Identity Security Distinguished Engineer

Posted Yesterday
Be an Early Applicant
4 Locations
In-Office
140K-300K Annually
Senior level
Insurance
The Role
Lead identity security engineering strategy across user, development, and production environments. Guide IAM architecture, privileged access management, threat detection, adversarial testing, compliance automation, and security-control validation. Mentor engineers, define identity security roadmaps, build automation and proofs of concept, collaborate with business and security leaders, and modernize protective controls using offensive and defensive security expertise.
Summary Generated by Built In

Why Join GEICO?

At GEICO, we offer a rewarding career where your ambitions are met with endless possibilities.

 

Every day we honor our iconic brand by offering quality coverage to millions of customers and being there when they need us most. We thrive on relentless innovation to exceed our customers' expectations while making a real impact on local communities nationwide.

 

Founded in 1936, GEICO is a member of the Berkshire Hathaway family of companies and one of the largest auto insurers in the United States. When you join our company, we want you to feel valued, supported, and proud to work here. That's why we offer the GEICO Pledge: Great Company, Great Culture, Great Rewards, and Great Careers.

GEICO is seeking an Identity Security Distinguished Engineer to provide security specific strategic and technical direction for our identity and access management solutions with our user, development and production domains. This individual will play a lead role within GEICO’s Cybersecurity team, with a focus on defensive and protective controls, compliance and governance automation and driving modernization in our identity strategy.

Our Distinguished Engineer will be the technical and engineering lead for a team of engineers who proactively and holistically deliver secure IAM configuration, threat detection, strategic partnership on the IAM roadmap and create automated proof and validation of our controls. You will help our business transformation as we transition from a traditional IT Security model to a tech organization with engineering excellence as its mission, while co-creating a culture of leveraging security to enable the business and protecting against the latest threats.

You will innovate and lead new initiatives, improve Security, enhance existing systems while also identifying new opportunities with an offensive security mindset to find critical problems and solve at a rapid pace. You will help lead the confirmation our systems are protected through automated testing and continuous improvement to raise the bar and foster a proactive security culture which also enables the business without impact. The ideal candidate has deep technical expertise in this domain and an attacker/defender adversarial background.

​​​As a Distinguished Engineer, you will: 

  • Influence and educate staff at all levels to bring a security minded approach to difficult challenges balancing usability and security.

  • Provide technical guidance and mentorship to the team, fostering a culture of innovation, collaboration, and continuous improvements.

  • Collaborate with cross-functional leaders, team members, IAM engineering, and peer security teams to solve complex problems with minimal business impact.

  • Proactively identify opportunities to enhance security measures, streamline processes, and optimize tooling to fortify our environment against emerging threats.

  • Deliver automation initiatives, conduct advanced research, and develop proofs of concept to enhance our security capabilities and improve overall efficiency.

  • Help develop and implement engineered automation to ensure compliance with industry regulations and frameworks which demonstrates without manual efforts.

  • Work with our business partners to help derive and validate mitigation techniques for identified threats and/or non-compliance.

  • ​​Define roadmaps for securing various identities with purposeful and functional security without impacting or unnecessary overhead.

  • Automated adversarial testing of our identity systems to ensure detection mechanisms function appropriately and efficiently.

  • Provide motivating demonstrations and communications to show the value of our security measures to the business, highlighting the low impact on systems, improved operability and resiliency.

Qualifications

  • Extensive experience in identity products and protocols products Active Directory, Kerberos, LDAP, SAML, SCIM, OAuth, and OIDC.

  • Deep skills in privileged access management tools and services (build/buy).

  • Extensive experience in offensive and defensive security roles, with a strong hacker mindset.

  • Experience building and designing (architecture, design patterns, reliability, and scaling) of security systems with micro-services and extensible REST APIs.

  • Experience communicating and presentation to senior and junior staff with the ability to influence stakeholders.

  • Experience in a multi-platform environment with Linux, Mac, Windows.

  • Experience with multiple IaaS platforms from top tier providers.

  • ​Experience with solving security control requirements with engineering approaches.

  • ​Ability to excel in a fast-paced, startup-like environment.

  • Ability to design, perform experiments, and influence security detection and protection solutions.

  • Strong knowledge of industry-standard security tools, frameworks, and best practices including ITDR, EPM, MITRE, CIS and NIST.

  • Demonstrated fluency and specialization with at least one modern language such as Python or Go.

  • In depth expertise in cryptographic protocols, digital certificates, and encryption standards such as X.509, Transport Layer Security (TLS), and Advanced Encryption Standard (AES).

  • Experience working with auditors and demonstrating security controls.

Experience

  • 8+ years in a dedicated security role, preferably in the tech industry

  • 5+ years of experience with security, identity, architecture, and design

  • 5+ years of experience with open-source frameworks is desired.

  • 3+ years of experience with AWS, GCP, Azure, or other cloud providers

  • 3+ years in a senior security role, preferably architecture, influencing company direction on security strategy.

  • Education with practical examples in penetration testing, writing test scripts and determining countermeasures.

  • Experience applying security controls to exceed third party attestation requirements (PCI, SOC, …).

  • Desired certifications: CISSP, CISA, CISM, CCSK, CCSP, CEH, C|CISO and related GIAC.

Education

  • Bachelor’s degree in Computer Science, Cyber Security, or equivalent education with work experience

  • Third party certifications on penetration testing/ethical hacking, exploit detection and evasion techniques, and related.


