FreshRemote.Work

Staff Software Engineer - Vulnerability Management Engineering (Remote)

TX Austin, United States

GEICO is seeking an experienced full-stack engineer with a deep technical expertise and passion for building high-performance, low maintenance, zero-downtime, and highly scalable systems. The ideal candidate has a proven track record of design, development, and implementation of scalable solutions in hybrid environments using commercial and open-source products, preferably in Cybersecurity domain. This role will be responsible for leading enterprise initiatives and collaboration with cross-functional teams as well as designing and implementing secure and scalable solutions to drive Vulnerability Management initiatives.

As a Staff Engineer, you’re not just a technical expert—you’re a lead, a problem solver, an innovator who thrives in a fast-paced, constantly evolving environment. You will turn complex security challenges into elegant, practical solutions while fostering collaboration across teams and stakeholders. You have exposure to Cybersecurity and are well-versed with Vulnerability Management Lifecycle - asset discovery, internal/external scans, contextualization and risk-based assessment, triaging of CVEs, detection authoring, security data pipeline, reporting, and remediation.

Staff Engineer works closely with infrastructure, development, product, and other organizations across GEICO to integrate security into the ecosystem from design through deployment to sustainable operations. The Staff Engineer brings in expertise in requirements identification, feasibility analysis, secure infrastructure designs, technology evaluation and selection, and implementation of scalable systems using CI/CD and DevSecOps to raise the bar on engineering excellence and security best practices.

​​​As a Staff Engineer, you will: 

  • Provide technical leadership for cybersecurity program strategy, software development, integration decisions, analyzing design constraints and trade-offs in system and security design

  • Lead design, development, and delivery of security solutions to drive Vulnerability Management initiatives.

  • Deliver automation initiatives, conduct advanced research, and develop proofs of concept to enhance our security capabilities and improve overall efficiency

  • Achieve security business outcomes through force multiplication

  • Develop, integrate, and maintain multilevel cybersecurity designs, architectures, policies, and procedures

  • Provide secure design guidance and recommendations to developers, infrastructure, and product engineers

  • Influence and educate partner teams to bring an engineering first approach to develop sustainable security systems.

  • Mentor peers and team members in security technologies, enterprise solution design, deployment, and effective customer interaction

  • Provide motivating demonstrations and communications to show the value of our security measures to the business, highlighting the low impact on systems, improved operability and resiliency

Qualifications

  • Tech lead with full-stack software development and DevSecOps experience in a hybrid environment (AWS, Azure, on-prem)

  • Development and leadership in Cybersecurity domain, preferably in Vulnerability Management Engineering

  • Specialization with at least one modern languages such as Java, Go, Python or C#, and a scripting language

  • Extensive knowledge and experience of building data intensive large-scale distributed systems on cloud

  • ​Experience building the architecture and design of new and current systems (architecture, design patterns, reliability, and scaling) 

  • ​Fluency in DevOps concepts and best practices in CI/CD pipelines and infrastructure as a code

  • ​Experience with application performance monitoring tools and performance assessments

  • Ability to design, implement, deploy, and operate systems to solve complex security problems in a fast-paced, startup-like environment

  • Strong knowledge of industry-standard security tools, frameworks, and best practices including MITRE, CIS and NIST

  • Experience working with auditors and demonstrating security controls

Experience

  • 6+ years of non-internship professional software engineering experience of building large-scale distributed systems

  • 4+ years of experience with architecture and design in a tech lead role

  • 4+ years of experience with AWS, GCP, Azure, or other cloud providers

  • 3+ years of experience in open-source frameworks

  • Foundational knowledge of security best practices for system design and development

  • Experience of building applications for security domain

  • Experience of assessing security vulnerabilities and driving their remediation is a plus

  • A professional security certifications (e.g., CISSP, CCSP, CSSLP) is a plus

Education

  • Bachelor’s degree in Computer Science, Information Systems, Cyber Security, or equivalent education with work experience


 

Annual Salary

$90,000.00 - $260,000.00

The above annual salary range is a general guideline. Multiple factors are taken into consideration to arrive at the final hourly rate/ annual salary to be offered to the selected candidate. Factors include, but are not limited to, the scope and responsibilities of the role, the selected candidate’s work experience, education and training, the work location as well as market and business considerations.


 

At this time, GEICO will not sponsor a new applicant for employment authorization for this position.


 

Benefits:

As an Associate, you’ll enjoy our Total Rewards Program* to help secure your financial future and preserve your health and well-being, including:

  • Premier Medical, Dental and Vision Insurance with no waiting period**
  • Paid Vacation, Sick and Parental Leave
  • 401(k) Plan
  • Tuition Assistance
  • Paid Training and Licensures

*Benefits may be different by location.  Benefit eligibility requirements vary and may include length of service.

**Coverage begins on the date of hire. Must enroll in New Hire Benefits within 30 days of the date of hire for coverage to take effect.

The equal employment opportunity policy of the GEICO Companies provides for a fair and equal employment opportunity for all associates and job applicants regardless of race, color, religious creed, national origin, ancestry, age, gender, pregnancy, sexual orientation, gender identity, marital status, familial status, disability or genetic information, in compliance with applicable federal, state and local law. GEICO hires and promotes individuals solely on the basis of their qualifications for the job to be filled.

GEICO reasonably accommodates qualified individuals with disabilities to enable them to receive equal employment opportunity and/or perform the essential functions of the job, unless the accommodation would impose an undue hardship to the Company. This applies to all applicants and associates. GEICO also provides a work environment in which each associate is able to be productive and work to the best of their ability. We do not condone or tolerate an atmosphere of intimidation or harassment. We expect and require the cooperation of all associates in maintaining an atmosphere free from discrimination and harassment with mutual respect by and for all associates and applicants.

Apply

Job Profile

Regions

North America

Countries

United States

Restrictions

Hybrid

Benefits/Perks

Dental Health and well-being Hybrid work Medical Paid training Paid Training and Licensures Paid Vacation Parental leave Total Rewards Program Tuition Assistance Vision Vision Insurance

Tasks
  • Automation
  • Conduct advanced research
  • Conduct research and develop proofs of concept
  • Design
  • Design and implement security solutions
  • Develop proofs of concept
  • Implementation
  • Lead cybersecurity initiatives
  • Mentor peers
  • Mentor team members
  • Provide technical leadership
  • Systems architecture
Skills

Application Performance Application performance monitoring Applications Architecture Asset Discovery Automation AWS Azure Building C CI/CD Cloud Cloud Architecture Collaboration Compliance CVEs Cybersecurity Cyber Security Data-intensive systems Data Pipeline Deployment Design Design Patterns DevOps DevOps Concepts DevSecOps Distributed Systems Engineering External Scans Full-stack development GCP Go Hybrid Environments Java Large-scale distributed systems Leadership Management Monitoring Monitoring tools On-Prem Operations Performance Performance assessments Performance monitoring Python Reliability Reporting Resiliency Risk-based Assessment Scripting Scripting Languages Secure Infrastructure Security Security Best Practices Security Data Pipeline Security measures Security solutions Security Technologies Security Tools Software Development Software Engineering System design Systems architecture Technical Leadership Vulnerability Management

Experience

5 years

Education

Computer Science Engineering Equivalent Equivalent Education Information Systems Work experience

Certifications

CISSP Cloud

Timezones

America/Anchorage America/Chicago America/Denver America/Los_Angeles America/New_York Pacific/Honolulu UTC-10 UTC-5 UTC-6 UTC-7 UTC-8 UTC-9