Lead Security Engineer
Indexed description
We apply that same compassion and empathy as we work with each other and our local communities. Genworth values all perspectives, characteristics, and experiences so that employees can bring their full, authentic selves to work to help each other and our company succeed. We celebrate our diversity and understand that being intentional about inclusion is the only way to create a sense of belonging for all associates. We also invest in the vitality of our local communities through grants from the Genworth Foundation, event sponsorships, and employee volunteerism.
Our four values guide our strategy, our decisions, and our interactions:
- Make it human. We care about the people that make up our customers, colleagues, and communities.
- Make it about others. We do what's best for our customers and collaborate to drive progress.
- Make it happen. We work with intention toward a common purpose and forge ways forward together.
- Make it better. We create fulfilling purpose-driven careers by learning from the world and each other.
This role is not eligible for employment visa sponsorship.
POSITION LOCATION
Lynchburg, VA, Richmond, VA, Remote
This position is available to Virginia residents as Richmond or Lynchburg, VA hybrid in-office applicants or remote applicants residing in states/locations under Eastern or Central Standard Time: Alabama, Arkansas, Connecticut, Delaware, Florida, Georgia, Illinois, Indiana, Iowa, Kansas, Kentucky, Louisiana, Maine, Maryland, Massachusetts, Michigan, Minnesota, Mississippi, Missouri, Nebraska, New Hampshire, New Jersey, New York, North Carolina, North Dakota, Ohio, Oklahoma, Pennsylvania, Rhode Island, South Carolina, South Dakota, Tennessee, Texas, Vermont, Virginia, Washington DC, West Virginia or Wisconsin.
- Hybrid in-office would be required if you reside within 50 miles of our Richmond or Lynchburg, VA office. Required in-office days are Tuesdays, Wednesdays and Thursdays, with working hours targeting our core business hours of 9am-5pm EST.
What You Will Be Doing
- Design, implementation, and ongoing support of enterprise Identity and Access Management solutions with a primary focus on SailPoint IdentityIQ and SailPoint Identity Security Cloud.
- Engineer and enhance identity lifecycle processes, including joiner, mover, leaver, provisioning, deprovisioning, access requests, certifications, role management, and policy enforcement.
- Design, configure, and troubleshoot SailPoint workflows, rules, connectors, access profiles, roles, identity profiles, transforms, and integrations with enterprise systems.
- Support migration, modernization, or coexistence efforts between SailPoint IdentityIQ and Identity Security Cloud, ensuring secure, scalable, and maintainable solutions.
- Partner with application owners, infrastructure teams, HR, compliance, audit, and business stakeholders to onboard applications and improve identity governance controls.
- Reliable, well-documented IAM solutions that support secure access, operational efficiency, and compliance requirements.
- Successful onboarding of applications, data sources, and access models into SailPoint platforms.
- Improved automation for identity lifecycle management, access fulfillment, certification campaigns, and policy controls.
- Technical documentation, runbooks, test evidence, and implementation notes that support audit readiness and long-term operational support.
- Strengthen the organization’s security posture by ensuring the right people have the right access at the right time.
- Reduce access risk through improved governance, automated controls, timely deprovisioning, and clear certification processes.
- Enable business agility by simplifying access requests, approval, and fulfillment processes while maintaining strong security and compliance standards.
- Contribute to the maturity of the IAM program by identifying opportunities to streamline legacy processes and improve platform reliability.
- Own complex IAM engineering work from requirements and design through build, testing, implementation, and production support.
- Take accountability for technical quality, secure configuration, documentation, change readiness, and operational handoff.
- Proactively identify risks, dependencies, defects, and blockers, and communicate status clearly to leadership and stakeholders.
- Work closely with security architecture, IAM operations, application teams, infrastructure, cloud, HR, legal, compliance, audit, and business partners.
- Translate business and compliance requirements into practical IAM designs and implementation plans.
- Provide technical guidance, mentoring, and knowledge sharing to engineers, administrators, and support teams.
- A security-first mindset with practical experience balancing risk reduction, user experience, operational needs, and regulatory expectations.
- A strong understanding of identity governance, access management, least privilege, segregation of duties, access certification, and audit readiness.
- A continuous improvement mindset focused on simplification, automation, reliability, and measurable IAM program maturity.
- Strong problem-solving, analytical, and troubleshooting skills with the ability to resolve complex identity, access, data, and integration issues.
- Clear written and verbal communication skills, including the ability to explain technical IAM concepts to non-technical stakeholders.
- Demonstrated ownership, collaboration, attention to detail, and ability to lead work across multiple teams and priorities.
- Bachelor’s degree in Cyber Security, Information Security, Computer Science, Information Technology, Engineering, or a related field, or equivalent professional experience.
- Relevant SailPoint certifications, cloud security certifications, or IAM/security certifications are preferred.
- 5–7 years of professional experience in Identity and Access Management, information security, or security engineering.
- Hands-on experience with SailPoint IdentityIQ and SailPoint Identity Security Cloud, including configuration, administration, development, and support.
- Experience with SailPoint workflows, rules, connectors, provisioning, certifications, access requests, roles, policies, identity profiles, access profiles, transforms, and source integrations.
- Knowledge of Java, BeanShell, JavaScript, XML, JSON, REST APIs, SCIM, JDBC, web services, and related integration patterns.
- Experience integrating IAM platforms with Active Directory, Entra ID / Azure AD, LDAP, HR systems, SaaS applications, databases, and enterprise applications.
- Understanding of SAML, OAuth, OpenID Connect, MFA, SSO, privileged access concepts, Zero Trust principles, and cloud identity patterns.
- Familiarity with SDLC, Agile delivery, change management, DevOps practices, Git, CI/CD pipelines, testing, and production support processes.
- Technical leadership and solution design
- Identity governance and administration expertise
- Secure engineering and compliance-oriented delivery
- Cross-functional collaboration and stakeholder management
- Root-cause analysis and production issue resolution
- Documentation, audit readiness, and operational excellence
- 5–7 years of IAM, hands on SailPoint IdentityIQ and Identity Security Cloud
- Experience supporting regulated environments, audit requests, SOX controls, access reviews, and compliance reporting preferred.
- Experience leading technical workstreams, mentoring engineers, and delivering IAM capabilities in complex enterprise environments.
- Competitive Compensation & Total Rewards Incentives
- Comprehensive Healthcare Coverage
- Multiple 401(k) Savings Plan Options
- Auto Enrollment in Employer-Directed Retirement Account Feature (100% employer-funded!)
- Generous Paid Time Off – Including 12 Paid Holidays, Volunteer Time Off and Paid Family Leave
- Disability, Life, and Long Term Care Insurance
- Tuition Reimbursement, Student Loan Repayment and Training & Certification Support
- Wellness support including gym membership reimbursement and Employee Assistance Program resources (work/life support, financial & legal management)
- Caregiver and Mental Health Support Services
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search