Jobs and Careers
GE

Sr. Staff Security Operations Engineer – VM & Offensive Security - REMOTE

GEICO
United StatesRemotefull_timeVerifiedPosted 15 Aug 2025
💰 $260,000/yr($120,000/yr$260,000/yr)

About the role

At GEICO, we offer a rewarding career where your ambitions are met with endless possibilities. 

Every day we honor our iconic brand by offering quality coverage to millions of customers and being there when they need us most. We thrive through relentless innovation to exceed our customers’ expectations while making a real impact for our company through our shared purpose. 

When you join our company, we want you to feel valued, supported and proud to work here. That’s why we offer The GEICO Pledge: Great Company, Great Culture, Great Rewards and Great Careers.

GEICO is seeking an experienced Sr. Staff Engineer, Operations Engineer with a passion for managing complex programs across multiple departments and team to build Vulnerability Management & Offensive Security operational excellence from the ground up. You will help drive our business transformation as we transition from a traditional IT model to a tech organization with engineering excellence as its mission.

The Sr. Staff Engineer, Operations is a key member of the Vulnerability Management & Offensive Security leadership team working across the organization to ensure successful delivery of effective security controls and prioritization of initiatives and issue management. In this role you will own a portfolio of initiatives such as compliance, security engineering, operational excellence, and vendor engagement. This is beyond technical project management and requires a background in Vulnerability Management and Offensive Security, driving deliveries of solutions, and proving success with KPIs and visible metrics. The ideal candidate will have excellent communication skills, real world examples in engaging the right technical partners and leadership to drive towards solutions and get people working together.

​​​As a Sr Staff Engineer, you will lead efforts to identify, plan, and deliver program security outcomes by independently engaging a broad set of internal and external stakeholders. This also includes the following:

  • Monitor and track signals of security gaps, initiative delays, compliance risks due to system issues, and drive resolution.
  • Create visuals on current performance and risk indicators related to Vulnerability Management & Offensive Security initiatives and operations.
  • Help to develop standards on reporting Vulnerability Management & Offensive Security tool effectiveness, maturity, resilience and other factors in determining risks as they come up.
  • Help drive automation of routine tasks to drive growth in security protection and detection technologies.
  • Provide expert guidance, demonstrations and lead discussions on security best practices to stakeholders and leadership.
  • Works in lockstep with our CSIRT, GRC, Platform Security, Development/Product organizations and Technology partner teams to ensure protection coverages, proper detection event notifications, documentation and standards we can all use.
  • Organize, store and manage operational best practices documentation for security solutions to protect our business products and assets in a hybrid environment (on-prem and multi-cloud).
  • Partner with the project sponsors, delivery teams, and stakeholders to deliver quality solutions on time and within budget by coordinating project activities across multiple systems, departments, and teams.
  • Create, maintain, and actively manage a detailed project schedule, change control process, and documentation.
  • Identify and raise appropriate security risks, in addition to presenting detailed and implementable solutions or alternatives and drive those campaigns to resolution.
  • Drive vendor management Manage by identifying vendors, coordinating vendor activities, and working with Sourcing to develop statement of work and procure services.

Qualifications

  • Demonstrated understanding of vulnerability management and offensive security tooling and practices including – vulnerability scanning of infrastructure, penetration testing, red/purple teaming, risk assessment, prioritization, and remediation of vulnerabilities.
  • Familiar with CVEs, CWEs, CVSS, and OWASP projects - Web Top Ten, API Top Ten, Mobile Top Ten, and OWASP AI. 
  • Knowledge of data access languages such as SQL and GraphQL and the ability to construct queries against data sources.
  • Extensive experience in engineering and solution delivery in a dynamic service provider environment.
  • Strong knowledge of project management methodologies and best practices.
  • Proven track record of successfully managing large/complex projects across cross-functional teams, building processes and coordinating delivery 
  • Working knowledge of security services and their impact on production systems including runt

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

GEICO

View company profile →