GEICO is seeking an experienced Staff Engineer to provide enterprise support for application security in our hybrid, multi-cloud environments. The
Product Security Tools Staff Engineer proactively leads and supports Product Security activities that guide the design, development and security of code and code repositories for cloud-hosted and open-source applications. Current tools include CI/CD integrations, SAST, DAST, SCA, container scanning, and automated threat modeling.
Position Description:Our Product Security tooling team is focused on enabling our engineering teams to build and develop code securely, supporting our code and application scanning tools (vendor & open source). We are looking for an experienced Staff Engineer who can help scale out, automate, and support our Tooling applications, specifically our build-time container scanning tooling. The ideal candidate is experienced in understanding and challenging our Security & Engineering organizations on how and where to implement secure code guardrails and security scanning. We are aiming to expand out our coverage of our security scanning tools more broadly within the enterprise, in a more integrated fashion while also navigating quickly-changing and legacy environments across our tech stack.
Position Responsibilities:As a Staff Engineer, you will
- Own managing our vendor/open source tooling, integrating functionality across multiple technology platforms such as GitHub Enteprise and Azure DevOps
- Build out applications and automations to reach our team goals, better integrate across the Tech platforms, and focus on prioritizing the most critical vulns/findings engineering teams should fix
- Develop and implement security policies and procedures
- Collaborate with development teams to ensure secure coding practices are followed
- Stay up to date with the latest security threats and trends
- Provide guidance and mentorship to junior engineers
- Provide technical leadership to multiple areas and provide technical and thought leadership to the enterprise
- Be accountable for the quality, usability, and performance of the solutions
Qualifications:- CI/CD pipeline experience, specifically ADO pipelines & GitHub Actions are required for this role
- Proficiency in programming languages such as Java, Python, or Golang
- Experience with security tools such as vulnerability scanners or static code scanning tools
- Knowledge of web application security and how to support engineers with managing their security vulnerabilities as a result of the Product Security scanning tools
- Strong analytical and problem-solving skills
- Excellent communication and collaboration skills
- Knowledge of various managed and database technologies like such as Cosmos, SQL, MySQL, MongoDB
- Understanding and knowledge of application development life cycle methodologies such as waterfall, rapid prototyping, incremental, and DevOps
- Familiar with navigating implementing and supporting vendor tools deployed in an enterprise environment
- Understanding and applied use of OWASP Top 10, NIST CSF, PCI-DSS, etc.
Experience:- 6+ years of experience in application security, or in a related domain
- 6+ years experience with programming languages, including understanding and interacting with CI/CD pipelines for application deployments
Education:- Bachelor's degree in Computer Science, Information Systems, or equivalent education or work experience
Annual Salary$110,000.00 - $230,000.00
The above annual salary range is a general guideline. Multiple factors are taken into consideration to arrive at the final hourly rate/ annual salary to be offered to the selected candidate. Factors include, but are not limited to, the scope and responsibilities of the role, the selected candidate's work experience, education and training, the work location as well as market and business considerations.
At this time, GEICO will not sponsor a new applicant for employment authorization for this position.