Geico

Staff Security Engineer – Cyber Governance & Automation

Geico$110K — $230K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in Cyber Governance, Risk, and Compliance (GRC)
  • Proven expertise in automated governance frameworks and compliance tools
  • Strong understanding of regulatory requirements like NYDFS, PCI DSS, NIST CSF, SOC, and ISO
  • Demonstrated experience in leading cross-functional teams and influencing organizational strategy
  • Excellent communication skills for engaging with technical and executive audiences
  • Experience with AI applications in security and compliance context
  • Knowledge of cloud and on-premise security technologies.

Responsibilities

  • Define and execute the vision and strategy for GEICO's cyber governance automation capabilities
  • Drive automation initiatives to ensure compliance with evolving regulatory frameworks
  • Own the governance automation platform, ensuring audit readiness and evidence collection
  • Implement a risk-based remediation framework for control non-compliance
  • Collaborate with teams to operationalize governance standards and metrics effectively
  • Report on governance outcomes to executive leadership, focusing on risk and compliance readiness
  • Continuously assess and improve governance processes and tools across the organization.

Benefits

  • Flexible work arrangements
  • Professional development opportunities
  • Collaborative and innovative work environment
  • Access to cutting-edge technology and resources
  • Comprehensive health and wellness programs
Full Job Description

This role is designed for a stafflevel security practitioner with deep Cyber Governance, Risk, and Compliance (GRC) expertise who shapes the vision, strategy, and outcomes of GEICOs cyber governance automation capabilities. The Staff Security Engineer owns the endtoend automated cyber governance program, including defining and delivering the roadmap for continuous control monitoring and validation, scalable evidence collection, and realtime audit readiness across GEICOs hybrid cloud and onprem environments.

This position partners closely with engineering and platform teams to translate complex regulatory, policy, and control requirements into prioritized,well-definedautomation capabilities, ensuring solutions are scalable, sustainable, and aligned to enterprise risk priorities. Success in this role means turning governance requirements into durable,outcome drivenproducts thatdemonstratecontrol effectiveness and reduce audit friction.

Cyber Governance Product & Program Ownership

  • Contribute to the vision, strategy, and roadmap for GEICOs cyber governance automation capabilities, driving delivery through prioritized execution and continuous improvement.

  • Define how policies, standards, regulatory frameworks, and technical controls are operationalized and continuously validated through automated evidence collection.

  • Own governance automation platforms endtoend as the system of record for control health, evidence, and audit readiness across cloud and onprem environments.

  • Drive near100% automation coverage, including designing scalable onprem automation strategies and governing compensating controls where full automation is not feasible, while maintaining audit defensibility.

  • Define and enforce governance standards for automation coverage targets, evidence SLAs, control performance metrics, and telemetry requirements.

  • Own the governance automation roadmap, prioritizing work based on risk reduction, regulatory requirements, and operational efficiency.

  • Establish and operationalize a standardized, riskbased remediation lifecycle, including severity classification, timelines, escalation paths, closure criteria, and enforced SLAs.

  • Maintain ownership of remediation scheduling frameworks and forwardlooking visibility into upcoming deadlines.

  • Ensure all noncompliance is consistently tracked, prioritized, and driven to closure through scalable workflows.

  • Partner with compliance, risk, audit, and engineering leaders to ensure governance capabilities align with enterprise risk priorities and regulatory obligations (e.g., NYDFS, PCI DSS, NIST CSF, SOC, ISO).

  • Act as the single point of accountability for governance automation outcomes, including executivelevel risk, remediation, and auditreadiness reporting with forecasting.

Technical Strategy & Product Stewardship

  • Own theproduct strategyanddirectionfor GEICOs Automated Cyber Governance capabilities, ensuring clearsystemofrecorddefinitions, scalability expectations, and alignment tolongtermenterprise needs.

  • Partner with engineering and platform teams todefine and prioritize governance automation capabilities, providing product requirements, architectural guardrails, and acceptance criteria rather than performing direct system development.

  • Define andmaintainintegration principles, system boundaries, and data standardsto ensure reliable, secure, and consistent evidence flows across cloud platforms, security tools, and internal systems.

