Geico

Identity Security Distinguished Engineer

Geico$140K — $300K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Extensive knowledge of identity protocols like Active Directory, Kerberos, LDAP, SAML, SCIM, OAuth, and OIDC.
  • Strong background in privileged access management tools and methodologies.
  • Experience in offensive and defensive security roles with a hacker perspective.
  • Expertise in architecting security systems with microservices and REST APIs.
  • Proficient in communication and presentation tailored for varied audiences, influencing decision-making.
  • Hands-on experience across multi-platform environments including Linux, Mac, and Windows.
  • Familiar with major IaaS platforms from top providers like AWS and Azure.
  • Ability to apply engineering principles to solve security control challenges.
  • Competent in creating experiments to enhance security detection and prevention strategies.

Responsibilities

  • Educate staff on integrating a security mindset into complex challenges.
  • Mentor team members to foster a culture of collaboration and innovation.
  • Work with cross-functional teams to tackle problems with minimal disruption.
  • Identify and enhance security measures while streamlining tools and processes.
  • Lead automation projects to enhance security capabilities through proofs of concept.
  • Ensure compliance with industry regulations using engineered automation solutions.
  • Collaborate with business partners to develop and validate security mitigation techniques.
  • Define identity security roadmaps that balance functionality and security.

Benefits

  • Opportunity to lead and innovate in a critical cybersecurity role.
  • Work within a highly collaborative team fostering professional growth.
  • Contribute to a proactive security culture that enables business efficiency.
  • Engage in advanced research and development of security solutions.
  • Participate in shaping the organization's security strategy during a transformative phase.
Full Job Description
GEICO is seeking an Identity Security Distinguished Engineer to provide security specific strategic and technical direction for our identity and access management solutions with our user, development and production domains. This individual will play a lead role within GEICO's Cybersecurity team, with a focus on defensive and protective controls, compliance and governance automation and driving modernization in our identity strategy.

Our Distinguished Engineer will be the technical and engineering lead for a team of engineers who proactively and holistically deliver secure IAM configuration, threat detection, strategic partnership on the IAM roadmap and create automated proof and validation of our controls. You will help our business transformation as we transition from a traditional IT Security model to a tech organization with engineering excellence as its mission, while co-creating a culture of leveraging security to enable the business and protecting against the latest threats.

You will innovate and lead new initiatives, improve Security, enhance existing systems while also identifying new opportunities with an offensive security mindset to find critical problems and solve at a rapid pace. You will help lead the confirmation our systems are protected through automated testing and continuous improvement to raise the bar and foster a proactive security culture which also enables the business without impact. The ideal candidate has deep technical expertise in this domain and an attacker/defender adversarial background.

As a Distinguished Engineer, you will:
  • Influence and educate staff at all levels to bring a security minded approach to difficult challenges balancing usability and security.
  • Provide technical guidance and mentorship to the team, fostering a culture of innovation, collaboration, and continuous improvements.
  • Collaborate with cross-functional leaders, team members, IAM engineering, and peer security teams to solve complex problems with minimal business impact.
  • Proactively identify opportunities to enhance security measures, streamline processes, and optimize tooling to fortify our environment against emerging threats.
  • Deliver automation initiatives, conduct advanced research, and develop proofs of concept to enhance our security capabilities and improve overall efficiency.
  • Help develop and implement engineered automation to ensure compliance with industry regulations and frameworks which demonstrates without manual efforts.
  • Work with our business partners to help derive and validate mitigation techniques for identified threats and/or non-compliance.
  • Define roadmaps for securing various identities with purposeful and functional security without impacting or unnecessary overhead.
  • Automated adversarial testing of our identity systems to ensure detection mechanisms function appropriately and efficiently.
  • Provide motivating demonstrations and communications to show the value of our security measures to the business, highlighting the low impact on systems, improved operability and resiliency.


Qualifications
  • Extensive experience in identity products and protocols products Active Directory, Kerberos, LDAP, SAML, SCIM, OAuth, and OIDC.
  • Deep skills in privileged access management tools and services (build/buy).
  • Extensive experience in offensive and defensive security roles, with a strong hacker mindset.
  • Experience building and designing (architecture, design patterns, reliability, and scaling) of security systems with micro-services and extensible REST APIs.
  • Experience communicating and presentation to senior and junior staff with the ability to influence stakeholders.
  • Experience in a multi-platform environment with Linux, Mac, Windows.
  • Experience with multiple IaaS platforms from top tier providers.
  • Experience with solving security control requirements with engineering approaches.
  • Ability to excel in a fast-paced, startup-like environment.
  • Ability to design, perform experiments, and influence security detection and protection solutions.
  • Strong knowledge of industry-standard security tools, frameworks, and best practices including ITDR, EPM, MITRE, CIS and NIST.
  • Demonstrated fluency and specialization with at least one modern language such as Python or Go.
  • In depth expertise in cryptographic protocols, digital certificates, and encryption standards such as X.509, Transport Layer Security (TLS), and Advanced Encryption Standard (AES).
  • Experience working with auditors and demonstrating security controls.


Experience
  • 8+ years in a dedicated security role, preferably in the tech industry
  • 5+ years of experience with security, identity, architecture, and design
  • 5+ years of experience with open-source frameworks is desired.
  • 3+ years of experience with AWS, GCP, Azure, or other cloud providers
  • 3+ years in a senior security role, preferably architecture, influencing company direction on security strategy.
  • Education with practical examples in penetration testing, writing test scripts and determining countermeasures.
  • Experience applying security controls to exceed third party attestation requirements (PCI, SOC, ...).
  • Desired certifications: CISSP, CISA, CISM, CCSK, CCSP, CEH, C|CISO and related GIAC.


Education
  • Bachelor's degree in Computer Science, Cyber Security, or equivalent education with work experience
  • Third party certifications on penetration testing/ethical hacking, exploit detection and evasion techniques, and related.


Annual Salary
$140,000.00 - $300,000.00
The above annual salary range is a general guideline. Multiple factors are taken into consideration to arrive at the final hourly rate/ annual salary to be offered to the selected candidate. Factors include, but are not limited to, the scope and responsibilities of the role, the selected candidate's work experience, education and training, the work location as well as market and business considerations.

GEICO will consider sponsoring a new qualified applicant for employment authorization for this position.

About Geico

GEICO (Government Employees Insurance Company) is an American auto insurance company with headquarters in Chevy Chase, Maryland. It is the second largest auto insurer in the United States, after State Farm. GEICO is a wholly owned subsidiary of Berkshire Hathaway that provides coverage for more than 24 million motor vehicles owned by more than 15 million policy holders as of 2017. GEICO writes private passenger automobile insurance in all 50 U.S. states and the District of Columbia. The insurance agency sells policies through local agents, called GEICO Field Representatives, and over the phone directly to the consumer, and through their website.
Learn more about Geico
Size
40,000 employees
Industry
Founded
1936

Similar Jobs

More Jobs at Geico

More Information Technology Jobs

Find similar Identity Security Distinguished Engineer jobs: