Application Security Engineer at Genworth North America Corporation
Richmond, VA
$96,700–$145,000from the description
Jun 29, 2026
Richmond, VA
Jul 20, 2026
What this job asks for AI summary
This role sits within an application security function, responsible for managing vulnerability scanning tools, AST platforms, and cloud security tooling across both datacenter and cloud environments. Day-to-day work involves threat modeling, supporting secure software development lifecycle programs, coordinating DevSecOps automation, and advising internal teams on remediation. It suits an experienced security engineer with a background in cloud platforms, penetration testing, and compliance frameworks such as NIST, SOC2, and HIPAA.
Senior level · 5+ years · Richmond, VA · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 15 people in the Richmond, VA area plausibly meet what this posting asks for (information security analysts). range 5–25
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $126,230 (middle half $96,830–$160,900). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
The role is located in Richmond, VA and Lynchburg, VA; Richmond is used as the primary CBSA. No remote option is stated.
The title carries no seniority level word, so advertised seniority is Unspecified; the 5+ years requirement and scope (SME, cross-team stakeholder engagement, threat modeling ownership) support a Senior classification.
Degree is listed as 'Computer Science or similar degree' under 'What you bring' but no hard language ('required', 'must') is used, and no equivalent-experience clause is present — treated as preferred rather than a hard gate.
Cloud platforms (AWS, Azure, GCP) are listed together as a single requirement; AWS is used as the primary name with Azure and GCP as alternatives.
Infrastructure as Code (IaC) and Policy as Code (PaC) are listed as concepts rather than specific tools; Terraform is the canonical IaC tool and is used as the representative skill name.
Scripting/programming languages are listed as a broad set of alternatives; Python is used as the primary name with the others captured as alternatives.
Compliance frameworks (SOC2, ISO 27001, NIST 800-53) are framed with 'familiarity with' — treated as preferred. HIPAA/PHI/PII/PCI experience is stated more firmly ('experience assessing') and is treated as required.
An alt SOC of 15-1252 (Software Developers) is noted because the role has meaningful DevSecOps/automation/scripting responsibilities, though the primary focus is security analysis and risk management.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.