
Staff Engineer – Platform Security Engineering – Encryption and Tokenization
GEICO
full-time
Posted on:
Location Type: Hybrid
Location: Chevy Chase • California • Maryland • United States
Visit company websiteExplore more
Salary
💰 $110,000 - $230,000 per year
Job Level
Tech Stack
About the role
- Lead the design, development, and evolution of encryption, tokenization, and key management solutions within a defined platform or product domain.
- Drive hands‑on implementation of secure data protection capabilities, contributing directly to production‑ready systems while setting technical direction for the team.
- Ensure the quality, reliability, and operational excellence of encryption and tokenization services, including high availability, disaster recovery, observability, and auditable logging.
- Partner closely with compliance, security, data governance, and application teams to ensure cryptographic solutions align with company policies and regulatory requirements.
- Contribute to architectural decisions by proposing scalable, resilient designs for key management systems and data protection workflows.
- Apply knowledge of modern cryptography trends and standards to improve platform security and inform technical decisions.
- Provide technical mentorship and guidance to engineers on the team, helping raise the bar on secure coding, design quality, and operational practices.
- Collaborate with product and engineering stakeholders to integrate encryption and tokenization solutions that support business and platform goals.
- Identify opportunities to improve performance, cost efficiency, and developer experience within the encryption and key management ecosystem.
Requirements
- Strong understanding of cryptographic encryption, tokenization, and Key Management Systems (KMS).
- Experience designing and implementing secure, scalable solutions for data at rest encryption, using open-source cryptographic libraries and protocols (e.g., FPE, AEAD).
- Strong software engineering skills, with experience building production grade services (Go preferred).
- Working knowledge of key management technologies and libraries, such as Google Tink, PKCS#11, JCE , and OpenSSL .
- Experience operating stateful systems such as PostgreSQL, including replication and reliability considerations.
- Proven problem-solving skills with a security first mindset and proactive approach to risk mitigation.
- Experience applying site reliability engineering (SRE) practices, including monitoring, alerting, and incident response (Grafana, Prometheus, Open Telemetry , eBPF ).
- Experience building and maintaining CI/CD pipelines and infrastructure as code (e.g., Bazel, Terraform, Argo CD/Workflows/Rollouts).
- Bachelor’s degree in computer science, Information Systems, or equivalent work experience with a focus on security and cryptography.
Benefits
- Comprehensive Total Rewards program that offers personalized coverage tailor-made for you and your family’s overall well-being.
- Financial benefits including market-competitive compensation; a 401K savings plan vested from day one that offers a 6% match; performance and recognition-based incentives; and tuition assistance.
- Access to additional benefits like mental healthcare as well as fertility and adoption assistance.
- Supports flexibility- We provide workplace flexibility as well as our GEICO Flex program, which offers the ability to work from anywhere in the US for up to four weeks per year.
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
cryptographic encryptiontokenizationKey Management Systems (KMS)secure data protectionproduction grade servicesopen-source cryptographic librariesdata at rest encryptionsite reliability engineering (SRE)CI/CD pipelinesinfrastructure as code
Soft Skills
problem-solvingproactive risk mitigationtechnical mentorshipcollaborationcommunication
Certifications
Bachelor’s degree in computer scienceBachelor’s degree in Information Systems