
At GEICO, we offer a rewarding career where your ambitions are met with endless possibilities.
Every day we honor our iconic brand by offering quality coverage to millions of customers and being there when they need us most. We thrive through relentless innovation to exceed our customers’ expectations while making a real impact for our company through our shared purpose.
When you join our company, we want you to feel valued, supported and proud to work here. That’s why we offer The GEICO Pledge: Great Company, Great Culture, Great Rewards and Great Careers.
This role is designed for a staff‑level security practitioner with deep Cyber Governance, Risk, and Compliance (GRC) expertise who shapes the vision, strategy, and outcomes of GEICO’s cyber governance automation capabilities. The Staff Security Engineer owns the end‑to‑end automated cyber governance program, including defining and delivering the roadmap for continuous control monitoring and validation, scalable evidence collection, and real‑time audit readiness across GEICO’s hybrid cloud and on‑prem environments.
This position partners closely with engineering and platform teams to translate complex regulatory, policy, and control requirements into prioritized,well-definedautomation capabilities, ensuring solutions are scalable, sustainable, and aligned to enterprise risk priorities. Success in this role means turning governance requirements into durable,outcome drivenproducts thatdemonstratecontrol effectiveness and reduce audit friction.
Cyber Governance Product & Program Ownership
Contribute to the vision, strategy, and roadmap for GEICO’s cyber governance automation capabilities, driving delivery through prioritized execution and continuous improvement.
Define how policies, standards, regulatory frameworks, and technical controls are operationalized and continuously validated through automated evidence collection.
Own governance automation platforms end‑to‑end as the system of record for control health, evidence, and audit readiness across cloud and on‑prem environments.
Drive near‑100% automation coverage, including designing scalable on‑prem automation strategies and governing compensating controls where full automation is not feasible, while maintaining audit defensibility.
Define and enforce governance standards for automation coverage targets, evidence SLAs, control performance metrics, and telemetry requirements.
Own the governance automation roadmap, prioritizing work based on risk reduction, regulatory requirements, and operational efficiency.
Establish and operationalize a standardized, risk‑based remediation lifecycle, including severity classification, timelines, escalation paths, closure criteria, and enforced SLAs.
Maintain ownership of remediation scheduling frameworks and forward‑looking visibility into upcoming deadlines.
Ensure all non‑compliance is consistently tracked, prioritized, and driven to closure through scalable workflows.
Partner with compliance, risk, audit, and engineering leaders to ensure governance capabilities align with enterprise risk priorities and regulatory obligations (e.g., NYDFS, PCI DSS, NIST CSF, SOC, ISO).
Act as the single point of accountability for governance automation outcomes, including executive‑level risk, remediation, and audit‑readiness reporting with forecasting.
Technical Strategy & Product Stewardship
Own theproduct strategyanddirectionfor GEICO’s Automated Cyber Governance capabilities, ensuring clearsystem‑of‑recorddefinitions, scalability expectations, and alignment tolong‑termenterprise needs.
Partner with engineering and platform teams todefine and prioritize governance automation capabilities, providing product requirements, architectural guardrails, and acceptance criteria rather than performing direct system development.
Define andmaintainintegration principles, system boundaries, and data standardsto ensure reliable, secure, and consistent evidence flows across cloud platforms, security tools, and internal systems.
Evaluate and guide the responsible use of AI capabilities within governance platforms(e.g., evidence classification, control mapping suggestions, risk summarization), ensuring explainability, auditability, and alignment with regulatory expectations.
Serve as theprimary point of accountability for governance automation outcomes, working with engineering leaders to resolve complex platform challenges and ensuresolutionsremainreliable, sustainable, and fit for purpose.
Ownership of100% source system adoptionfeeding governance evidence (e.g., cloud, IAM, logging, asset inventory)
Accountability foridentifyingand closing:Missing telemetry, Integration gaps, Inconsistent or unreliable data sources, Enforcement of standardized telemetry and data requirements across teams
Ownership of automated control quality assurance,includingFalse positive / false negative reduction, Control tuning, Drift detection
Ensuring all automated evidenceisAudit‑defensible, Traceable, Aligned to regulatory intent
Ownership ofcontrol change managementfor new and modified controls
Translating regulatory, policy, and control changes into:Engineering requirements
Implementation guidance, Evidence expectations
Proactive stakeholder communication:What is changing,Whyit matters, Compliance deadlines, Tracking and escalatingcontrol adoption readiness risks
Automation & Continuous Control Monitoring
Define how security policies, standards, and control requirements aretranslated into automated, continuouslymonitoredcontrol capabilities, including clear requirements, success criteria, andevidenceexpectations.
Establish standards and expectations forautomated detection of controlnon‑adherence, and partner with engineering and remediation teams to ensureappropriate remediationguidance, workflows, or integrations are in place.
