Lead Security Engineer

At Genworth, we empower families to navigate the aging journey with confidence. We are compassionate, experienced allies for those navigating care with guidance, products, and services that meet families where they are. Further, we are the spouses, children, siblings, friends, and neighbors of those that need care—and we bring those experiences with us to work in serving our millions of policyholders each day.

We apply that same compassion and empathy as we work with each other and our local communities. Genworth values all perspectives, characteristics, and experiences so that employees can bring their full, authentic selves to work to help each other and our company succeed. We celebrate our diversity and understand that being intentional about inclusion is the only way to create a sense of belonging for all associates. We also invest in the vitality of our local communities through grants from the Genworth Foundation, event sponsorships, and employee volunteerism.

Our four values guide our strategy, our decisions, and our interactions:

  • Make it human. We care about the people that make up our customers, colleagues, and communities.
  • Make it about others. We do what's best for our customers and collaborate to drive progress.
  • Make it happen. We work with intention toward a common purpose and forge ways forward together.
  • Make it better. We create fulfilling purpose-driven careers by learning from the world and each other.

POSITION TITLE

Lead Security Engineer – Identity and Access Management

This role is not eligible for employment visa sponsorship.

POSITION LOCATION

Lynchburg, VA, Richmond, VA, Remote

This position is available to Virginia residents as Richmond or Lynchburg, VA hybrid in-office applicants or remote applicants residing in states/locations under Eastern or Central Standard Time: Alabama, Arkansas, Connecticut, Delaware, Florida, Georgia, Illinois, Indiana, Iowa, Kansas, Kentucky, Louisiana, Maine, Maryland, Massachusetts, Michigan, Minnesota, Mississippi, Missouri, Nebraska, New Hampshire, New Jersey, New York, North Carolina, North Dakota, Ohio, Oklahoma, Pennsylvania, Rhode Island, South Carolina, South Dakota, Tennessee, Texas, Vermont, Virginia, Washington DC, West Virginia or Wisconsin.

*Hybrid in-office would be required if you reside within 50 miles of our Richmond or Lynchburg, VA office. Required in-office days are Tuesdays, Wednesdays and Thursdays, with working hours targeting our core business hours of 9am-5pm EST.

YOUR ROLE

As an IT Security team member, you’ll play a crucial role in providing hands-on design, best practice implementation, configuration, integration, and deployment of Identity and Access Management products (SailPoint IIQ & other homegrown applications). You will be responsible for adhering to standards and policies for secure implementations, overseeing compliance, and supporting key IT and business stakeholders. As an ideal candidate, you will rely on extensive experience with Identity and Access Management, secure development practices and maintaining and maturing IAM Program.

What you will be doing

  • Design, implementation, and ongoing support of enterprise Identity and Access Management solutions with a primary focus on SailPoint IdentityIQ and SailPoint Identity Security Cloud.
  • Engineer and enhance identity lifecycle processes, including joiner, mover, leaver, provisioning, deprovisioning, access requests, certifications, role management, and policy enforcement.
  • Design, configure, and troubleshoot SailPoint workflows, rules, connectors, access profiles, roles, identity profiles, transforms, and integrations with enterprise systems.
  • Support migration, modernization, or coexistence efforts between SailPoint IdentityIQ and Identity Security Cloud, ensuring secure, scalable, and maintainable solutions.
  • Partner with application owners, infrastructure teams, HR, compliance, audit, and business stakeholders to onboard applications and improve identity governance controls.


Deliverables / Results

  • Reliable, well-documented IAM solutions that support secure access, operational efficiency, and compliance requirements.
  • Successful onboarding of applications, data sources, and access models into SailPoint platforms.
  • Improved automation for identity lifecycle management, access fulfillment, certification campaigns, and policy controls.
  • Technical documentation, runbooks, test evidence, and implementation notes that support audit readiness and long-term operational support.

Impact / Value Add

  • Strengthen the organization’s security posture by ensuring the right people have the right access at the right time.
  • Reduce access risk through improved governance, automated controls, timely deprovisioning, and clear certification processes.
  • Enable business agility by simplifying access requests, approval, and fulfillment processes while maintaining strong security and compliance standards.
  • Contribute to the maturity of the IAM program by identifying opportunities to streamline legacy processes and improve platform reliability.

