Staff Engineer – Vulnerability Management Automation (Platform and Tools - VMs)

GEICO

Actively hiring
Remote (Md Bethesda Office, US) Posted 104 days ago $110,000$230,000 / year

At a glance

AI generated

TL;DR

GEICO's Platform and Tools - VMs team is hiring a Staff Engineer to lead the architecture, development, and operation of large-scale automation for vulnerability management and OS patch orchestration on Kubernetes. This role involves designing APIs, event-driven pipelines, and controllers that ensure diverse fleets remain current and compliant with minimal downtime. The ideal candidate will work closely with Platform/SRE, Security, and application teams to deliver reliable platforms and tooling that transform manual workflows into self-service solutions. Key responsibilities include defining technical roadmaps, establishing standards for scanning and remediation, mentoring engineers, and driving adoption of best practices across the organization. Candidates should have a strong background in software engineering, experience with vulnerability scanners like Tenable/Nessus and Qualys, proficiency in configuration management tools such as Ansible and Terraform, and expertise in cloud services and Kubernetes.

Skills

Python Go Kubernetes Terraform Ansible Puppet Chef Salt Prometheus Grafana AWS Azure OpenStack CVSS KEV EPSS CIS STIG SLO CI/CD Kafka SNS SQS PubSub PostgreSQL Redis OAuth OpenTelemetry

What you'll do

  • Define and execute the technical roadmap for vulnerability management platforms.
  • Design and implement services for asset enrichment, risk scoring, and intelligent targeting.
  • Build controllers/schedulers for maintenance windows with automated backoff/rollback mechanisms.
  • Integrate scanner data from Tenable/Nessus, Qualys, Rapid7 into unified pipelines with deduplication.
  • Drive adoption of best practices for scanning, prioritization, and safe remediation across teams.

What we're looking for

  • 8+ years of professional software or platform engineering experience with automation at scale.
  • Deep knowledge and hands-on experience in Linux and Windows Server administration and patching.
  • Proficiency with vulnerability scanners (Tenable/Nessus, Qualys, Rapid7) and risk models (CVSS, KEV).
  • Experience with configuration management tools (Ansible/Puppet/Chef/Salt) and IaC frameworks (Terraform).
  • Solid understanding of cloud services (AWS/Azure/GCP), Kubernetes, and event-driven data pipelines.
  • Strong documentation, communication, and stakeholder management skills.

Market check

Salary context

This $110,000–$230,000 range sits above 34% of similar postings on FindRole.

Peer median band

$134,800$244,000

Median floor and ceiling across peers.

Typical midpoint (25–75%)

$168,500$214,500

Middle half of comparable postings.

Based on 240 comparable postings.

* 240 is the maximum number of comparable postings sampled.

Employer

About GEICO

GEICO (Government Employees Insurance Company) is one of the largest auto insurers in the United States, offering affordable auto, home, renters, and other personal insurance products. Industry: Insurance

GEICO currently has 128 open roles on FindRole.

Listed pay typically runs $110,000–$230,000 across 128 roles with salary data.

Most-posted roles

View all roles at GEICO

More like this

Similar roles

Staff Engineer – CMaaS (Platform and Tools - VMs)

GEICO

Remote (Md Bethesda Office, US) 104 days ago $110,000$230,000
Terraform Ansible Kubernetes Python Docker Git CI/CD AWS GCP Azure Linux Windows Puppet Chef SaltStack Prometheus Grafana Java TypeScript
Remote

Staff Engineer – CMaaS (Platform and Tools - VMs)

GEICO

Remote (Md Bethesda Office, US) 104 days ago $110,000$230,000
Terraform Kubernetes Ansible Python Git CI/CD AWS Docker Puppet Chef Linux Windows Go Typescript Java Azure OpenStack GCP CIS Benchmarks NIST SP 800-53 DISA STIGs PCI DSS
Remote

Staff Engineer - Full Stack Applications (HYBRID)

GEICO

Remote (Wa Remote Zone 1, US) 29 days ago $100,000$230,000
Python C# .Net Java C++ SQL NoSQL Docker Kubernetes Azure React Angular DevOps PowerShell ActiveDirectory WindowsAuthentication SAML OAuth AzureDevOps Visio RESTAPIs Microservices AWS GCP
Remote