CrawlJobs Logo

Senior Staff Security Engineer – Vulnerability Management

geico.com Logo

Geico

Location Icon

Location:
United States , Chevy Chase

Category Icon

Job Type Icon

Contract Type:
Not provided

Salary Icon

Salary:

130000.00 - 260000.00 USD / Year

Job Description:

GEICO is seeking a highly experienced Senior Staff Security Engineer to lead the strategy, architecture, and technical execution of Vulnerability Management across a complex, hybrid technology ecosystem. This role blends deep security engineering expertise with strong architectural leadership and the ability to influence engineering practices at scale. You will drive the organization’s vulnerability lifecycle maturity, champion security‑by‑design, and elevate the skills and effectiveness of engineers across multiple teams. This is a high‑impact technical role who maintains a strong connection with both customers and underlying systems for shaping the company’s vulnerability management maturity, influencing engineering culture, and safeguarding critical systems. The Senior Staff Security Engineer will drive meaningful, measurable improvements to security posture while enabling teams to build and ship technology with confidence. They demonstrate a keen ability to dive deep into complex problems to fully understand how systems operate, discerning when to make incremental improvements and when to challenge the status quo to drive impactful results. They are well-versed with Vulnerability Management Lifecycle - asset discovery, internal/external scans, contextualization and risk-based assessment, triaging of CVEs, detection authoring, security data pipeline, reporting, and remediation. This role is an advisor to the Sr Director and is critical to our cybersecurity objectives. The position requires a strong security and engineering background. The successful candidate will play a key role in maintaining a strong security posture for the company through close collaboration with infrastructure, development, product, and other organizations across GEICO to integrate security into the ecosystem from design through deployment to sustainable operations.

Job Responsibility:

  • Lead the full vulnerability lifecycle: discovery, validation, risk analysis, prioritization, and remediation measurement
  • Leverage business contextualization, underlying systems, and threat intelligence to perform risk assessment for identifying true risk to drive remediation
  • Build integrations among scanning tools, asset inventory, CMDBs, ticketing, CI/CD, and monitoring pipelines to streamline workflows
  • Evaluate, test, and implement emerging tools and technologies that advance VM automation and intelligence
  • Design automation to reduce manual work, increase accuracy, and accelerate remediation
  • Generate data‑driven insights that help teams understand, prioritize, and resolve vulnerabilities efficiently
  • Collaborate with cloud, infrastructure, DevOps, and product engineering groups to integrate vulnerability management into pipelines and delivery workflows
  • Work closely with risk, compliance, governance, and incident response teams to ensure alignment with organizational and regulatory standards
  • Communicate vulnerability trends, risk implications, and remediation strategies to technical and non‑technical stakeholders
  • Define KPIs, SLAs, dashboards, and reporting models to drive accountability and measurable vulnerability reduction
  • Establish repeatable processes, playbooks, and workflows that ensure consistent VM operations across teams and environments
  • Ensure the reliability, performance, and scalability of VM tools and data pipelines
  • Mentor junior and mid‑level engineers, offering guidance on advanced security concepts, engineering best practices, and career development
  • Serve as a multiplier by elevating skillsets across teams through coaching, pairing, design reviews, and knowledge‑sharing
  • Influence architecture and engineering leadership with clear communication, strong decision‑making, and the ability to simplify complex security issues

Requirements:

  • 8+ years of experience in cybersecurity or security engineering roles
  • Deep expertise with vulnerability management tools, methodologies, and industry standards
  • Hands‑on experience with modern infrastructure, cloud services (AWS/Azure/GCP), container platforms, and operating systems
  • Proficiency with a modern programming language (Python, Go, Java, etc.) and scripting for automation at scale
  • Strong understanding of security architecture, networking, operating systems, identity, and cloud services
  • Proven ability to lead, mentor, and inspire engineers across multiple teams
  • Strong communication skills with the ability to influence senior stakeholders and translate complex risks into actionable guidance
  • Hands-on experience implementing cybersecurity frameworks e.g. NIST CSF
  • Hands-on experience with leading compliance initiatives to meet e.g. PCI, SOX, NYDFS, etc.
  • Bachelor’s degree in computer science, Cyber Security, or equivalent education with relevant work experience

