Jobs and Careers
GE

Senior Cybersecurity Engineer - Cyber Governance

GEICO
Chevy Chase, United Statesfull_timeVerifiedPosted 17 Oct 2025
💰 $215,000/yr($80,000/yr$215,000/yr)

About the role

At GEICO, we offer a rewarding career where your ambitions are met with endless possibilities. 

Every day we honor our iconic brand by offering quality coverage to millions of customers and being there when they need us most. We thrive through relentless innovation to exceed our customers’ expectations while making a real impact for our company through our shared purpose. 

When you join our company, we want you to feel valued, supported and proud to work here. That’s why we offer The GEICO Pledge: Great Company, Great Culture, Great Rewards and Great Careers.

The Senior Cybersecurity Engineer plays a critical role in advancing GEICO’s cybersecurity governance and compliance program. This position leads the design, implementation and continues improvement of policies, standards and compliance operations to ensure audit readiness, regulatory adherence and evidence automation across multiple cybersecurity domains. The ideal candidate brings deep expertise in security frameworks (NYDFS 500, PCI DSS, NIST CSF, ISO 27001), strong experience with audit evidence collection/management, and a passion for fostering collaborative partnerships. They will serve as a trusted advisor, providing expert guidance on evidence collection, controls mapping and compliance processes to evidence owners across the organization.

Essential Functions

Governance & Compliance

  • Assist in maturing the cybersecurity governance program, ensuring adherence to corporate policies and standards, regulatory requirements, and industry frameworks.
  • Drive NY DFS compliance and NIST CSF Maturity Programs
  • Develop and maintain control framework alignment
  • Support staff engineers and policy owners to develop, review, and update policies and standards to align with evolving requirements and best practices.
  • Partner with internal teams to drive policy lifecycle management, controls mapping and ensure alignment with enterprise risk management objectives.
  • Conduct assessment against AI standards (e.g ISO/IEC 42001:2023, 23894, NIST AI 600-1, NIST AI RMF)
  • Assess impact of emerging threats on compliance and coordinate threat-driven policy updates.
  • Ensure controls are mapped across frameworks in the automated governance solution and drive compliance automation validation in partnership with the platform team. Assess compliance gaps and partner and guide on remediation plans

Audit Readiness & Evidence Management

  • Coordinate evidence refresh cycle for all applicable frameworks.
  • Validate evidence submissions, ensure timely updates, and document exceptions or remediation plans.
  • Maintain centralized knowledge base and repositories (e.g., GRC tools, SharePoint, Confluence) to streamline evidence collection and control mapping.
  • Support internal and external audits by providing accurate, complete evidence and narrative explanations.

Risk Management & Advisory

  • Apply a risk-based approach to control evaluation, prioritization, and remediation.
  • Partner with stakeholders to address compliance gaps and track progress toward closure.
  • Provide subject matter expertise on regulatory requirements, compliance trends, and security frameworks.
  • Support continuous improvement through automation, metrics, and reporting dashboards.

Collaboration & Enablement

  • Partner with control owners, internal controls team, and leadership to ensure alignment across business and technical functions.
  • Provide training and guidance to evidence owners on requirements, documentation standards, and deadlines.
  • Communicate clearly with technical and non-technical stakeholders to ensure understanding of compliance obligations.
  • Mentor and guide more junior engineers on the team

Metrics & Reporting

  • Design and implement cyber governance metrics, KPIs, and executive dashboards to measure security posture, policy compliance, and control effectiveness.

Minimum Qualifications

  • 5+ years of extensive experience in cybersecurity governance, risk and compliance (GRC) roles with demonstrated experience in one or more compliance frameworks such as NYDFS 500, PCI DSS, NIST CSF, ISO 27001
  • Proven experience supporting audit readiness and evidence collection for internal, external, or regulatory audits.
  • Strong organizational skills with the ability to prioritize tasks effectively, maintain exceptional attention to details, and consistently deliver results on or before deadlines.
  • Proven experience in fostering cross-functional partnerships and serving as a trusted advisor to evidence owners b

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

GEICO

View company profile →