Staff Engineer – Platform Security Engineering – Encryption and Tokenization

GEICO
US
Remote

Job Description

Position Description

As a Staff Engineer, you will work closely with engineers and partner teams to design, build, and evolve secure data protection platforms, enhancing existing systems and applying expertise in encryption and tokenization to solve complex technical problems. You will lead the design and delivery of key components within the platform security domain, contributing directly to production‑ready implementations while shaping technical direction, execution plans, and engineering practices that enable reliable product delivery and support new platform capabilities.

Position Responsibilities

  • Lead the design, development, and evolution of encryption, tokenization, and key management solutions within a defined platform or product domain.
  • Drive hands‑on implementation of secure data protection capabilities, contributing directly to production‑ready systems while setting technical direction for the team.
  • Ensure the quality, reliability, and operational excellence of encryption and tokenization services, including high availability, disaster recovery, observability, and auditable logging.
  • Partner closely with compliance, security, data governance, and application teams to ensure cryptographic solutions align with company policies and regulatory requirements.
  • Contribute to architectural decisions by proposing scalable, resilient designs for key management systems and data protection workflows.
  • Apply knowledge of modern cryptography trends and standards to improve platform security and inform technical decisions.
  • Provide technical mentorship and guidance to engineers on the team, helping raise the bar on secure coding, design quality, and operational practices.
  • Collaborate with product and engineering stakeholders to integrate encryption and tokenization solutions that support business and platform goals.
  • Identify opportunities to improve performance, cost efficiency, and developer experience within the encryption and key management ecosystem.

Qualifications

  • Strong understanding of cryptographic encryption, tokenization, and key‑management systems.
  • Experience designing and implementing secure, scalable solutions for data at rest encryption, using open‑source cryptographic libraries and protocols (e.g., FPE, AEAD).
  • Strong software engineering skills, with experience building production‑grade services (Go preferred).
  • Working knowledge of key‑management technologies and libraries, such as Google Tink, PKCS#11, JCE, and OpenSSL.
  • Experience operating stateful systems such as PostgreSQL, including replication and reliability considerations.
  • Proven problem‑solving skills with a security‑first mindset and proactive approach to risk mitigation.
  • Experience applying site reliability engineering practices, including monitoring, alerting, and incident response (Grafana, Prometheus, Open Telemetry, eBPF).
  • Experience building and maintaining CI/CD pipelines and infrastructure‑as‑code (e.g., Bazel, Terraform, Argo CD/Workflows/Rollouts).
  • Strong communication skills, with the ability to explain technical concepts clearly to engineers and partner teams.
  • Familiarity with hardware security modules (HSMs) and cryptography standards.

Experience

  • 6+ years of experience in security or software engineering with a focus on encryption, tokenization, key management, or cryptography.
  • 3+ years of experience contributing to system design, architecture, and security‑focused solutions.
  • Experience working with open‑source security or cryptography frameworks.
  • Experience building and operating systems in cloud environments (AWS, GCP, Azure preferred).

Education

Bachelor’s degree in computer science, information systems, or equivalent work experience with a focus on security and cryptography.

Annual Salary

$110,000.00 – $230,000.00 (general guideline; final offer considers role scope, experience, education, location, and market factors).

Equal Employment Opportunity Statement

The equal employment opportunity policy of the GEICO Companies provides for a fair and equal employment opportunity for all associates and job applicants regardless of race, color, religious creed, national origin, ancestry, age, gender, pregnancy, sexual orientation, gender identity, marital status, familial status, disability, or genetic information, in compliance with applicable federal, state, and local law. GEICO hires and promotes individuals solely on the basis of their qualifications for the job to be filled. GEICO reasonably accommodates qualified individuals with disabilities to enable them to receive equal employment opportunity and/or perform the essential functions of the job, unless the accommodation would impose an undue hardship to the Company. GEICO also provides a work environment in which each associate is able to be productive and work to the best of their ability. We do not condone or tolerate an atmosphere of intimidation or harassment. We expect and require the coopera

Skills & Requirements

Technical Skills

EncryptionTokenizationKey ManagementData ProtectionCryptographyGoPostgreSQLMonitoringCI/CDInfrastructure-as-Code

Salary

$110,000+

year

Employment Type

FULL TIME

Level

mid

Posted

4/8/2026

Apply Now

You will be redirected to GEICO's application portal.