> Markdown version of [/jobs/ext/526300-staff-engineer-product-security](https://www.wearedevelopers.com/jobs/ext/526300-staff-engineer-product-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Engineer - Product Security - **Company:** GEICO - **Location:** Richardson, TX, United States - **Experience:** Expert - **Salary:** $110,000.0 - $230,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Microsoft Azure, Information Systems, Computer Programming, Databases, Continuous Integration, DevOps, Github, Python (Programming Language), MongoDB, MySQL, Open Source Technology, Open Web Application Security, PCI Data Security Standards, Rapid Prototyping Process, Secure Coding, Web Application Security, Software Deployment, Software Engineering, SQL Databases, Software Security, Information Technology, Tenable Nessus, Vulnerability Analysis, Golang, Programming Languages - **Published:** June 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=7437a94e65cab7a1 ## About the Role Do you have experience in Tooling?, Do you have a Bachelor's degree?, * CI/CD pipeline experience, specifically ADO pipelines & GitHub Actions are required for this role * Proficiency in programming languages such as Java, Python, or Golang * Experience with security tools such as vulnerability scanners or static code scanning tools * Knowledge of web application security and how to support engineers with managing their security vulnerabilities as a result of the Product Security scanning tools * Strong analytical and problem-solving skills * Excellent communication and collaboration skills * Knowledge of various managed and database technologies like such as Cosmos, SQL, MySQL, MongoDB * Understanding and knowledge of application development life cycle methodologies such as waterfall, rapid prototyping, incremental, and DevOps * Familiar with navigating implementing and supporting vendor tools deployed in an enterprise environment * Understanding and applied use of OWASP Top 10, NIST CSF, PCI-DSS, etc. Experience: * 6+ years of experience in application security, or in a related domain * 6+ years experience with programming languages, including understanding and interacting with CI/CD pipelines for application deployments Education: * Bachelor's degree in Computer Science, Information Systems, or equivalent education or work experience ## Description Our Product Security tooling team is focused on enabling our engineering teams to build and develop code securely, supporting our code and application scanning tools (vendor & open source). We are looking for an experienced Staff Engineer who can help scale out, automate, and support our Tooling applications, specifically our build-time container scanning tooling. The ideal candidate is experienced in understanding and challenging our Security & Engineering organizations on how and where to implement secure code guardrails and security scanning. We are aiming to expand out our coverage of our security scanning tools more broadly within the enterprise, in a more integrated fashion while also navigating quickly-changing and legacy environments across our tech stack., As a Staff Engineer, you will * Own managing our vendor/open source tooling, integrating functionality across multiple technology platforms such as GitHub Enteprise and Azure DevOps * Build out applications and automations to reach our team goals, better integrate across the Tech platforms, and focus on prioritizing the most critical vulns/findings engineering teams should fix * Develop and implement security policies and procedures * Collaborate with development teams to ensure secure coding practices are followed * Stay up to date with the latest security threats and trends * Provide guidance and mentorship to junior engineers * Provide technical leadership to multiple areas and provide technical and thought leadership to the enterprise * Be accountable for the quality, usability, and performance of the solutions, Great Rewards: We offer compensation and benefits built to enhance your physical well-being, mental and emotional health and financial future. * Comprehensive Total Rewards program that offers personalized coverage tailor-made for you and your family's overall well-being. * Financial benefits including market-competitive compensation; a 401K savings plan vested from day one that offers a 6% match; performance and recognition-based incentives; and tuition assistance. * Access to additional benefits like mental healthcare as well as fertility and adoption assistance. * Supports flexibility- We provide workplace flexibility as well as our GEICO Flex program, which offers the ability to work from anywhere in the US for up to four weeks per year. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [MySQL Protocol Features You Should Be Aware Of](https://www.wearedevelopers.com/videos/100267-mysql-protocol-features-you-should-be-aware-of) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)