Nice to have:

  • Exposure to comprehensive security assessment, penetration testing, threat modeling, or security research
  • Familiarity with SIEM, SOAR, and asset intelligence integrations
  • Security certifications (CISSP, GCSA, OSCP, cloud security certs) are a plus
  • Experience embedding security controls into CI/CD pipelines and DevSecOps workflows
What we offer:
  • Comprehensive Total Rewards program that offers personalized coverage tailor-made for you and your family’s overall well-being
  • Financial benefits including market-competitive compensation
  • a 401K savings plan vested from day one that offers a 6% match
  • performance and recognition-based incentives
  • and tuition assistance
  • Access to additional benefits like mental healthcare as well as fertility and adoption assistance
  • Supports flexibility- We provide workplace flexibility as well as our GEICO Flex program, which offers the ability to work from anywhere in the US for up to four weeks per year

Additional Information:

Job Posted:
February 21, 2026

Employment Type:
Fulltime
Work Type:
Hybrid work
Job Link Share:

Looking for more opportunities? Search for other job offers that match your skills and interests.

Briefcase Icon

Similar Jobs for Senior Staff Security Engineer – Vulnerability Management

Information Security Risk Lead

The Information Security Risk Lead is responsible for driving efforts to support...
Location
Location
Thailand , Bangkok
Salary
Salary:
Not provided
https://www.citi.com/ Logo
Citi
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Master’s/Bachelor’s/University degree or equivalent experience in Computer Science, Cyber Security, Computer/Information Engineering, Information Technology or a related discipline is preferred
  • One or more industry-recognized cybersecurity-related certifications such as CISSP, CISA, CISM, CRISC, ISO 27001
  • 6 - 10 years or above of relevant experience in Cyber Security Management / Cyber Security Operations / Technology Risk Management / Third-party Risk Management or IT Audit, preferably with experience gained from banking / finance services industry / consultancy / control compliance or legal disciplines
  • Experience in assessing cyber regulatory compliance from BOT, SEC etc.
  • Strong understanding of International Standards/Frameworks such as: NIST, ISO 27001series, COBIT, CIS, GDPR, DORA, etc.
  • Proficient in interpreting and applying policies, standards and procedures
  • Excellent project management and organizational skills (PMP, PRINCE2, etc. is a plus)
  • Strong consultation, reporting writing and communication skills with highly proficiency in both spoken and written English and Thai
  • Thai language fluency is a must.
Job Responsibility
Job Responsibility
  • Manage and validate deliverables of all Information Security (IS) programs, ensuring closure per agreed timelines and goals
  • Engagement with local regulators BOT, SEC, TB-CERT, Thai-CERT, MDES, NCSA, etc. on IS related matters
  • Manage regulatory exams and internal & external audits
  • Work closely with Global & Regional Information Security teams to improve processes and reduce risk, and support the IS regulatory related activities for Thailand
  • Manage internal/external resources to organize cyber-attack simulations exercise, coordinating and overseeing vulnerability, mitigation/remediation/correction action plans, and issues management process
  • Accountable for delivery of the associated remediation from regulatory assessments
  • Proficiency in preparing periodic updates / reports / presentation deck for both internal stakeholders and regulators
  • Provide timely and appropriate updates to regional and global stakeholders
  • escalate issues in a timely manner to senior management
  • Build and develop partnerships with business, IT, risk, compliance, IS, senior management staff and stakeholders
  • Fulltime
Read More
Arrow Right

Head of Physical Security

Develop and execute the bank's comprehensive Physical Security Strategy and poli...
Location
Location
Egypt , Cairo, New Cairo
Salary
Salary:
Not provided
ethicshr.com Logo
Ethics HR
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor’s degree in Security Management, Engineering, or a related field from a reputable university
  • Minimum of 15 years of experience in physical security, facilities security, or corporate security, with at least 5 years in a senior leadership role within banking, financial services, or critical infrastructure environments
  • Strong knowledge of CBE physical security guidelines, Egyptian safety and security regulations, and international security standards
  • Proven experience in securing bank branches, cash centers, data centers, and head office facilities
  • Hands-on experience with access control, CCTV, intrusion detection, and physical security technologies
  • Demonstrated ability to manage security vendors, guard forces, and large operational security teams
  • Strong incident management, crisis response, and investigation skills
  • Excellent leadership, decision-making, and stakeholder coordination abilities
  • High integrity, discipline, and ability to operate under pressure in high-risk scenarios
  • Ability to work effectively in a fast-paced, start-up, or transformation environment
Job Responsibility
Job Responsibility
  • Develop and execute the bank's comprehensive Physical Security Strategy and policy framework from the establishment phase onward
  • Oversee the design, procurement, and deployment of all physical security systems (CCTV, access control, alarms, fire suppression, perimeter control) for all corporate and technical facilities
  • Establish and manage security operations center (SOC) protocols for monitoring, dispatch, and response to physical threats, emergencies, and intrusions
  • Coordinate with external security providers and law enforcement agencies in Cairo/Egypt as required for investigations and incident response
  • Manage personnel security measures, including employee safety programs, visitor management, and executive protection protocols
  • Conduct regular physical security risk assessments and vulnerability tests of all bank locations, including data centers and infrastructure facilities
  • Ensure strict compliance with local Egyptian security standards, labor laws related to safety, and CBE requirements regarding physical protection of bank assets and premises
  • Oversee the integration of physical security protocols with Business Continuity Planning (BCP) and Disaster Recovery (DR) procedures
  • Manage the security budget, vendor relationships, and maintenance of all physical security hardware and software
  • Lead and manage the physical security team and/or contracted security staff
Read More
Arrow Right

Wealth technology Risk and compliance lead

Wealth technology Risk and compliance lead in India to oversee all tech mandator...
Location
Location
India , Chennai; Pune
Salary
Salary:
Not provided
https://www.citi.com/ Logo
Citi
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 15+ years of relevant experience
  • 8-10+ years of managerial experience
  • Strong technical background is a must
  • Risk and compliance background would be a good addition
  • Previous experience facing audits and regulators
  • PMP Certification, MBA, Specific to business Licenses and other
  • Experience with financial products
  • Working knowledge of the industry and competitors’ products and services
  • Advanced knowledge of strategic direction of the function within relevant part of the business
  • Proficient computer skills with a focus on Microsoft Office applications
Job Responsibility
Job Responsibility
  • S&S lead in India to oversee all tech mandatory book of work and to keep the risk and compliance dashboards in green and healthy state
  • Lead all the squads that are responsible for the tech risk and cyber security risks
  • Responsible for the ownership of all issues and Corrective action plans remediations across wealth technology
  • Lead all initiatives that impacts critical tech upgrades across wealth
  • Tech Risk & Cybersecurity - Lead tech risk remediation and manage cybersecurity vulnerabilities across the domain
  • Oversee technology solutions from design to implementation including third party reviews and vulnerability assessments
  • Manage technology batches upgrades and security protocols aligned with cyber security standards and modern tech stacks
  • Stakeholder & Solution Management – Collaborate closely with senior stakeholders and regulators to manage expectations and deliver technology programs
  • Work closely with all CTI and CISo partners to accelerate the process and governance around tech risk and compliance
  • Risk mitigation & Compliance – Assess and manage wealth tech risk ensuring robust controls and regulatory compliance
  • Fulltime
Read More
Arrow Right

Information Security Engineering and Architecture Engineer III

The Information Security (InfoSec) Engineering and Architecture (ISEA) Engineer ...
Location
Location
United States , Los Angeles
Salary
Salary:
121056.00 - 199742.00 USD / Year
lacare.org Logo
L.A. Care Health Plan
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor's Degree in Science or Technology
  • At least 6 years of experience in a senior Information Security role
  • Operational experience configuring and managing a Security Information and Event Management (SIEM) platform
  • Operational experience using and configuring a vulnerability management platform
  • Operational experience using a static application security testing platform
  • Operational experience assessing and securing cloud computing environments (e.g., AWS, Azure, etc.)
  • Strong working knowledge in one or more of the following disciplines: DevOps, Digital Forensics, Penetration Testing, Programming (Java preferred), and/or System or Network Administration
  • Working knowledge of data loss prevention (DLP) toolsets
  • Strong understanding of networking and communication protocols (such as TCP/IP, UDP, SSL/TLS, IPSEC, HTTP/S, etc.)
  • Understanding of web service frameworks and service architectures (such as event-driven, service-oriented, or server less architectures)
Job Responsibility
Job Responsibility
  • Ensures all InfoSec tools are configured appropriately and running at their current supported versions
  • Proactively develops and enforces security plans and standards
  • Interfaces directly with technical and business staff to design and implement security architectures
  • Develops systems and processes to prevent information and infrastructure breaches
  • Designs and implements elegant solutions to complex security and risk problems
  • Applies appropriate technologies while following security engineering best practices
  • Conducts research to identify attack vectors
  • Identifies and assesses vulnerabilities and risks
  • Develops and implements technical solutions to counter vulnerabilities and risks
  • Develops plans for incident response
What we offer
What we offer
  • Paid Time Off (PTO)
  • Tuition Reimbursement
  • Retirement Plans
  • Medical, Dental and Vision
  • Wellness Program
  • Volunteer Time Off (VTO)
  • Fulltime
Read More
Arrow Right

FX Applications Support Senior Analyst

As an FX Application Support Analyst, you will play a key role in running and ma...
Location
Location
Australia , Sydney
Salary
Salary:
Not provided
https://www.citi.com/ Logo
Citi
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 5-8 years’ experience in an Application Support role
  • experience installing, configuring or supporting business applications
  • experience with some programming languages and willingness/ability to learn
  • advanced execution capabilities and ability to adjust quickly to changes and re-prioritization
  • effective written and verbal communications including ability to explain technical issues in simple terms that non-IT staff can understand
  • demonstrated analytical skills
  • issue tracking and reporting using tools
  • knowledge/experience of problem management tools
  • good all-round technical skills
  • ability to effectively share information with other support team members and with other technology teams
Job Responsibility
Job Responsibility
  • provides technical and business support for users of Citi Applications
  • maintains application systems that have completed development stage and are running in daily operations
  • manages, maintains and supports applications and their operating environments, focusing on stability, quality and functionality
  • start of day checks, continuous monitoring, and regional handover
  • perform same day risk reconciliations
  • develop and maintain technical support documentation
  • identifies ways to maximize potential of applications used
  • assess risk and impact of production issues and escalate to business and technology management
  • ensures storage and archiving procedures are in place and functioning correctly
  • formulates and defines scope and objectives for complex application enhancements and problem resolution
What we offer
What we offer
  • rewarding work in a supportive environment
  • clear opportunities for progression
  • exciting company benefits
  • diverse team of professionals
  • global network of people, data and relationships
  • Fulltime
Read More
Arrow Right

Staff Platform Security Engineer

Fivetran is building data pipelines to power the modern data stack for thousands...
Location
Location
United States , Oakland
Salary
Salary:
196033.00 - 245041.50 USD / Year
fivetran.com Logo
Fivetran
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Application Security Expertise: Deep expertise in identifying and mitigating security vulnerabilities within applications (e.g., OWASP Top 10), particularly in Java codebases.
  • Secure SDLC: Extensive experience integrating security into the software development lifecycle, from design and code review to testing and deployment.
  • Java Proficiency: Senior-level experience with Java codebases: building, running, profiling, and optimizing Java applications in secure environments.
  • Container Security: Strong experience with Docker image creation, optimization, and vulnerability mitigation, specifically for applications.
  • CI/CD & Automation: Proficiency with CI/CD tools (e.g., Jenkins, GitLab CI, GitHub Actions) and experience integrating security tools into automated pipelines.
  • Tooling Familiarity: Familiarity with a range of security tools for CI/CD security, static analysis (SAST), dynamic analysis (DAST), dependency analysis (SCA), and secrets management.
  • Adversarial AI & Defense: Familiarity with modern attack techniques, offensive security methodologies, and defense strategies, including OWASP Top 10 for LLMs (e.g., Prompt Injection, Data Poisoning, and Model Inversion).
  • Scripting: Proficiency in scripting or programming languages (e.g., Bash, Python, Go) to automate security processes and tool integration.
  • Problem-Solving: Excellent problem-solving and troubleshooting skills, with the ability to work independently in fast-paced environments.
  • Communication: Strong communication skills with the ability to effectively collaborate with and educate engineering teams on security principles and best practices.
Job Responsibility
Job Responsibility
  • Collaborate with engineering teams to integrate and manage security tooling within the SDLC, strategically automating security checks and feedback loops to enhance efficiency and security posture.
  • Perform vulnerability scanning and participate in penetration testing exercises, automating scanning processes judiciously to identify common weaknesses, while reserving manual efforts for complex and nuanced assessments. Report findings and assist with remediation efforts.
  • Develop and maintain automation scripts and infrastructure-as-code for security checks related to machine configurations, container images, IAM policies, firewall rules, and cloud storage policies.
  • Implement and configure security controls within enterprise applications based on security best practices and architectural guidance.
  • Contribute to threat modeling efforts by providing technical insights and implementing identified security controls.
  • Work directly with engineering teams to troubleshoot and resolve security challenges across the stack while promoting a security-first mindset, identifying and automating recurring troubleshooting steps or remediation processes where it significantly improves response times and reduces manual intervention.
  • Implement and operationalize security solutions for cloud-native and hybrid infrastructure based on architectural guidelines.
  • Collaborate with infrastructure and cloud security teams to implement and maintain security controls across the entire technology stack, strategically prioritizing automation for consistent enforcement, monitoring, and alerting to improve overall security and reduce manual overhead.
  • Implement and manage security assessment tools, including vulnerability scanners, SIEM agents, DLP endpoints, and EDR sensors.
  • Participate in security assessment reviews by providing practical implementation feedback and identifying potential operational challenges.
What we offer
What we offer
  • 100% employer-paid medical insurance*
  • Generous paid time-off policy (PTO), plus paid sick time, inclusive parental leave policy, holidays, and volunteer days off
  • RSU stock grants*
  • Professional development and training opportunities
  • Company virtual happy hours, free food, and fun team-building activities
  • Monthly cell phone stipend
  • Access to an innovative mental health support platform that offers personalized care and resources in areas such as: therapy, coaching, and self-guided mindfulness exercises for all covered employees and their covered dependents.
  • Fulltime
Read More
Arrow Right

