Staff Engineer - Platform Security Engineering – Encryption and Tokenization

GEICO GEICO · Insurance · Bethesda, MD +3

Staff Engineer focused on designing, implementing, and maintaining an Encryption and Tokenization platform to protect sensitive data. Responsibilities include leading the development of cryptographic solutions, ensuring operational excellence, partnering with compliance teams, and mentoring other engineers. Requires strong understanding of cryptography, KMS, and secure software engineering practices, with experience in cloud environments and SRE.

What you'd actually do

  1. Lead the design, development, and evolution of encryption, tokenization, and key management solutions within a defined platform or product domain.
  2. Drive hands‑on implementation of secure data protection capabilities, contributing directly to production‑ready systems while setting technical direction for the team.
  3. Ensure the quality, reliability, and operational excellence of encryption and tokenization services, including high availability, disaster recovery, observability, and auditable logging.
  4. Partner closely with compliance, security, data governance, and application teams to ensure cryptographic solutions align with company policies and regulatory requirements.
  5. Contribute to architectural decisions by proposing scalable, resilient designs for key management systems and data protection workflows.

Skills

Required

  • Strong understanding of cryptographic encryption, tokenization, and Key Management Systems (KMS).
  • Experience designing and implementing secure, scalable solutions for data at rest encryption, using open-source cryptographic libraries and protocols (e.g., FPE, AEAD).
  • Strong software engineering skills, with experience building production grade services (Go preferred).
  • Working knowledge of key management technologies and libraries, such as Google Tink, PKCS#11, JCE, and OpenSSL.
  • Experience operating stateful systems such as PostgreSQL, including replication and reliability considerations.
  • Proven problem-solving skills with a security first mindset and proactive approach to risk mitigation.
  • Experience applying site reliability engineering (SRE) practices, including monitoring, alerting, and incident response (Grafana, Prometheus, Open Telemetry, eBPF).
  • Experience building and maintaining CI/CD pipelines and infrastructure as code (e.g., Bazel, Terraform, Argo CD/Workflows/Rollouts).
  • Strong communication skills, with the ability to explain technical concepts clearly to engineers and partner teams.
  • Familiarity with hardware security modules (HSMs) and cryptography standards.
  • 6+ years of experience in security or software engineering with a focus on encryption, tokenization, key management, or cryptography.
  • 3+ years of experience contributing to system design, architecture, and security focused solutions.
  • Experience working with opensource security or cryptography frameworks.
  • Experience building and operating systems in cloud environments (AWS, GCP, Azure preferred).

Nice to have

  • Go preferred

What the JD emphasized

  • encryption, tokenization, and Key Management Systems (KMS)
  • data at rest encryption
  • key management technologies and libraries
  • hardware security modules (HSMs) and cryptography standards
  • encryption, tokenization, key management, or cryptography