Staff Security Engineer - Vulnerability Management
$110k - $230kGEICO Insurance Agent
Staff Security Engineer – Vulnerability ManagementSkip to main contentGEICO uses cookies to help us provide the best experience on GEICO Careers. By continuing to use our website, you consent to the use of cookies. For more information, please visit our cookie policy.#Staff Security Engineer – Vulnerability Management page is loaded## Staff Security Engineer – Vulnerability ManagementApplyremote type: Hybridlocations: Seattle, WA: Palo Alto, CA: Dallas, TX: Bethesda, MDtime type: Full timeposted on: Posted Todayjob requisition id: R0064529**Why Join GEICO?**At GEICO, we offer a rewarding career where your ambitions are met with endless possibilities.Every day we honor our iconic brand by offering quality coverage to millions of customers and being there when they need us most. We thrive on relentless innovation to exceed our customers' expectations while making a real impact on local communities nationwide.Founded in 1936, GEICO is a member of the Berkshire Hathaway family of companies and one of the largest auto insurers in the United States. When you join our company, we want you to feel valued, supported, and proud to work here. That's why we offer the GEICO Pledge: Great Company, Great Culture, Great Rewards, and Great Careers.GEICO is seeking a highly experienced **Staff Security Engineer** to lead the strategy, architecture, and execution of Vulnerability Management across a complex, hybrid technology ecosystem. This role combines deep hands-on engineering expertise with strong ownership, operational rigor, and the ability to influence outcomes across teams.This role reports directly to the hiring manager and is accountable for delivering measurable improvements in security posture, operational excellence, and engineering maturity.The position operates as a **hands-on advisor to the leadership** while remaining deeply embedded in day-to-day execution. This is not a purely strategic role—the individual is expected to actively contribute to team deliverables, participate in on-call rotations, and take ownership of operational outcomes alongside peers.Success in this role requires independent leadership, strong judgment, and the ability to consistently drive high-quality outcomes while influencing teams across infrastructure, product, and engineering.**Key Responsibilities****Ownership & Accountability*** Own outcomes end-to-end with a strong sense of accountability; does not defer responsibility for gaps or failures.* Drive work to closure with clear ownership of results, timelines, and quality.* Proactively identify and address risks, gaps, and inefficiencies without waiting for direction.* Maintain high standards of execution and hold self and others accountable to those standards.**Operational Excellence, Monitoring & Engineering Excellence*** Establish and enforce strong operational discipline across services, including monitoring, alerting, and reliability.* Ensure systems are observable, measurable, and consistently meet defined SLAs/SLOs.* Drive improvements in availability, performance, and scalability through data-driven decisions.* Reduce operational toil by simplifying systems, improving automation, and standardizing processes.* Build and maintain durable pipelines and integrations across asset inventory, scanning, ticketing, and engineering workflows.* Leverage advanced SQL and data mining techniques to analyze vulnerability, asset, and operational data; generate insights that drive prioritization, risk reduction, and system improvements.**Security Mindset with Offensive Perspective*** Apply a security-first engineering mindset from design through production and ongoing operations.* Drive **vulnerability research** by analyzing systems, dependencies, and emerging threats to uncover exploitable weaknesses.* Operate with an **offensive security mindset**, proactively identifying and validating real attack paths and risks.* Lead and evolve **attack surface and exposure management**, maintaining continuous visibility into internal and external exposure across assets, services, and environments.* Identify, prioritize, and reduce exposure through improvements in architecture, configuration, and implementation.* Challenge assumptions and existing designs where risks are not adequately addressed, acting as a constructive disruptor.* Integrate pragmatic, high-impact security improvements into engineering workflows without blocking delivery.**Curiosity & Continuous Learning*** Demonstrate a strong “learn and be curious” mindset to deeply understand systems, dependencies, and behaviors.* Actively uncover service potential, hidden risks, scaling limits, and architectural gaps.* Stay current with evolving technologies, threats, and engineering practices, applying insights to improve systems.**Relentless Execution*** Maintain urgency and consistently push for better outcomes, even under constraints.* Follow through commitments with discipline and focus.* Remove blockers, drive momentum, and ensure sustained progress across initiatives.* Continuously raise the bar on quality, reliability, and security outcomes.**Team Contribution & Leadership*** Operate as a team player contributing daily alongside peers, including participation in on-call rotations.* Provide advisory support to leadership while remaining grounded in execution and delivery.* Influence without authority by setting a high bar for ownership, engineering rigor, and operational discipline.* Mentor and elevate engineers through guidance, design reviews, and hands-on collaboration.**Vulnerability Management Execution*** Lead the full vulnerability lifecycle: discovery, validation, contextual risk analysis, prioritization, and remediation.* Leverage threat intelligence and system context to distinguish true risk from noise.* Drive automation across scanning, triage, remediation tracking, and reporting.* Generate actionable insights that enable teams to reduce risk efficiently and measurably.**Cross-Functional Partnership*** Collaborate with infrastructure, cloud, DevOps, and product engineering teams to integrate security into delivery workflows.* Partner with risk, governance, and incident response functions to ensure alignment on priorities and outcomes.* Communicate clearly with technical and non-technical stakeholders on risk, trade-offs, and remediation strategies.**Required Qualifications*** 8+ years of experience in cybersecurity or security engineering roles.* Deep expertise in vulnerability management, security engineering, and modern infrastructure (cloud, containers, distributed systems).* Strong programming/scripting skills (Python, Go, Java, or similar) with experience building automation at scale.* Strong data mining and analytical capabilities with exceptional SQL skills; ability to query, transform, and analyze large security datasets to derive actionable insights and drive decision-making.* Proven ability to operate with high ownership and deliver results independently.* Strong understanding of systems, networking, identity, and security architecture.* Ability to influence engineering teams and senior stakeholders with clear, outcome-oriented communication.**Preferred Qualifications*** Experience with vulnerability research, offensive security techniques, or threat modeling.* Familiarity with attack surface management and exposure analysis at scale.* Experience integrating security into CI/CD and DevSecOps practices.* Working knowledge and applied experience with regulatory and control frameworks, including **PCI and NYDFS**, is a strong plus.* Experience with SIEM, SOAR, and large-scale security data pipelines.* Relevant security certifications (CISSP, OSCP, cloud security certifications) are a plus.**Education*** Master’s degree in computer science, Cybersecurity, or equivalent practical experience.**Annual Salary**$110,000.00 - $230,000.00The above annual salary range is a general guideline. Multiple factors are taken into consideration to arrive at the final hourly rate/ annual salary to be offered to the selected candidate. Factors include, but are not limited to, the scope and responsibilities of the role, the selected candidate’s work experience, education and training, the work location as well as market and business considerations.GEICO will consider sponsoring a new qualified applicant for employment authorization for this position.**The GEICO Pledge:****Great Company:** Protecting customers through life’s twists and turns with innovation and integrity.**Great Careers:**Personalized development programs, mentorship, and certification assistance.**Great Culture:**Inclusive and collaborative culture rooted in shared success.**Great Rewards:**Competitive pay, benefits, and flexibility to support your well-being and future.The equal employment opportunity policy of the GEICO Companies provides for a fair and equal employment opportunity for all associates and job applicants regardless of race, color, religious creed, national origin, ancestry, age, gender, pregnancy, sexual orientation, gender identity, marital status, familial status, disability or genetic information, in compliance with applicable federal, state and local law. GEICO hires and promotes individuals solely on the basis of their qualifications for the job to be filled.GEICO reasonably accommodates qualified individuals with disabilities to enable them to receive equal employment opportunity and/or perform the essential functions of the job, unless the accommodation would impose an undue hardship to the Company. This applies to all applicants and associates. GEICO also provides a work environment in which each associate is able to be productive and work to the best of their ability. We do not condone or tolerate an atmosphere of intimidation or harassment. We expect and require the cooperation of all associates in maintaining an atmosphere free from discrimination and harassment with mutual respect by and for all associates and applicants. #J-18808-Ljbffr GEICO
