Senior Staff Engineer, Cybersecurity Compliance & Assurance

Posted Yesterday
Be an Early Applicant
4 Locations
In-Office
120K-260K Annually
Senior level
Insurance
The Role
Lead and mature GEICO's enterprise cybersecurity compliance program across regulatory frameworks (NY DFS, PCI DSS, NIST CSF, ISO 27001, SOC 2, CCPA/CPRA, SOX, HIPAA). Drive audit readiness, automated evidence collection, continuous monitoring, AI security compliance, gap analyses, remediation, executive metrics, and cross-functional initiatives with Technology, Legal, Privacy, Audit, and Risk teams.
Summary Generated by Built In

Why Join GEICO?

At GEICO, we offer a rewarding career where your ambitions are met with endless possibilities.

 

Every day we honor our iconic brand by offering quality coverage to millions of customers and being there when they need us most. We thrive on relentless innovation to exceed our customers' expectations while making a real impact on local communities nationwide.

 

Founded in 1936, GEICO is a member of the Berkshire Hathaway family of companies and one of the largest auto insurers in the United States. When you join our company, we want you to feel valued, supported, and proud to work here. That's why we offer the GEICO Pledge: Great Company, Great Culture, Great Rewards, and Great Careers.

GEICO is seeking an experienced Senior Staff Engineer, Cybersecurity Compliance & Assurance, to lead the design, implementation, and continuous improvement of its cybersecurity compliance and assurance program, ensuring sustained compliance with NY DFS, PCI DSS, CCPA/CPRA, NIST CSF, SOX, HIPAA, and other cyber regulatory obligations. This role will drive audit readiness, compliance by design, automated evidence collection, continuous control monitoring, and risk-based assessments across GEICO’s security domains.

GEICO is transforming cybersecurity through automation and a risk-based approach. The ideal candidate will have a proven track record of building effective compliance frameworks, driving end-to-end compliance, creating actionable metrics, meeting regulatory requirements, and demonstrating strong leadership and collaboration skills.

Key Responsibilities

  • Own and mature the enterprise cybersecurity compliance program, ensuring alignment with regulatory, contractual, and business requirements.

  • Lead cybersecurity compliance initiatives supporting NY DFS, PCI DSS, CCPA/CPRA, NIST CSF, SOX, HIPAA, SOC Type II, ISO 27001 and other applicable regulatory frameworks.

  • Lead and manage security attestations/certifications supporting SOC 2 Type II, ISO 27001

  • Lead the development, implementation, and continuous monitoring of AI security compliance, ensuring GEICO meets applicable standards such as ISO/IEC 42001 and the NIST AI RMF.

  • Conduct current-state and future-state assessments, compliance gap analyses, and maturity evaluations, including enterprise NIST Cybersecurity Framework assessments, to identify gaps, prioritize remediation, and develop strategic roadmaps that improve security and compliance posture.

  • Drive continuous audit readiness by establishing repeatable processes and partnering with technology teams to maintain documentation, evidence, and control execution that support internal audits, external assessments, regulatory examinations, and automated compliance monitoring.

  • Lead the identification, tracking, escalation, and remediation of compliance non-adherence, control deficiencies, audit findings, and regulatory observations through closure.

  • Maintain awareness of emerging regulatory requirements, advisories, enforcement actions, and industry guidance, proactively assessing impact and driving implementation plans.

  • Establish and maintain a compliance-by-design approach that translates regulatory and security requirements into actionable engineering controls across software development, cloud, infrastructure, and operational processes

  • Establish enterprise cybersecurity compliance metrics, key risk indicators, scorecards, and executive reporting that measure compliance effectiveness, control maturity, audit readiness, and progress toward strategic cybersecurity objectives.

  • Serve as a trusted advisor to senior leadership, providing recommendations on cybersecurity risk, regulatory compliance, governance strategy, and continuous improvement opportunities.

