Senior Cyber Security Engineer - GRC Automation (REMOTE)
GEICOAbout the role
At GEICO, we offer a rewarding career where your ambitions are met with endless possibilities.
Every day we honor our iconic brand by offering quality coverage to millions of customers and being there when they need us most. We thrive through relentless innovation to exceed our customers’ expectations while making a real impact for our company through our shared purpose.
When you join our company, we want you to feel valued, supported and proud to work here. That’s why we offer The GEICO Pledge: Great Company, Great Culture, Great Rewards and Great Careers.
GEICO is seeking a Security Engineer to optimize our organizations cybersecurity governance program. You will lead building automation in cyber governance with designing and implementing continuous monitoring and reporting of information security controls across the enterprise for all GEICOs applications and services.
You will collaborate with developers, engineers, and compliance & security teams across GEICO to institute the controls vital for the program. You will partner with application security, platform security, SRE, central security and compliance groups at GEICO to craft and roll out controls, processes, conduct gap assessments, automate collection of evidence and flag non-compliance with policies in real time.
As a Security Engineer you will:
Lead the automation efforts by understanding the information security policies, security standards, security technologies, GEICOs environment (multi-cloud, on-prem) structure.
Create a roadmap and a prioritized plan for automating security controls for continuous monitoring.
Define the programmatic control language, evidence required and frequency, type of assets for each automated control.
Create a unified security controls framework that maps back to security standards such as NIST CSF 2.0, PCI, NY DFS, SOX, etc., to collect evidence once to satisfy all relevant security standards.
Partner with security control owners, governance team, compliance team, other stakeholders on security controls automation
Determine complimentary products and solutions to scale and expedite overall automation goals
Partner with cloud technical teams (Azure, GCP, AWS, etc.) to deliver a successful outcome
Comfortable rolling up your sleeves to design and code modules for infrastructure, application, and processes.
Solve specific security and business problems through automation, utilizing code, and integrating cloud-native and tools via API.
Align on requirements and communicate results and recommendations both verbally and in writing.
Educate relevant stakeholders about our solutions and potential opportunities.
Work closely with various teams to drive feature innovation based upon customer needs.
Utilize programming languages like Python, C# or other object-oriented languages, SQL, and NoSQL databases, Container Orchestration services including Docker and Kubernetes, and a variety of Azure tools and services
Consistently share best practices and improve processes within and across teams
Follow GEICOs developer standards and guidelines
Qualifications:
Programming experience with at least one modern language such as Java, C++, or C# including object-oriented design
Experience contributing to the architecture and design (architecture, design patterns, reliability, and scaling) of new and current systems
In-depth knowledge of CS data structures and algorithms
Understanding of existing Operational Portals such as Azure Portal
Understanding of HTML-5, JavaScript/TypeScript, XML, and JSON
Understanding of micro-services oriented architecture and extensible REST APIs
Understanding of Azure Network such as security zones, VNETs, and Public Peered Services
Understanding of Azure PaaS and IaaS services
Understanding of security protocols and products such as of Active Directory, Windows Authentication, SAML, OAuth
Experience in Datacenter structure, capabilities, and offerings, including the Azure platform, and its native services
Knowledge of developer tooling across the software development life cycle (task management, source code, building, deployment, operations, real-time communication)
5+ years of security compliance framework experience
Expertise with security standards such as SOX, PCI-DSS, ISO27K, SOC or NIST (some combination of these is ideal)
Technical acumen required. Understanding of cloud, open sourced distributed systems are ideal
Great a
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s