Third-Party Cyber Risk Management Engineer II

GEICO

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Bethesda, MDPalo Alto, CADallas, TXSeattle, WA
Salary
$60,000–$215,000 / yr
Posted
3 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $158k
This role $138k
$41k most similar roles pay here $234k

This role pays less than 70% of similar roles. Most pay $130,900–$184,925 — the shaded band above. At the midpoint, this role pays about $138k versus about $158k for comparable roles.

Based on 240 similar postings.

Employer

About GEICO

GEICO (Government Employees Insurance Company) is one of the largest auto insurers in the United States, offering affordable auto, home, renters, and other personal insurance products. Industry: Insurance

GEICO currently has 82 open roles on FindRole.

Listed pay typically runs $110,000–$230,000 across 80 roles with salary data.

Most-posted roles

View all roles at GEICO

At a glance

TL;DR · Third-Party Cyber Risk Management Engineer II

The Third-Party Cyber Risk Management - Engineer II joins the Trustworthy Engineering organization on the Third-Party Cyber Risk Management team. This role focuses on managing the third-party ecosystem by performing risk-based security assessments, conducting reassessments, and enforcing secure data-sharing practices for entities accessing company data. Day-to-day responsibilities include maintaining and reconciling records in industry-recognized tools, resolving data gaps across enterprise systems, and tracking remediation status against established SLAs. The role involves collaborating with Legal and Supplier Management to ensure compliance with standards like NIST CSF and ISO 27001. Candidates should possess experience with GRC platforms such as Archer or ServiceNow, and familiarity with reporting tools like Power BI or SQL. The position addresses the critical business problem of securing third-party data flows while potentially utilizing AI and automation to streamline assessment workflows and reporting metrics.

What you'll do

  • Execute third-party security assessments and reassessments using industry-recognized tools following defined standards.
  • Manage the inventory of third parties to ensure all required risk assessments are completed.
  • Reconcile third-party records across multiple systems to identify data gaps and ensure secure data sharing.
  • Track third-party security issues by maintaining records, monitoring remediation status against SLAs, and escalating gaps.
  • Implement configuration items for assessment tools, including inventory attributes, workflow steps, and reporting fields.
  • Produce quarterly and executive-level reports on assessment metrics and issue management.
  • Perform root-cause analysis on data quality issues or defects in third-party records and workflows.
  • Explore AI and automation opportunities to streamline risk assessment workflows and reduce manual effort.

What we're looking for

  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or equivalent education or work experience.
  • 1-2+ years of experience in cybersecurity, IT risk, or third-party/vendor risk management.
  • Experience conducting risk or security assessments in a cybersecurity, IT risk, or vendor risk context.
  • Working knowledge of cybersecurity and data-privacy regulations and standards such as NYDFS or NIST CSF.
  • Familiarity with data security and third-party risk frameworks like ISO 27001, NIST, and CIS.
  • Experience working with GRC, TPCRM, or workflow platforms like Archer or ServiceNow (preferred).
  • Experience with data reconciliation, reporting, or dashboarding tools such as Excel, Power BI, or SQL (preferred).
  • CompTIA Security+ or Cybersecurity Analyst+ certifications are highly desired; CISSP, CISM, CRISC, or CTPRP are encouraged.

More like this

Similar roles

Security Risk Management Specialist II

Affirm

Remote 30 days ago $130,000$180,000
Python Cursor Claude Agentic Coding Platforms AWS GCP Azure Low-code Platforms NIST ISO 27001 SOC 2 PCI DSS GRC Third Party Risk Management Security Governance Automation
3+ yrs exp Remote

Director, Risk Management: Cyber & Third Party Risk

Capital One Financial

McLean, VA +2 7 days ago $209,500$239,100
Third Party Risk Management Information Security Cloud Computing Risk Assessment Enterprise Risk Management CISSP CISM CISA PMP Lean Agile Six Sigma
7+ yrs exp

Cybersecurity Engineer and Risk Analyst

Booz Allen Hamilton

San Diego, CA 56 days ago $69,300$158,000
RMF ACAS STIGing eMASS DevSecOps Network Security System Administration Windows Linux Firewalls Intrusion Prevention Systems Big Data Analytics Configuration Management Data Flow Diagrams Boundary Diagrams Systems Development Lifecycle
3+ yrs exp

Cybersecurity Engineer and Risk Analyst

Booz Allen Hamilton

San Diego, CA 28 days ago $99,000$225,000
RMF ACAS STIG eMASS DevSecOps Vulnerability Assessment Network Security Linux Windows Virtualization Intrusion Prevention Systems Firewalls Big Data Analytics Cybersecurity Policy Systems Development Lifecycle
4+ yrs exp

Cybersecurity Engineer and Risk Analyst

Booz Allen Hamilton

San Diego, CA 28 days ago $69,300$158,000
RMF eMASS ACAS STIG Evaluate-STIG Network Security Big Data Analytics Windows Linux Firewalls Intrusion Prevention Systems Cybersecurity Policy Systems Development Lifecycle Information Technology
4+ yrs exp