 

Annual Salary

$140,000.00 - $300,000.00

The above annual salary range is a general guideline. Multiple factors are taken into consideration to arrive at the final hourly rate/ annual salary to be offered to the selected candidate. Factors include, but are not limited to, the scope and responsibilities of the role, the selected candidate’s work experience, education and training, the work location as well as market and business considerations.


 

GEICO will consider sponsoring a new qualified applicant for employment authorization for this position.


 

The GEICO Pledge:

Great Company: Protecting customers through life’s twists and turns with innovation and integrity.

Great Careers: Personalized development programs, mentorship, and certification assistance.

Great Culture: Inclusive and collaborative culture rooted in shared success.

Great Rewards: Competitive pay, benefits, and flexibility to support your well-being and future.

 

The equal employment opportunity policy of the GEICO Companies provides for a fair and equal employment opportunity for all associates and job applicants regardless of race, color, religious creed, national origin, ancestry, age, gender, pregnancy, sexual orientation, gender identity, marital status, familial status, disability or genetic information, in compliance with applicable federal, state and local law. GEICO hires and promotes individuals solely on the basis of their qualifications for the job to be filled.

 

GEICO reasonably accommodates qualified individuals with disabilities to enable them to receive equal employment opportunity and/or perform the essential functions of the job, unless the accommodation would impose an undue hardship to the Company. This applies to all applicants and associates. GEICO also provides a work environment in which each associate is able to be productive and work to the best of their ability. We do not condone or tolerate an atmosphere of intimidation or harassment. We expect and require the cooperation of all associates in maintaining an atmosphere free from discrimination and harassment with mutual respect by and for all associates and applicants.

Skills Required

  • Extensive experience with identity products and protocols, including Active Directory, Kerberos, LDAP, SAML, SCIM, OAuth, and OIDC
  • Deep expertise with privileged access management tools and services
  • Extensive experience in offensive and defensive security roles
  • Experience architecting and designing reliable, scalable security systems using microservices and extensible REST APIs
  • Experience communicating with and influencing senior and junior staff and stakeholders
  • Experience working in Linux, Mac, and Windows environments
  • Experience with multiple IaaS platforms from top-tier providers
  • Experience solving security control requirements through engineering approaches
  • Ability to work effectively in a fast-paced, startup-like environment
  • Ability to design and perform experiments and influence security detection and protection solutions
  • Strong knowledge of ITDR, EPM, MITRE, CIS, and NIST security tools, frameworks, and practices
  • Fluency and specialization in at least one modern programming language, such as Python or Go
  • In-depth expertise in cryptographic protocols, digital certificates, and encryption standards including X.509, TLS, and AES
  • Experience working with auditors and demonstrating security controls
  • At least 8 years of experience in a dedicated security role
  • At least 5 years of experience with security, identity, architecture, and design
  • At least 3 years of experience with AWS, GCP, Azure, or other cloud providers
  • At least 3 years in a senior security role, preferably architecture or security strategy
  • Practical education or experience in penetration testing, writing test scripts, and determining countermeasures
  • Experience applying security controls to exceed third-party attestation requirements such as PCI and SOC
  • Bachelor's degree in Computer Science, Cyber Security, or equivalent education and work experience
  • At least 5 years of experience with open-source frameworks
  • Certifications such as CISSP, CISA, CISM, CCSK, CCSP, CEH, C|CISO, or GIAC
  • Third-party certifications in penetration testing, ethical hacking, exploit detection, or evasion techniques

GEICO Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about GEICO and has not been reviewed or approved by GEICO.

  • Healthcare Strength Healthcare coverage is described as comprehensive, spanning medical, prescription, behavioral health, dental (including orthodontia), and vision options with multiple plan types. Wellness resources, HSAs/FSAs, and related programs add breadth to the core health offering.
  • Retirement Support Retirement support includes a 401(k) with an employer match, and the match level is still characterized as good even after adjustments. Access to a credit union and financial education tools further strengthens the overall retirement/financial support picture.
  • Flexible Benefits Work-life programs provide flexibility through hybrid scheduling and limited remote-work options, alongside a broad menu of ancillary benefits such as commuter pre-tax programs, employee discounts, and charitable gift matching. Education support via tuition assistance and scholarships adds additional optionality for different needs.

GEICO Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chevy Chase, MD
26,259 Employees
Year Founded: 1936

What We Do

We know you know GEICO, but we want you to know that with us, you’ll find a rewarding career no matter which path you take. Our over 40,000 associates have been unexpectedly delighted to find that their jobs have turned into illuminating careers. You know us for insurance. Get to know us for great careers, too.

Similar Jobs

PNC Bank Logo PNC Bank

Scrum Master

Machine Learning • Payments • Security • Software • Financial Services
Remote or Hybrid
USA
55000 Employees

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Inside Sales Representative

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Remote or Hybrid
10 Locations
40000 Employees
45K-85K Annually

Leader Bank Logo Leader Bank

Senior SBA Closing Specialist

Fintech • Insurance • Payments • Social Impact • Financial Services
Remote or Hybrid
United States
420 Employees
107K-134K Annually

PNC Bank Logo PNC Bank

Infrastructure Engineer

Machine Learning • Payments • Security • Software • Financial Services
Remote or Hybrid
USA
55000 Employees
86K-173K Annually

Similar Companies Hiring

Alaffia Health Thumbnail
Payments • Machine Learning • Insurance • Healthtech • Artificial Intelligence
New York, NY
59 Employees
MassMutual India Thumbnail
Big Data • Fintech • Information Technology • Insurance • Financial Services
Hyderabad, Telangana
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account