Enterprise Manager, Technology & Cybersecurity Risk
Job Description
At Genworth, we empower families to navigate the aging journey with confidence. We are compassionate, experienced allies for those navigating care with guidance, products, and services that meet families where they are. Further, we are the spouses, children, siblings, friends, and neighbors of those that need care—and we bring those experiences with us to work in serving our millions of policyholders each day.
\n\nWe apply that same compassion and empathy as we work with each other and our local communities. Genworth values all perspectives, characteristics, and experiences so that employees can bring their full, authentic selves to work to help each other and our company succeed. We celebrate our diversity and understand that being intentional about inclusion is the only way to create a sense of belonging for all associates. We also invest in the vitality of our local communities through grants from the Genworth Foundation, event sponsorships, and employee volunteerism.
\n\nOur four values guide our strategy, our decisions, and our interactions:
\n- \n
- Make it human. We care about the people that make up our customers, colleagues, and communities. \n
- Make it about others. We do what's best for our customers and collaborate to drive progress. \n
- Make it happen. We work with intention toward a common purpose and forge ways forward together. \n
- Make it better. We create fulfilling purpose-driven careers by learning from the world and each other. \n
\n
POSITION TITLE
\nEnterprise Manager, Technology & Cybersecurity Risk
\n\nPOSITION LOCATION
\nRichmond, Virginia
\n\nThis position is available to Virginia residents as Richmond, Virginia in-office applicants
\n\n*A Hybrid schedule of both Remote and In-Office days is required. In office days are Tuesday, Wednesday and Thursday with working hours targeting our core business hours of 9am-5pm EST.
\n\nYOUR ROLE
\nThe Enterprise Manager, Technology Risk & Cybersecurity Risk is a senior individual contributor responsible for leading risk identification, assessment, and mitigation activities across the organization’s technology environment, with a strong emphasis on technology and cybersecurity risk management and supporting oversight of third-party risk.
\nThis role serves as a subject matter expert in technology risk, partnering closely with Technology, Cybersecurity, and Business teams to ensure risks are effectively managed, controls are appropriately designed, and regulatory and industry expectations are met.
\nThis role operates with minimal supervision, significant independent judgment, and cross-functional influence, contributing to enterprise risk objectives and strengthening the organization’s overall risk posture.
\n\nWhat you will be doing
\n1. Technology Risk Management
\n- \n
- Lead and execute enterprise-wide technology risk assessments across applications, infrastructure, cloud platforms, and data environments \n
- Identify, evaluate, and prioritize risks related to system availability, security, resilience, and data integrity \n
- Maintain and manage the technology risk register, including risk identification, scoring, and remediation tracking \n
- Evaluate and challenge the design and effectiveness of IT general controls (ITGCs) and application controls \n
- Align risk and control frameworks to industry standards (e.g., NIST, ISO 27001, COBIT, SOC 2, CIS Controls) \n
- Partner with Technology and Security teams to drive control improvements and remediation of identified risk \n
- Support risk appetite and tolerance definition, including development and monitoring of key risk indicators (KRIs) \n
- Provide oversight and challenge to ensure risks are properly identified and managed within technology initiatives, projects, and change efforts \n
- Support regulatory, audit, and compliance activities by providing documentation, evidence, and subject matter expertise \n
- Monitor emerging technology risks (e.g., cloud, AI, cyber threats) and translate them into actionable mitigation strategies \n
2. Cybersecurity Risk Oversight
\n- \n
- Lead cybersecurity risk assessments across enterprise environments (on-prem, cloud, hybrid) \n
- Partner with Information Security leadership to identify and prioritize cyber risks \n
- Evaluate cybersecurity controls across key domains:\n
