Staff Engineer - Product Security

GEICO GEICO · Insurance · Seattle, WA +3

Staff Engineer focused on Product Security Tools, leading and supporting application security in hybrid, multi-cloud environments. Responsibilities include managing vendor/open-source security tools (SAST, DAST, SCA, container scanning), integrating them with CI/CD pipelines (GitHub Enterprise, Azure DevOps), and building automations to enhance security coverage and prioritize critical vulnerabilities. The role requires collaboration with development teams to ensure secure coding practices and staying updated on security threats.

What you'd actually do

  1. Own managing our vendor/open source tooling, integrating functionality across multiple technology platforms such as GitHub Enteprise and Azure DevOps
  2. Build out applications and automations to reach our team goals, better integrate across the Tech platforms, and focus on prioritizing the most critical vulns/findings engineering teams should fix
  3. Develop and implement security policies and procedures
  4. Collaborate with development teams to ensure secure coding practices are followed
  5. Stay up to date with the latest security threats and trends

Skills

Required

  • CI/CD pipeline experience
  • ADO pipelines & GitHub Actions
  • Java
  • Python
  • Golang
  • vulnerability scanners
  • static code scanning tools
  • web application security
  • application development life cycle methodologies
  • vendor tools deployed in an enterprise environment
  • OWASP Top 10
  • NIST CSF
  • PCI-DSS

Nice to have

  • Cosmos
  • SQL
  • MySQL
  • MongoDB
  • waterfall
  • rapid prototyping
  • incremental
  • DevOps

What the JD emphasized

  • required for this role