Skip to main contentA logo with &quat;the muse&quat; in dark blue text.
GEICO

Principal Engineer - Application Security

Chevy Chase, MD

GEICO is seeking an experienced Principal Engineer to provide enterprise support for application security in our hybrid, multi-cloud environments. You will proactively and holistically lead and support Application Security activities that guide the design, development, security of code, and code repositories for cloud-hosted and open-source applications. Solutions include CICD integrations, SAST, DAST, IAST, SCA, secure cloud platform engineering, automated threat modeling.

Position Description:

Our Application Security Principal Engineer is a senior level position that reports to the Director of Application Security and works closely with development teams, product teams, other teams across the organization to integrate security into the product lifecycle from design through deployment. The Application Security Principal Engineer is a subject matter expert in defining security requirements, defining secure application security design, performing application security assessments, threat modeling and providing developers with remediation guidance and advice. On any given day, the Application Security Principal Engineer can be pulled in to evaluate a new system, review a proposed application design, or provide guidance on application security/coding best practices.

Want more jobs like this?

Get Software Engineering jobs in Chevy Chase, MD delivered to your inbox every week.

By signing up, you agree to our Terms of Service & Privacy Policy.


Position Responsibilities

As a Principal Engineer, you will:
  • Work independently with developers, system/network engineers, product owners, and other engineers to ensure secure design, development, and implementation of cloud-based applications
  • Define and document secure architecture patterns and anti-patterns
  • Perform security architecture design reviews of our products (primarily cloud)
  • Define security best practices and standards and ensure Product Development teams understand them
  • Provide remediation guidance and recommendations to developers and engineers
  • Serve as a technical advisor and consultant to colleagues and/or GEICO leadership on the implementation of the Cybersecurity application security policy and standards.
  • Provide technical thought leadership for integration decisions, analyzing design constraints and trade-offs in system and security design, and ensuring integrity of GEICO mission objectives, while protecting GEICO assets from cyber threats and vulnerabilities.
  • Work with Product Development teams to help prioritize and validate urgency of mitigation of identified product vulnerabilities and security feature enhancement requests
  • Interface with the Product and Vulnerability Management teams to track security feature enhancement requests
Qualifications:
  • Direct experience working with development teams to define, develop and document secure solutions
  • Experience breaking down complex systems and applications to find flaws with analysis and threat modeling
  • Strong familiarity with common vulnerabilities and attack vectors
  • Knowledge of web service technologies, load balancer services (i.e., Nginx, Cloudflare, F5, etc.) and RESTful APIs
  • Knowledge of ubiquitous encryption technologies (PGP, SSH, SSL, etc.) and common authentication protocols (OpenID Connect, OAUTH, SAML, RADIUS, LDAP, KERBEROS, etc.)
  • Solid understanding of secure network, system, and service design in cloud (Azure, AWS etc.) and conventional environments
  • Understanding and applied use of OWASP Top 10, NIST SP800 Series, NIST CSF, FIPS 140-2, ISO 27001, PCI-DSS, etc.
  • Knowledge of various aspects of a technology architecture like integration, network, and security
  • Advanced understanding and knowledge of application development life cycle methodologies (such as waterfall, spiral, agile software development, rapid prototyping, incremental, synchronize and stabilize, and DevOps/ SecDevOps)
  • Exposure to multiple, diverse security technologies, platforms, and processing environments
  • Strong command of strategic and emerging security/ cloud technology trends, and the practical application of existing and emerging technologies to new and evolving business and operating models.
  • Good understanding of product management, agile principles and development methodologies and capability of supporting agile teams by providing advice and guidance on opportunities, impact, and risks, taking account of technical and architectural debt
  • Experience collaborating closely with senior executives on strategic initiatives
  • A background integrating security testing into the SDLC
  • Experience providing security training to developers
  • Additional programming languages such as Java, Python, Object C
  • Demonstrated experience using DAST and SAST tools and services
  • One or more of the following Cybersecurity certifications are highly desired: Security+, Certified Information System Security Professional (CISSP) or Certified Information Security Manager (CISM)
Experience:
  • 6+ years planning and designing application security, cloud security, systems security, or platform security
  • 5+ of experience in at least two security solution design and development disciplines, including technical or security infrastructure architecture, cloud security, network security management, secure application development or secure cloud development.
  • 4+ years of experience in application and open-source security
  • 3+ years of experience with AWS, GCP, Azure, or another cloud service
  • 2+ years of experience in open-source frameworks
Education
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or equivalent education or work experience
Benefits:

At GEICO, we make sure you have the support and resources to leverage and develop your skills, secure your financial future, and take care of your health and well-being. GEICO continually seeks to provide a workplace where everyone can be their authentic self. To help achieve this goal, we support associate-led Employee Resource Groups that foster a true sense of community. Through GEICO's competitive benefits offerings and various training and development opportunities, we have you covered with our Total Rewards Program * that includes:
  • Premier Medical, Dental and Vision Insurance with no waiting period
  • Paid Vacation, Sick and Parental Leave
  • 401(k) Plan
  • Tuition Assistance including Direct Billing and Reimbursement payment plan options
  • Paid Training, Licensures and Certificates
*Benefits may be different by location. Benefit eligibility requirements vary and may include length of service.

Coverage begins on the date of hire. Must enroll in New Hire Benefits within 30 days of the date of hire coverage to take effect.

GEICO is proud to be an equal opportunity employer. We are committed to cultivating an environment where equal employment opportunities are available to all associates and job applicants regardless of race, color, religious creed, national origin, ancestry, age, gender, pregnancy, sexual orientation, gender identity, marital status, familial status, disability or genetic information, in compliance with applicable federal, state and local law. GEICO celebrates diversity and believes it is critical to our success. As such, we are committed to recruit, develop and retain the most talented individuals to join our team.

#LI-AW1

At this time, GEICO will not sponsor a new applicant for employment authorization for this position.

Benefits:

As an Associate, you'll enjoy our Total Rewards Program * to help secure your financial future and preserve your health and well-being, including:
  • Premier Medical, Dental and Vision Insurance with no waiting period
  • Paid Vacation, Sick and Parental Leave
  • 401(k) Plan
  • Tuition Reimbursement
  • Paid Training and Licensures
*Benefits may be different by location. Benefit eligibility requirements vary and may include length of service.

Coverage begins on the date of hire. Must enroll in New Hire Benefits within 30 days of the date of hire for coverage to take effect.

The equal employment opportunity policy of the GEICO Companies provides for a fair and equal employment opportunity for all associates and job applicants regardless of race, color, religious creed, national origin, ancestry, age, gender, pregnancy, sexual orientation, gender identity, marital status, familial status, disability or genetic information, in compliance with applicable federal, state and local law. GEICO hires and promotes individuals solely on the basis of their qualifications for the job to be filled.

GEICO reasonably accommodates qualified individuals with disabilities to enable them to receive equal employment opportunity and/or perform the essential functions of the job, unless the accommodation would impose an undue hardship to the Company. This applies to all applicants and associates. GEICO also provides a work environment in which each associate is able to be productive and work to the best of their ability. We do not condone or tolerate an atmosphere of intimidation or harassment. We expect and require the cooperation of all associates in maintaining an atmosphere free from discrimination and harassment with mutual respect by and for all associates and applicants.

Client-provided location(s): Chevy Chase, MD, USA
Job ID: geico-R0047257
Employment Type: Full Time

Perks and Benefits

  • Health and Wellness

    • FSA
    • On-Site Gym
    • Health Insurance
    • Dental Insurance
    • Vision Insurance
    • Life Insurance
    • Short-Term Disability
    • Long-Term Disability
  • Parental Benefits

    • Non-Birth Parent or Paternity Leave
    • Birth Parent or Maternity Leave
  • Vacation and Time Off

    • Personal/Sick Days
    • Paid Holidays
    • Paid Vacation
  • Financial and Retirement

    • Relocation Assistance
    • Performance Bonus
    • 401(K)
  • Professional Development

    • Promote From Within
    • Tuition Reimbursement
  • Diversity and Inclusion

    • Diversity, Equity, and Inclusion Program

Company Videos

Hear directly from employees about what it is like to work at GEICO.