This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
GEICO is seeking an experienced Staff Engineer with a passion for building high performance, low maintenance, zero-downtime platforms, and applications. You will help drive our insurance business transformation as we transition from a traditional IT model to a tech organization with engineering excellence as its mission, while co-creating the culture of psychological safety and continuous improvement. The Platform and Tools - VMs team is dedicated to realizing a secure, reliable, scalable, and highly efficient next-generation virtual machine lifecycle management and orchestration platform running on Kubernetes. This role sits at the intersection of security engineering, platform engineering, and software development, and includes meaningful overlap with configuration management work.
Job Responsibility:
Define the technical roadmap for vulnerability management and patch automation platforms
Establish standards, patterns, and paved roads for scanning, triage, remediation, and verification
Mentor engineers across Security and Platform teams on software and systems design best practices
Drive design reviews, architecture decisions, and quality gates for reliability and security
Design and implement services for asset/CMDB enrichment, risk scoring, and intelligent targeting
Build controllers/schedulers for maintenance windows, deployment rings/canaries, pre/post checks, automated backoff/rollback, and progressive delivery
Deliver self‑service CLIs/SDKs and internal UIs to request, schedule, and track remediation
Implement idempotent, policy‑driven workflows for patching and baseline enforcement across Windows and Linux
Integrate with image pipelines to shift‑left patching and hardening
Integrate scanner data and external intel into unified pipelines
Build prioritization engines that combine exploitability, exposure, and business context
Operate and automate patch tooling and package managers with safety guardrails
Enforce CIS Level 1 hardening via policy and code with drift detection
Integrate with CMDB and ITSM/ticketing for change control, approvals, and auditability
Provide APIs/webhooks and event streams for downstream consumers
Publish reusable modules, reference implementations, and runbooks
Define and track SLOs for patch compliance, time‑to‑remediate, change success rate
Implement observability, health checks, and alerting across the platform
Ensure resilience through canaries, rate limiting, circuit breakers, retries
Establish disaster recovery strategies and conduct game days/chaos testing
Maintain compliance with security and regulatory requirements
Troubleshoot and resolve complex issues
fulfill on‑call responsibilities
Requirements:
Strong software engineering background building production services and tooling (Python or Go preferred
TypeScript a plus)
Deep knowledge of Linux and Windows Server administration and patching in enterprise environments
Hands‑on experience with vulnerability scanners and their APIs (Tenable/Nessus, Qualys, Rapid7) and risk models (CVSS, KEV, EPSS)
Proficiency with configuration management and IaC (Ansible/Puppet/Chef/Salt
Terraform/Pulumi/Crossplane, Helm/Kustomize)
Experience with event‑driven and batch data pipelines (e.g., Kafka/SNS/SQS/PubSub), relational data stores, and caching
Familiarity with cloud (AWS/Azure/GCP), containers/Kubernetes, and image pipelines (e.g., Packer)
Solid understanding of authN/authZ, secrets management, and least‑privilege access for platforms and automation
Excellence in observability and reliability practices (OpenTelemetry/Prometheus/Grafana) with an SLO mindset
Strong documentation, communication, and stakeholder management skills
8+ years of professional software or platform engineering experience, including building and operating automation at scale
6+ years administering or engineering for Windows and/or Linux in enterprise environments
4+ years integrating vulnerability scanners and/or building remediation workflows and platforms
3+ years implementing configuration management or hardening frameworks (CIS, STIG) via policy/code
Demonstrated leadership driving cross‑team adoption and measurable risk reduction
4+ years of hands-on experience with Azure, OpenStack, AWS, GCP, or other cloud services
2+ years working with open-source frameworks
Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or equivalent experience
What we offer:
Comprehensive Total Rewards program
401K savings plan with 6% match
performance and recognition-based incentives
tuition assistance
mental healthcare
fertility and adoption assistance
workplace flexibility
GEICO Flex program (work from anywhere in the US for up to four weeks per year)