  • Evaluate and guide the responsible use of AI capabilities within governance platforms(e.g., evidence classification, control mapping suggestions, risk summarization), ensuring explainability, auditability, and alignment with regulatory expectations.

  • Serve as theprimary point of accountability for governance automation outcomes, working with engineering leaders to resolve complex platform challenges and ensuresolutionsremainreliable, sustainable, and fit for purpose.

  • Ownership of100% source system adoptionfeeding governance evidence (e.g., cloud, IAM, logging, asset inventory)

  • Accountability foridentifyingand closing: Missing telemetry, Integration gaps, Inconsistent or unreliable data sources, Enforcement of standardized telemetry and data requirements across teams

  • Ownership of automated control quality assurance,includingFalse positive / false negative reduction, Control tuning, Drift detection

  • Ensuring all automated evidenceisAuditdefensible, Traceable, Aligned to regulatory intent

  • Ownership ofcontrol change managementfor new and modified controls

  • Translating regulatory, policy, and control changes into:Engineering requirements

  • Implementation guidance, Evidence expectations

  • Proactive stakeholder communication:What is changing,Whyit matters, Compliance deadlines, Tracking and escalatingcontrol adoption readiness risks

Automation & Continuous Control Monitoring

  • Define how security policies, standards, and control requirements aretranslated into automated, continuouslymonitoredcontrol capabilities, including clear requirements, success criteria, andevidenceexpectations.

  • Establish standards and expectations forautomated detection of controlnonadherence, and partner with engineering and remediation teams to ensureappropriate remediationguidance, workflows, or integrations are in place.

  • Ensure evidence outputs areauditready, traceable, repeatable, and aligned to regulatory intent, materially reducing reliance onpointintime, manual evidence collection.

  • Apply AIassisted techniques to improve control validation and evidence quality, such as anomaly detection, evidence completeness checks, control drift identification, and signal prioritization across large control populations.

  • Leverage AIenabled insights to reduce noise and surface material control failures, ensuring governance automation focuses on true risk rather than generating lowvalue alerts.

CrossFunctionalLeadership & Enablement

  • Serve as atrusted partner and advisorto engineering, infrastructure, cloud, and security teams by providing clarity on governance requirements, regulatory intent, and how they are operationalized through scalable solutions.

  • Influence partner teams to adopt aproductandautomation firstapproachto governance, compliance, and policy adherence, reducing manual effort and improving consistency across the enterprise.

  • Communicate complex technical and regulatory concepts clearly to a broad range of stakeholders, including engineers, risk and audit partners, and executive leadership.

  • Contribute to raising the organizationsgovernance, automation, and product maturitythrough guidance, enablement, andcrossfunctionalcollaboration.

Program Maturity & Continuous Improvement

  • Continuously assess governance automation capabilities, processes, and supporting tools toidentifyopportunities toscale adoption, increase automation coverage, and improve effectiveness.

  • Own the definition and evolution ofcyber governance metrics and reporting, including dashboards that provide clear visibility into control health, automation coverage, audit readiness, and risk posture for executive and stakeholder audiences.

  • Track product and program outcomes,identifygaps against regulatory and riskobjectives, andprioritize improvement initiativesthat advance maturityquarter over quarter.

  • IncorporateAIdriven

About Geico

GEICO (Government Employees Insurance Company) is an American auto insurance company with headquarters in Chevy Chase, Maryland. It is the second largest auto insurer in the United States, after State Farm. GEICO is a wholly owned subsidiary of Berkshire Hathaway that provides coverage for more than 24 million motor vehicles owned by more than 15 million policy holders as of 2017. GEICO writes private passenger automobile insurance in all 50 U.S. states and the District of Columbia. The insurance agency sells policies through local agents, called GEICO Field Representatives, and over the phone directly to the consumer, and through their website.
Learn more about Geico
Size
40,000 employees
Industry
Founded
1936

Similar Jobs

More Jobs at Geico

More Information Technology Jobs

Find similar Staff Security Engineer – Cyber Governance & Automation jobs: