Geico

Senior Engineer - Production Security

Geico$100K — $215K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in software/security engineering or related field.
  • Proficient in Python or similar modern programming languages.
  • Hands-on experience with full-stack development tools like Git and relational databases.
  • In-depth knowledge of application security risks and key secure coding practices.
  • Strong project management skills, adept at juggling multiple priorities.
  • Effective written and verbal communication skills for diverse audiences.
  • Proven ability to leverage AI-assisted tools in software development.

Responsibilities

  • Provide technical leadership in AI security and secure design.
  • Plan and deliver engineering work while managing multiple priorities.
  • Design and deploy production-ready security services and integrations.
  • Conduct threat modeling and security architecture reviews for AI platforms.
  • Review code for security vulnerabilities and ensure best practices are followed.
  • Translate business needs into clear technical specifications and solutions.
  • Identify process and tooling gaps and implement improvements.

Benefits

  • Opportunity to work in a rapidly evolving field of AI security.
  • Collaborative environment promoting knowledge sharing and teamwork.
  • Focus on hands-on development rather than high-level architecture.
  • Proactive approach to resolving technical barriers.
  • Support for continuous learning and improvement in engineering practices.
Full Job Description
GEICO is seeking a Senior Security Engineer to strengthen the security of AI-enabled products and the engineering platforms that support them. This role combines product security judgment with hands-on software development. The engineer will assess designs, review code, build security automation, and partner with engineering and product teams to translate business needs and security requirements into practical, production-ready solutions. The successful candidate operates effectively with high-level direction, clarifies ambiguous problems, prioritizes competing work, and owns deliverables through completion. This is a Senior Engineer role focused on vital team-level contributions and technical leadership within the team, rather than enterprise-wide architecture ownership. What You Will Do 3 Provide technical leadership within the team for AI security, product security, secure design, and security engineering work. 3 Plan, estimate, prioritize, and deliver engineering work to schedule while managing multiple concurrent priorities and context switches. 3 Design, build, test, deploy, and troubleshoot production-ready security services, integrations, automation, and developer tooling. 3 Perform threat modeling and security architecture reviews for AI-enabled applications, services, APIs, data flows, agentic workflows, and supporting platforms. 3 Review code and designs for authentication, authorization, role-based access control, input validation, data protection, logging, error handling, database access, and other security concerns. 3 Translate business needs, customer feedback, and security requirements into clear technical requirements, implementation plans, and measurable outcomes. 3 Use data and risk context to recommend priorities and make sound design or configuration decisions, with attention to security, compliance, privacy, reliability, and customer data handling. 3 Work across engineering, product, platform, risk, and cybersecurity teams to remove blockers, resolve issues, and drive agreed actions to completion. 3 Proactively identify process, tooling, and control gaps, then implement practical improvements that reduce manual effort and strengthen security outcomes. 3 Contribute significantly to design, code, security, observability, performance, and operational-readiness reviews using established architecture and engineering guidance. 3 Document technical decisions, operating procedures, support guidance, and lessons learned so solutions can be maintained and improved by the team. 3 Help teammates overcome technical obstacles and share knowledge through reviews, pairing, technical discussions, and clear documentation. AI and Product Security Focus 3 Assess security risks associated with AI models, agents, prompts, retrieval-augmented generation, model context protocols, tools, data sources, memory, and downstream actions. 3 Apply secure-by-design practices to AI-enabled systems, including least privilege, trustworthy identity, authorization boundaries, input and output controls, secrets protection, audit logging, data governance, and resilient failure handling. 3 Build or integrate automated safeguards, evaluation workflows, security tests, and monitoring that help teams identify and reduce AI and application security risk throughout the development lifecycle. 3 Partner with developers to provide actionable remediation guidance and validate that security issues are addressed effectively. Required Qualifications 3 Solid professional experience in software engineering, security engineering, product security, application security, or a related technical field. 3 Hands-on experience writing, reviewing, testing, and troubleshooting code, with strong proficiency in Python or a comparable modern programming language. 3 Experience with full-stack or platform development using tools and technologies such as GitHub, Git, terminal and CLI workflows, APIs, relational databases such as PostgreSQL, and automated testing. 3 Practical experience conducting threat modeling, secure design reviews, architecture reviews, or secure code reviews. 3 Working knowledge of common application and API security risks, secure authentication and authorization patterns, input validation, logging, error handling, database security, and secure SDLC practices. 3 Ability to organize complex work, create realistic project plans, manage dependencies, communicate status and risks, and drive work to completion. 3 Ability to make progress with incomplete information, ask effective clarifying questions, and apply sound engineering judgment under ambiguity. 3 Strong written and verbal communication skills for technical and non-technical audiences. 3 Ability to listen to different perspectives, incorporate feedback, and confidently explain a well-reasoned recommendation. 3 Experience integrating AI-assisted development practices into the software development lifecycle while retaining accountability for architecture, technical decisions, testing, security, and operational readiness. 3 Proven ability to validate AI-generated outputs, identify inaccurate or insecure recommendations, and ensure resulting code meets expectations for security, quality, maintainability, reliability, testability, and compliance. 3 Strong portfolio of hands-on engineering work demonstrating effective use of AI-enabled development capabilities, including code generation, code review, debugging, refactoring, test generation, documentation, and engineering automation. 3 Demonstrated track record of leveraging AI-assisted software development tools and workflows to design, develop, test, troubleshoot, and deliver production-quality software solutions. 3 Experience working in an Agentic Development Environment where AI assistants or coding agents can inspect project context, propose or modify code, generate tests, summarize repositories, create pull requests, and support iterative debugging while the engineer remains accountable for correctness, security, and maintainability. 3 Hands-on familiarity with modern AI-enabled developer tools and workflows such as Cursor, Claude Code, GitHub Copilot, GitHub pull request automation, AI-assisted code review, repository-aware chat, terminal-based coding agents, and secure prompt/context management for engineering tasks. Preferred Qualifications 3 Experience building or securing generative AI, agentic AI, RAG, MCP-based integrations, or AI-enabled developer workflows. 3 Experience with Python application frameworks, data validation libraries such as Pydantic, PostgreSQL, cloud services, containers, CI/CD, and infrastructure automation. 3 Experience integrating security testing and controls into engineering workflows and developer tooling. 3 Familiarity with product security, cloud security, API security, threat modeling methodologies, and security or compliance frameworks relevant to enterprise environments. 3 Experience balancing near-term delivery with maintainability, operational readiness, and longer-term improvement opportunities. 3 Experience designing guardrails, evaluation frameworks, security controls, and governance mechanisms for AI-generated code and AI-assisted engineering workflows. 3 Experience building, extending, or securing AI-assisted development platforms, coding assistants, developer agents, agentic workflows, MCP integrations, RAG systems, or AI-enabled engineering productivity solutions. How You Work 3 Highly organized and detail-oriented, with the ability to manage multiple priorities simultaneously. 3 Takes ownership of problems and follows through until outcomes are delivered. 3 Thrives in a fast-paced environment and switches context with minimal loss of momentum. 3 Acts on ambiguity instead of waiting for perfect information. 3 Curious, driven, and eager to learn unfamiliar technologies and business domains. 3 Proactive in identifying improvement opportunities and turning ideas into implemented solutions. 3 Direct, respectful, and audience-aware in communication. 3 Open to differing perspectives while confident in evidence-based technical judgment. What Success Looks Like 3 Security risks are identified early and translated into clear, actionable engineering decisions. 3 Committed work is planned, prioritized, communicated, and delivered with high quality. 3 AI security safeguards and security automation are reliable, testable, maintainable, and usable by partner teams. 3 Engineering teams receive practical guidance that helps them resolve issues and build more secure products. 3 The team benefits from new and improved tools, documentation, repeatable practices, and shared technical knowledge. Annual Salary $100,000.00 - $215,000.00 The above annual salary range is a general guideline. Multiple factors are taken into consideration to arrive at the final hourly rate/ annual salary to be offered to the selected candidate. Factors include, but are not limited to, the scope and responsibilities of the role, the selected candidate's work experience, education and training, the work location as well as market and business considerations. GEICO will consider sponsoring a new qualified applicant for employment authorization for this position.

About Geico

GEICO (Government Employees Insurance Company) is an American auto insurance company with headquarters in Chevy Chase, Maryland. It is the second largest auto insurer in the United States, after State Farm. GEICO is a wholly owned subsidiary of Berkshire Hathaway that provides coverage for more than 24 million motor vehicles owned by more than 15 million policy holders as of 2017. GEICO writes private passenger automobile insurance in all 50 U.S. states and the District of Columbia. The insurance agency sells policies through local agents, called GEICO Field Representatives, and over the phone directly to the consumer, and through their website.
Learn more about Geico
Size
40,000 employees
Industry
Founded
1936

Similar Jobs

More Jobs at Geico

More Information Technology Jobs

Find similar Senior Engineer - Production Security jobs: