CrawlJobs Logo

Staff Software Engineer, Vulnerability Management

geico.com Logo

Geico

Location Icon

Location:
United States , Chevy Chase

Category Icon

Job Type Icon

Contract Type:
Not provided

Salary Icon

Salary:

115000.00 - 230000.00 USD / Year

Job Description:

GEICO is seeking an experienced full-stack engineer with a deep technical expertise and passion for building high-performance, low maintenance, zero-downtime, and highly scalable systems. The ideal candidate has a proven track record of design, development, and implementation of scalable solutions in hybrid environments using commercial and open-source products, preferably in Cybersecurity domain. This role will be responsible for leading enterprise initiatives and collaboration with cross-functional teams as well as designing and implementing secure and scalable solutions to drive Vulnerability Management initiatives. As a Staff Engineer, you’re not just a technical expert—you’re a lead, a problem solver, an innovator who thrives in a fast-paced, constantly evolving environment. You will turn complex security challenges into elegant, practical solutions while fostering collaboration across teams and stakeholders. You have exposure to Cybersecurity and Vulnerability Management Lifecycle - asset discovery, internal/external scans, contextualization and risk-based assessment, security data pipeline, reporting, and remediation. Staff Engineer works closely with infrastructure, development, product, and other organizations across GEICO from design through deployment to sustainable operations. The Staff Engineer brings in expertise in requirements identification, feasibility analysis, system designs, technology evaluation and selection, development, unit/integration testing, deployment, and operation of scalable systems using CI/CD and DevSecOps to raise the bar on engineering excellence.

Job Responsibility:

  • Lead software design, development, and delivery of integrated systems to drive Vulnerability Management initiatives
  • Deliver automation initiatives, conduct advanced research, and develop proofs of concept to enhance our capabilities and improve overall efficiency
  • Achieve business outcomes through force multiplication
  • Develop, integrate, and maintain multilevel cybersecurity designs, architectures, policies, and procedures
  • Provide secure design guidance and recommendations to developers, infrastructure, and product engineers
  • Influence and educate partner teams to bring an engineering first approach to develop sustainable security systems
  • Mentor peers and team members in security technologies, enterprise solution design, deployment, and effective customer interaction
  • Provide motivating demonstrations and communications to show the value of our security measures to the business, highlighting the low impact on systems, improved operability and resiliency

Requirements:

  • Tech-lead with data engineering and software development experience in a hybrid environment (AWS, Azure, on-prem)
  • Proficiency in at least one modern programming language (Python, Java, Scala, Go) and deep experience building scalable production-grade data services, APIs, or ingestion frameworks
  • Expertise in designing, building, and operating large‑scale, resilient, and high‑performance data pipelines across distributed systems, with strong knowledge of ETL/ELT patterns, data orchestration, and data quality frameworks
  • Advanced proficiency in modern data storage and processing technologies, including SQL/NoSQL databases (e.g., PostgreSQL), query optimization, and data modeling for analytical and operational use cases
  • Hands‑on experience with reporting and analytics tools such as Power BI, Tableau, or equivalent, including developing semantic models, optimizing reporting datasets, and enabling business teams with curated data
  • Strong applied skills in distributed compute ecosystems (e.g., Spark or similar), and the ability to optimize workloads for performance, cost efficiency, and reliability
  • Extensive knowledge and experience of building data intensive large-scale distributed systems on cloud
  • Experience building the architecture and design of new and current systems (architecture, design patterns, reliability, and scaling)
  • Fluency in DevOps concepts and best practices in CI/CD pipelines and infrastructure as a code
  • Experience with application performance monitoring tools and performance assessments
  • Ability to design, implement, deploy, and operate systems to solve complex security problems in a fast-paced, startup-like environment
  • Development and leadership in Cybersecurity domain, preferably in Vulnerability Management Engineering
  • Strong knowledge of industry-standard security tools, frameworks, and best practices including MITRE, CIS and NIST
  • Experience working with auditors and demonstrating security controls
  • 8+ years of non-internship professional software and data engineering experience of building large-scale distributed systems
  • 4+ years of experience with architecture and design in a tech lead role
  • 4+ years of experience with building and operating high‑performance data pipelines across distributed systems, with strong knowledge of ETL/ELT patterns, asynchronous data ingestion, data orchestration, and data quality frameworks using SQL/NoSQL databases (e.g., PostgreSQL), Power BI, Tableau, or equivalent
  • 3+ years of experience in open-source frameworks
  • Foundational knowledge of security best practices for system design and development
  • Experience of building applications for security domain
  • Bachelor’s degree in Computer Science, Information Systems, Cyber Security, or equivalent education with work experience

