Senior Engineer - Product/AI Security

Senior
CompanyGovernment Employees Insurance Company
LocationBethesda, MD, Palo Alto, CA, Dallas, TX, Seattle, WA
CategorySecurity
SenioritySenior
Workplace-
Posted2026-09-22
Estimated salary$13K - $20K (a market estimate, not the employer's figure)
Viaworkday

Description

Why Join GEICO?

At GEICO, we offer a rewarding career where your ambitions are met with endless possibilities.

Every day we honor our iconic brand by offering quality coverage to millions of customers and being there when they need us most. We thrive on relentless innovation to exceed our customers' expectations while making a real impact on local communities nationwide.

Founded in 1936, GEICO is a member of the Berkshire Hathaway family of companies and one of the largest auto insurers in the United States. When you join our company, we want you to feel valued, supported, and proud to work here. That's why we offer the GEICO Pledge: Great Company, Great Culture, Great Rewards, and Great Careers.

GEICO is seeking a Senior Security Engineer to strengthen the security of AI-enabled products and the engineering platforms that support them. This role combines product security judgment with hands-on software development.

The engineer will assess designs, review code, build security automation, and partner with engineering and product teams to translate business needs and security requirements into practical, production-ready solutions.

The successful candidate operates effectively with high-level direction, clarifies ambiguous problems, prioritizes competing work, and owns deliverables through completion. This is a Senior Engineer role focused on vital team-level contributions and technical leadership within the team, rather than enterprise-wide architecture ownership.

What You Will Do

  • Provide technical leadership within the team for AI security, product security, secure design, and security engineering work.
  • Plan, estimate, prioritize, and deliver engineering work to schedule while managing multiple concurrent priorities and context switches.
  • Design, build, test, deploy, and troubleshoot production-ready security services, integrations, automation, and developer tooling.
  • Perform threat modeling and security architecture reviews for AI-enabled applications, services, APIs, data flows, agentic workflows, and supporting platforms.
  • Review code and designs for authentication, authorization, role-based access control, input validation, data protection, logging, error handling, database access, and other security concerns.
  • Translate business needs, customer feedback, and security requirements into clear technical requirements, implementation plans, and measurable outcomes.
  • Use data and risk context to recommend priorities and make sound design or configuration decisions, with attention to security, compliance, privacy, reliability, and customer data handling.
  • Work across engineering, product, platform, risk, and cybersecurity teams to remove blockers, resolve issues, and drive agreed actions to completion.
  • Proactively identify process, tooling, and control gaps, then implement practical improvements that reduce manual effort and strengthen security outcomes.
  • Contribute significantly to design, code, security, observability, performance, and operational-readiness reviews using established architecture and engineering guidance.
  • Document technical decisions, operating procedures, support guidance, and lessons learned so solutions can be maintained and improved by the team.
  • Help teammates overcome technical obstacles and share knowledge through reviews, pairing, technical discussions, and clear documentation.

AI and Product Security Focus

  • Assess security risks associated with AI models, agents, prompts, retrieval-augmented generation, model context protocols, tools, data sources, memory, and downstream actions.
  • Apply secure-by-design practices to AI-enabled systems, including least privilege, trustworthy identity, authorization boundaries, input and output controls, secrets protection, audit logging, data governance, and resilient failure handling.
  • Build or integrate automated safeguards, evaluation workflows, security tests, and monitoring that help teams identify and reduce AI and application security risk throughout the development lifecycle.
  • Partner with developers to provide actionable remediation guidance and validate that security issues are addressed effectively.

Required Qualifications

  • Solid professional experience in software engineering, security engineering, product security, application security, or a related technical field.
  • Hands-on experience writing, reviewing, testing, and troubleshooting code, with strong proficiency in Python or a comparable modern programming language.
  • Experience with full-stack or platform development using tools and technologies such as GitHub, Git, terminal and CLI workflows, APIs, relational databases such as PostgreSQL, and automated testing.
  • Practical experience conducting threat modeling, secure design reviews, architecture reviews, or secure code reviews.
  • Working knowledge of common application and API security risks, secure authentication and authorization patterns, input validation, logging, error handling, database security, and secure SDLC practices.
  • Ability to organize complex work, create realistic project plans, manage dependencies, communicate status and risks, and drive work to completion.
  • Ability to make progress with incomplete information, ask effective clarifying questions, and apply sound engineering judgment under ambiguity.
  • Strong written and verbal communication skills for technical and non-technical audiences.
  • Ability to listen to different perspectives, incorporate feedback, and confidently explain a well-reasoned recommendation.
  • Experience integrating AI-assisted development practices into the software development lifecycle while retaining accountability for architecture, technical decisions, testing, security, and operational readiness.
  • Proven ability to validate AI-generated outputs, identify inaccurate or insecure recommendations, and ensure resulting code meets expectations for security, quality, maintainability, reliability, testability, and compliance.
  • Strong portfolio of hands-on engineering work demonstrating effective use of AI-enabled development capabilities, including code generation, code review, debugging, refactoring, test generation, documentation, and engineering automation.
  • Demonstrated track record of leveraging AI-assisted software development tools and workflows to design, develop, test, troubleshoot, and deliver production-quality software solutions.
  • Experience working in an Agentic Development Environment where AI assistants or coding agents can inspect project context, propose or modify code, generate tests, summarize repositories, create pull requests, and support iterative debugging while the engineer remains accountable for correctness, security, and maintainability.
  • Hands-on familiarity with modern AI-enabled developer tools and workflows such as Cursor, Claude Code, GitHub Copilot, GitHub pull request automation, AI-assisted code review, repository-aware chat, terminal-based coding agents, and secure prompt/context management for engineering tasks.

Preferred Qualifications

  • Experience building or securing generative AI, agentic AI, RAG, MCP-based integrations, or AI-enabled developer workflows.
  • Experience with Python application frameworks, data validation libraries such as Pydantic, PostgreSQL, cloud services, containers, CI/CD, and infrastructure automation.
  • Experience integrating security testing and controls into engineering workflows and developer tooling.
  • Familiarity with product security, cloud security, API security, threat modeling methodologies, and security or compliance frameworks relevant to enterprise environments.
  • Experience balancing near-term delivery with maintainability, operational readiness, and longer-term improvement opportunities.
  • Experience designing guardrails, evaluation frameworks, security controls, and governance mechanisms for AI-generated code and AI-assisted engineering workflows.
  • Experience building, ext