CVS Health

Senior Endpoint Security Engineer - Configuration Compliance

Work At Home-Massachusetts Full time

At CVS Health, we’re building a world of health around every consumer and surrounding ourselves with dedicated colleagues who are passionate about transforming health care.

As the nation’s leading health solutions company, we reach millions of Americans through our local presence, digital channels and more than 300,000 purpose-driven colleagues – caring for people where, when and how they choose in a way that is uniquely more connected, more convenient and more compassionate. And we do it all with heart, each and every day.

Position Summary

The Senior Endpoint Security Engineer plays a critical role in defining, implementing, and managing secure policy configuration policies across the organization's IT systems and infrastructure. This role ensures that security policy configurations are aligned with industry best practices and focuses on ensuring compliance with security standards, minimizing security gaps, vulnerabilities, and risk, through configuration management, and supporting organizational goals for a strong security posture.  The Senior Endpoint Security Engineer works closely with IT, DevOps, and security teams to enforce secure baselines and automate policy compliance.

Key Responsibilities:

Secure Policy Configuration Management (Hardening)

  • Develop, implement, and maintain secure configuration policy framework and baselines for operating systems, databases, applications, and network devices (e.g., firewalls, routers).

  • Collaborate with stakeholders to align secure configuration policies with business and compliance requirements.

  • Automate configuration scanning, remediation, and validation processes by developing and integrating workflows using tools like Qualys, ServiceNow, and APIs or scripting languages to enhance efficiency and scalability.

  • Regularly review and update policies to reflect changes in the threat landscape or regulatory requirements.

  • Stay informed of emerging security threats, compliance requirements, and best practices related to secure configurations.

  • Implement and maintain tools, processes, and configuration scan templates aligned with policy changes to continuously monitor, detect, and enforce secure configurations (e.g., Minimum Security Baseline scanners, configuration management tools).Conduct security audits and assessments to identify deviations and implement corrective actions.

  • Develop and deliver executive-level reports on compliance with configuration policies, including metrics on policy adherence and risk mitigation.

  • Lead root cause analysis and remediation efforts for configuration-related security incidents.

Collaboration and Integration

  • Work closely with IT, DevOps, and Security Operations teams to ensure secure configuration policies are integrated into system and application lifecycles.

  • Partner with compliance and risk teams to ensure configurations meet regulatory standards (e.g., PCI DSS, HIPAA, SOX).

  • Provide guidance and support during internal and external audits.

Continuous Improvement and Training

  • Promote a culture of security awareness and best practices within the organization.

  • Drive automation initiatives to streamline configuration management processes.

  • Provide training and resources to ensure teams understand and adhere to secure configuration policies.

Required Qualifications

  • 5+ years of experience in information security, with a focus on secure configuration management or related areas.

  • 5+ years of experience with secure configuration frameworks including CIS Benchmarks and configuration management tools (e.g., Qualys, Rapid7, Tanium).

  • 5+ years of strong understanding of operating systems (Windows, Linux, macOS) and network device configurations.

  • 5+ years with security architecture awareness. Strong grasp of how configuration compliance integrates with vulnerability, asset, and change management systems.

  • 5+ years of analytical problem-solving experience. Demonstrated ability to identify root causes through multi-angle analysis of compliance, telemetry, and policy logic.

Preferred Qualifications

  • Proficient knowledge and experience with database query languages (e.g., MySQL, SQL).

  • Knowledge of security monitoring and ITSM platforms (e.g., Splunk, ServiceNow, Archer).

  • Strong knowledge of compliance standards (e.g., ISO 27001, PCI DSS, HIPAA).

  • Experience with system hardening and secure configuration standards/frameworks (e.g., NIST SP 800-53, DISA STIGs).

  • Proven ability to diagnose and resolve technical issues within Qualys PC, agent-based systems, and automation framework.

  • Qualys Query Language (QQL) for data analysis, validation and reporting.

  • Familiarity with scripting languages (e.g., Python, PowerShell, Bash) for automation.

  • Certified Information Systems Security Professional (CISSP).

  • Certified Information Systems Auditor (CISA).

  • CompTIA Security+ or Cybersecurity Analyst (CySA+).

  • Qualys Security Configuration Assessment (SCA).

Education

Bachelor’s degree or equivalent experience (HS diploma + 4 years relevant experience)

Anticipated Weekly Hours

40

Time Type

Full time

Pay Range

The typical pay range for this role is:

$92,700.00 - $203,940.00

This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls.  The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors.  This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. 
 

Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.

Great benefits for great people

We take pride in our comprehensive and competitive mix of pay and benefits – investing in the physical, emotional and financial wellness of our colleagues and their families to help them be the healthiest they can be. In addition to our competitive wages, our great benefits include:

  • Affordable medical plan options, a 401(k) plan (including matching company contributions), and an employee stock purchase plan.

  • No-cost programs for all colleagues including wellness screenings, tobacco cessation and weight management programs, confidential counseling and financial coaching.

  • Benefit solutions that address the different needs and preferences of our colleagues including paid time off, flexible work schedules, family leave, dependent care resources, colleague assistance programs, tuition assistance, retiree medical access and many other benefits depending on eligibility.

For more information, visit https://jobs.cvshealth.com/us/en/benefits

We anticipate the application window for this opening will close on: 12/10/2025

Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.