CybersecurityJobs.io
← Back to all jobs

Job Description

Genworth offers a hybrid work setup and a total rewards package designed to support your health, growth, and day to day wellbeing. This Senior Security Engineer role focuses on securing application development across physical datacenter and cloud environments, with opportunities to partner across teams, improve security automation, and help strengthen application security outcomes.

Location: Richmond, VA (hybrid) or Lynchburg, VA (hybrid). In office days are Tuesday, Wednesday and Thursday, with working hours targeting 9am to 5pm EST.

Compensation: USD 96,700 - 145,000 annually (national range). Actual compensation may vary by geographic location, experience, skills, and other job-related factors. This role is also eligible to participate in a bonus incentive plan, based on individual and company performance and not guaranteed.

Benefits

  • Competitive Compensation & Total Rewards Incentives
  • Comprehensive Healthcare Coverage
  • Multiple 401(k) Savings Plan Options
  • Auto Enrollment in an employer-directed retirement account feature (100% employer-funded)
  • Generous Paid Time Off including 12 paid holidays, Volunteer Time Off, and Paid Family Leave
  • Disability, Life, and Long Term Care Insurance
  • Tuition Reimbursement, Student Loan Repayment, and Training & Certification Support
  • Wellness support including gym membership reimbursement and Employee Assistance Program resources (work/life support, financial & legal management)
  • Caregiver and Mental Health Support Services

What You’ll Do

In this role, you will manage and support application security technologies and processes that help internal partners develop more secure applications. You will coordinate vulnerability scanning and security tooling across cloud and datacenter environments, provide application security guidance, and serve as a subject-matter-expert for critical application security issues.

  • Manage and support application vulnerability scanning technologies, AST platforms, and cloud security tooling
  • Collaborate with stakeholders to design secure applications, test for security weaknesses, and partner on remediation
  • Identify, respond to, and remediate information security issues with key stakeholders
  • Coordinate orchestration, automation, and lifecycle management of security technologies and platforms
  • Support day-to-day lifecycle activities including threat assessment, threat modeling, and risk avoidance
  • Create reasonable, actionable reporting that demonstrates direct impact to the security posture
  • Define and implement metrics using Key Risk Indicators (KRIs) and security scorecards to measure control effectiveness
  • Serve as a subject-matter-expert for Application Security, including triage and support for critical issues, security risk assessments, and CI/CD security issues with partners and stakeholders
  • Evaluate business and technical requirements to identify and implement tools, processes, and technologies that improve security posture
  • Support continuous improvement of existing compliance processes

Requirements

  • Computer Science or similar degree
  • 5+ years of experience
  • Experience using vulnerability scanning technologies, AST platforms, and cloud security tooling
  • Formal experience with threat modeling
  • Experience leading projects, initiatives, and resources through direct and indirect leadership
  • Deep knowledge of assessing and prioritizing risk, including ability to think from an attacker perspective to conduct threat models
  • Cloud experience with AWS, Azure, and/or GCP
  • Understanding of Infrastructure as Code (IaaC) and Policy as Code (PaC) concepts
  • Experience implementing secure Software Development Lifecycle programs
  • Familiarity with security controls, guidelines, and frameworks such as SOC2, ISO 27001, and NIST 800-53
  • Ability to automate tasks and build code solutions to repetitive problems
  • Scripting or programming experience in one or more: Java, .NET, HTML, Ruby, PHP, Perl, C#, Python, JavaScript, PowerShell, Bash
  • Experience with penetration testing and web application assessment
  • Experience assessing software compliance with HIPAA, PHI, PII, and PCI regulations

Technologies

AWS, Azure, GCP, Infrastructure as Code (IaaC), Policy as Code (PaC), Java, .NET, HTML, Ruby, PHP, Perl, C#, Python, JavaScript, PowerShell, Bash, SOC2, ISO 27001, NIST 800-53, HIPAA, PCI, CI/CD

Eligibility: This position is available to Virginia residents for in-office applicants in Richmond or Lynchburg, Virginia.

Similar Jobs