Job Closed
This listing is no longer active.
Get more with GEICO
Staff Engineer - Product Security (REMOTE)
Location
United States
Posted
99 days ago
Salary
$100K - $230K / year
No structured requirement data.
Job Description
Staff Engineer - Product Security (REMOTE)
GEICO
At GEICO, we offer a rewarding career where your ambitions are met with endless possibilities. Every day we honor our iconic brand by offering quality coverage to millions of customers and being there when they need us most. We thrive through relentless innovation to exceed our customers’ expectations while making a real impact for our company through our shared purpose. When you join our company, we want you to feel valued, supported and proud to work here. That’s why we offer The GEICO Pledge: Great Company, Great Culture, Great Rewards and Great Careers. GEICO is seeking an experienced Staff Engineer to provide enterprise support for product security in our hybrid, multi-cloud environments. You will proactively and holistically lead and support Product Security activities that guide the design, development, security of code, and code repositories for cloud, hybrid, and open-source applications. Position Description: Our Product Security Staff Engineer is a senior level position that reports to the Manager of Secure Product Design and works closely with development teams, product teams, and others across the organization to integrate security into the product lifecycle. The Product Security Staff Engineer is a subject matter expert in defining security requirements, defining secure application design, performing application security assessments, threat modeling, and providing developers with remediation guidance and solutions. On any given day, the Product Security Staff Engineer can be pulled in to evaluate a new system, review a proposed application design, or provide solutions for application security/coding best practices. Position Responsibilities As a Staff Engineer, you will: - Work independently with developers, system/network engineers, product owners, and other engineers to ensure secure design, development, and implementation of cloud-based applications - Define and document secure architecture patterns and anti-patterns - Perform security architecture design reviews of our products including web applications, services, and mobile applications. - Define security best practices and standards and partner with Product Development teams to implement them. - Provide remediation guidance and recommendations to developers and engineers. - Serve as a technical advisor and consultant to colleagues and/or GEICO leadership on the implementation of the Cybersecurity application security policy and standards. - Provide technical thought leadership for integration decisions, analyzing design constraints and trade-offs in system and security design, and ensuring integrity of GEICO mission objectives, while protecting GEICO assets from cyber threats and vulnerabilities. - Work with Product Development teams to help prioritize and validate urgency of mitigation of identified product vulnerabilities and security feature enhancement requests - Interface with the Product and Cyber Security teams to track security feature enhancement requests - Help develop actionable insights, prioritizing the work, based on risk, and impact, and allocate resources effectively, using Geico specific large data sets. Qualifications: - Hands-on product development experience, with strict SLA and SLR, using a mature S-SDLC. - Direct experience working with development teams to define, develop and document secure solutions - Experience breaking down complex systems and applications to find flaws with analysis and threat modeling - Strong familiarity with common vulnerabilities and attack vectors - Knowledge of web service technologies, load balancer services (i.e., Nginx, Cloudflare, F5, etc.) and RESTful APIs - Knowledge of ubiquitous encryption technologies (PGP, SSH, SSL, etc.) and common authentication protocols (OpenID Connect, OAUTH, SAML, RADIUS, LDAP, KERBEROS, etc.) - Solid understanding of secure network, system, and service design in cloud (Azure, AWS etc.) and conventional environments - Understanding and applied use of OWASP Top 10, NIST SP800 Series, NIST CSF, FIPS 140-2, ISO 27001, PCI-DSS, etc. - Knowledge of various aspects of a technology architecture like integration, network, and security - Advanced understanding and knowledge of application development life cycle methodologies (such as waterfall, spiral, agile software development, rapid prototyping, incremental, synchronize and stabilize, and DevOps/ SecDevOps) - Exposure to multiple, diverse security technologies, platforms, and processing environments - Strong command of strategic and emerging security/ cloud technology trends, and the practical application of existing and emerging technologies to new and evolving business and operating models. - Good understanding of product management, agile principles and development methodologies and capability of supporting agile teams by providing advice and guidance on opportunities, impact, and risks, taking account of technical and architectural debt - Experience collaborating closely with senior executives on strategic initiatives - A background integrating security testing into the SDLC - Experience providing security training to developers - Ability to find security defects within programming languages such as Go, Rust, Java, Python, Object C, and mobile device languages - Demonstrated experience using DAST and SAST tools and services - One or more of the following Cybersecurity certifications are highly desired: Security+, Certified Information System Security Professional (CISSP) or Certified Information Security Manager (CISM) Experience: - 6+ years planning and designing application security, cloud security, systems security, or platform security - 5+ of experience in at least two security solution design and development disciplines, including technical or security infrastructure architecture, cloud security, network security management, secure application development or secure cloud development. - 4+ years of experience in application and open-source security - 3+ years of experience with AWS, GCP, Azure, or another cloud service - 2+ years of experience in open-source frameworks Education - Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or equivalent education or work experience Annual Salary $100,000.00 - $230,000.00The above annual salary range is a general guideline. Multiple factors are taken into consideration to arrive at the final hourly rate/ annual salary to be offered to the selected candidate. Factors include, but are not limited to, the scope and responsibilities of the role, the selected candidate’s work experience, education and training, the work location as well as market and business considerations. GEICO will consider sponsoring a new qualified applicant for employment authorization for this position. The GEICO Pledge: Great Company: At GEICO, we help our customers through life’s twists and turns. Our mission is to protect people when they need it most and we’re constantly evolving to stay ahead of their needs. We’re an iconic brand that thrives on innovation, exceeding our customers’ expectations and enabling our collective success. From day one, you’ll take on exciting challenges that help you grow and collaborate with dynamic teams who want to make a positive impact on people’s lives. Great Careers: We offer a career where you can learn, grow, and thrive through personalized development programs, created with your career – and your potential – in mind. You’ll have access to industry leading training, certification assistance, career mentorship and coaching with supportive leaders at all levels. Great Culture: We foster an inclusive culture of shared success, rooted in integrity, a bias for action and a winning mindset. Grounded by our core values, we have an an established culture of caring, inclusion, and belonging, that values different perspectives. Our teams are led by dynamic, multi-faceted teams led by supportive leaders, driven by performance excellence and unified under a shared purpose. As part of our culture, we also offer employee engagement and recognition programs that reward the positive impact our work makes on the lives of our customers. Great Rewards: We offer compensation and benefits built to enhance your physical well-being, mental and emotional health and financial future. - Comprehensive Total Rewards program that offers personalized coverage tailor-made for you and your family’s overall well-being. - Financial benefits including market-competitive compensation; a 401K savings plan vested from day one that offers a 6% match; performance and recognition-based incentives; and tuition assistance. - Access to additional benefits like mental healthcare as well as fertility and adoption assistance. - Supports flexibility- We provide workplace flexibility as well as our GEICO Flex program, which offers the ability to work from anywhere in the US for up to four weeks per year. The equal employment opportunity policy of the GEICO Companies provides for a fair and equal employment opportunity for all associates and job applicants regardless of race, color, religious creed, national origin, ancestry, age, gender, pregnancy, sexual orientation, gender identity, marital status, familial status, disability or genetic information, in compliance with applicable federal, state and local law. GEICO hires and promotes individuals solely on the basis of their qualifications for the job to be filled. GEICO reasonably accommodates qualified individuals with disabilities to enable them to receive equal employment opportunity and/or perform the essential functions of the job, unless the accommodation would impose an undue hardship to the Company. This applies to all applicants and associates. GEICO also provides a work environment in which each associate is able to be productive and work to the best of their ability. We do not condone or tolerate an atmosphere of intimidation or harassment. We expect and require the cooperation of all associates in maintaining an atmosphere free from discrimination and harassment with mutual respect by and for all associates and applicants.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Information Security GRC Manager
CubiCasaEasy-to-use smartphone app for creating floor plans, interactive tours, 3D renders and more. More than 4M orders!
