Hiring.Camp

R1054567 Senior Analyst, IT Compliance & Risk - Data Protection

CVS Health

·

Today

Salary
$79k – $173k
Location
Woonsocket-1 CVS Drive, United States of America · Wellesley-93 Worcester St
Workplace
Remote
Type
Full-time
Department
Legal
Seniority
Senior
Experience
3+ years
Closing date
Today
Source
Workday

Description

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.

Position Description:

The Corporate Functions & PCW IT Compliance Team is looking for a resource to become our Data Protection Domain SME, focusing on information classification, data obfuscation, encryption, and data security controls and governance. This person will help our team build-out, maintain, and continuously improve upon the support framework for Data Protection. He or she will serve as a key player in our day-to-day operations, navigate the Compliance workload and emerging priorities, and provide front-line support for our application teams, ensuring compliance with data privacy and protection policies, industry regulations, and any contractual obligations.

 

Responsibilities:

  • Develop and implement data security governance framework that aligns with industry best practices, regulatory requirements, and company policies.
  • Guide and assist application teams with identifying data protection gaps and developing remedial action plans for non-conformance to policy requirements.
  • Assess and interpret IT policies and control standards for system and operational compliance.
  • Maintain key files and relevant data sources for compliance governance and reporting, including operational metrics. This includes maintaining data quality, consistency, and integrity.
  • Assist with compilation and maintenance of process documentation, job-aids, FAQs, and other support-related materials for our application teams

  • Promote industry best practices for Data Privacy and Protection, ensuring compliance with relevant regulations and standards such as PCI, SOX, HIPAA, HiTrust, NIST, and others.
  • Stay updated on industry trends, emerging data security and privacy engineering technologies, and security threats to continuously improve and evolve data protection strategy and solutions.

Location

Hybrid schedule in Woonsocket RI or Wellesley MA highly preferred. Will consider remote.

 

Required Qualifications

  • Strong knowledge of data protection techniques and best practices, including data obfuscation / masking, sensitive information classifications, encryption at rest and in transit, data retention and destruction.
  • 3+ years of experience with implementing data security and privacy engineering solutions and frameworks.
  • Knowledge of IT security-related regulations and frameworks such as PCI, HIPAA, SOX, SOC1, SOC2, HiTrust, GDPR, CCPA, NIST, and ISO 27001.
  • Strong problem-solving, analytical, critical thinking, and organizational skills with demonstrated versatility to handle concurrent high priority tasks.
  • Strong oral and written and communication skills with ability to clearly articulate and communicate complex problems and solutions in a simple, logical, and impactful manner to both technical and non-technical stakeholders.
  • Self-motivated with ability to work independently with minimal supervision or without direction, and ability to prioritize work effectively.
  • Demonstrated ability to handle concurrent high priority tasks and work in dynamic environment on a daily basis.
  • Comfortable operating within areas of ambiguity with ability to iterate and make progress in a consistent manner.
  • Experience working on technical projects involving multiple teams, providing management with status on potential issues as well as driving those issues to closure.
  • Intermediate to advanced proficiency in MS Excel (pivot tables, lookups, conditional formatting, Power Query, etc.).

Preferred Qualifications

  • Security certifications such as CISSP, CRISC, CISA, CISM, CCSP, etc.
  • Product Management and Program Management experience.
  • Process improvement exposure / Lean / Six Sigma. 



Education

  • Bachelor’s Degree in Computer Science, Information Technology, Cybersecurity, or related field or equivalent work experience (HS diploma + 3 years relevant experience).
  • Ongoing education in cybersecurity, data privacy and protection, or related domains is a plus.

Anticipated Weekly Hours

40

Time Type

Full time

Pay Range

The typical pay range for this role is:

$79,310.00 - $173,040.00

This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls.  The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors.  This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. 
 

Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.

Great benefits for great people

We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.

This full‑time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well‑being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.


Additional details about available benefits are provided during the application process and on
Benefits Moments.

We anticipate the application window for this opening will close on: 10/22/2026

Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.

Skills

ExcelCybersecuritySOXComplianceProgram ManagementSix SigmaHIPAAGDPRISO 27001CISSP