Nice to have:

  • Experience of assessing security vulnerabilities and driving their remediation
  • Professional security certification (e.g., CISSP, CCSP, CSSLP)
What we offer:
  • Comprehensive Total Rewards program that offers personalized coverage tailor-made for you and your family’s overall well-being
  • Financial benefits including market-competitive compensation
  • a 401K savings plan vested from day one that offers a 6% match
  • performance and recognition-based incentives
  • and tuition assistance
  • Access to additional benefits like mental healthcare as well as fertility and adoption assistance
  • Supports flexibility- We provide workplace flexibility as well as our GEICO Flex program, which offers the ability to work from anywhere in the US for up to four weeks per year

Additional Information:

Job Posted:
February 21, 2026

Employment Type:
Fulltime
Work Type:
Hybrid work
Job Link Share:

Looking for more opportunities? Search for other job offers that match your skills and interests.

Briefcase Icon

Similar Jobs for Staff Software Engineer, Vulnerability Management

Staff Product Security Engineer

We’re looking for a Staff Product Security Engineer to lead the design and imple...
Location
Location
United States
Salary
Salary:
184000.00 - 252000.00 USD / Year
alpha-sense.com Logo
AlphaSense
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 7+ years of experience in product, application, or cloud security engineering
  • Deep understanding of secure SDLC, threat modeling, and secure architecture design
  • Proven expertise with AWS cloud security concepts and best practices
  • Strong experience with container security, orchestration, and runtime protection
  • Proficiency in Python, Java, and/or JavaScript for security automation, code review, and tooling
  • Experience securing AI/ML pipelines, data workflows, or model-serving infrastructure
  • Familiarity with DevSecOps and continuous integration/deployment environments
Job Responsibility
Job Responsibility
  • Embed robust security practices throughout the software and AI development lifecycle (SDLC)
  • Lead secure design reviews, threat modeling, and risk assessments for AI-driven products, APIs, and backend services
  • Partner with engineering and product teams to ensure security, privacy, and compliance by design
  • Build and maintain security automation and governance frameworks that integrate seamlessly into development workflows
  • Architect and enforce security controls for AI/ML systems, including model training, data pipelines, and inference environments
  • Identify and mitigate AI-specific attack vectors such as data poisoning, model inversion, prompt injection, and model theft
  • Collaborate with governance and compliance teams to align with ethical AI principles and frameworks like NIST AI RMF and the EU AI Act
  • Implement model provenance, integrity, and auditability controls to ensure responsible and secure AI operations
  • Partner with DevOps and SRE teams to secure service meshes, container networking, and secrets management
  • Drive software supply chain security, including artifact integrity, dependency management, and vulnerability reduction
What we offer
What we offer
  • Competitive compensation, benefits, and career growth opportunities
  • Opportunity to shape and drive product security strategy
  • Collaborative and security-minded engineering culture
  • Work on cutting-edge security challenges in a fast-growing company
  • Performance-based bonus, equity, and a generous benefits program
  • Fulltime
Read More
Arrow Right

Staff Product Security Engineer

As a Staff Product Security Engineer, you will play a crucial role in safeguardi...
Location
Location
France , Paris
Salary
Salary:
Not provided
dashlane.com Logo
Dashlane
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Strong understanding of application security best practices, including experience with threat modeling and risk assessments
  • Demonstrated experience building or improving an SDLC program
  • Familiarity with CI/CD pipelines and their security implications
  • Familiarity with cloud infrastructure (e.g., AWS, Azure, Kubernetes), and Infrastructure-as-Code (e.g., Terraform)
  • Interest in enabling secure use of AI tools to drive efficiency, creativity, and impact internally
  • Communication & Collaboration: You engage and listen empathetically to others, adjusting your communication style to fit the audience and message. You are experienced in communicating with technical and non-technical audiences
  • Mentoring: You enjoy using your knowledge and experience to support and uplevel those around you
  • Motivated Learner: You learn new technologies and processes quickly, and understand where to look for knowledge when you need it
  • Adaptability: You are a jack or jane of all trades - you’re comfortable digging into non-technical parts of the business to provide security support and guidance
Job Responsibility
Job Responsibility
  • Drive the continuous improvement of Dashlane’s security program across the product and company
  • Conduct architecture design reviews, threat modeling, and technical security assessments of Dashlane’s product (application and infrastructure) to identify security risks and provide mitigation guidance
  • Ensure security best practices are integrated throughout the software development lifecycle (SDLC)
  • Build upon and scale Vulnerability Management to ensure the team can track, analyze, and manage vulnerabilities and their remediation
  • Perform risk assessments of Dashlane’s internal systems, environments, assets, and data, and implement security best practices accordingly
  • Evaluate and implement security tooling and/or build customized tooling in-house where necessary
  • Participate in Compliance and Incident Response
  • Innovate and propose new forward-looking security features that protect Dashlane and our users
What we offer
What we offer
  • Equal Parental leave - regardless of gender, up to 20 weeks fully paid leave to take care of their new baby, within the first year of birth or adoption
  • Health insurance covered by Dashlane
  • Mentorship program - select your mentor from our internal pool and continue your learning path!
  • Commute allowance
  • Meal Vouchers (Swile)
  • Mental health services through Spring Health for you and family members
  • 4 extra days off (one per quarter) to acknowledge the importance of your wellbeing
  • Spot in daycare
  • Time off saving account
  • Donation matching program - give back to the community and support actions that lead to positive social impact under the historically marginalized communities. Every donation will be matched by Dashlane
  • Fulltime
Read More
Arrow Right

Staff Application Security Engineer

As a Staff Application Security Engineer at Culture Amp, you will play a pivotal...
Location
Location
Australia , Melbourne; Sydney
Salary
Salary:
Not provided
cultureamp.com Logo
Culture Amp
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Extensive experience in application security engineering, with a proven track record of leading security initiatives in SaaS or cloud-native environments
  • Deep technical expertise in secure software development, secure coding practices, and common security frameworks (e.g., OWASP Top 10, NIST, PCI, SOC 2)
  • Proficiency in multiple programming languages (e.g., Ruby, Python, JavaScript, Go) and experience with modern web application architectures and cloud platforms (e.g. AWS)
  • Strong knowledge of security automation, CI/CD integration, and DevSecOps practices
  • Experience designing and implementing security tools, frameworks, and processes that scale with developer velocity
  • Demonstrated ability to lead and influence cross-functional teams, drive change, and deliver results in ambiguous or complex environments
  • Excellent communication skills, with the ability to explain complex security concepts to technical and non-technical audiences
  • Experience mentoring and developing engineers, and a passion for building a culture of security and continuous improvement
  • Familiarity with security-related compliance requirements and standards relevant to SaaS businesses
Job Responsibility
Job Responsibility
  • Lead and drive the most complex and high-impact application security reviews, threat modeling, and risk assessments across our product portfolio, providing expert guidance and direction for other team members
  • Collaborate with engineering, product, and platform teams to embed security into the SDLC, including secure design, code review, and automated security testing (DevSecOps)
  • Develop and scale security automation, tools, and centralized libraries that enable developers to build secure applications efficiently and at scale
  • Proactively identify, assess, and address security risks and vulnerabilities in our SaaS environment, including cloud-native and microservices architectures
  • Own and evolve our vulnerability management programs, ensuring timely triage, remediation, and communication of security issues
  • Mentor and support engineers across the organization, fostering a culture of security awareness, knowledge sharing, and continuous learning
  • Influence and drive cross-functional security initiatives, partnering with compliance, privacy, and infrastructure teams to meet regulatory and customer requirements (e.g., SOC 2, ISO 27001, OWASP)
  • Stay current with the latest security threats, technologies, and best practices, and advocate for their adoption within Culture Amp
  • Represent Culture Amp’s security expertise internally and externally, including supporting customer security reviews and contributing to the broader security community
What we offer
What we offer
  • Employee Share Options Program
  • Programs, coaching, and budgets to help you thrive personally and professionally
  • Access to external providers for mental wellbeing and coaching support
  • Monthly Camper Life Allowance
  • Team budgets dedicated to team building activities and connection
  • Intentional quarterly wellbeing pauses
  • Extended year-end breaks
  • Excellent parental leave and in work support program available from day 1
  • 5 Social Impact Days a year
  • MacBooks for you to do your best & a work from home office budget
Read More
Arrow Right

Staff Application Security Engineer

As a Staff Application Security Engineer at Culture Amp, you will play a pivotal...
Location
Location
Australia , Sydney
Salary
Salary:
Not provided
cultureamp.com Logo
Culture Amp
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Extensive experience in application security engineering, with a proven track record of leading security initiatives in SaaS or cloud-native environments
  • Deep technical expertise in secure software development, secure coding practices, and common security frameworks (e.g., OWASP Top 10, NIST, PCI, SOC 2)
  • Proficiency in multiple programming languages (e.g., Ruby, Python, JavaScript, Go) and experience with modern web application architectures and cloud platforms (e.g. AWS)
  • Strong knowledge of security automation, CI/CD integration, and DevSecOps practices
  • Experience designing and implementing security tools, frameworks, and processes that scale with developer velocity
  • Demonstrated ability to lead and influence cross-functional teams, drive change, and deliver results in ambiguous or complex environments
  • Excellent communication skills, with the ability to explain complex security concepts to technical and non-technical audiences
  • Experience mentoring and developing engineers, and a passion for building a culture of security and continuous improvement
  • Familiarity with security-related compliance requirements and standards relevant to SaaS businesses
Job Responsibility
Job Responsibility
  • Lead and drive the most complex and high-impact application security reviews, threat modeling, and risk assessments across our product portfolio, providing expert guidance and direction for other team members
  • Collaborate with engineering, product, and platform teams to embed security into the SDLC, including secure design, code review, and automated security testing (DevSecOps)
  • Develop and scale security automation, tools, and centralized libraries that enable developers to build secure applications efficiently and at scale
  • Proactively identify, assess, and address security risks and vulnerabilities in our SaaS environment, including cloud-native and microservices architectures
  • Own and evolve our vulnerability management programs, ensuring timely triage, remediation, and communication of security issues
  • Mentor and support engineers across the organization, fostering a culture of security awareness, knowledge sharing, and continuous learning
  • Influence and drive cross-functional security initiatives, partnering with compliance, privacy, and infrastructure teams to meet regulatory and customer requirements (e.g., SOC 2, ISO 27001, OWASP)
  • Stay current with the latest security threats, technologies, and best practices, and advocate for their adoption within Culture Amp
  • Represent Culture Amp’s security expertise internally and externally, including supporting customer security reviews and contributing to the broader security community
What we offer
What we offer
  • Employee Share Options Program
  • Programs, coaching, and budgets to help you thrive personally and professionally
  • Access to external providers for mental wellbeing and coaching support
  • Monthly Camper Life Allowance
  • Team budgets dedicated to team building activities and connection
  • Intentional quarterly wellbeing pauses
  • Extended year-end breaks
  • Excellent parental leave and in work support program available from day 1
  • 5 Social Impact Days a year
  • MacBooks for you to do your best & a work from home office budget
  • Fulltime
Read More
Arrow Right

Staff Engineer – Vulnerability Management Automation

GEICO is seeking an experienced Staff Engineer with a passion for building high ...
Location
Location
United States , Chevy Chase; Palo Alto; Dallas; Seattle
Salary
Salary:
110000.00 - 230000.00 USD / Year
geico.com Logo
Geico
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Strong software engineering background building production services and tooling (Python or Go preferred
  • TypeScript a plus)
  • Deep knowledge of Linux and Windows Server administration and patching in enterprise environments
  • Hands‑on experience with vulnerability scanners and their APIs (Tenable/Nessus, Qualys, Rapid7) and risk models (CVSS, KEV, EPSS)
  • Proficiency with configuration management and IaC (Ansible/Puppet/Chef/Salt
  • Terraform/Pulumi/Crossplane, Helm/Kustomize)
  • Experience with event‑driven and batch data pipelines (e.g., Kafka/SNS/SQS/PubSub), relational data stores, and caching
  • Familiarity with cloud (AWS/Azure/GCP), containers/Kubernetes, and image pipelines (e.g., Packer)
  • Solid understanding of authN/authZ, secrets management, and least‑privilege access for platforms and automation
  • Excellence in observability and reliability practices (OpenTelemetry/Prometheus/Grafana) with an SLO mindset
Job Responsibility
Job Responsibility
  • Define the technical roadmap for vulnerability management and patch automation platforms
  • Establish standards, patterns, and paved roads for scanning, triage, remediation, and verification
  • Mentor engineers across Security and Platform teams on software and systems design best practices
  • Drive design reviews, architecture decisions, and quality gates for reliability and security
  • Design and implement services for asset/CMDB enrichment, risk scoring, and intelligent targeting
  • Build controllers/schedulers for maintenance windows, deployment rings/canaries, pre/post checks, automated backoff/rollback, and progressive delivery
  • Deliver self‑service CLIs/SDKs and internal UIs to request, schedule, and track remediation
  • Implement idempotent, policy‑driven workflows for patching and baseline enforcement across Windows and Linux
  • Integrate with image pipelines to shift‑left patching and hardening
  • Integrate scanner data and external intel into unified pipelines
What we offer
What we offer
  • Comprehensive Total Rewards program
  • 401K savings plan with 6% match
  • performance and recognition-based incentives
  • tuition assistance
  • mental healthcare
  • fertility and adoption assistance
  • workplace flexibility
  • GEICO Flex program (work from anywhere in the US for up to four weeks per year)
  • Fulltime
Read More
Arrow Right

Director of Threat Exposure Engineering

The Director of CTEM Development defines the technical vision and strategic dire...
Location
Location
United States , Philadelphia
Salary
Salary:
Not provided
comcastcorporation.com Logo
Comcast
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 10 - 15+ years of engineering leadership experience overseeing large, complex technical environments
  • Strong engineering background with deep understanding of development practices, SDLC, coding standards, and modern architecture
  • Ability to lead technical strategy, set engineering direction, and own platform roadmaps
  • Experience managing engineering teams of 15- 20+ people, including global and distributed teams
  • Skilled in people leadership, team development, performance management, and talent retention
  • Experience with scanning, discovery, configuration assessment, telemetry, and exposure validation platforms
  • Strong understanding of secure coding, CI/CD pipelines, automation, testing, observability, and reliability engineering
  • Broad familiarity with multiple programming languages and development methodologies
  • Proven ability to manage budgets, resource planning, forecasting, and operational execution
  • Experience collaborating across architecture, SDLC, product, and cybersecurity teams
Job Responsibility
Job Responsibility
  • Oversees engineering, operation, and continuous improvement of CTEM platforms, including scanning, discovery, configuration assessment, exposure validation, and telemetry
  • Leads the global engineering lifecycle, including architecture for distributed assessment engines, telemetry pipelines, detection logic, secure configuration evaluation, and adversarial validation workflows
  • Drives automation-first engineering and ensures excellence in CI/CD, secure coding, testing, observability, and reliability to deliver scalable and resilient platforms
  • Ensures CTEM platforms meet operational, reliability, scalability, and performance standards, while leading technical analysis to improve detection accuracy, discovery fidelity, telemetry quality, and overall exposure reduction
  • Owns the global CTEM roadmap, set engineering strategies, and define technical direction aligned with broader cybersecurity and business goals
  • Collaborates across internal teams—including SDLC, Security Architecture, and Product—to ensure interoperability and alignment with enterprise standards
  • Supports financial and operational planning, prepare and manage budgets, monitor forecasts and expenditures, and guide headcount strategy
  • Establishes reporting standards, track engineering progress, analyze costs, and use operational metrics to drive measurable outcomes
  • Manages vendors and partners
  • Leads globally distributed engineering teams, including managers and professional staff
What we offer
What we offer
  • Paid Time off
  • Physical Wellbeing benefits
  • Financial Wellbeing benefits
  • Emotional Wellbeing benefits
  • Life Events + Family Support benefits
  • Fulltime
Read More
Arrow Right

