Full-Time

Distinguished Engineer

Application Security

Posted on 9/18/2024

Geico

Geico

10,001+ employees

Direct-to-consumer auto and home insurance

Financial Services

Compensation Overview

$130k - $300kAnnually

Senior, Expert

No H1B Sponsorship

Bethesda, MD, USA

Category
Cybersecurity
IT & Security
Required Skills
Microsoft Azure
Agile
Python
Java
AWS
Development Operations (DevOps)
Requirements
  • Direct experience working with senior leadership development teams, and architects to define secure solutions
  • Experience breaking down complex systems and applications to find flaws with analysis and threat modeling
  • Expert familiarity with common vulnerabilities and attack vectors
  • Extensive experience with web service technologies, load balancer services (i.e., Nginx, Cloudflare, F5, etc.) and RESTful APIs
  • Knowledge of and experience with ubiquitous encryption technologies (PGP, SSH, SSL, etc.) and common authentication protocols (OpenID Connect, OAUTH, SAML, RADIUS, LDAP, KERBEROS, etc.)
  • Solid understanding of secure network, system, and service design in cloud (Azure, AWS etc.) and conventional environments
  • Deep experience with applied use of OWASP Top 10, NIST SP800 Series, NIST CSF, FIPS 140-2, ISO 27001, PCI-DSS, etc.
  • Expert understanding and knowledge of application development life cycle methodologies (such as waterfall, spiral, agile software development, rapid prototyping, incremental, synchronize and stabilize, and DevOps/ SecDevOps)
  • Experience with diverse security technologies, platforms, and processing environments
  • Strong command of strategic and emerging security/ cloud technology trends, and the practical application of existing and emerging technologies to new and evolving business and operating models.
  • Expert understanding of product management, agile principles and development methodologies and capability of supporting agile teams by providing advice and guidance on opportunities, impact, and risks, taking account of technical and architectural debt
  • Experience collaborating and partnering closely with senior executives on strategic initiatives
  • An extensive background integrating security testing into the SDLC
  • Experience providing security training to developers
  • Ability to find security defects within programming languages such as Go, Java, Python, Object C
  • Demonstrated expertise using DAST and SAST tools and services and implementing effective remediation roadmaps.
  • One or more of the following Cybersecurity certifications are highly desired: Security+, Certified Information System Security Professional (CISSP) or Certified Information Security Manager (CISM)
Responsibilities
  • Work independently with executives, senior leadership, developers, system/network engineers, product owners, and other distinguished engineers to ensure secure design, development, and implementation of applications and services.
  • Define strategic roadmaps for secure architecture patterns and anti-patterns with quantitative approaches.
  • Define security best practices and standards and partner with Product Development teams and their leadership to implement them.
  • Be accountable for Application Security technical strategy and roadmaps.
  • Serve as a technical advisor and consultant to colleagues and GEICO leadership on the implementation of the Cybersecurity application security policy and standards.
  • Provide technical thought leadership for integration decisions, analyzing design constraints and trade-offs in system and security design, and ensuring integrity of GEICO mission objectives, while protecting GEICO assets from cyber threats and vulnerabilities.
  • Work with Product Development teams to help prioritize and validate urgency of mitigation of identified product vulnerabilities and security feature enhancement requests.

GEICO provides a range of insurance products, with a primary focus on auto insurance. The company sells policies directly to consumers, which allows them to offer lower rates by eliminating intermediaries like brokers. Customers can obtain quotes, manage their policies, and file claims through GEICO's user-friendly website. In addition to auto insurance, GEICO also covers motorcycles, ATVs, RVs, and offers home and renters insurance. What sets GEICO apart from its competitors is its strong online presence and memorable advertising campaigns that enhance brand recognition and customer loyalty. The company's goal is to simplify the insurance process for its customers while providing competitive rates and comprehensive coverage options.

Company Stage

Acquired

Total Funding

N/A

Headquarters

Tulsa, Oklahoma

Founded

1936

Simplify Jobs

Simplify's Take

What believers are saying

  • Expansion into North Texas boosts GEICO's commercial insurance capabilities.
  • AI integration in claims processing reduces costs and improves operational efficiency.
  • Growing demand for cybersecurity insurance presents new product opportunities for GEICO.

What critics are saying

  • Regulatory scrutiny and penalties for data breaches may harm GEICO's reputation.
  • Departure of key marketing personnel could disrupt customer acquisition strategies.
  • Unresolved claims, like the stolen car case, may lead to negative publicity.

What makes Geico unique

  • GEICO's direct-to-consumer model offers competitive rates by eliminating intermediaries.
  • Strong online presence allows easy policy management and claims filing for customers.
  • Memorable advertising campaigns enhance brand recognition and customer loyalty.

Help us improve and share your feedback! Did you find this helpful?

INACTIVE