  • Lead cross-functional initiatives involving Security, Technology, Legal, Privacy, Internal Audit, Compliance, and Enterprise Risk Management to improve compliance effectiveness and reduce organizational risk.

What You Will Need

  • Deep expertise in cybersecurity governance, risk, and compliance, including cybersecurity domains and regulatory compliance frameworks.

  • Extensive experience supporting NY DFS, PCI DSS, NIST CSF, CCPA/CPRA, ISO 27001, and related frameworks.

  • Proven success implementing enterprise-wide compliance initiatives and influencing outcomes across multiple teams and business functions without direct authority.

  • Deep technical understanding of cloud-hosted environments, preferably Microsoft Azure, AWS and security implications across modern technology platforms.

  • Strong communication skills, with the ability to engage executives, auditors, regulators, engineers, and business stakeholders and translate complex technical and regulatory requirements into clear business outcomes.

  • Strong problem-solving skills, creativity, and the ability to drive innovation through others while developing scalable solutions that strengthen the organization’s security posture.

  • Demonstrated ownership, sound judgment, and leadership maturity in navigating successes, setbacks, and complex decisions.

  • Ability to balance multiple assignments across teams and dependency areas while maintaining execution focus.

Qualifications

  • 10+ years of experience in governance, risk, and compliance, including leadership of enterprise cybersecurity compliance programs.

  • Proven ability to lead a successful cybersecurity compliance program in a multi-cloud or hybrid environment.

  • Strong knowledge of regulatory frameworks, compliance standards, and risk management, including NY DFS, PCI DSS, NIST CSF, ISO 27001, SOC Type II and CCPA/CPRA.

  • Experience conducting cybersecurity maturity assessments, control effectiveness reviews, and building compliance roadmaps, operating models, and implementation plans.

  • Proven ability to establish executive-level metrics, dashboards, and reporting that measure cybersecurity posture, compliance effectiveness, and organizational risk exposure.

  • Experience partnering with leaders and cross-functional teams, including Legal, Privacy, Compliance, Risk Management, and Engineering, to drive enterprise-wide governance initiatives.

  • Relevant certifications (e.g., CISSP, CISM, CISA, CRISC); additional certifications or coursework in AI, machine learning, or data analytics are a plus.

  • Strong understanding of security controls and implementation across multi-cloud environments and data centers.

  • Proven experience managing audits and regulatory engagements, ideally with exposure to compliance automation platforms.

  • Excellent verbal and written communication skills, with the ability to communicate effectively with senior leadership and highly technical personnel.

  • Experience in strategic planning and roadmap development.

  • Excellent problem-solving skills, proactivity, and the ability to thrive in an ambiguous environment.

  • Bachelor’s degree in computer science, Information Systems, or equivalent education or work experience; advanced coursework or certifications in relevant technical disciplines are a plus.


 

Annual Salary

$120,000.00 - $260,000.00

The above annual salary range is a general guideline. Multiple factors are taken into consideration to arrive at the final hourly rate/ annual salary to be offered to the selected candidate. Factors include, but are not limited to, the scope and responsibilities of the role, the selected candidate’s work experience, education and training, the work location as well as market and business considerations.


 

GEICO will consider sponsoring a new qualified applicant for employment authorization for this position.


 

The GEICO Pledge:

Great Company: Protecting customers through life’s twists and turns with innovation and integrity.

Great Careers: Personalized development programs, mentorship, and certification assistance.

Great Culture: Inclusive and collaborative culture rooted in shared success.

Great Rewards: Competitive pay, benefits, and flexibility to support your well-being and future.

 

The equal employment opportunity policy of the GEICO Companies provides for a fair and equal employment opportunity for all associates and job applicants regardless of race, color, religious creed, national origin, ancestry, age, gender, pregnancy, sexual orientation, gender identity, marital status, familial status, disability or genetic information, in compliance with applicable federal, state and local law. GEICO hires and promotes individuals solely on the basis of their qualifications for the job to be filled.