The Information Security Governance, Risk, and Compliance (GRC) Manager provides tactical leadership and operational oversight for key components of the company’s enterprise GRC program. This role is responsible for the day-to-day management of GRC analysts, driving compliance initiatives, managing the integrated risk assessment lifecycle, and ensuring control effectiveness. The Manager will serve as a key point of contact for internal business units and external auditors, directly supporting the strategic directives set by program leadership. The position requires a proven ability to lead teams, implement policy, and translate complex security and compliance requirements into clear business actions. What You Will Work On - Manage and mentor a team of GRC Security Analysts, providing clear direction and facilitating continuous professional development. - Oversee and execute the security risk assessment process, including identifying, analyzing, and documenting emerging and ongoing risks across the organization and its third parties. - Lead efforts to document, enforce, and communicate security policies and control frameworks that are aligned with key regulations and standards (e.g., NIST, ISO, GDPR, GLBA). - Develop, implement, and maintain security policies and controls specifically for the safe and ethical deployment and use of artificial intelligence (AI) systems. - Act as the primary operational liaison for internal and external audits, coordinating the collection of evidence, tracking the resolution of findings, and ensuring sustained audit readiness. - Provide direct support to the third-party risk management program, ensuring rigorous security review of vendors and business partners to mitigate external risk. - Facilitate IT compliance activities, focusing on the operational effectiveness of technical and general IT controls. - Collaborate with business units and technical teams to ensure adequate security controls are available and implemented during the onboarding of new solutions and systems. - Define and track qualitative and quantitative metrics to measure the success and maturity of the security program, reporting regularly to program leadership. - Support incident response and disaster recovery efforts, ensuring GRC documentation and controls are properly applied to corporate resiliency programs. - Ensure the protection of critical data is maintained through established data classification, data loss prevention (DLP), and records retention requirements. - Manage information security training requirements for the organization, to include identifying role-based security training for all organizational roles in accordance with the roles capacity to introduce risk in the performance of their duties. Who We Are Looking For - 7+ years of experience in cybersecurity, with a focus on governance, compliance, risk management, or audit. - 3+ years of demonstrated experience managing or leading a distributed or hybrid team. - Expert-level understanding of major regulatory frameworks and standards, including but not limited to NIST, ISO, GDPR, and GLBA. - Proven ability to manage GRC-related projects and work with cross-functional stakeholders to deliver outcomes on time and within scope. - Strong technical acumen in cloud computing security (AWS, GCP, or Azure), DevOps, and application security. - Exceptional written and verbal communication skills, with the ability to articulate security risk and compliance requirements to technical staff and business leadership. - Prior experience in defining metrics, preparing management reports, and implementing process improvements using GRC tools. - Demonstrated experience in conducting tabletop exercises for business continuity is preferable. Education Requirements - Bachelor’s degree in computer science, information assurance, MIS, or a related technical field, or equivalent practical experience. Certification Requirements - Holds or is actively working toward one or more of the following: CISSP, CISM, CISA, CRISC, or CGRC. What You Can Expect - Compensation: The base salary for this position ranges from $150,000 to $200,000 annually, depending on your location, experience, and qualifications. Additional compensation offerings include company profit-sharing bonus program, communication stipends, and referral bonuses. - Inclusive benefits package offering: - Comprehensive medical, dental, and company paid vision insurance, 401(k) retirement plan with employer match, voluntary life and AD&D insurance options, voluntary supplemental insurances for accident, critical illness, and legal services, paid time off (PTO) and paid holidays, employee assistance and wellness programs, company paid short term disability coverage, company contributions to health saving funds (with participation in the high deductible health plan. We offer company paid access to Galileo for virtual primary care and Rula for virtual mental health resources. - Through our Anniversary Program, we celebrate the meaningful milestones and long tenure that reflect how much we value your contributions and commitment to our team. - Career and skill development resources to help advance your career and personal growth. - A mission-driven environment where your work makes a measurable impact on the real estate industry. What We Value - Wherever it Leads, Whatever it Takes® - No matter how remote, complex, or unexpected. Our commitment never wavers. - Hire NICE people - Skills can be taught but character shines through. We seek those who bring integrity, kindness, and grit. - Lift others up - We lead with empathy and strive to improve the lives of those around us. - Sweat the details - Excellence lives in the little things. Getting it just so is how we make a big impact. - Raise the bar - We don’t settle for industry standards, we redefine them. About Us Our story began in the mountain town of Truckee, California more than 20 years ago, when we pioneered simple, web-based valuation technology solutions for an industry that relied on paper. Today, we’ve grown one of the highest-coverage networks of real professionals in the county. As we continue our journey to modernize valuation we’ll hold on to our promise from day one: to go wherever it leads and do whatever it takes to serve our customer with remarkable technology and uncompromising service. Clear Capital is an equal-opportunity employer. To all recruitment agencies: Clear Capital does not accept agency resumes. Please do not forward resumes to our jobs alias, Clear Capital employees, or any other company location. Clear Capital is not responsible for any fees related to unsolicited resumes.
