GEICO
Senior Cybersecurity Engineer - Cyber Governance (HYBRID)
GEICO, Seattle, Washington, us, 98127
Senior Cybersecurity Engineer - Cyber Governance (HYBRID)
GEICO is hiring a Senior Cybersecurity Engineer - Cyber Governance (HYBRID).
The role leads the design, implementation and continuous improvement of policies, standards and compliance operations to ensure audit readiness, regulatory adherence and evidence automation across multiple cybersecurity domains.
The ideal candidate has deep expertise in security frameworks (NYDFS 500, PCI DSS, NIST CSF, ISO 27001), strong experience with audit evidence collection/management, and a collaborative mindset to work with evidence owners across the organization. Base pay range : $80,000.00/yr - $215,000.00/yr Note:
This range is provided by GEICO. Your actual pay will be based on your skills and experience — talk with your recruiter to learn more. Responsibilities
Assist in maturing the cybersecurity governance program, ensuring adherence to corporate policies and standards, regulatory requirements, and industry frameworks. Drive NY DFS compliance and NIST CSF Maturity Programs. Develop and maintain control framework alignment. Support staff engineers and policy owners to develop, review, and update policies and standards to align with evolving requirements and best practices. Partner with internal teams to drive policy lifecycle management, controls mapping and ensure alignment with enterprise risk management objectives. Conduct assessments against AI standards (e.g., ISO/IEC 42001:2023, 23894, NIST AI 600-1, NIST AI RMF). Assess impact of emerging threats on compliance and coordinate threat-driven policy updates. Ensure controls are mapped across frameworks in the automated governance solution and drive compliance automation validation in partnership with the platform team; assess compliance gaps and guide remediation plans. Audit Readiness & Evidence Management
Coordinate evidence refresh cycles for all applicable frameworks. Validate evidence submissions, ensure timely updates, and document exceptions or remediation plans. Maintain centralized knowledge bases and repositories (e.g., GRC tools, SharePoint, Confluence) to streamline evidence collection and control mapping. Support internal and external audits by providing accurate, complete evidence and narrative explanations. Risk Management & Advisory
Apply a risk-based approach to control evaluation, prioritization, and remediation. Partner with stakeholders to address compliance gaps and track progress toward closure. Provide subject matter expertise on regulatory requirements, compliance trends, and security frameworks. Support continuous improvement through automation, metrics, and reporting dashboards. Collaboration & Enablement
Partner with control owners, internal controls team, and leadership to ensure alignment across business and technical functions. Provide training and guidance to evidence owners on requirements, documentation standards, and deadlines. Communicate clearly with technical and non-technical stakeholders to ensure understanding of compliance obligations. Mentor and guide more junior engineers on the team. Metrics & Reporting
Design and implement cyber governance metrics, KPIs, and executive dashboards to measure security posture, policy compliance, and control effectiveness. Qualifications
Minimum Qualifications 5+ years of experience in cybersecurity governance, risk and compliance (GRC) roles with demonstrated experience in NYDFS 500, PCI DSS, NIST CSF, ISO 27001. Proven experience supporting audit readiness and evidence collection for internal, external, or regulatory audits. Strong organizational skills with the ability to prioritize tasks, maintain attention to detail, and deliver results on or before deadlines. Proven experience fostering cross-functional partnerships and serving as a trusted advisor to evidence owners. Experience using GRC or evidence management tools (e.g., ServiceNow GRC, Archer, Drata, Vanta, SharePoint). Excellent communication and problem-solving skills with the ability to influence and collaborate across diverse teams. Ability to manage multiple work streams simultaneously and prioritize by urgency and impact. Preferred Qualifications Experience in financial services, insurance, or other regulated industries. Knowledge of cloud security compliance across AWS, Azure, and GCP. Familiarity with continuous control monitoring and automation practices. Certifications: CISA, CISM, CRISC, CISSP. Education
Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related discipline; or equivalent work experience. Core Competencies
Strategic and analytical mindset with strong attention to detail. Ability to manage multiple priorities in a dynamic environment. Demonstrated leadership in driving program maturity and continuous improvement. Commitment to collaboration, inclusion, and operational excellence. The above salary range is a general guideline; final offer negotiable based on role scope, experience, location and market conditions. The GEICO Pledge and related benefits are described in the posting and may be subject to change. EEO statements: GEICO is an equal opportunity employer. We hire and promote solely on qualifications for the job. GEICO complies with applicable laws and provides reasonable accommodations where required. Seniority level
Mid-Senior level Employment type
Full-time Job function
Information Technology Industries
#J-18808-Ljbffr
GEICO is hiring a Senior Cybersecurity Engineer - Cyber Governance (HYBRID).