Staff Platform Security Engineer

Fivetran is building data pipelines to power the modern data stack for thousands...
Location
Location
United States , Denver
Salary
Salary:
171389.00 - 214236.00 USD / Year
fivetran.com Logo
Fivetran
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Application Security Expertise: Deep expertise in identifying and mitigating security vulnerabilities within applications (e.g., OWASP Top 10), particularly in Java codebases
  • Secure SDLC: Extensive experience integrating security into the software development lifecycle, from design and code review to testing and deployment
  • Java Proficiency: Senior-level experience with Java codebases: building, running, profiling, and optimizing Java applications in secure environments
  • Container Security: Strong experience with Docker image creation, optimization, and vulnerability mitigation, specifically for applications
  • CI/CD & Automation: Proficiency with CI/CD tools (e.g., Jenkins, GitLab CI, GitHub Actions) and experience integrating security tools into automated pipelines
  • Tooling Familiarity: Familiarity with a range of security tools for CI/CD security, static analysis (SAST), dynamic analysis (DAST), dependency analysis (SCA), and secrets management
  • Adversarial AI & Defense: Familiarity with modern attack techniques, offensive security methodologies, and defense strategies, including OWASP Top 10 for LLMs (e.g., Prompt Injection, Data Poisoning, and Model Inversion)
  • Scripting: Proficiency in scripting or programming languages (e.g., Bash, Python, Go) to automate security processes and tool integration
  • Problem-Solving: Excellent problem-solving and troubleshooting skills, with the ability to work independently in fast-paced environments
  • Communication: Strong communication skills with the ability to effectively collaborate with and educate engineering teams on security principles and best practices
Job Responsibility
Job Responsibility
  • Collaborate with engineering teams to integrate and manage security tooling within the SDLC, strategically automating security checks and feedback loops to enhance efficiency and security posture
  • Perform vulnerability scanning and participate in penetration testing exercises, automating scanning processes judiciously to identify common weaknesses, while reserving manual efforts for complex and nuanced assessments. Report findings and assist with remediation efforts
  • Develop and maintain automation scripts and infrastructure-as-code for security checks related to machine configurations, container images, IAM policies, firewall rules, and cloud storage policies
  • Implement and configure security controls within enterprise applications based on security best practices and architectural guidance
  • Contribute to threat modeling efforts by providing technical insights and implementing identified security controls
  • Work directly with engineering teams to troubleshoot and resolve security challenges across the stack while promoting a security-first mindset, identifying and automating recurring troubleshooting steps or remediation processes where it significantly improves response times and reduces manual intervention
  • Implement and operationalize security solutions for cloud-native and hybrid infrastructure based on architectural guidelines
  • Collaborate with infrastructure and cloud security teams to implement and maintain security controls across the entire technology stack, strategically prioritizing automation for consistent enforcement, monitoring, and alerting to improve overall security and reduce manual overhead
  • Implement and manage security assessment tools, including vulnerability scanners, SIEM agents, DLP endpoints, and EDR sensors
  • Participate in security assessment reviews by providing practical implementation feedback and identifying potential operational challenges
What we offer
What we offer
  • 100% employer-paid medical insurance*
  • Generous paid time-off policy (PTO), plus paid sick time, inclusive parental leave policy, holidays, and volunteer days off
  • RSU stock grants*
  • Professional development and training opportunities
  • Company virtual happy hours, free food, and fun team-building activities
  • Monthly cell phone stipend
  • Access to an innovative mental health support platform that offers personalized care and resources in areas such as: therapy, coaching, and self-guided mindfulness exercises for all covered employees and their covered dependents
  • Fulltime
Read More
Arrow Right

Senior Security Engineer, Security Operations

The senior security engineer role provides a unique opportunity to shape the sec...
Location
Location
United States , REMOTE; SAN FRANCISCO; ROSEVILLE; LEHI; WEST PALM BEACH; IRVINE
Salary
Salary:
146000.00 - 170000.00 USD / Year
goodleap.com Logo
GoodLeap
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Strong communicator with the ability to lead technical architecture discussions, drive technical decisions, and effectively communicate with non-technical audiences
  • Expertise in security event management, monitoring, threat hunting, incident response, playbook creation, orchestration/automations
  • Experience with threat modeling methodologies
  • Expertise with EDR solutions/platforms, such as CrowdStrike, S1, Palo Alto Cortex EDR
  • Experience with AWS services, including KMS, SST, Container Registry, ELBs, Lambda, API Gateway, CloudTrail, and IAM (knowledge of GCP and/or Azure is a plus)
  • Proven ability to establish credibility and build trust with business, engineers, and operational staff
  • Experience designing, configuring, and implementing security and fraud monitoring for core enterprise systems, e.g., ERP, HCM, Salesforce
  • Experience working with and creating solutions based AI and ML toolsets – e.g., creation of AI skills, agents, MCP clients, vibe coding
  • Strong understanding of both human and non-human identity management and common enterprise and consumer authentication standards and use cases
  • Practical experience with CI/CD pipelines and DevOps tools, including Infrastructure-as-Code (IaC) tools like Terraform, Pulumi, or CDK
Job Responsibility
Job Responsibility
  • Lead, participate in, and contribute to security and fraud monitoring, detection, and response activities, inclusive of investigations, threat hunting,etc. Create playbooks for specific incident response scenarios
  • Identify potential misuse and abuse cases in enterprise systems, propose solutions to detect these scenarios, and identify and implement monitoring and detection solutions for such scenarios
  • Support or develop components of the security analytics platform
  • Support embedded (product) security team
  • Support general security operations team with vulnerability management, tools management, and more
What we offer
What we offer
  • bonus
  • equity
  • Fulltime
Read More
Arrow Right