Ownership

  • Own complex IAM engineering work from requirements and design through build, testing, implementation, and production support.
  • Take accountability for technical quality, secure configuration, documentation, change readiness, and operational handoff.
  • Proactively identify risks, dependencies, defects, and blockers, and communicate status clearly to leadership and stakeholders.

Collaboration

  • Work closely with security architecture, IAM operations, application teams, infrastructure, cloud, HR, legal, compliance, audit, and business partners.
  • Translate business and compliance requirements into practical IAM designs and implementation plans.
  • Provide technical guidance, mentoring, and knowledge sharing to engineers, administrators, and support teams.

What you bring

Perspective

  • A security-first mindset with practical experience balancing risk reduction, user experience, operational needs, and regulatory expectations.
  • A strong understanding of identity governance, access management, least privilege, segregation of duties, access certification, and audit readiness.
  • A continuous improvement mindset focused on simplification, automation, reliability, and measurable IAM program maturity.

Qualities

  • Strong problem-solving, analytical, and troubleshooting skills with the ability to resolve complex identity, access, data, and integration issues.
  • Clear written and verbal communication skills, including the ability to explain technical IAM concepts to non-technical stakeholders.
  • Demonstrated ownership, collaboration, attention to detail, and ability to lead work across multiple teams and priorities.

Education

  • Bachelor’s degree in Cyber Security, Information Security, Computer Science, Information Technology, Engineering, or a related field, or equivalent professional experience.
  • Relevant SailPoint certifications, cloud security certifications, or IAM/security certifications are preferred.

Skills

  • 5–7 years of professional experience in Identity and Access Management, information security, or security engineering.
  • Hands-on experience with SailPoint IdentityIQ and SailPoint Identity Security Cloud, including configuration, administration, development, and support.
  • Experience with SailPoint workflows, rules, connectors, provisioning, certifications, access requests, roles, policies, identity profiles, access profiles, transforms, and source integrations.
  • Knowledge of Java, BeanShell, JavaScript, XML, JSON, REST APIs, SCIM, JDBC, web services, and related integration patterns.
  • Experience integrating IAM platforms with Active Directory, Entra ID / Azure AD, LDAP, HR systems, SaaS applications, databases, and enterprise applications.
  • Understanding of SAML, OAuth, OpenID Connect, MFA, SSO, privileged access concepts, Zero Trust principles, and cloud identity patterns.
  • Familiarity with SDLC, Agile delivery, change management, DevOps practices, Git, CI/CD pipelines, testing, and production support processes.

Competencies

  • Technical leadership and solution design
  • Identity governance and administration expertise
  • Secure engineering and compliance-oriented delivery
  • Cross-functional collaboration and stakeholder management
  • Root-cause analysis and production issue resolution
  • Documentation, audit readiness, and operational excellence

Experience

  • 5–7 years of IAM, hands on SailPoint IdentityIQ and Identity Security Cloud
  • Experience supporting regulated environments, audit requests, SOX controls, access reviews, and compliance reporting preferred.
  • Experience leading technical workstreams, mentoring engineers, and delivering IAM capabilities in complex enterprise environments.

ADDITIONAL INFORMATION

National Range: $120,900 - $187,000

Disclaimer: This role is aligned to a national market-based pay range. Actual compensation will vary based on geographic location, experience, skills, and other job-related factors. In addition to base salary, this role is eligible to participate in a bonus incentive plan. Incentive compensation is based on individual and company performance and is not guaranteed.

Employee Benefits & Well-Being

Genworth employees make a difference in people’s lives every day. We’re committed to making a difference in our employees’ lives.

  • Competitive Compensation & Total Rewards Incentives
  • Comprehensive Healthcare Coverage
  • Multiple 401(k) Savings Plan Options
  • Auto Enrollment in Employer-Directed Retirement Account Feature (100% employer-funded!)
  • Generous Paid Time Off – Including 12 Paid Holidays, Volunteer Time Off and Paid Family Leave
  • Disability, Life, and Long Term Care Insurance
  • Tuition Reimbursement, Student Loan Repayment and Training & Certification Support
  • Wellness support including gym membership reimbursement and Employee Assistance Program resources (work/life support, financial & legal management)
  • Caregiver and Mental Health Support Services

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available