- Endpoint Security and Management Engineer We are seeking a highly motivated Endpoint Security and Management Engineer to support the deployment... ...Tanium, including patch management, compliance enforcement, vulnerability detection, and system monitoring. Integrate Tanium...Suggested
- A cybersecurity company is seeking a Cybersecurity Vulnerability Analyst to support a Vulnerability Disclosure Program for the federal government... ...experience in IT or cybersecurity, along with an active Security+ certification and Secret security clearance. Responsibilities...Suggested
- ..., Data Science, or Software Engineering. In lieu of a degree in one... ...understanding of information security principles and practices, Utilize... ...NIST frameworks to assess vulnerability severity and risk impact.... ...sent to the Vulnerability Management Analyst team for system owner...SuggestedFull timeMonday to Friday
$50k - $290k
...Evaluator to assess and improve operational networks in Annapolis Junction, MD. Candidates must evaluate vulnerabilities, recommend countermeasures, and support security solutions. A Bachelor’s degree with relevant experience is required, with higher education preferred...Suggested$130k - $145k
Systems Security Engineer (SSE), Journeyman KAIROS, Inc is a growing Woman Owned Small Business... ...life cycle Cybersecurity, Program Management, Engineering, Logistics, Additive Manufacturing... ...(CPI) assessments. Understand vulnerabilities and attack vectors that may impact...SuggestedContract workTemporary workFor contractorsWork at officeLocal area- PD Inc is seeking a Senior Database Vulnerability Analyst in Fort Meade, MD to support cybersecurity services and manage vulnerabilities for key database applications. Candidates... ...Clearance. The role includes reviewing security controls, analyzing vulnerabilities, and generating...
- Job Title: Senior Database Vulnerability Analyst Location: Fort Meade, MD 20755 Clearance... ...options, software used and not used, default security controls that are enabled, disabled, or... ...and high severity vulnerabilities are managed with increased visibility and escalated...Full timeWork experience placementCasual work
- PD Inc is looking for a Senior Windows Vulnerability Analyst at Fort Meade, MD. This role requires at least 5 years of experience with Microsoft... ...current 8570/8140 requirement certification. The Analyst will manage OS vulnerability analysis, compliance validation, and provide...
- Job Title: Senior Windows Vulnerability Analyst Location: Fort Meade, MD 20755 Clearance Level... ..., software used and not used, default security controls that are enabled, disabled, or... ...and high severity vulnerabilities are managed with increased visibility and escalated...Full timeWork experience placementCasual workWork at office
- General Dynamics Information Technology is looking for an Endpoint Security and Management Engineer in Maryland. This role focuses on deploying and managing enterprise systems using the Tanium platform. The successful candidate will enhance enterprise endpoint security...
- ...Tester in its National Security Sector's Cyber &... ...web application tests, vulnerability risk assessments, physical... ...physical pentests and social engineering analysis, as well as... ...advice to program managers, customer technical... ...collaborate with technical staff and customers to...Immediate startFlexible hoursShift work
$74k - $118k
Prime Therapeutics in Annapolis, MD, is seeking a Security Engineer specializing in CyberArk to support privileged access management initiatives. The ideal candidate will have a strong background in information security and experience with CyberArk PAM solutions. This...Remote job- Gigatec in Annapolis, Maryland, is seeking a Network Engineer to support Weapons CSE vulnerability assessments. You will configure, secure, and maintain network infrastructures while managing switches, routers, firewalls, and VMware clusters. Applicants need a TS/SCI clearance...
$166.5k - $289.2k
...Technical Architect for the Mission Data Management (MDM) Operating Unit (OU). The preferred... ...appropriate collaboration between Chief Engineers across the OU and the programs that they... ...experience Active DoD Secret or higher security clearance with ability to get TS/SCI...For subcontractorWork at officeRelocationRelocation packageShift work- Legato, LLC is seeking a Software Engineer in Laurel, MD, to support their Software Management Team. The role involves developing and enhancing complex software systems and requires a TS/SCI with Polygraph security clearance. Candidates should have experience in coding...
