, risk acceptance, and executive reporting
- Experience evaluating identity and access management, privileged access, vulnerability management, endpoint security, cloud security, network security, logging and monitoring, data protection, incident response readiness, application security, infrastructure, platform, change management, business continuity, and disaster recovery controls
- Experience supporting merger, acquisition, divestiture, separation, or transition services activities from a cybersecurity risk perspective
- 3+ years of people leadership experience building, leading, and managing high-performing security or risk teams
- Strong leadership, collaboration, relationship-building, and matrixed-enterprise partnership skills
- Working knowledge of HIPAA, NIST CSF, NIST 800-53, ISO 27001, HITRUST, SOC 2, PCI DSS, and other applicable requirements
- Experience with TPRM, GRC platforms, security ratings services, continuous monitoring, technology risk reporting, and cyber risk reporting tools
- Ability to influence senior stakeholders and lead cross-functional internal and external partnerships
- Excellent written and verbal communication skills, including executive, governance committee, regulator, client, and Board-level communication
- Bachelor's degree in Computer Science, Information Security, Cybersecurity, Business, or related field, or equivalent professional experience
- Preferred: CISSP, CISM, CRISC, CTPRP, CCSP, CISA, or HCISPP certifications
- Preferred: healthcare, health insurance, pharmacy, or retail industry experience
- Preferred: master's degree or Juris Doctor
- Preferred: familiarity with cyber risk quantification, control maturity models, threat-informed assessment, continuous control monitoring, technology resilience, cloud security posture, fourth-party risk, AI/ML vendor risk, software supply chain risk, enterprise risk aggregation, and transaction-related cybersecurity risk
- Preferred: experience supporting regulatory examinations, client due diligence, transaction diligence, or related audits
Benefits
Comp & perks- CVS Health bonus, commission or short-term incentive program in addition to base pay
- Award target in the company’s equity award program
- Medical coverage
- Dental coverage
- Vision coverage
- Paid time off
- Retirement savings options
- Wellness programs
- Other resources supporting physical, emotional, and financial well-being, based on eligibility