We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.
The AVP, Technology Assurance leads Internal Audit’s technology audit and assurance coverage across CVS Health. The role brings together three areas of coverage under a single leader: established technology and cybersecurity audit, emerging risk assurance, and Internal Audit’s advisory presence on the company’s largest enterprise system implementations.
The AVP provides independent, third-line assurance and advisory support across the technology landscape. Technology risk ownership, technology and AI strategy, and decisions about how solutions are designed, built, and deployed remain with technology, digital, and business leadership; this role evaluates and advises on them independently. Consistent with how the Emerging Risk Assurance function operates, the AVP adds value early and surfaces gaps without assuming management responsibility for decisions that belong to the business, preserving the independence that makes the assurance credible.
The AVP sets direction and quality standards for their teams and represents Internal Audit with senior technology, digital, and business leadership on cross-cutting matters. Because both the established IT/cybersecurity audit and emerging risk assurance pillars report to this role, the AVP owns coordination across them directly - ensuring coverage is complete and efficient, with clear ownership of where the two disciplines meet.
The AVP also serves as Internal Audit’s embedded advisory presence on governance and steering forums for large-scale ERP implementations. This is an advisory role that surfaces control and risk considerations to program leadership ahead of go-live, and is distinct from any formal testing the program may later require.
Responsibilities
The ideal candidate has led technology audit or technology assurance teams at scale and can operate as a leader of leaders, managing through the Executive Directors. Comfort operating at the intersection of established IT controls and emerging AI risk is essential, since this role is the point where those two audit disciplines meet.
Technology and Cybersecurity Audit Leadership
Set strategy and audit plan coverage for IT corporate audit and cybersecurity, aligned to enterprise risk appetite.
Oversee the Executive Director, DDAT/IT Audit in execution of the IT and cyber audit plan, including cybersecurity controls, incident response, and regulatory compliance reviews.
Hold the primary Internal Audit relationship with technology leadership, providing independent perspective on control effectiveness, IT governance, and risk management maturity.
Report technology audit results, themes, and emerging risks to the CAE and Audit Committee.
Emerging Risk Assurance Oversight
Oversee the Executive Director, Emerging Risk Assurance and the third-line assurance function over AI, machine learning, intelligent automation, and other algorithmic or autonomous decision-making risk.
Ensure emerging risk assurance work stays positioned as independent evaluation of governance and controls, distinct from strategy-setting or management of how AI and emerging solutions are built and deployed.
Coordinate emerging risk coverage against established technology audit coverage owned by the DDAT/IT Audit team, so the two pillars stay aligned without duplicating work.
Maintain the human-in-the-loop versus human-over-the-loop distinction across audit approach and reporting, including for AI-related changes to the SOX control environment.
Support the Emerging Risk Assurance team's advisory role with the AI Governance Council and technology teams during design of new AI use cases and governance structures.
ERP Program Advisory
Serve as Internal Audit's embedded advisory presence on governance and steering forums for large-scale ERP implementations.
Surface control and risk considerations to program leadership ahead of go-live in an advisory capacity.
Define the boundary between this advisory role and any downstream formal audit or SOX testing the program later requires.
Keep the CAE informed on ERP program risk and readiness at key milestones.
Leadership, People Management, and Communication
Lead, develop, and hold accountable the leaders of both functions and their teams, building a high-performance culture across established and emerging technology audit disciplines
Build bench strength and succession depth across the technology assurance pillar.
Communicate audit results clearly and credibly to both technical and non-technical stakeholders, translating complex technology risk into actionable business insight.
Build trusted working relationships with technology leadership, the AI Governance Council, ERP program leadership, and business partners while preserving audit independence.
Model Internal Audit's leadership standards: communicate openly, act with integrity, and win together.
Location
Required Qualifications
15+ years of progressive experience in internal audit, risk, compliance, or related fields, including team leadership
Experience leading through Director-level people managers who own their respective functional areas, operating in complex, ambiguous, multi-functional environments
Ability to influence and partner across functions at the executive level
Strong project and program management skills, with the ability to manage multiple priorities and meet deadlines
Exceptional communication and executive presentation skills
Experience with audit committee and senior leadership reporting
Strategic mindset with the ability to develop and execute enterprise-wide initiatives
Team leadership skills
Proficiency in audit tools, data analytics, and Microsoft Office suite
Travel - Based on the needs of the business to Hartford, CT/Woonsocket, RI
Education
Bachelor's degree (required)
Pay Range
The typical pay range for this role is:
$185,400.00 - $375,950.00
This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company’s equity award program.
Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.
Great benefits for great people
We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.
This full‑time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well‑being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.
Additional details about available benefits are provided during the application process and on Benefits Moments.
We anticipate the application window for this opening will close on: 09/11/2026
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.