We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.
The Chief of Staff to the Deputy Chief Information Security Officer (Deputy CISO) is a leadership role responsible for driving execution, alignment, and operational discipline across the cybersecurity organization. Reporting to the Deputy CISO and working closely with the Chief Information Security Officer (CISO), this leader serves as a strategic partner and force multiplier for cybersecurity priorities, ensuring that key programs, budget commitments, strategic initiatives, and executive deliverables are coordinated, measurable, and delivered with impact.
This role requires a seasoned, proactive, and highly organized professional who can operate across executive, business, technology, finance, and security teams. The Chief of Staff will help advance the Deputy CISO program by managing critical planning rhythms, supporting cybersecurity strategy, strengthening program governance, coordinating budget and resource planning, and enabling clear communication between the Deputy CISO, CISO, and enterprise stakeholders.
Lead cross-functional cyber program governance, ensuring major initiatives, milestones, dependencies, risks, and executive decisions are tracked and driven to completion.
Monitor progress against strategic cybersecurity goals, identify roadblocks, escalate issues appropriately, and proactively recommend solutions to the Deputy CISO and CISO.
Prepare executive-level updates, decision materials, and performance narratives for the Deputy CISO, CISO, and senior leadership forums.
Develop and manage recurring cybersecurity status reports, executive briefings, leadership readouts, and program updates that clearly communicate progress, risks, decisions, and required actions.
Create clear, concise, and audience-appropriate communications for the Deputy CISO and CISO, including talking points, leadership messages, presentation narratives, and enterprise-facing updates.
Establish and maintain the Deputy CISO operating cadence, including leadership meetings, governance forums, business reviews, strategic planning sessions, and executive reporting routines.
Drive alignment across cybersecurity programs to ensure priorities, funding, resourcing, sequencing, and delivery plans support enterprise security strategy and risk reduction objectives.
Collaborate closely with cybersecurity leaders across security operations, governance, risk, compliance, engineering, architecture, identity, threat management, resilience, and related functions to align priorities, resolve dependencies, and advance enterprise cyber objectives.
Maintain an integrated communications calendar for key cybersecurity deliverables, leadership forums, enterprise updates, board materials, audit responses, and stakeholder engagement milestones.
Support cybersecurity budget planning, resource prioritization, financial governance, and investment tracking to ensure alignment with strategic objectives and enterprise financial commitments.
Partner with finance, procurement, and security leaders to support forecasting, budget reviews, investment cases, vendor spend visibility, and resource allocation decisions.
Develop and maintain mechanisms for tracking cybersecurity program health, including key risks, dependencies, issues, decisions, performance indicators, and executive action items.
Facilitate and prepare for key meetings, including developing agendas, preparing materials, capturing minutes, and ensuring follow-up on action items.
Foster strong working relationships with cyber leaders to promote transparency, coordination, accountability, and consistent execution across the cybersecurity leadership team.
Effectively communicate and collaborate with senior leaders across CVS Health, including the executive suite, legal, HR, finance, and other business units.
Serve as a communication bridge between the Deputy CISO, CISO, cybersecurity leadership, business partners, and enabling functions to ensure timely information flow, message consistency, and coordinated follow-up.
Represent the Deputy CISO in selected forums, planning discussions, and stakeholder engagements as needed, ensuring decisions, actions, and follow-through remain aligned with CISO and Deputy CISO priorities.
Attend, lead, and facilitate meetings on behalf of the Deputy CISO as appropriate, representing Deputy CISO priorities, guiding discussion, capturing key decisions, and ensuring timely follow-up on actions and commitments.
Coordinate sensitive, time-critical, or high-visibility cybersecurity matters on behalf of the Deputy CISO, ensuring appropriate stakeholder engagement, escalation, and follow-through.
Produce dashboards, scorecards, and narrative reports that summarize cybersecurity program performance, budget status, risk posture, delivery progress, and key decisions for executive review.
Identify trends, emerging risks, and operational insights from program data, metrics, audits, assessments, and leadership inputs to inform Deputy CISO and CISO decision-making.
Support preparation for board, executive committee, regulatory, audit, and enterprise risk discussions by consolidating inputs, clarifying messages, and ensuring materials are accurate and actionable.
10+ years of experience in a fast-paced, complex organizational environment, with at least 3-5 years in a Chief of Staff, strategic operations, or similar high-impact role supporting senior executives.
Proven ability to interact effectively with all levels of an organization, from individual contributors to the executive suite, with poise, professionalism, and influence.
Bachelor’s degree in Business Administration, Information Technology, Cybersecurity, or a related field.
Master’s degree in Cybersecurity, Information Security, Information Technology, Business Administration, or a related field preferred.
Experience in cybersecurity, security operations, risk management, or technology leadership support.
Relevant cybersecurity, security program, governance, risk, or project/program management certifications preferred, such as CISSP, CISM, CRISC, CGEIT, PMP, PgMP, or similar credentials.
Pay Range
The typical pay range for this role is:
$175,100.00 - $334,750.00
This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company’s equity award program.
Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.
Great benefits for great people
We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.
This full‑time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well‑being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.
Additional details about available benefits are provided during the application process and on Benefits Moments.
We anticipate the application window for this opening will close on: 09/02/2026
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.