GEICO

Staff Engineer - Platform Security Engineering – Encryption and Tokenization

Chevy Chase, MD Full time

At GEICO, we offer a rewarding career where your ambitions are met with endless possibilities. 

Every day we honor our iconic brand by offering quality coverage to millions of customers and being there when they need us most. We thrive through relentless innovation to exceed our customers’ expectations while making a real impact for our company through our shared purpose. 

When you join our company, we want you to feel valued, supported and proud to work here. That’s why we offer The GEICO Pledge: Great Company, Great Culture, Great Rewards and Great Careers.

At GEICO, we offer a rewarding career where your ambitions are met with endless possibilities. 

Every day we honor our iconic brand by offering quality coverage to millions of customers and being there when they need us most. We thrive through relentless innovation to exceed our customers’ expectations while making a real impact for our company through our shared purpose. 

When you join our company, we want you to feel valued, supported, and proud to work here. That’s why we offer The GEICO Pledge: Great Company, Great Culture, Great Rewards, and Great Careers. 

 

GEICO’s Platform Security Engineering organization has an exciting opportunity for an accomplished Staff Engineer – Platform Security Engineering – Encryption and Tokenization. This individual will be crucial in the design, implementation, and maintenance of a robust Encryption and Tokenization platform, ensuring the protection of sensitive data throughout the organization. 

 

Position Description: 

As a Staff Engineer, you will work closely with engineers and partner teams to design, build, and evolve secure data protection platforms, enhancing existing systems and applying your expertise in encryption and tokenization to solve complex technical problems. You will lead the design and delivery of key components within the platform security domain, contributing directly to production‑ready implementations while helping shape technical direction, execution plans, and engineering practices that enable reliable product delivery and support new platform capabilities. 

 

 

Position Responsibilities 

As a Staff Engineer, you will: 

  • Lead the design, development, and evolution of encryption, tokenization, and key management solutions within a defined platform or product domain. 

  • Drive hands‑on implementation of secure data protection capabilities, contributing directly to production‑ready systems while setting technical direction for the team. 

  • Ensure the quality, reliability, and operational excellence of encryption and tokenization services, including high availability, disaster recovery, observability, and auditable logging. 

  • Partner closely with compliance, security, data governance, and application teams to ensure cryptographic solutions align with company policies and regulatory requirements. 

  • Contribute to architectural decisions by proposing scalable, resilient designs for key management systems and data protection workflows. 

  • Apply knowledge of modern cryptography trends and standards to improve platform security and inform technical decisions. 

  • Provide technical mentorship and guidance to engineers on the team, helping raise the bar on secure coding, design quality, and operational practices. 

  • Collaborate with product and engineering stakeholders to integrate encryption and tokenization solutions that support business and platform goals. 

  • Identify opportunities to improve performance, cost efficiency, and developer experience within the encryption and key management ecosystem 

 

Qualifications 

  • Strong understanding of cryptographic encryption, tokenization, and Key Management Systems (KMS). 

  • Experience designing and implementing secure, scalable solutions for data at rest encryption, using open-source cryptographic libraries and protocols (e.g., FPE, AEAD). 

  • Strong software engineering skills, with experience building production grade services (Go preferred). 

  • Working knowledge of key management technologies and libraries, such as Google Tink, PKCS#11, JCE, and OpenSSL. 

  • Experience operating stateful systems such as PostgreSQL, including replication and reliability considerations. 

  • Proven problem-solving skills with a security first mindset and proactive approach to risk mitigation. 

  • Experience applying site reliability engineering (SRE) practices, including monitoring, alerting, and incident response (Grafana, Prometheus, Open Telemetry, eBPF). 

  • Experience building and maintaining CI/CD pipelines and infrastructure as code (e.g., Bazel, Terraform, Argo CD/Workflows/Rollouts). 

  • Strong communication skills, with the ability to explain technical concepts clearly to engineers and partner teams. 

  • Familiarity with hardware security modules (HSMs) and cryptography standards. 

 

Experience: 

  • 6+ years of experience in security or software engineering with a focus on encryption, tokenization, key management, or cryptography. 

  • 3+ years of experience contributing to system design, architecture, and security focused solutions.focused solutions. 

  • Experience working with opensource security or cryptography frameworks.source security or cryptography frameworks 

  • Experience building and operating systems in cloud environments (AWS, GCP, Azure preferred). 

 

Education: 

Bachelor’s degree in computer science, Information Systems, or equivalent work experience with a focus on security and cryptography.

#LI-RP2


 

Annual Salary

$110,000.00 - $230,000.00

The above annual salary range is a general guideline. Multiple factors are taken into consideration to arrive at the final hourly rate/ annual salary to be offered to the selected candidate. Factors include, but are not limited to, the scope and responsibilities of the role, the selected candidate’s work experience, education and training, the work location as well as market and business considerations.


 

GEICO will consider sponsoring a new qualified applicant for employment authorization for this position.


 

The GEICO Pledge:

Great Company: At GEICO, we help our customers through life’s twists and turns. Our mission is to protect people when they need it most and we’re constantly evolving to stay ahead of their needs.

We’re an iconic brand that thrives on innovation, exceeding our customers’ expectations and enabling our collective success. From day one, you’ll take on exciting challenges that help you grow and collaborate with dynamic teams who want to make a positive impact on people’s lives.

Great Careers: We offer a career where you can learn, grow, and thrive through personalized development programs, created with your career – and your potential – in mind.  You’ll have access to industry leading training, certification assistance, career mentorship and coaching with supportive leaders at all levels.

Great Culture: We foster an inclusive culture of shared success, rooted in integrity, a bias for action and a winning mindset. Grounded by our core values, we have an an established culture of caring, inclusion, and belonging, that values different perspectives. Our teams are led by dynamic, multi-faceted teams led by supportive leaders, driven by performance excellence and unified under a shared purpose.

As part of our culture, we also offer employee engagement and recognition programs that reward the positive impact our work makes on the lives of our customers.

Great Rewards: We offer compensation and benefits built to enhance your physical well-being, mental and emotional health and financial future.

  • Comprehensive Total Rewards program that offers personalized coverage tailor-made for you and your family’s overall well-being.
  • Financial benefits including market-competitive compensation; a 401K savings plan vested from day one that offers a 6% match; performance and recognition-based incentives; and tuition assistance.
  • Access to additional benefits like mental healthcare as well as fertility and adoption assistance.
  • Supports flexibility- We provide workplace flexibility as well as our GEICO Flex program, which offers the ability to work from anywhere in the US for up to four weeks per year.

The equal employment opportunity policy of the GEICO Companies provides for a fair and equal employment opportunity for all associates and job applicants regardless of race, color, religious creed, national origin, ancestry, age, gender, pregnancy, sexual orientation, gender identity, marital status, familial status, disability or genetic information, in compliance with applicable federal, state and local law. GEICO hires and promotes individuals solely on the basis of their qualifications for the job to be filled.

GEICO reasonably accommodates qualified individuals with disabilities to enable them to receive equal employment opportunity and/or perform the essential functions of the job, unless the accommodation would impose an undue hardship to the Company. This applies to all applicants and associates. GEICO also provides a work environment in which each associate is able to be productive and work to the best of their ability. We do not condone or tolerate an atmosphere of intimidation or harassment. We expect and require the cooperation of all associates in maintaining an atmosphere free from discrimination and harassment with mutual respect by and for all associates and applicants.