Staff Security Engineer – Cyber Governance & Automation

GEICO GEICO · Insurance · Bethesda, MD +3

Staff Security Engineer focused on Cyber Governance, Risk, and Compliance (GRC) automation. The role involves defining and delivering a roadmap for continuous control monitoring, evidence collection, and audit readiness across hybrid environments. It requires partnering with engineering teams to translate regulatory requirements into scalable automation capabilities and ensuring durable, outcome-driven products that demonstrate control effectiveness.

What you'd actually do

  1. Contribute to the vision, strategy, and roadmap for GEICO’s cyber governance automation capabilities, driving delivery through prioritized execution and continuous improvement.
  2. Define how policies, standards, regulatory frameworks, and technical controls are operationalized and continuously validated through automated evidence collection.
  3. Own governance automation platforms end‑to‑end as the system of record for control health, evidence, and audit readiness across cloud and on‑prem environments.
  4. Own end to end accountability for achieving near 100% automation coverage, including designing scalable on‑prem automation strategies and governing compensating controls where full automation is not feasible, while maintaining audit defensibility.
  5. Define and enforce governance standards for automation coverage targets, evidence SLAs, control performance metrics, and telemetry requirements.

Skills

Required

  • Cyber Governance, Risk, and Compliance (GRC) expertise
  • Automation strategy and implementation
  • Roadmap definition and execution
  • Continuous control monitoring
  • Evidence collection and validation
  • Audit readiness
  • Hybrid cloud and on-prem environments
  • Regulatory compliance (NYDFS, PCI DSS, NIST CSF, SOC, ISO)
  • Risk management
  • Product ownership
  • System of record definition
  • Scalability and sustainability
  • Integration principles and data standards
  • Explainability and auditability of AI capabilities

Nice to have

  • Experience with AI capabilities within governance platforms

What the JD emphasized

  • near 100% automation coverage
  • continuous control monitoring
  • scalable evidence collection
  • real-time audit readiness
  • regulatory requirements
  • enterprise risk priorities
  • control effectiveness
  • audit friction
  • automation coverage targets
  • evidence SLAs
  • control performance metrics
  • telemetry requirements
  • risk-based remediation lifecycle
  • remediation timelines
  • escalation paths
  • closure criteria
  • enforced SLAs
  • remediation scheduling frameworks
  • forward-looking visibility
  • upcoming deadlines
  • non-compliance
  • enforcement timelines
  • scalable workflows
  • transparent reporting
  • forecasting of remediation status
  • leadership
  • enterprise risk priorities
  • regulatory obligations
  • NYDFS
  • PCI DSS
  • NIST CSF
  • SOC
  • ISO
  • executive-level risk
  • remediation
  • audit-readiness reporting
  • explainability
  • auditability
  • regulatory expectations
  • platform challenges
  • reliable
  • sustainable
  • fit for purpose
  • source system adoption
  • integration feeding governance evidence
  • cloud
  • IAM
  • logging
  • asset inventory
  • Missing telemetry
  • Integration gaps
  • Inconsistent or unreliable data sources
  • standardized telemetry
  • data requirements
  • automated control quality assurance