Senior Security Risk Management Specialist
Reinsurance Group of America, IncorporatedTrusted Partner. Proven Results.
• Conduct comprehensive security risk assessments of enterprise systems and processes, as well as provide recommendations for risk mitigation. • Review, analyze, and provide recommendations for policy, standard, and baseline configuration exceptions. • Perform vendor risk assessments to include inherent & residual risk identification, analysis, and mitigation, and additionally track risk remediation to completion. • Provide recommendations for vendor contractual requirements stemming from vendor risk assessment outcomes. • Serve as a project security advisor including risk analysis gate checks in the secure SDLC process. • Conduct thorough threat modeling exercises to identify potential security vulnerabilities and risks. • Stay current on security trends, threats, and best practices to continuously improve the organization's security posture. • Perform other duties as assigned.
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description This role involves serving as Bloom's Information Security Officer, focusing on building security into the foundation of the organization. - Own the security program end-to-end: designing and implementing controls, architecting systems to prevent breaches, and driving a culture of proactive risk management. - Use data and metrics to measure effectiveness, identify gaps, and demonstrate continuous improvement. - Build and lead a proactive security program with a prevention-first mindset. - Evaluate, refine, and enforce security policies, standards, and procedures. - Conduct regular risk assessments and threat modeling. - Lead tabletop exercises, penetration testing, and red team activities. - Build, operate, and monitor the security program, ensuring effective education of stakeholders. - Serve as the primary owner for HIPAA, HITRUST, and SOC 2 Type II compliance oversight. - Maintain knowledge of NIST standards and emerging healthcare security regulations. - Translate regulatory requirements into engineering specifications and operational procedures. - Partner with Engineering, IT, and DevOps to embed security controls into infrastructure. - Define and track key security metrics and KPIs. - Develop and deliver security awareness training. Qualifications - Bachelor’s degree in information systems, Computer Science, Engineering, or a related technical field, or a minimum of four (4) years of experience in lieu of degree. - 7+ years of progressive experience in information security, with at least 3 years in a security program leadership role. - Previous experience guiding an organization through successful assessments in SOC 2 and/or HITRUST R2. Requirements - Deep expertise in healthcare security and privacy regulations, particularly HIPAA Security Rule requirements. - Hands-on experience achieving and maintaining HITRUST CSF certification and SOC 2 Type II attestation. - Strong working knowledge of NIST frameworks and FedRAMP. - Proven track record implementing technical security controls and managing a comprehensive security program. - Experience with cloud security (AWS, Azure, or GCP) and modern DevSecOps practices. - Demonstrated ability to use metrics and data analysis to drive security program improvements. - Excellent communication skills—able to translate technical risk into business terms for executives and board members. - Relevant certifications: CISSP, CISM, HCISPP, HITRUST CCSFP, or equivalent. - Experience in a high-growth healthcare technology or digital health environment. - First-hand experience building security programs or security-first architectures. - Experience with GRC platforms and security automation tools. Benefits - Competitive compensation. - Comprehensive health coverage. - Long-term growth opportunities. - Remote work environment. - BeBloom™, a proprietary employee training and engagement program. Core Values - Put People First: Uphold and promote a people-first culture within the organization. - Be Stronger Together: Embrace a team player mentality. - Do What’s Right: Adhere to high ethical standards. - Embrace a Growth Mindset: Embrace a culture of continuous learning. - Drive Solutions: Demonstrate ingenuity and skill by sharing ideas and solutions.