- \n
- Identity & Access Management (IAM) \n
- Data protection & encryption \n
- Network and endpoint security \n
- Incident response capabilities \n
\n - Assess alignment to frameworks (NIST CSF, NIST 800-53, ISO 27001/27002, CIS Controls) \n
- Oversee vulnerability management, penetration testing, and remediation tracking \n
- Support cyber incident readiness (tabletop exercises, post-incident reviews) \n
- Evaluate risks in emerging areas (cloud, AI, ransomware, supply chain threats) \n
- Monitor evolving threat landscape and regulatory expectations \n
- Develop cybersecurity KRIs and executive reporting \n
- Provide independent risk challenge to security initiatives and control designs \n
- Contribute to AI / generative AI cybersecurity risk management \n
3. Risk Reporting & Insights (Supporting)
\n- \n
- Develop and deliver clear, concise risk reporting for leadership, including risk summaries, key issues, and trends \n
- Support development of risk dashboards and reporting artifacts, with less emphasis on building tools and more focus on interpretation and insight \n
- Translate complex technology risks into business-relevant narratives for executive stakeholders. \n
- Contribute to risk committee materials and presentations \n
4. AI Enablement
\n- \n
- Leverage AI and Generative AI tools to enhance reporting, summarization, and analysis \n
- Implement continuous improvement initiatives to increase efficiency and reduce cycle time \n
- Support responsible use of AI by identifying and mitigating associated risks (e.g., data privacy, bias, accuracy) \n
What you bring
\nEducation
\n- \n
- Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, Risk Management, Business, or a related field \n
- \n
- 5+ years of experience in:\n
- \n
- Technology Risk / IT Risk \n
- Cybersecurity Risk \n
- IT Audit / Controls \n
- Risk Management / GRC \n
\n - Strong experience conducting technology risk assessments and control evaluations \n
- Familiarity with IT control frameworks and regulatory expectations \n
Technical & Risk Expertise
\n- \n
- Deep understanding of:\n
- \n
- IT General Controls (ITGCs) \n
- Application controls \n
- Cybersecurity principles and practices \n
\n - Experience with frameworks such as: \n
- NIST, ISO 27001, COBIT, SOC 2, CIS Controls \n
- Strong understanding of risk identification, assessment, and mitigation methodologies \n
Communication Skills
\n- \n
- Ability to clearly communicate technical risks to non-technical stakeholders \n
- Strong written and verbal communication skills \n
- Experience preparing executive-level risk summaries and presentations \n
Nice to have
\n- \n
- Professional certifications such as:\n
- \n
- CISA, CRISC, CISM, CISSP \n
\n - Experience with GRC platforms (e.g., Archer, ServiceNow GRC, OneTrust) \n
- Experience in cloud risk management (AWS, Azure, GCP) \n
- Background in internal audit or regulatory compliance \n
- Exposure to third-party risk management frameworks and practices \n
Employee Benefits & Well-Being
\nGenworth employees make a difference in people’s lives every day. We’re committed to making a difference in our employees’ lives.
\n- \n
- Competitive Compensation & Total Rewards Incentives \n
- Comprehensive Healthcare Coverage \n
- Multiple 401(k) Savings Plan Options \n
- Auto Enrollment in Employer-Directed Retirement Account Feature (100% employer-funded!) \n
- Generous Paid Time Off – Including 12 Paid Holidays, Volunteer Time Off and Paid Family Leave \n
- Disability, Life, and Long Term Care Insurance \n
- Tuition Reimbursement, Student Loan Repayment and Training & Certification Support \n
- Wellness support including gym membership reimbursement and Employee Assistance Program resources (work/life support, financial & legal management) \n
- Caregiver and Mental Health Support Services \n
ADDITIONAL
\n- \n
- At this time, Genworth will not sponsor a new applicant for employment authorization for this position. \n
National Range: $109,000 – $169,000
\n\nDisclaimer: This role is aligned to a national market-based pay range. Actual compensation will vary based on geographic location, experience, skills, and other job-related factors. In addition to base salary, this role is eligible to participate in a bonus incentive plan. Incentive compensation is based on individual and company performance and is not guaranteed.
\n