Staff Engineer – Vulnerability Management Automation (Platform and Tools - VMs)

GEICO

Actively hiring
Remote (Md Bethesda Office, US) Posted 104 days ago $110,000$230,000 / year

At a glance

AI generated

TL;DR

GEICO's Platform and Tools - VMs team is hiring a Staff Engineer to lead the architecture, build, and operation of large-scale automation for vulnerability management and OS patch orchestration on Kubernetes. This role involves designing APIs, event-driven pipelines, and controllers that ensure diverse fleets remain current and compliant with minimal downtime. The ideal candidate will work closely with Platform/SRE, Security, and application teams to deliver reliable platforms and tooling that transform manual workflows into self-service solutions. Key responsibilities include defining technical roadmaps, establishing standards for vulnerability management, mentoring engineers, and driving innovation through standardization and automation. Candidates should have a strong background in software engineering, experience with cloud services, and proficiency in Python or Go, along with hands-on knowledge of Linux and Windows Server administration and patching in enterprise environments.

Skills

Python Go Kubernetes Terraform Ansible Puppet Chef Salt Prometheus Grafana AWS Azure GCP OpenTelemetry CVSS KEV EPSS Tenable Nessus Qualys Rapid7 Packer Helm Kustomize CI/CD

What you'll do

  • Define and execute the technical strategy for vulnerability management platforms.
  • Design and implement services for asset enrichment, risk scoring, and intelligent targeting.
  • Build controllers/schedulers for maintenance windows with automated backoff/rollback features.
  • Integrate scanner data from Tenable/Nessus, Qualys, Rapid7 into unified pipelines.
  • Drive standardization and automation to reduce operational overhead across engineering teams.

What we're looking for

  • 8+ years of professional software or platform engineering experience with automation at scale.
  • Deep knowledge and hands-on experience in Linux and Windows Server administration and patching.
  • Proficiency with vulnerability scanners (Tenable/Nessus, Qualys, Rapid7) and risk models (CVSS, KEV).
  • Experience with configuration management tools (Ansible/Puppet/Chef/Salt) and IaC frameworks (Terraform).
  • Strong background in cloud services (AWS/Azure/GCP), containers/Kubernetes, and image pipelines.
  • Solid understanding of observability practices (OpenTelemetry/Prometheus/Grafana) and SLO mindset.

Market check

Salary context

This $110,000–$230,000 range sits above 34% of similar postings on FindRole.

Peer median band

$134,800$244,000

Median floor and ceiling across peers.

Typical midpoint (25–75%)

$168,500$214,500

Middle half of comparable postings.

Based on 240 comparable postings.

* 240 is the maximum number of comparable postings sampled.

Employer

About GEICO

GEICO (Government Employees Insurance Company) is one of the largest auto insurers in the United States, offering affordable auto, home, renters, and other personal insurance products. Industry: Insurance

GEICO currently has 128 open roles on FindRole.

Listed pay typically runs $110,000–$230,000 across 128 roles with salary data.

Most-posted roles

View all roles at GEICO

More like this

Similar roles

Staff Engineer – CMaaS (Platform and Tools - VMs)

GEICO

Remote (Md Bethesda Office, US) 104 days ago $110,000$230,000
Terraform Ansible Kubernetes Python Docker Git CI/CD AWS GCP Azure Linux Windows Puppet Chef SaltStack Prometheus Grafana Java TypeScript
Remote

Staff Engineer – CMaaS (Platform and Tools - VMs)

GEICO

Remote (Md Bethesda Office, US) 104 days ago $110,000$230,000
Terraform Kubernetes Ansible Python Git CI/CD AWS Docker Puppet Chef Linux Windows Go Typescript Java Azure OpenStack GCP CIS Benchmarks NIST SP 800-53 DISA STIGs PCI DSS
Remote

Staff Engineer - Full Stack Applications (HYBRID)

GEICO

Remote (Wa Remote Zone 1, US) 29 days ago $100,000$230,000
Python C# .Net Java C++ SQL NoSQL Docker Kubernetes Azure React Angular DevOps PowerShell ActiveDirectory WindowsAuthentication SAML OAuth AzureDevOps Visio RESTAPIs Microservices AWS GCP
Remote