> Markdown version of [/jobs/ext/2004633-security-engineer](https://www.wearedevelopers.com/jobs/ext/2004633-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Genworth Financial, Inc. - **Location:** Lynchburg, VA, United States - **Experience:** Expert - **Salary:** $96,700.0 - $145,000.0 - **Contract:** Permanent contract - **Skills:** HTML, Java (Programming Language), JavaScript (Programming Language), .NET Framework, PHP (Programming Language), Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Bash Shell, C Sharp (Programming Language), Cloud Computing, Cloud Computing Security, Cyber Security, Computer Programming, Continuous Integration, Perl (Programming Language), Python (Programming Language), Windows PowerShell, Ruby, Software Licensing Audit, Software Engineering, Web Applications, Policy as Code, Scripting, Google Cloud, Cloud Platform System, Software Security, Information Technology, Devsecops, Vulnerability Analysis - **Published:** August 9, 2026 - **Apply:** https://www.dice.com/job-detail/98fbccdc-7127-4620-9712-c51ad3cbb848 ## About the Role ? Computer Science or similar degree ? Experience using vulnerability scanning technologies, AST platforms, and cloud security tooling. ? Formal experience with threat modeling. ? Experience leading projects, initiatives, and resources through direct and indirect leadership. ? Deep knowledge of Assessing and prioritization of Risk with an ability to think like a bad actor and use that context to conduct threat models. ? Cloud experience (AWS, Azure, Google Cloud Platform) ? Infrastructure as Code (IaaC) and Policy as Code (PaC) Concepts. ? Experience implementing secure Software Development Lifecycle programs. ? Familiarity with technical security controls, guidelines, and frameworks outlined by standards such as SOC2, ISO 27001, NIST 800-53. ? Ability to automate tasks and code solutions to repetitive problems. ? Scripting or programming experience (Java, .NET, HTML, Ruby, PHP, Perl, C#, Python, JavaScript, PowerShell, Bash) ? Experience with penetration testing and web application assessment. ? Experience assessing software compliance with HIPAA, PHI, PII and PCI regulations. ## Description As an Senior Security Engineer, Application you will manage the technologies and processes supporting secure application development in both physical datacenter and cloud environments. You will be responsible for providing application security services and support to internal partners to ensure adherence to the policies and standards of the company. As an ideal candidate you will have 5+ years of experience in a Security Engineering role with proven experience in Application Security, DevSecOps, and experience securing applications in cloud environments. What you will be doing: ? Manage and support application vulnerability scanning technologies, AST platforms, and cloud security tooling. ? Collaborate with business stakeholders to design secure applications, test applications for security weakness, and partner on remediation of identified issues. ? Work with key stakeholders to identify, respond to, and remediate information security issues. ? Coordinate the orchestration, automation, and management of security technologies and platforms. ? Support day-to-day life cycle management, including identification, threat assessment, threat modeling and risk avoidance. ? Create reasonable and actionable reports showing direct impact to the security posture. ? Define and implement meaningful metrics to measure the effectiveness of security controls through Key Risk Indicators (KRIs) and security scorecards. ? Serve as a subject-matter-expert for Application Security; act as a key point of contact for critical issues, security risk assessments and triaging CI/CD issues with partners and stakeholders. ? Evaluate business and technical requirements to identify and implement tools, processes, and technologies to improve our security posture in our environments. ? Ensure the continuous improvement of existing compliance processes. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [The Resilience of the World Wide Web](https://www.wearedevelopers.com/videos/1281-the-resilience-of-the-world-wide-web) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)