The role
From CVS Health's own posting.
We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.
POSITION SUMMARY
CVS Health is seeking a Senior Cloud Data Security Engineer – Data Loss Prevention (DLP) to help safeguard the sensitive data assets of one of the nation's largest healthcare, pharmacy, and retail organizations. The Senior Cloud Data Security Engineer – Data Loss Prevention (DLP) serves as a senior member of the Data Protection Team and is responsible for designing, implementing, and advancing enterprise-wide data protection capabilities that secure Data in Motion (DIM), Data in Use (DIU), and cloud-hosted data across a highly complex and regulated environment. The Senior Cloud Data Security Engineer – Data Loss Prevention (DLP) will lead the development and maturation of strategic DLP programs spanning cloud, endpoint, email, network, SaaS, and AI/ML ecosystems while ensuring alignment with business objectives, regulatory requirements, and evolving cyber threats.
The Senior Cloud Data Security Engineer – Data Loss Prevention (DLP) partners closely with Cybersecurity, Infrastructure, Cloud Engineering, Data Engineering, AI/ML, Enterprise Architecture, Privacy, Compliance, and business teams to deliver scalable and effective data protection solutions. The Senior Cloud Data Security Engineer – Data Loss Prevention (DLP) is responsible for preventing unauthorized disclosure, misuse, loss, or exfiltration of sensitive information, including PHI, PII, PCI, and proprietary CVS Health data. This position will drive data classification and labeling initiatives, enhance visibility into data movement across enterprise platforms, and build automated detection and response capabilities that improve security outcomes while minimizing operational friction.
As CVS Health accelerates adoption of cloud services, artificial intelligence, and machine learning technologies, the Senior Cloud Data Security Engineer – Data Loss Prevention (DLP) will play a critical role in securing AI-enabled business processes, identifying and mitigating risks associated with shadow AI usage, and implementing controls that protect sensitive information throughout AI/ML pipelines, model training environments, and generative AI platforms. Success in the Senior Cloud Data Security Engineer – Data Loss Prevention (DLP) position requires deep expertise in enterprise DLP technologies, cloud security architectures, data governance, automation, and regulatory compliance, along with the ability to influence technical strategy, lead complex initiatives, and serve as a trusted subject matter expert for enterprise data protection.
PRIMARY DUTIES AND RESPONSIBILITIES
Design, implement, and continuously mature enterprise Data Loss Prevention (DLP) strategies, policies, and controls across cloud, endpoint, email, network, SaaS, and collaboration platforms to protect sensitive data from unauthorized access, disclosure, misuse, and exfiltration.
Lead the end-to-end DLP program lifecycle, including data classification and labeling, policy development, rule tuning, incident management, investigations, root cause analysis, remediation, and continuous improvement of data protection capabilities governing PHI, PII, PCI, and proprietary information.
Architect and enhance cloud data protection capabilities across AWS, Azure, GCP, and hybrid environments utilizing technologies and frameworks such as Microsoft Purview, CASB, CNAPP, CSPM, SASE, DSPM, Conditional Access, and Zero Trust architectures.
Design, implement, and enforce data protection controls for AI/ML platforms, generative AI solutions, Large Language Models (LLMs), AI agents, MLOps pipelines, and shadow AI use cases to prevent unauthorized ingestion, exposure, retention, or transmission of sensitive and regulated data.
Develop dashboards, metrics, key risk indicators, and executive reporting that measure DLP effectiveness, control coverage, incident trends, and enterprise data protection posture, while driving automation of policy enforcement, alert triage, and response workflows to improve operational efficiency.
Partner with Cybersecurity, Privacy, Compliance, Legal, Risk Management, Infrastructure, Cloud Engineering, Data Engineering, Enterprise Architecture, and business stakeholders to define data protection strategy, security standards, governance processes, and roadmap priorities aligned with regulatory and business requirements.
Serve as the enterprise subject matter expert for DLP, cloud data security, and AI/ML data protection, providing leadership and guidance for cloud transformations, AI platform deployments, digital modernization initiatives, and other strategic programs while ensuring alignment with industry frameworks including NIST, CIS, CSA, HIPAA, PCI-DSS, and MITRE ATLAS.
REQUIRED QUALIFICATIONS
5+ years of experience designing, implementing, and supporting enterprise cloud security and data protection solutions, with a strong emphasis on Data Loss Prevention (DLP) in large-scale environments.
5+ years of hands-on expertise administering and optimizing enterprise DLP platforms such as Microsoft Purview, Zscaler, Palo Alto, or equivalent data protection technologies.
5+ years of demonstrated success creating, deploying, and enforcing DLP policies and controls across cloud, endpoint, email, network, SaaS, and collaboration platforms.
5+ years working with at least two major cloud platforms, including AWS, Azure, and/or Google Cloud Platform (GCP), implementing security and data protection controls.
5+ years of practical experience leveraging Zero Trust principles, CASB, CSPM, CNAPP, Conditional Access, and related cloud security frameworks.
5+ years of responsibility for data classification, information protection, and governance initiatives involving PHI, PII, PCI, confidential, and proprietary data.
5+ years partnering with cybersecurity, engineering, infrastructure, compliance, and business stakeholders to investigate data security incidents, perform root cause analysis, and drive remediation activities.
PREFERRED QUALIFICATIONS
Hands-on experience developing and tuning advanced DLP detection logic using Regex, dictionaries, Exact Data Match (EDM), fingerprinting, and related content inspection techniques, with proficiency in security analytics and reporting tools such as Splunk, Chronicle, Power BI, or comparable platforms.
Experience implementing and supporting network security, email security, secure web gateway, proxy, and firewall technologies focused on preventing data exfiltration and unauthorized data movement.
Experience securing AI/ML environments, including Large Language Models (LLMs), Generative AI solutions, AI agents, and MLOps platforms, with a strong focus on data protection, governance, and risk management.
Demonstrated success leading DLP, information protection, or data security engineering initiatives and delivering enterprise-scale solutions through collaboration with cybersecurity, engineering, infrastructure, data, and business stakeholders.
Experience supporting mission-critical security platforms in large enterprise environments, including participation in on-call rotations and the ability to provide off-hours and weekend support when required.
Relevant industry certifications such as Microsoft Information Protection Administrator (SC-400), Microsoft Security Operations Analyst (SC-200), CCSP, CISSP, CCSK, AWS Security Specialty, or equivalent cloud and security certifications.
Strong communication, stakeholder management, and problem-solving skills, with the ability to influence technical decisions and translate complex sec