Application Security Principal Engineer
GEICOAbout the role
GEICO is seeking an experienced Principal Engineer to provide enterprise support for application security in our hybrid, multi-cloud environments. You will proactively and holistically lead and support Application Security activities that guide the design, development, security of code, and code repositories for cloud-hosted and open-source applications. Solutions include CICD integrations, SAST, DAST, IAST, SCA, secure cloud platform engineering, automated threat modeling.
Position Description:
Our Application Security Principal Engineer is a senior level position that reports to the Director of Application Security and works closely with development teams, product teams, other teams across the organization to integrate security into the product lifecycle from design through deployment. The Application Security Principal Engineer is a subject matter expert in defining security requirements, defining secure application security design, performing application security assessments, threat modeling and providing developers with remediation guidance and advice. On any given day, the Application Security Principal Engineer can be pulled in to evaluate a new system, review a proposed application design, or provide guidance on application security/coding best practices.
Position Responsibilities
As a Principal Engineer, you will:
Work independently with developers, system/network engineers, product owners, and other engineers to ensure secure design, development, and implementation of cloud-based applications
Define and document secure architecture patterns and anti-patterns
Perform security architecture design reviews of our products (primarily cloud)
Define security best practices and standards and ensure Product Development teams understand them
Provide remediation guidance and recommendations to developers and engineers
Serve as a technical advisor and consultant to colleagues and/or GEICO leadership on the implementation of the Cybersecurity application security policy and standards.
Provide technical thought leadership for integration decisions, analyzing design constraints and trade-offs in system and security design, and ensuring integrity of GEICO mission objectives, while protecting GEICO assets from cyber threats and vulnerabilities.
Work with Product Development teams to help prioritize and validate urgency of mitigation of identified product vulnerabilities and security feature enhancement requests
Interface with the Product and Vulnerability Management teams to track security feature enhancement requests
Qualifications:
Direct experience working with development teams to define, develop and document secure solutions
Experience breaking down complex systems and applications to find flaws with analysis and threat modeling
Strong familiarity with common vulnerabilities and attack vectors
Knowledge of web service technologies, load balancer services (i.e., Nginx, Cloudflare, F5, etc.) and RESTful APIs
Knowledge of ubiquitous encryption technologies (PGP, SSH, SSL, etc.) and common authentication protocols (OpenID Connect, OAUTH, SAML, RADIUS, LDAP, KERBEROS, etc.)
Solid understanding of secure network, system, and service design in cloud (Azure, AWS etc.) and conventional environments
Understanding and applied use of OWASP Top 10, NIST SP800 Series, NIST CSF, FIPS 140-2, ISO 27001, PCI-DSS, etc.
Knowledge of various aspects of a technology architecture like integration, network, and security
Advanced understanding and knowledge of application development life cycle methodologies (such as waterfall, spiral, agile software development, rapid prototyping, incremental, synchronize and stabilize, and DevOps/ SecDevOps)
Exposure to multiple, diverse security technologies, platforms, and processing environments
Strong command of strategic and emerging security/ cloud technology trends, and the practical application of existing and emerging technologies to new and evolving business and operating models.
Good understanding of product management, agile principles and development methodologies and capability of supporting agile teams by providing advice and guidance on opportunities, impact, and risks, taking account of technical and architectural debt
Experience collaborating closely with senior executives on strategic initiatives
A background integrating security testing into the SDLC
Experience providing security training to developers
Additional programming languages such as Java, Python, Object C
Demonstrated experience using DAST and SAST tools and services
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s