CVS Health is committed to building a world of health around every individual. The Lead Data Privacy Engineer will advance enterprise data protection capabilities by designing and implementing scalable privacy and security solutions, partnering across various teams to embed privacy-by-design principles and drive the organization's data protection strategy.
Responsibilities:
- Lead the strategy, prioritization, implementation, and continuous improvement of enterprise data protection and privacy engineering capabilities across structured and unstructured data environments, including enterprise data discovery, inventory, and data mapping initiatives to improve visibility, governance, and protection of regulated and sensitive data assets
- Design, deploy, and optimize Privacy Enhancing Technologies (PETs), including encryption, tokenization, anonymization, pseudonymization, data classification, Data Loss Prevention (DLP), and other privacy-preserving solutions that protect sensitive information while enabling business innovation
- Partner with engineering, product, legal, compliance, and cybersecurity teams to embed privacy-by-design principles and translate regulatory requirements into scalable architectures, technical standards, governance controls, and enterprise data protection solutions
- Conduct privacy risk assessments, privacy impact assessments, threat modeling, and control evaluations to identify, mitigate, and monitor privacy and security risks while supporting audit, compliance, investigation, and regulatory obligations
- Drive enterprise data governance, privacy metrics, automation, advanced analytics, emerging privacy technologies, and continuous improvement initiatives by monitoring industry trends and regulatory developments and leading cross-functional teams to strengthen the organization's privacy posture, data protection effectiveness, and operational efficiency
Requirements:
- 7+ years of experience in Privacy Engineering, Security Engineering, Data Protection, Cybersecurity, or related technical disciplines, including implementation of privacy and data protection requirements associated with GDPR, CCPA/CPRA, HIPAA, or similar regulatory frameworks
- 5+ years of experience designing and implementing enterprise data protection capabilities, including encryption, tokenization, key management, data classification, Data Loss Prevention (DLP), or insider risk controls
- 5+ years of hands-on experience developing solutions using one or more programming or scripting languages such as Python, Java, Go, or similar
- 5+ years of experience working in cloud and DevSecOps environments, including CI/CD pipelines, Infrastructure as Code (IaC), privacy threat modeling, privacy impact assessments, and security automation
- 3+ years of experience leading enterprise-scale privacy, data protection, cybersecurity, or compliance initiatives while partnering with cross-functional stakeholders across engineering, product, legal, compliance, and security teams
- Professional certifications such as CDPSE, CIPP, CIPT, CIPM, CISSP, or equivalent
- Experience with industry frameworks and standards such as NIST, ISO 27001, HITRUST, FIPS, PCI DSS, and HIPAA, including supporting regulatory audits, compliance assessments, investigations, and remediation activities
- Experience with AWS, Azure, GCP, SQL/NoSQL databases, data lakes, and large-scale data platforms
- Experience leveraging AI, automation, or advanced analytics to enhance privacy and data protection capabilities
- Experience protecting PHI, PII, and other regulated data within healthcare, health insurance, financial services, or similarly regulated environments