Sr Staff Engineer - AI Security

GEICO GEICO · Insurance · Seattle, WA +3

Senior Staff Engineer focused on AI security, responsible for developing enterprise strategy, defining security requirements for AI and agentic applications, performing security assessments, threat modeling, and providing remediation guidance. The role involves integrating security into the product lifecycle for agentic enterprise and consumer applications.

What you'd actually do

  1. Work independently with developers, system/network engineers, product owners, and other engineers to ensure secure design, development, and implementation of AI and agentic based applications
  2. Drive AI Security strategy across GEICO
  3. Develop secure agentic development best practices standards and drive adoption across the developer community
  4. Define and document secure architecture patterns and anti-patterns
  5. Perform security architecture design reviews of our products including web applications, services, and mobile applications.

Skills

Required

  • AI security strategy
  • Secure design for AI and agentic applications
  • Threat modeling
  • Security assessments
  • Remediation guidance
  • Secure architecture patterns
  • OWASP Top 10
  • NIST SP800 Series
  • NIST CSF
  • FIPS 140-2
  • ISO 27001
  • PCI-DSS
  • Cloud security (Azure, AWS)
  • Encryption technologies
  • Authentication protocols
  • Application development lifecycle methodologies
  • SCA, DAST, SAST tools
  • Experience with programming languages like Go, Rust, Java, Python

Nice to have

  • Security+
  • CISSP
  • CSSLP
  • CISM

What the JD emphasized

  • Expert knowledge in AI and agentic applications, services, design patterns, and protocols
  • Hands-on AI product development experience, with strict SLA and SLR, using a mature S-SDLC.
  • Direct experience working with development teams to define, develop and document secure solutions
  • Experience breaking down complex systems and applications to find flaws with analysis and threat modeling
  • Strong familiarity with common vulnerabilities and attack vectors
  • Understanding and applied use of OWASP Top 10, NIST SP800 Series, NIST CSF, FIPS 140-2, ISO 27001, PCI-DSS, etc.

Other signals

  • AI security strategy
  • secure design for agentic applications
  • threat modeling
  • security assessments