Staff Software Engineer, Vulnerability Management

GEICO GEICO · Insurance · Bethesda, MD +3

Staff Software Engineer role focused on Vulnerability Management within GEICO, requiring expertise in full-stack development, cybersecurity, DevSecOps, and building scalable systems in hybrid cloud environments. The role involves technical leadership, designing and implementing security solutions, automation, and mentoring.

What you'd actually do

  1. Provide technical leadership for cybersecurity program strategy, software development, integration decisions, analyzing design constraints and trade-offs in system and security design
  2. Lead design, development, and delivery of security solutions to drive Vulnerability Management initiatives.
  3. Deliver automation initiatives, conduct advanced research, and develop proofs of concept to enhance our security capabilities and improve overall efficiency
  4. Achieve security business outcomes through force multiplication
  5. Develop, integrate, and maintain multilevel cybersecurity designs, architectures, policies, and procedures

Skills

Required

  • full-stack software development
  • DevSecOps experience
  • hybrid environment (AWS, Azure, on-prem)
  • Cybersecurity domain development and leadership
  • Vulnerability Management Engineering
  • Java, Go, Python or C#
  • scripting language
  • building data intensive large-scale distributed systems on cloud
  • architecture and design of new and current systems
  • DevOps concepts and best practices
  • CI/CD pipelines
  • infrastructure as a code
  • application performance monitoring tools
  • performance assessments
  • design, implement, deploy, and operate systems to solve complex security problems
  • industry-standard security tools, frameworks, and best practices
  • MITRE
  • CIS
  • NIST
  • working with auditors and demonstrating security controls
  • 8+ years of non-internship professional software engineering experience
  • 4+ years of experience with architecture and design in a tech lead role
  • 4+ years of experience with AWS, GCP, Azure, or other cloud providers
  • 3+ years of experience in open-source frameworks
  • Foundational knowledge of security best practices for system design and development
  • building applications for security domain

Nice to have

  • assessing security vulnerabilities and driving their remediation
  • Professional security certification (e.g., CISSP, CCSP, CSSLP)

What the JD emphasized

  • deep technical expertise
  • proven track record
  • Vulnerability Management Lifecycle
  • asset discovery
  • internal/external scans
  • contextualization and risk-based assessment
  • triaging of CVEs
  • detection authoring
  • security data pipeline
  • reporting
  • remediation
  • secure design guidance
  • security best practices