 

GEICO reasonably accommodates qualified individuals with disabilities to enable them to receive equal employment opportunity and/or perform the essential functions of the job, unless the accommodation would impose an undue hardship to the Company. This applies to all applicants and associates. GEICO also provides a work environment in which each associate is able to be productive and work to the best of their ability. We do not condone or tolerate an atmosphere of intimidation or harassment. We expect and require the cooperation of all associates in maintaining an atmosphere free from discrimination and harassment with mutual respect by and for all associates and applicants.

Skills Required

  • 10+ years of experience in governance, risk, and compliance, including leadership of enterprise cybersecurity compliance programs
  • Deep expertise in cybersecurity governance, risk, and compliance and regulatory compliance frameworks
  • Extensive experience supporting NY DFS, PCI DSS, NIST CSF, CCPA/CPRA, ISO 27001, SOC Type II, SOX, and HIPAA
  • Proven ability to lead enterprise-wide compliance initiatives and influence cross-functional teams without direct authority
  • Deep technical understanding of cloud-hosted environments, preferably Microsoft Azure and AWS, and security implications across modern platforms
  • Proven experience conducting cybersecurity maturity assessments, control effectiveness reviews, and building compliance roadmaps and operating models
  • Proven experience managing audits and regulatory engagements, including maintaining documentation, evidence, and audit readiness processes
  • Proven experience with compliance automation platforms or automated evidence collection and continuous control monitoring
  • Ability to establish executive-level metrics, dashboards, key risk indicators, and reporting for cybersecurity posture and compliance effectiveness
  • Strong communication skills with ability to engage executives, auditors, regulators, engineers, and business stakeholders
  • Bachelor's degree in computer science, Information Systems, or equivalent education or work experience
  • Relevant certifications such as CISSP, CISM, CISA, or CRISC
  • Experience or coursework in AI, machine learning, or data analytics (helpful for AI security compliance)

GEICO Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about GEICO and has not been reviewed or approved by GEICO.

  • Healthcare Strength Healthcare coverage is described as comprehensive, spanning medical, prescription, behavioral health, dental (including orthodontia), and vision options with multiple plan types. Wellness resources, HSAs/FSAs, and related programs add breadth to the core health offering.
  • Retirement Support Retirement support includes a 401(k) with an employer match, and the match level is still characterized as good even after adjustments. Access to a credit union and financial education tools further strengthens the overall retirement/financial support picture.
  • Flexible Benefits Work-life programs provide flexibility through hybrid scheduling and limited remote-work options, alongside a broad menu of ancillary benefits such as commuter pre-tax programs, employee discounts, and charitable gift matching. Education support via tuition assistance and scholarships adds additional optionality for different needs.

GEICO Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chevy Chase, MD
26,259 Employees
Year Founded: 1936

What We Do

We know you know GEICO, but we want you to know that with us, you’ll find a rewarding career no matter which path you take. Our over 40,000 associates have been unexpectedly delighted to find that their jobs have turned into illuminating careers. You know us for insurance. Get to know us for great careers, too.

Similar Jobs

Realtor.com Logo Realtor.com

Staff Software Engineer

Big Data • Real Estate • Software
Hybrid
Austin, TX, USA
1250 Employees

Ambiq  Logo Ambiq

Support Engineer

Hardware • Internet of Things • Software • Wearables • Semiconductor
Easy Apply
In-Office
Austin, TX, USA
220 Employees

PwC Logo PwC

Consultant

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
17 Locations
370000 Employees
77K-202K Annually

PwC Logo PwC

Consultant

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
17 Locations
370000 Employees
77K-202K Annually

Similar Companies Hiring

Globe Life Thumbnail
Insurance • Financial Services
McKinney, TX
3000 Employees
MassMutual India Thumbnail
Big Data • Fintech • Information Technology • Insurance • Financial Services
Hyderabad, Telangana
Granted Thumbnail
Mobile • Insurance • Healthtech • Financial Services • Artificial Intelligence
New York, New York
23 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account