Ensure evidence outputs areaudit‑ready, traceable, repeatable, and aligned to regulatory intent, materially reducing reliance onpoint‑in‑time, manual evidence collection.
Apply AI‑assisted techniques to improve control validation and evidence quality, such as anomaly detection, evidence completeness checks, control drift identification, and signal prioritization across large control populations.
Leverage AI‑enabled insights to reduce noise and surface material control failures, ensuring governance automation focuses on true risk rather than generating low‑value alerts.
Cross‑FunctionalLeadership & Enablement
Serve as atrusted partner and advisorto engineering, infrastructure, cloud, and security teams by providing clarity on governance requirements, regulatory intent, and how they are operationalized through scalable solutions.
Influence partner teams to adopt aproduct‑and automation firstapproachto governance, compliance, and policy adherence, reducing manual effort and improving consistency across the enterprise.
Communicate complex technical and regulatory concepts clearly to a broad range of stakeholders, including engineers, risk and audit partners, and executive leadership.
Contribute to raising the organization’sgovernance, automation, and product maturitythrough guidance, enablement, andcross‑functionalcollaboration.
Program Maturity & Continuous Improvement
Continuously assess governance automation capabilities, processes, and supporting tools toidentifyopportunities toscale adoption, increase automation coverage, and improve effectiveness
Own the definition and evolution ofcyber governance metrics and reporting, including dashboards that provide clear visibility into control health, automation coverage, audit readiness, and risk posture for executive and stakeholder audiences.
Track product and program outcomes,identifygaps against regulatory and riskobjectives, andprioritize improvement initiativesthat advance maturityquarter over quarter
IncorporateAI‑driveninsights into governance metrics and reporting, such as trend analysis, control health forecasting, or remediation prioritization, to improve executive visibility anddecision-making
Promote continuous learning andbest practicesharing across cyber governance, risk, audit, and engineering communitiesto improve consistency, effectiveness, andlong-termsustainability.
Metrics, Reporting & Executive Insight
Establishesand enforces the cyber governance metric model that directly drives control effectiveness, remediation accountability, and enterprise risk reduction. The Staff Security Engineer has clear ownership of defining, standardizing, and operationalizing metrics that are automation‑backed, auditable, and actively used to hold teams accountable
Accountable for defining and owning core governance metrics, including:
Automation coverage (%) across regulatory and internal control sets
Continuous vs. manual control execution ratio
Evidence freshness and SLA adherence for automated controls
Control failure rates and recurrence trends
Remediation mean time to resolution (MTTR)
Tool, control, and automation adoption and utilization rates
SLA adherence by severity tier for policy, control, and regulatory findings
Executive reporting produced by this role:
Clearly ties automation outcomes tomeasurable risk reduction
Demonstrates sustained, real‑timeaudit readinessand control health
Quantifiesoperational efficiency gainsfrom automation, including reduced manual effort, faster remediation, and fewer audit‑driven escalations
Required Qualifications
6+ years of experience across Cyber Governance, Risk, and Controls (GRC), withdemonstratedownership ofcomplex,cross functionalprograms or productsthat deliver measurable compliance and risk outcomes.
Proven experiencedefining, scaling, and evolving governance automation or compliance platforms, including ownership of outcomes such as control validation, evidence quality, and audit readiness.
Strong technical fluency with cloud platforms, integrations, and automation concepts, with the ability topartner effectively with engineering teamsto define requirements and evaluate implementation approaches (without direct system development responsibility).
Deep understanding of major security and compliance frameworks (e.g., NIST CSF, NYDFS 500, PCI DSS, SOC, ISO 27001) and the ability totranslate regulatory expectations into scalable governance capabilities
Demonstrated ability tolead and align complex initiativesacross GRC, engineering, risk, and audit stakeholders, with accountability for outcomes, adoption, and long‑term sustainability.
Technical Skills
Strong technical fluency across modern engineering concepts, with the ability topartner effectively with engineering teamson the design and delivery of scalable governance automation capabilities.
Experience owning and scalingoff‑the‑shelfautomated governance and compliance platforms(e.g.,Drata, Vantaor similar), including defining control mappings, evidence models, automation coverage targets, and integration strategy.
Working knowledge of APIs, authentication mechanisms (e.g., OAuth, SAML), and common data formats (e.g., JSON, XML), sufficient todefine requirements, evaluate approaches, and assess integration feasibility
Familiarity with cloud platforms (AWS, Azure, and/or GCP) and an understanding of how security controls areimplemented,validated, andevidencedwithin cloud environments.
Exposure to containers,cloud‑nativeservices, and CI/CD environments to support informeddecision‑makingand collaboration (nice to have).
