GEICO is seeking a Security Engineer to optimize our organizations cybersecurity governance program. You will lead building automation in cyber governance with designing and implementing continuous monitoring and reporting of information security controls across the enterprise for all GEICOs applications and services. You will collaborate with developers, engineers, and compliance & security teams across GEICO to institute the controls vital for the program. You will partner with application security, platform security, SRE, central security and compliance groups at GEICO to craft and roll out controls, processes, conduct gap assessments, automate collection of evidence and flag non-compliance with policies in real time.
· Lead the automation efforts by understanding the information security policies, security standards, security technologies, GEICOs environment (multi-cloud, on-prem) structure.
· Create a roadmap and a prioritized plan for automating security controls for continuous monitoring.
· Define the programmatic control language, evidence required and frequency, type of assets for each automated control.
· Create a unified security controls framework that maps back to security standards such as NIST CSF 2.0, PCI, NY DFS, SOX, etc., to collect evidence once to satisfy all relevant security standards.
· Partner with security control owners, governance team, compliance team, other stakeholders on security controls automation
· Determine complimentary products and solutions to scale and expedite overall automation goals
· Partner with cloud technical teams (Azure, GCP, AWS, etc.) to deliver a successful outcome
· Comfortable rolling up your sleeves to design and code modules for infrastructure, application, and processes.
· Solve specific security and business problems through automation, utilizing code, and integrating cloud-native and tools via API.
· Align on requirements and communicate results and recommendations both verbally and in writing.
· Educate relevant stakeholders about our solutions and potential opportunities.
· Work closely with various teams to drive feature innovation based upon customer needs.
· Utilize programming languages like Python, C# or other object-oriented languages, SQL, and NoSQL databases, Container Orchestration services including Docker and Kubernetes, and a variety of Azure tools and services
· Consistently share best practices and improve processes within and across teams
· Follow GEICOs developer standards and guidelines
Qualifications
· Programming experience with at least one modern language such as Java, C++, or C# including object-oriented design
· Experience contributing to the architecture and design (architecture, design patterns, reliability, and scaling) of new and current systems
· In-depth knowledge of CS data structures and algorithms
· Understanding of existing Operational Portals such as Azure Portal
· Understanding of HTML-5, JavaScript/TypeScript, XML, and JSON
· Understanding of micro-services oriented architecture and extensible REST APIs
· Understanding of Azure Network such as security zones, VNETs, and Public Peered Services
· Understanding of Azure PaaS and IaaS services
· Understanding of security protocols and products such as of Active Directory, Windows Authentication, SAML, OAuth
· Experience in Datacenter structure, capabilities, and offerings, including the Azure platform, and its native services
· Knowledge of developer tooling across the software development life cycle (task management, source code, building, deployment, operations, real-time communication)
· 5+ years of security compliance framework experience
· Expertise with security standards such as SOX, PCI-DSS, ISO27K, SOC or NIST (some combination of these is ideal)
· Technical acumen required. Understanding of cloud, open sourced distributed systems are ideal
· Great at both collaboration and independent problem solving
· Superb written communication and technical research skills
· Ability to develop relationships and work effectively with different teams at all levels and across functions relative to technical, policy, and business concerns
· Ability to resolve conflicts and drive issues to resolution
· Work independently with little or no supervision while maintaining a high level of efficiency
· Bachelor's Degree or equivalent experience preferred.
Annual Salary
$115,000.00 - $260,000.00The above annual salary range is a general guideline. Multiple factors are taken into consideration to arrive at the final hourly rate/ annual salary to be offered to the selected candidate. Factors include, but are not limited to, the scope and responsibilities of the role, the selected candidate’s work experience, education and training, the work location as well as market and business considerations.
Benefits:
As an Associate, you’ll enjoy our Total Rewards Program* to help secure your financial future and preserve your health and well-being, including:
Premier Medical, Dental and Vision Insurance with no waiting period**Paid Vacation, Sick and Parental Leave401(k) PlanTuition AssistancePaid Training and Licensures*Benefits may be different by location. Benefit eligibility requirements vary and may include length of service.
**Coverage begins on the date of hire. Must enroll in New Hire Benefits within 30 days of the date of hire for coverage to take effect.
The equal employment opportunity policy of the GEICO Companies provides for a fair and equal employment opportunity for all associates and job applicants regardless of race, color, religious creed, national origin, ancestry, age, gender, pregnancy, sexual orientation, gender identity, marital status, familial status, disability or genetic information, in compliance with applicable federal, state and local law. GEICO hires and promotes individuals solely on the basis of their qualifications for the job to be filled.
GEICO reasonably accommodates qualified individuals with disabilities to enable them to receive equal employment opportunity and/or perform the essential functions of the job, unless the accommodation would impose an undue hardship to the Company. This applies to all applicants and associates. GEICO also provides a work environment in which each associate is able to be productive and work to the best of their ability. We do not condone or tolerate an atmosphere of intimidation or harassment. We expect and require the cooperation of all associates in maintaining an atmosphere free from discrimination and harassment with mutual respect by and for all associates and applicants.