Senior Security Engineer

  • GENWORTH
  • Richmond, Virginia
  • 08/26/2026
Full time Information Technology Telecommunications Java Software Engineer

Job Description

Genworth is seeking a Senior Security Engineer, Application to lead application security across our financial platforms supporting long-term care and protection products. In this role, you will design and implement security controls, conduct threat modeling and secure code reviews, and guide developers in addressing vulnerabilities in web, API, and cloud-based applications. Partnering closely with engineering, DevOps, and architecture teams, you will embed security into CI/CD pipelines, champion secure coding practices, and support audits and compliance. Join a collaborative, mission-driven environment focused on integrity and families' long-term financial security.

Responsibilities

  • Design, implement, and maintain application security controls across Genworth's financial platforms
  • Conduct threat modeling, secure code reviews, and vulnerability assessments on web and API services
  • Collaborate with software engineering and Dev
  • Ops teams to embed security into CI/CD pipelines
  • Develop and enforce secure coding standards and security best practices for development teams
  • Investigate, triage, and remediate application security incidents and vulnerabilities
  • Evaluate and integrate security tools such as SAST, DAST, SCA, and secrets management into workflows
  • Partner with architecture and product teams to ensure security requirements are defined and met
  • Create and deliver security training and guidance for developers and technical stakeholders
  • Contribute to security roadmaps, risk assessments, and compliance initiatives relevant to financial services
  • Document security designs, procedures, and remediation plans to support audits and governance

Required Skills

  • Application security engineering
  • Threat modeling
  • Secure code review (Java, .
  • NET, JavaScript, APIs)
  • SAST/DAST/SCA tools (e.g., Veracode, Burp Suite)
  • Web and API security (OWASP Top 10)
  • Dev
  • Sec
  • Ops and CI/CD integration
  • Identity and access management concepts
  • Cloud security for AWS/Azure
  • Incident response for application vulnerabilities
  • Security documentation and developer training