$130k - $216k
## Technology Cybersecurity Managing ConsultantApplylocations: US - VA, McLean: US - VA, Alexandria: US - MD... ...the value and effectiveness of their existing security tooling and platforms (e.g., SIEM, EDR, vulnerability management).* Assess current cybersecurity tools,...Temporary workFlexible hours- ...deep understanding of cybersecurity engineering and risk management. This role demands a Bachelor’s... ...experience in cybersecurity, and a required security clearance. Responsibilities include... ..., and strategizing remediation of vulnerabilities. #J-18808-Ljbffr SPS - Systems...
- Job Summary Leidos is seeking a Lead Security Engineer to support a mission‑critical program,... ...geographically distributed systems; and will manage a team of Information Systems Security... ...teams to improve understanding of vulnerabilities, attack vectors, and effective...Immediate startFlexible hours
- ...Cybersecurity Compliance Analyst to Enter manage the overall compliance posture of... ...automated compliance findings, coordinate with security assessors and Authorizing Officials, and... ...the ATO Automation Platform’s automated vulnerability tracking and remediation status features...Contract workWork at office
$75k - $200k
Itezz, Inc. is seeking a Network Security Specialist to manage and support Network Security Boundaries. The role requires strong troubleshooting skills, a Bachelor’s degree in a technical discipline, and 5 years of experience. Candidates must hold a TS/SCI with Agency Appropriate...$70k - $135k
Braxton-Grant Technologies, Inc in Maryland is seeking an Endpoint Security Specialist to manage EDR/XDR platforms and respond to security incidents. Candidates must be US citizens with at least three years of relevant experience. The position offers a competitive salary...- ...safeguard networks from cyber threats. The successful candidate will join an agile team using the SAFe methodology, ensuring the overall security of enterprise-wide information systems while conducting investigations on security incidents. This position offers a competitive...
- ...mission‑critical programs across national security, defense, and public service delivery... ...scale. The Junior Security Engineer supports 24x7 enterprise cybersecurity... ..., and assisting with containment, vulnerability management, and compliance activities. The role...Minimum wageFull timeContract workTemporary workWork experience placementRemote work
- AUGUST SCHELL ENTERPRISES, INC. is looking for a Lead Penetration Tester in Annapolis Junction, MD to join a high-performing agile team. The selected candidate will work in a dynamic environment applying advanced cybersecurity expertise to tackle complex challenges and ...
- ...Cyber & Analytics Business Area. You will perform various penetration tests and cyber incident responses, ensuring compliance with security standards across systems. The ideal candidate has a strong background in penetration testing tools and IT security, along with a...Flexible hours
- ...DNI is currently seeking a Senior System Security Engineer (SSE) to support the CPE C3N contract in... ...00-53, Department of Defense (DoD) Risk Management Framework (RMF), and Army policies Perform tactical cyber security vulnerability reviews for computer hardware, systems...Contract workTemporary work
$119.03k - $198.38k
...ever‑changing threat landscape. Through powerful solutions and managed services that simplify complexity, we enable our clients to operate... ...resilience, grow with confidence, and proactively manage to secure success. Work You'll Do Provide Cyber Threat Intelligence...Local area- GEICO is looking for a Staff Engineer with a strong background in software development. This role involves leading engineering teams to provide high-quality technology solutions and requires substantial expertise in programming languages and cloud services. The ideal candidate...
- ...and following when needed. Description: We are seeking a Security Engineer to design, develop, and maintain enterprise security audit... ...summaries and detailed results by SSP and associated devices. Vulnerability and compliance scan summaries and detailed results by SSP...Contract workTemporary workWork experience placementImmediate start
- ...energy affordability, energy security, and turn-key... ...Corporate Infrastructure & Security Engineer to support and develop the company... ...with the Corporate Operations Manager, this role will focus on... ...monitoring platforms. Assist with vulnerability remediation, incident...Remote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Security Engineer - Vulnerability Management. Be the first to apply!
- staff engineer Annapolis, MD
- senior staff systems engineer Annapolis, MD
- engineering aide Annapolis, MD
- software engineer staff Annapolis, MD
- assistant engineer Annapolis, MD
- technology administrator Annapolis, MD
- senior staff engineer Annapolis, MD
- senior application security engineer Annapolis, MD
- offensive security engineer Annapolis, MD
- IT security engineer Annapolis, MD


