Senior Staff Engineer – Cybersecurity Data Protection Engineer (HYBRID)

GEICO3 months ago
Palo Alto, CA, United States
Hybrid
Full-time
Junior Level (1-3 years)

Job Description

Position Overview

At GEICO, we offer a rewarding career where your ambitions are met with endless possibilities. Every day we honor our iconic brand by offering quality coverage to millions of customers and being there when they need us most. We thrive through relentless innovation to exceed our customers’ expectations while making a real impact for our company through our shared purpose. GEICO’s Cybersecurity organization has an exciting opportunity for an accomplished Senior Staff Engineer – Cybersecurity Data Protection Engineering. The selected candidate will play a key role within GEICO’s Cybersecurity Data Security, Protection, and Privacy team with a focus on data protection management. In this role, you will lead efforts to assess vulnerabilities, recommend controls and countermeasures, and mentor other team members while managing the overall data security and protection program.

Key Responsibilities

  • Develop and implement data protection strategies and initiatives, including classification and handling, data access controls, inventory, encryption, and retention.
  • Work closely with stakeholders to enforce data protection policies and respond to regulatory requirements.
  • Develop and maintain data security policies, procedures, and standards, ensuring organization-wide compliance.
  • Create and maintain data inventories and data flows, and manage data sharing controls.
  • Drive the design and implementation of data access controls to ensure only authorized access to sensitive data.
  • Co-develop and implement data retention policies and procedures, ensuring compliance with internal policies and external regulations.
  • Enforce data encryption standards and strategies to secure data at rest and in transit.
  • Lead incident response efforts related to data breaches and work with stakeholders to mitigate impacts.
  • Conduct regular data risk assessments to identify potential vulnerabilities and threats to information systems.
  • Stay updated with developments in cybersecurity to align data security processes with industry best practices.
  • Act as an expert and mentor for other data protection engineers, providing guidance on methodologies and best practices.
  • Manage and supervise the work of other data protection engineers, including reviewing and approving their work.
  • Represent the organization in external meetings with clients, stakeholders, and industry experts.

Required Qualifications

  • Proven experience with data discovery, classification, handling, access, inventory, and retention.
  • Proven experience with data protection technologies such as encryption, tokenization, and data loss prevention tools.
  • Familiarity with programming languages such as Python, Java, or .NET.
  • Experience with designing and implementing data security solutions for enterprise environments.
  • Experience in managing and supervising Data Protection Engineers.
  • Experience in developing and managing data protection programs focused on data discovery, data inventory, data risk assessments, and encryption for both structured and unstructured data.
  • Strong knowledge of cybersecurity laws, regulations, and best practices.
  • Knowledge of data security frameworks, standards, and protocols.
  • Strong understanding of data privacy laws and regulations (e.g., NYDFS, PCI, etc.).
  • Strong analytical and problem-solving skills.
  • Excellent communication and presentation skills.
  • Ability to excel in a fast-paced, startup-like environment.
  • Experience Required: 7+ years in cybersecurity with a focus on data protection and privacy; 4+ years in open-source frameworks; 3+ years in architecture and design; 3+ years with cloud services such as AWS, GCP, or Azure.
  • Education: Bachelor’s degree in Computer Science, Information Systems, or equivalent education or work experience.

Preferred Qualifications

  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • Certified in Risk and Information Systems Control (CRISC)

Benefits & Perks

  • Salary: $115,000.00 - $260,000.00 per year
  • Comprehensive Total Rewards program offering personalized coverage for you and your family’s overall well-being.
  • Market-competitive compensation with a 401K savings plan (6% match from day one), performance incentives, and tuition assistance.
  • Access to additional benefits such as mental healthcare, fertility, and adoption assistance.
  • Workplace flexibility including the GEICO Flex program, which allows you to work from anywhere in the US for up to four weeks per year.

Required Skills

Data Risk Assessment
Programming (Python, Java, .NET)
Team Leadership
Data Encryption
Cybersecurity
Security Policy Development
Data Inventory Management
Data Protection Engineering
Cloud Platforms (AWS, GCP, Azure)
Incident Response