Experience applying or governing AI‑assisted capabilities within security, cyber governance or risk platforms, with an understanding of model limitations, data quality considerations, and audit implications
What Success Looks Like
Cyber governance controls and evidence arecontinuouslymonitored, validated, andaudit‑ready, with minimal reliance on manual orpoint‑in‑timeprocesses.
Engineers and control owners experiencereduced audit friction, clear expectations, and repeatable governance workflows embedded into standard operating practices.
Leadership hasclear, reliable visibilityintocontrolhealth, risk posture, and remediation progress through consistent, trusted metrics.
Governance automation capabilitiesscale with the businessand adapt quickly to changing regulatory requirements, risk priorities, and technology evolution.
Annual Salary
$110,000.00 - $230,000.00
The above annual salary range is a general guideline. Multiple factors are taken into consideration to arrive at the final hourly rate/ annual salary to be offered to the selected candidate. Factors include, but are not limited to, the scope and responsibilities of the role, the selected candidate’s work experience, education and training, the work location as well as market and business considerations.
At this time, GEICO will not sponsor a new applicant for employment authorization for this position.
The GEICO Pledge:
Great Company: At GEICO, we help our customers through life’s twists and turns. Our mission is to protect people when they need it most and we’re constantly evolving to stay ahead of their needs.
We’re an iconic brand that thrives on innovation, exceeding our customers’ expectations and enabling our collective success. From day one, you’ll take on exciting challenges that help you grow and collaborate with dynamic teams who want to make a positive impact on people’s lives.
Great Careers: We offer a career where you can learn, grow, and thrive through personalized development programs, created with your career – and your potential – in mind. You’ll have access to industry leading training, certification assistance, career mentorship and coaching with supportive leaders at all levels.
Great Culture: We foster an inclusive culture of shared success, rooted in integrity, a bias for action and a winning mindset. Grounded by our core values, we have an an established culture of caring, inclusion, and belonging, that values different perspectives. Our teams are led by dynamic, multi-faceted teams led by supportive leaders, driven by performance excellence and unified under a shared purpose.
As part of our culture, we also offer employee engagement and recognition programs that reward the positive impact our work makes on the lives of our customers.
Great Rewards: We offer compensation and benefits built to enhance your physical well-being, mental and emotional health and financial future.
The equal employment opportunity policy of the GEICO Companies provides for a fair and equal employment opportunity for all associates and job applicants regardless of race, color, religious creed, national origin, ancestry, age, gender, pregnancy, sexual orientation, gender identity, marital status, familial status, disability or genetic information, in compliance with applicable federal, state and local law. GEICO hires and promotes individuals solely on the basis of their qualifications for the job to be filled.
GEICO reasonably accommodates qualified individuals with disabilities to enable them to receive equal employment opportunity and/or perform the essential functions of the job, unless the accommodation would impose an undue hardship to the Company. This applies to all applicants and associates. GEICO also provides a work environment in which each associate is able to be productive and work to the best of their ability. We do not condone or tolerate an atmosphere of intimidation or harassment. We expect and require the cooperation of all associates in maintaining an atmosphere free from discrimination and harassment with mutual respect by and for all associates and applicants.

GEICO (Government Employees Insurance Company) offers a variety of insurance such as vehicle, property, business, life, umbrella, travel, pet, jewelry and more.
The company, which was founded in 1936, is the third-largest auto insurer in the United States and insures vehicles in all 50 states and Washington, D.C.
GEICO, a member of the Berkshire Hathaway family of companies, constantly strives to make lives better by protecting people against unexpected events while saving them money and providing an outstanding customer experience. Visit geico.com to learn more
▪️ Building a Diverse Workforce ▪️
We are building a diverse and inclusive workforce. GEICO is dedicated to fostering a workplace where everyone feels valued, respected and supported. Our company is focused on building a diverse workforce through a culture of intentional inclusion.
▪️ Supporting Our Communities ▪️
Our commitment to being an engaged and involved corporate citizen is important to us. We work with supportive partners across the country that help us provide resources for people in need. Authenticity and inclusiveness are paramount as we give back to our communities.
▪️GEICO Cares ▪️
Our employees can make a big impact by participating in company-wide social impact programs such as Giving Back Together and FastPitch. They can also volunteer with local and national organizations such as Shoes That Fit, Reading is Fundamental, and more. To learn more, visit GEICO in the Community.
GEICO Has Office Locations In:
Regional offices:
• Buffalo, New York
• Dallas, Texas
• Fredericksburg, Virginia
• Indianapolis, Indiana
• Lakeland, Florida
• Macon, Georgia
• San Diego, California
• Tucson, Arizona
• Virginia Beach, Virginia
• Woodbury, New York
Service centers:
• Honolulu, Hawaii
• Kansas City, Kansas
• Iowa City, Iowa
Claims centers:
• Houston, Texas
• Marlton, New Jersey
• Seattle, Washington
Headquarters
Chevy Chase, MD