Job Description The Career Exploration and Elective Teacher is a state certified teacher responsible for delivering specific course content in an online environment. The Career Exploration teacher must provide instruction, support, and guidance; manage the learning process; and focus on students’ individual needs. Teachers monitor student progress through Stride K12’s learning management system and work actively with students and parents to advance each student’s learning and to develop and monitor a plan for post-secondary success via online tools.This non-negotiable salary for this position is $43,000 along with the opportunity for an annual bonus through the School. Start Date - 2026-2027 K12, a Stride Company, believes in Education for ANY ONE. We provide families an online option for a high-quality, personalized education experience. Students can thrive, find their passion, and learn in an environment that encourages discovery at their own pace. The mission of Ohio Virtual Academy (OHVA) is to provide an exemplary individualized and engaging educational experience for students by incorporating school and community/family partnerships coupled with a rigorous curriculum along with a data-driven and student-centered instructional model. Student success will be measured by valid and reliable assessment data, parent and student satisfaction, and continued institutional growth within the academic community. Join us! Summary: The Career Exploration and Elective Teacher is a state certified teacher responsible for delivering specific course content in an online environment. The Career Exploration teacher must provide instruction, support, and guidance; manage the learning process; and focus on students’ individual needs. Teachers monitor student progress through Stride K12’s learning management system and work actively with students and parents to advance each student’s learning and to develop and monitor a plan for post-secondary success via online tools. This is a full-time position. Ability to work independently, typically 40+ hours per week is required. Ability to maintain a professional home office without distraction during workday, typically 9-5 (or 8-4) or as defined by the school. Essential Functions: Reasonable accommodations may be made to enable individuals with disabilities to perform the essential duties. - Provides rich and engaging synchronous and asynchronous learning experiences for students - Commitment to personalizing learning for all students - Demonstrates a belief in all students’ ability to succeed and meet high expectations - Differentiates instruction based on student level of mastery - Augments course content according to prescribed policies and procedures using appropriate asynchronous and synchronous tools under guidance from principal and coach - Maintains grade book ensuring student academic integrity, makes student placement and promotion decisions, and alerts administrators to concerns about student performance and progress - Prepares students for high stakes standardized tests - Understands that a primary responsibility is to establish and maintain positive rapport with families and regularly communicates with and responds to students and learning coaches/parents in a timely manner - Supports learning coaches/parents with student curricular and instructional issues, as well as basic troubleshooting in a virtual classroom environment that is in line with academy policies and procedures - Travels as required (on average once per month and/or up to 25% of the time) for face-to-face professional development, student testing, and as required by school - Maintains and effectively applies knowledge of the State, National, and Industry Specific learning standards - Develops effective instructional tools and strategies to supplement and enhance provided curriculum - Collaborates regularly with the school and national professional learning community - Supports a project-based learning model Minimum Required Qualifications: - Bachelor’s degree AND - Active CTE state teaching certification OR - Active high school grade level state teaching certification with CTE Validation - Ability to clear required background check(s) Residency Requirement: Ohio OTHER REQUIRED QUALIFICATIONS: - Ability to work collaboratively with other teachers to interpret and produce numeric, tabular, and graphic representations of student data, and use it to drive instructional decisions - Receptive to receiving coaching on a regular basis with administrators and teacher trainers - Ability to embrace change and adapt to ensure excellent student outcomes - Proficient in Microsoft Excel, Outlook, Word; PowerPoint - Ability to rapidly learn and adapt to new technologies and teaching platforms DESIRED Qualifications: - Experience working with proposed age group - Experience supporting adults and children in the use of technology - Experience teaching in an online (virtual) and/or in a brick-and-mortar environment - Experience with project-based learning Work Environment: The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. - This is a virtual, home-based position Job Type Board Employee_CW The above job is not intended to be an all-inclusive list of duties and standards of the position. Incumbents will follow any other instructions, and perform any other related duties, as assigned by their supervisor. All employment is “at-will” as governed by the law of the state where the employee works. It is further understood that the “at-will” nature of employment is one aspect of employment that cannot be changed except in writing and signed by an authorized officer. If you are a job seeker with a disability and require a reasonable accommodation to apply for one of our jobs, you can request the appropriate accommodation by contacting stridecareers@k12.com. Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities Stride, Inc. is an equal opportunity employer. Applicants receive consideration for employment based on merit without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status, or any other basis prohibited by federal, state, or local law. Stride, Inc. complies with all legally required affirmative action obligations. Applicants will not be discriminated against because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant.




