Senior Manager Cybersecurity Governance & Assurance
$120k - $260kGEICO
Why Join GEICO?
At GEICO, we offer a rewarding career where your ambitions are met with endless possibilities.
Every day we honor our iconic brand by offering quality coverage to millions of customers and being there when they need us most. We thrive on relentless innovation to exceed our customers' expectations while making a real impact on local communities nationwide.
Founded in 1936, GEICO is a member of the Berkshire Hathaway family of companies and one of the largest auto insurers in the United States. When you join our company, we want you to feel valued, supported, and proud to work here. That's why we offer the GEICO Pledge: Great Company, Great Culture, Great Rewards, and Great Careers.
The Senior Manager of Cyber Governance & Assurance will lead and mature the enterprise cybersecurity governance program, establishing an effective operating model for policies, standards, control governance, cyber risk management and cyber assurance. This leader will partner with Cybersecurity, Technology, Legal, Privacy, Enterprise Risk and Internal Audit to translate regulatory and security requirements into actional controls, drive clear accountability and provide leadership with measurable visibility into compliance posture, control effectiveness and cyber risk. The successful candidate will combine strategic judgment, technical credibility and strong people leadership to influence decision across organizational boundaries and continuously improve how cybersecurity governance operates.
Key Responsibilities
- Own and mature the Cyber Governance operating model, including governance forums, establishing clear decision rights, roles and responsibilities, accountability and escalation paths across Cybersecurity and Tech.
- Advise senior leaders on cybersecurity governance, regulatory obligations and material cyber risk; present clear option, recommendations and decisions required.
- Lead the cybersecurity policy, standard and control lifecycle from development, and stakeholder review through approval, publication and periodic refresh.
- Translate regulatory and cybersecurity requirements into actionable technology standards, controls and engineering requirements.
- Ensure cyber security exceptions and acceptances do not introduce aggregated risk and address root cause of cyber systemic exceptions.
- Identify systemic control failures to identify root causes and partner with accountable owners to drive enterprise level remediation.
- Establish governance for the cybersecurity controls, including ownership, design expectations, evidence requirements, effectiveness monitoring, deficiencies and remediation oversight, hold implementation owners accountable.
- Drive control rationalization and harmonization across regulatory frameworks to reduce duplicative controls and create a common enterprise control framework.
- Partner with Technology and Engineering teams to embed compliance requirements and automated controls into engineering workflows and the software development cycle.
- Define cybersecurity governance KPIs, KRIs and compliance metrics covering compliance posture, control health, remediation progress and emerging risks.
- Lead the development and delivery of monthly and quarterly business reviews, translating cybersecurity governance performance, compliance posture, emerging risks and strategic initiatives into executive-level insights, recommendations and actionable decisions.
- Partner with Enterprise Risk and accountable risk owners to maintain accurate cyber risk records, escalation material exposure and oversee treatment commitments.
- Set governance requirements and priorities for continuous compliance monitoring and automation across multi-cloud and data center environments, partner with engineering teams responsible for delivery.
- Manage all cyber issues to closure.
- Build, mentor and lead a high-performing governance function, with clear priorities, ownership, coaching, while fostering a culture of accountability, innovation and continuous improvement.
- Lead monthly, quarterly annual priorities, resource planning, change adoption and performance management; establish an inclusive, accountable team culture and develop team members.
- Influence cross-functional stakeholders, constructively challenge proposed risk decisions and lead complex discussions to resolution without relying on direct authority.
What you will need
- Deep expertise in cybersecurity governance, control frameworks, risk management and regulatory compliance, with the ability to connect requirements to technical implementation.
- Demonstrated experience presenting to senior leadership, effectively communication performance, risks and strategic priorities while confidently addressing challenging questions and driving executive alignment.
- Demonstrated credibility with senior leaders, translates complex cyber and regulatory matters into business implications, presents clear options and facilitates decision.
- Exceptional written and verbal communication, including the ability to lead difficult, high-stakes discussions, challenge constructively and gain alignment without direct authority.
- Sound judgement and accountability in ambiguous environments, balancing regulatory obligations, business priorities and risk.
- Experience leading and developing technical governance, compliance or security engineering professionals, including performance management and coaching.
- Proven delivery of enterprise scale governance transformation, cross functional change and measurable process improvement.
- Working technical knowledge of multi-cloud and hybrid/data center security controls: MS Azure and AWS experience preferred.
Qualifications
- 7+ years of progressive experience in cybersecurity governance, risk and compliance, including at least 5 years leading teams and enterprise programs.
- Experience establishing or maturing governance and compliance capabilities in large, complex, multi-cloud and hybrid environments.
- Strong working knowledge of application security frameworks and standards such as ISO 27001, NIST 800-series, NY DFS, CPPA/CPRA, PCI DSS, NIST CSF, SOX is valuable as applicable to assigned scope.
- Experience overseeing cybersecurity audits or regulatory examinations and coordinating control remediation with accountable owners.
