CVS Health

Staff Engineer - Regulatory Technology

TX - Work from home Full time

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.

Position Summary

The Staff Engineer, Regulatory Technology Engineering is responsible for the development and delivery of technology solutions that support the strategic direction of technology compliance and audit management for CVS Health’s Digital, Data, Analytics & Technology (DDAT) Compliance organization. This role applies deep technical expertise to design, modernize, and operationalize technology solutions that support SOX, SOC 1, SOC 2, PCI, HITRUST, NIST 800‑53, NYDFS, and other cybersecurity and regulatory frameworks.

The role partners closely with engineering teams, process and control owners, and security architects to develop robust, audit‑ready control environments and automate evidence collection for complex, modern technology stacks, including cloud‑native platforms, distributed systems, AI/ML solutions, and DevSecOps implementations. This role requires an engineering mindset and the ability to translate regulatory requirements into scalable technical controls, automated testing approaches, and measurable compliance indicators.

You will contribute to the development and continuous improvement of compliance tooling, control processes, dashboards, and metrics. Additionally, you will collaborate with IT, business partners, Learning and Development, Internal Audit, Legal, and external assessors to ensure alignment, transparency, and consistent execution of the technology compliance program.

Required Qualifications

  • 7+ years of software engineering or software development experience, with a strong understanding of modern architectures and engineering practices
  • 7+ years of technical project leadership experience, supporting engineering initiatives on cross‑functional teams in highly collaborative environments
  • 5+ years of experience in internal audit, external assessments, risk management, regulatory compliance, or information security within a corporate environment
  • 5+ years of experience with audit methodologies, internal control frameworks, risk assessments, and control testing techniques, with the ability to apply them to cloud and modern technology environments
  • 3+ years of hands‑on experience with cloud security engineering, architecture, and/or automation, including designing or evaluating technical controls in cloud‑native platforms (AWS, Azure, GCP)

Preferred Qualifications

  • Strong understanding of the software development lifecycle (SDLC) and secure development practices
  • Experience with AI/ML platforms, tools, and related risk considerations
  • Understanding of regulatory frameworks and security standards such as NIST, ISO, HITRUST, HIPAA, PCI, SOC 1/SOC 2, and SOX, with the ability to interpret and translate requirements into technical solutions
  • Experience with DevOps/DevSecOps, CI/CD pipelines, infrastructure‑as‑code, and modern cloud infrastructure and cybersecurity patterns
  • Ability to document and translate complex technical requirements for development team consumption
  • Strong attention to detail with exceptional analytical and problem‑solving skills; able to evaluate technical systems, identify risks, and propose pragmatic solutions
  • Demonstrated ability to influence across engineering, security, and business teams, building strong relationships with technical and non‑technical stakeholders
  • Excellent written and verbal communication skills, capable of explaining complex technical and regulatory concepts in a clear and concise manner
  • Experience working with risk management frameworks and identifying cybersecurity risks in modern technology environments
  • Strong program management skills, including strategic planning, road‑mapping, and technical project execution
  • Industry experience in Healthcare, Insurance, or Retail is a plus
  • Relevant certifications such as CCSK, CCSP, CISSP, CRISC, or similar credentials

Education

  • Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or equivalent experience (High School Diploma and 4+ years of relevant experience).

Pay Range

The typical pay range for this role is:

$106,605.00 - $284,280.00


This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls.  The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors.  This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above.  This position also includes an award target in the company’s equity award program. 
 

Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.

Great benefits for great people

We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.

This full‑time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well‑being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.


Additional details about available benefits are provided during the application process and on
Benefits Moments.

We anticipate the application window for this opening will close on: 05/04/2026

Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.