A Staff Cyber Governance Security Engineer works with GEICO engineering teams to innovate and build new processes, systems, improve and enhance existing systems and identify new opportunities to apply your knowledge to solve critical problems. You will lead the end to end cyber governance program including ensuring cybersecurity practices and requirements are adopted by the enterprise partnering with Lines of Businesses and Tech partners. You will also lead the development of an Automated Continuous compliance platform for GEICO Cybersecurity Governance team, which enables real time evidence collection, identifying non-compliance with policies early and provides the team with remediation guidelines in an automated scalable way to reduce the audit fatigue and improve the developer experience. You will collaborate with developers, engineers, and compliance & security teams across GEICO to institute the programmatic controls vital for the program. You will partner with application security, platform security, SRE, central security and compliance groups at GEICO to craft and roll out controls, processes, automate collection of evidence and create dashboard on the security posture of GEICO.
Provide technical leadership for cybersecurity program strategy, automation, integration with cyber and IT technologies.
Lead the automation efforts by understanding the information security policies, security standards, security technologies, GEICOs environment (multi-cloud, on-prem) structure.
Collaborate with engineering teams to define the overall system architecture, ensuring scalability and performance optimization.
Ensure we have proper processes for cyber governance and integrated processes where applicable from a governance perspective.
Collaborate across teams and across the organization to solve our toughest problems
Solve audit fatigue and improve operational rigor
Ensure we meet regulatory compliance with evidence in a scalable manner
Determine complimentary products and solutions to scale and expedite overall automation goals
Partner with cloud technical teams (Azure, GCP, AWS, etc.) to deliver a successful outcome
Influence and educate partner teams to bring an engineering first approach to develop sustainable processes to adhere to policies
Comfortable rolling up your sleeves to design and code for automated, continuous compliance
Solve specific security and business problems through automation, utilizing code, and integrating cloud-native and tools via API.
Work closely with various teams to drive feature innovation based upon customer needs.
Utilize programming languages like Python, C# or other object-oriented languages, SQL, and NoSQL databases, Container Orchestration services including Docker and Kubernetes, and a variety of Azure tools and services
Follow GEICOs developer standards and guidelines
Triage product or system issues and debug/track/resolve by analyzing the sources of issues and the impact dependent systems
Be a role model and mentor, helping to coach and strengthen the technical expertise and know-how of our engineering and product community
Influence and educate executives
Consistently share best practices and improve processes within and across teams
Determine and support resource requirements, evaluate operational processes, measure outcomes to ensure desired results, demonstrate adaptability and sponsor continuous learning
Qualifications
Programming experience with at least one modern language such as Java, C++, or C# including object-oriented design
Experience contributing to the architecture and design (architecture, design patterns, reliability, and scaling) of new and current systems
Understanding of existing Operational Portals such as Azure Portal
Understanding of HTML-5, JavaScript/TypeScript, XML, and JSON
Understanding of Azure Network such as security zones, VNETs, and Public Peered Services
Understanding of Azure PaaS and IaaS services
Understanding of AWS cloud enviornment
Understanding of security protocols and products such as of Active Directory, Windows Authentication, SAML, OAuth
5+ years of security compliance framework experience
Expertise with security standards such as SOX, PCI-DSS, ISO27K, SOC or NIST (some combination of these is ideal)
Technical acumen required. Understanding of cloud, open sourced distributed systems are ideal
Great at both collaboration and independent problem solving
Superb written communication and technical research skills
Ability to develop relationships and work effectively with different teams at all levels and across functions relative to technical, policy, and business concerns
Ability to resolve conflicts and drive issues to resolution
Work independently with little or no supervision while maintaining a high level of efficiency
Education
Bachelor's Degree or equivalent experience preferred.
Experience & Security Certifications
6+ years of professional software engineering experience
3+ years of experience with architecture and design
2+ years of experience with AWS, GCP, Azure, or another cloud service
2+ years of experience in open-source frameworks
Professional security certifications (e.g., CISSP, CCSP, CSSLP) is a plus
Annual Salary
$85,000.00 - $230,000.00
The above annual salary range is a general guideline. Multiple factors are taken into consideration to arrive at the final hourly rate/ annual salary to be offered to the selected candidate. Factors include, but are not limited to, the scope and responsibilities of the role, the selected candidate’s work experience, education and training, the work location as well as market and business considerations.
GEICO will consider sponsoring a new qualified applicant for employment authorization for this position.
Benefits:
As an Associate, you’ll enjoy our Total Rewards Program* to help secure your financial future and preserve your health and well-being, including:
Premier Medical, Dental and Vision Insurance with no waiting period**
Paid Vacation, Sick and Parental Leave
401(k) Plan
Tuition Assistance
Paid Training and Licensures
*Benefits may be different by location. Benefit eligibility requirements vary and may include length of service.
**Coverage begins on the date of hire. Must enroll in New Hire Benefits within 30 days of the date of hire for coverage to take effect.
The equal employment opportunity policy of the GEICO Companies provides for a fair and equal employment opportunity for all associates and job applicants regardless of race, color, religious creed, national origin, ancestry, age, gender, pregnancy, sexual orientation, gender identity, marital status, familial status, disability or genetic information, in compliance with applicable federal, state and local law. GEICO hires and promotes individuals solely on the basis of their qualifications for the job to be filled.
GEICO reasonably accommodates qualified individuals with disabilities to enable them to receive equal employment opportunity and/or perform the essential functions of the job, unless the accommodation would impose an undue hardship to the Company. This applies to all applicants and associates. GEICO also provides a work environment in which each associate is able to be productive and work to the best of their ability. We do not condone or tolerate an atmosphere of intimidation or harassment. We expect and require the cooperation of all associates in maintaining an atmosphere free from discrimination and harassment with mutual respect by and for all associates and applicants.