- Experience with strategic planning, program roadmaps, priorities and resource allocation
- Bachelor’s degree in a related field or equivalent professional experience. CISSP, CISM, CISA or CRISC preferred.
Annual Salary
$120,000.00 - $260,000.00The above annual salary range is a general guideline. Multiple factors are taken into consideration to arrive at the final hourly rate/ annual salary to be offered to the selected candidate. Factors include, but are not limited to, the scope and responsibilities of the role, the selected candidate’s work experience, education and training, the work location as well as market and business considerations.
GEICO will consider sponsoring a new qualified applicant for employment authorization for this position.The GEICO Pledge:
Great Company: Protecting customers through life’s twists and turns with innovation and integrity.
Great Careers: Personalized development programs, mentorship, and certification assistance.
Great Culture: Inclusive and collaborative culture rooted in shared success.
Great Rewards: Competitive pay, benefits, and flexibility to support your well-being and future.
The equal employment opportunity policy of the GEICO Companies provides for a fair and equal employment opportunity for all associates and job applicants regardless of race, color, religious creed, national origin, ancestry, age, gender, pregnancy, sexual orientation, gender identity, marital status, familial status, disability or genetic information, in compliance with applicable federal, state and local law. GEICO hires and promotes individuals solely on the basis of their qualifications for the job to be filled.
GEICO reasonably accommodates qualified individuals with disabilities to enable them to receive equal employment opportunity and/or perform the essential functions of the job, unless the accommodation would impose an undue hardship to the Company. This applies to all applicants and associates. GEICO also provides a work environment in which each associate is able to be productive and work to the best of their ability. We do not condone or tolerate an atmosphere of intimidation or harassment. We expect and require the cooperation of all associates in maintaining an atmosphere free from discrimination and harassment with mutual respect by and for all associates and applicants.
- Synertex LLC is seeking a skilled Data Manager in Bethesda, MD. This full-time, on-site role entails supporting critical Intelligence Community initiatives with expertise in data management and governance. You'll ensure data accessibility, reliability, and integration,...SeniorFull time
- Saliense Consulting LLC is seeking a senior IT security professional to support a Federal Agency within a dynamic, mission-driven environment. You will translate system requirements into risk-based recommendations and collaborate with system owners and security officers...Senior
- Saliense, based in Alexandria, VA, seeks an experienced IT and security leader to advance a Federal Agency information security program. The role emphasizes implementing RMF/CSF, risk‑based recommendations, and collaboration with system owners and ISOs to secure acquisitions...Senior
- ...information security risk specialist to join a 24x7 SOC and Incident Response team. You will monitor, detect, investigate, and respond to cybersecurity threats across enterprise networks, endpoints, and applications, leveraging SIEM, EDR, IDS/IPS, and forensic tools. The role...Senior
- Nestlé USA is seeking a Senior Manager to lead Revenue Growth Management and Trade Governance. You will drive Nestlé Next compliance, define fair trade investment strategies, and partner with sales, legal, credit, and supply chain to refine deductions and fines processes...Senior
$160k - $220k
ActioNet, Inc. seeks a Program Manager to provide leadership and accountability for delivering Security Operations Center services.... ...20K with TS/DOE Q clearance. The role requires overseeing SOC governance, staffing for Tier 1-3, and executive reporting, while coordinating...SeniorContract work$170k - $250k
...and commit dates with program management, and manage the dependencies... ...Represent Shield AI as the senior security authority with Authorizing Officials, SCAs, government program security officers, and... ...qualifications: ~ Bachelor’s degree in Cybersecurity, Electrical Engineering,...SeniorFull timeTemporary workPart timeWorldwide- Quantum Sky is seeking a Program Manager to lead a large, multi-site DoD IT and Cybersecurity program in support of the F-35 JPO. You will oversee all aspects of program delivery, including cost, schedule, staffing, subcontractor integration, risk mitigation, and quality...SeniorFor subcontractorWorldwide
- Nestlé USA is seeking a Senior Manager to lead Revenue Growth Management, ensuring Nestlé Next compliance and equitable trade practices across customer portfolios. You will define investment strategies and partner with sales, legal, credit, and supply chain to optimize...Senior
- Medallia is seeking an experienced Product Manager to own the roadmap for Medallia Experience Cloud in the Public Sector, including... ...-powered capabilities, for federal, defense, state, and local government agencies. In this hybrid role, you will translate security, compliance...SeniorLocal area
$184k - $245k
...the pioneer and market leader in Experience Management. Our award-winning SaaS platform, Medallia... ...self. The Role and Team We are seeking a Senior Staff Product Security Engineer to lead Medallia's security strategy and assurance efforts for AI-powered products, agentic...SeniorTemporary workWork experience placementLocal area3 days per week- ...technology and network solutions for government customers. Founded in 1985, NDi'... ...NDi is Seeking a Strong Program Manager with in-depth experience leading Cybersecurity Operations within Federal... ...provide cybersecurity and Information Assurance support for a large Information...For contractors