Operations & Security Manager

The SOC Manager is the designated leader responsible for the day-to-day manageme...
Location
Location
United States , Tallahassee
Salary
Salary:
Not provided
nttdata.com Logo
NTT DATA
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Master’s degree in engineering, information technology, or related field (or equivalent formal training and experience)
  • Minimum 10 years of overall experience, including at least 7 years in Information SPAA, cybersecurity, system administration, or engineering
  • At least 7 years as ISSO, security analyst, or security engineer with hands-on experience in: NIST Risk Management Framework (RMF)
  • audit log reviews
  • system monitoring
  • SPAA processes
  • FISMA requirements
  • vulnerability and compliance scanning
  • continuous monitoring
  • security testing and evaluation
Job Responsibility
Job Responsibility
  • Lead the design and implementation of complex IT security solutions, including Threat Management, Vulnerability Management, and Identity and Access Management
  • Evaluate security control compliance with federal and State of Florida requirements and client monitoring strategies
  • Develop and manage security standards for physical and virtual desktop environments
  • Identify and manage risks associated with information systems
  • Coordinate with the client’s Cybersecurity Unit to maintain compliance and Authorization to Operate (ATO)
  • Ensure secure operation, maintenance, and disposal of assigned assets and systems
  • Conduct annual assessments to ensure policy and standards compliance
  • Address security requirements throughout the system lifecycle
  • Establish and review audit trails and retain audit logs
  • Generate and interpret documentation for CSAM compliance
Read More
Arrow Right

Staff Software Engineer - CAD Infra Engineering

Dandy is hiring a Staff Software Engineer to join our rapidly scaling technology...
Location
Location
United States
Salary
Salary:
221000.00 - 268000.00 USD / Year
meetdandy.com Logo
Dandy
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 8+ years of software engineering experience, preferably in a high-growth startup environment
  • An expert in Google Cloud Platform and Google Kubernetes Engine
  • Experience with GPU infrastructure and maintaining cloud to client application test parity is strongly preferred
  • Experience in identifying and remediating security vulnerabilities within a cloud environment
  • Experience with building observability platforms (i.e., metrics, logging, and tracing)
  • Experience with infrastructure as code platforms (Terraform, Pulumi)
  • Experience designing the architecture and automation of infrastructure within a cloud environment
  • A collaborative, pragmatic, and growth-oriented mindset
  • The ability to clearly and concisely communicate about complex technical, architectural, and/or organizational problems and propose thorough iterative solutions
  • Experience with performance and optimization problems and a demonstrated ability to both diagnose and prevent these problems
Job Responsibility
Job Responsibility
  • Solve technical problems of the highest scope and complexity for your team
  • Collaborate with stakeholders within the tech org to influence the overall objectives and long-term goals of your team
  • Advocate for improvements to product quality, security, and performance that have a particular impact across your team and others
  • Develop and maintain infrastructure, systems, and tooling to support Dandy’s products in a secure, well-tested, and performant way
  • Reinvent an analog experience and disrupt a legacy industry through novel and scalable system design
  • Collaborate with Product Engineers and other stakeholders within Engineering, Product and Data to maintain a high bar for quality in a fast-paced, iterative environment
  • Advocate for improvements to infrastructure quality, security, and performance
  • Craft code that meets our internal standards for style, maintainability, and best practices
  • Recognize impediments to our efficiency as a team ("technical debt"), propose and implement solutions
What we offer
What we offer
  • Offers Equity
  • Offers Bonus
  • healthcare
  • dental
  • mental health support
  • parental planning resources
  • retirement savings options
  • generous paid time off
  • Fulltime
Read More
Arrow Right