The role leads the design, implementation and continuous improvement of policies, standards and compliance operations to ensure audit readiness, regulatory adherence and evidence automation across multiple cybersecurity domains.
The ideal candidate has deep expertise in security frameworks (NYDFS 500, PCI DSS, NIST CSF, ISO 27001), strong experience with audit evidence collection/management, and a collaborative mindset to work with evidence owners across the organization. Base pay range : $80,000.00/yr - $215,000.00/yr Note:
This range is provided by GEICO. Your actual pay will be based on your skills and experience — talk with your recruiter to learn more. Responsibilities
Assist in maturing the cybersecurity governance program, ensuring adherence to corporate policies and standards, regulatory requirements, and industry frameworks. Drive NY DFS compliance and NIST CSF Maturity Programs. Develop and maintain control framework alignment. Support staff engineers and policy owners to develop, review, and update policies and standards to align with evolving requirements and best practices. Partner with internal teams to drive policy lifecycle management, controls mapping and ensure alignment with enterprise risk management objectives. Conduct assessments against AI standards (e.g., ISO/IEC 42001:2023, 23894, NIST AI 600-1, NIST AI RMF). Assess impact of emerging threats on compliance and coordinate threat-driven policy updates. Ensure controls are mapped across frameworks in the automated governance solution and drive compliance automation validation in partnership with the platform team; assess compliance gaps and guide remediation plans. Audit Readiness & Evidence Management
Coordinate evidence refresh cycles for all applicable frameworks. Validate evidence submissions, ensure timely updates, and document exceptions or remediation plans. Maintain centralized knowledge bases and repositories (e.g., GRC tools, SharePoint, Confluence) to streamline evidence collection and control mapping. Support internal and external audits by providing accurate, complete evidence and narrative explanations. Risk Management & Advisory
Apply a risk-based approach to control evaluation, prioritization, and remediation. Partner with stakeholders to address compliance gaps and track progress toward closure. Provide subject matter expertise on regulatory requirements, compliance trends, and security frameworks. Support continuous improvement through automation, metrics, and reporting dashboards. Collaboration & Enablement
Partner with control owners, internal controls team, and leadership to ensure alignment across business and technical functions. Provide training and guidance to evidence owners on requirements, documentation standards, and deadlines. Communicate clearly with technical and non-technical stakeholders to ensure understanding of compliance obligations. Mentor and guide more junior engineers on the team. Metrics & Reporting
Design and implement cyber governance metrics, KPIs, and executive dashboards to measure security posture, policy compliance, and control effectiveness. Qualifications
Minimum Qualifications 5+ years of experience in cybersecurity governance, risk and compliance (GRC) roles with demonstrated experience in NYDFS 500, PCI DSS, NIST CSF, ISO 27001. Proven experience supporting audit readiness and evidence collection for internal, external, or regulatory audits. Strong organizational skills with the ability to prioritize tasks, maintain attention to detail, and deliver results on or before deadlines. Proven experience fostering cross-functional partnerships and serving as a trusted advisor to evidence owners. Experience using GRC or evidence management tools (e.g., ServiceNow GRC, Archer, Drata, Vanta, SharePoint). Excellent communication and problem-solving skills with the ability to influence and collaborate across diverse teams. Ability to manage multiple work streams simultaneously and prioritize by urgency and impact. Preferred Qualifications Experience in financial services, insurance, or other regulated industries. Knowledge of cloud security compliance across AWS, Azure, and GCP. Familiarity with continuous control monitoring and automation practices. Certifications: CISA, CISM, CRISC, CISSP. Education
Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related discipline; or equivalent work experience. Core Competencies
Strategic and analytical mindset with strong attention to detail. Ability to manage multiple priorities in a dynamic environment. Demonstrated leadership in driving program maturity and continuous improvement. Commitment to collaboration, inclusion, and operational excellence. The above salary range is a general guideline; final offer negotiable based on role scope, experience, location and market conditions. The GEICO Pledge and related benefits are described in the posting and may be subject to change. EEO statements: GEICO is an equal opportunity employer. We hire and promote solely on qualifications for the job. GEICO complies with applicable laws and provides reasonable accommodations where required. Seniority level
Mid-Senior level Employment type
Full-time Job function
Information Technology Industries
#J-18808-Ljbffr