$130k
...Job Description Overview Senior Cybersecurity Analyst LOCATION:... ...security, information system management, software development, design... ...data and recommendations to Government and Military leadership.... ...8510.01 – DoD Information Assurance Assessment and Authorization...SeniorFull timeFlexible hours$204.8k - $425.5k
...technology. These changes create new cybersecurity, resilience and regulatory challenges... ...industrial sectors. As an OT Cybersecurity Senior Manager in Technology Consulting, you will... ...across a full spectrum of services in assurance, consulting, tax, strategy and transactions...SeniorRemote work- Capital One, based in McLean, VA, is seeking a Manager, Risk Management: Card Data Management to lead risk, governance, and compliance activities for high-priority data and data products. The role partners with data producers and consumers to ensure timely data management...Senior
- OneZero Solutions, LLC is seeking a Program Manager III to lead DSCA Cybersecurity Support Services, directing contract performance and the Digital Transformation... ...initiative. The role owns quality, risk, and formal government reporting while advancing automated, AI-enabled...SeniorContract work
- Capital One in McLean, VA seeks a Principal Associate Project Manager for Product Operations: Governance & People Excellence. You will lead cross-functional, end-to-end projects and drive governance, OKR reporting, and strategic learning initiatives that impact the finance...Senior
$146.7k - $335.1k
EY is seeking a Senior Manager for its Government & Public Sector-Financial Accounting Advisory Services team in McLean, Virginia. This role involves... ...relationships, managing audit engagements, and leading assurance staff. The successful candidate will need a CPA license...SeniorFlexible hours- BDO USA’s Assurance Experienced Associate prepares financial statements with disclosures and applies basic GAAP as needed. The role documents, validates, tests, and assesses client internal control systems and may participate in reviews and agreed-upon procedures engagements...Senior
- Capital One is seeking a Senior Manager to lead Cyber Risk & Analysis within Enterprise Services Risk Operations (ESRO). You will oversee end-to-end controls lifecycle management, design assessments for new controls, and guide a team of risk professionals to help lines...Senior
- Harris in Bethesda, Maryland, is seeking an experienced quality control professional to join their team. This role involves ensuring the quality of projects through inspections, documentation, and compliance with standards. The ideal candidate will have over 5 years of ...Senior
- BDO USA is seeking an Assurance Senior in Maryland to coordinate the day-to-day audit process, including planning, fieldwork and wrap-up. You will prepare financial statements with disclosures, apply GAAP, and document internal controls. The role also serves as a client...Senior
- BDO USA is seeking an Assurance Senior Associate for Non-Profit & Healthcare to coordinate day-to-day in-charge duties of planning, fieldwork, and wrap-up, including preparing financial statements with disclosures and applying GAAP as needed. The role serves as the client...Senior
- ATL Professional Services LLC in Falls Church, VA, seeks a Sr. Management Analyst to provide Mission Assurance and Force Health Protection support to the DHA. The role requires coordinating with DHA, MHS, and DoD entities to sustain mission-critical functions and manage...Senior
- Freddie Mac, headquartered in McLean, VA, is seeking an Operational Risk Senior Manager to lead SFA ORM initiatives and risk governance across model and AI risks. You will evaluate controls, report on risk events, and support audits, exams, and process design reviews in...Senior
- Supernus Pharmaceuticals is seeking a QA professional to perform a range of quality assurance activities, ensuring compliance with FDA regulations and internal standards. The role involves audits, supplier oversight, deviation reviews, and maintains GMP/GCP/GLP documentation...SeniorVisa sponsorship
- EY is seeking a Senior Manager in the Government & Public Sector Assurance practice in McLean, VA. You will lead audit engagements for federal, state, local, and education clients, acting as primary client contact and overseeing teams to deliver high-quality assurance...SeniorLocal areaFlexible hours
- BDO USA is seeking an Assurance Senior Associate for Non-Profit & Healthcare in McLean, VA. You will coordinate audit planning, fieldwork... ...the team to apply GAAP/GAAS standards, document controls, and communicate findings to engagement management. #J-18808-Ljbffr BDO USASenior
$96.5k - $110.1k
Capital One in McLean is seeking a Senior Associate, Project Manager to oversee model risk management processes. The successful candidate will support Divisional Model Risk Officers and ensure efficient operations through analytical problem-solving and stakeholder collaboration...Senior- A cybersecurity and data operations firm is seeking Cyber Eviction Analysts to support the DHS's Hunt and Incident Response Team. The role requires extensive experience in incident response and the ability to think independently. Candidates must have a strong understanding...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Manager Cybersecurity Governance & Assurance. Be the first to apply!
- senior software engineer ruby on rails Bethesda, MD
- sr finance manager Bethesda, MD
- senior customer service Bethesda, MD
- senior accounts receivable analyst Bethesda, MD
- senior compensation manager Bethesda, MD
- senior cloud data engineer Bethesda, MD
- senior manager Bethesda, MD
- senior living Bethesda, MD
- senior network engineer Bethesda, MD
- senior vmware engineer Bethesda, MD
