Senior Manager Cybersecurity Governance & Assurance

GEICO

California (MD)

Hybrid

USD 120,000 - 260,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

GEICO is seeking a Senior Manager Cybersecurity Governance & Assurance to mature the enterprise governance program. The role partners with Cybersecurity, Technology, Legal, Privacy, Enterprise Risk and Internal Audit to translate requirements into actionable controls and provide leadership with measurable visibility into compliance posture.

The candidate will own the governance operating model, drive policy lifecycle, optimize controls across multi-cloud and data center environments, and lead a

Qualifications

  • 7+ years in cybersecurity governance, risk and compliance, incl. 5+ years leading teams and programs.
  • Experience maturing governance and compliance in large multi-cloud/hybrid env.
  • Knowledge of security frameworks: ISO 27001, NIST 800-series, PCI DSS, NIST CSF, SOX.

Responsibilities

  • Mature the Cyber Governance operating model and governance forums.
  • Advise senior leaders on governance, regulatory obligations, and cyber risk.
  • Lead policy, standard and control lifecycle across organization.
  • Embed compliance into engineering workflows and SDLC.

Skills

Governance
Risk management
Regulatory compliance
Executive communication
Leadership

Education

Bachelor’s degree
CISSP/CISM/CISA/CRISC preferred

Tools

MS Azure
AWS

Job description

## Senior Manager Cybersecurity Governance & AssuranceApply: Hybrid: Palo Alto, CA: Dallas, TX: Bethesda, MD: Seattle, WA: Full time: Posted Today: R0066120**Why Join GEICO?**At GEICO, we offer a rewarding career where your ambitions are met with endless possibilities.Every day we honor our iconic brand by offering quality coverage to millions of customers and being there when they need us most. We thrive on relentless innovation to exceed our customers' expectations while making a real impact on local communities nationwide.Founded in 1936, GEICO is a member of the Berkshire Hathaway family of companies and one of the largest auto insurers in the United States. When you join our company, we want you to feel valued, supported, and proud to work here. That's why we offer the GEICO Pledge: Great Company, Great Culture, Great Rewards, and Great Careers.The Senior Manager of Cyber Governance & Assurance will lead and mature the enterprise cybersecurity governance program, establishing an effective operating model for policies, standards, control governance, cyber risk management and cyber assurance. This leader will partner with Cybersecurity, Technology, Legal, Privacy, Enterprise Risk and Internal Audit to translate regulatory and security requirements into actional controls, drive clear accountability and provide leadership with measurable visibility into compliance posture, control effectiveness and cyber risk. The successful candidate will combine strategic judgment, technical credibility and strong people leadership to influence decision across organizational boundaries and continuously improve how cybersecurity governance operates. **Key Responsibilities*** Own and mature the Cyber Governance operating model, including governance forums, establishing clear decision rights, roles and responsibilities, accountability and escalation paths across Cybersecurity and Tech.* Advise senior leaders on cybersecurity governance, regulatory obligations and material cyber risk; present clear option, recommendations and decisions required.* Lead the cybersecurity policy, standard and control lifecycle from development, and stakeholder review through approval, publication and periodic refresh.* Translate regulatory and cybersecurity requirements into actionable technology standards, controls and engineering requirements.* Ensure cyber security exceptions and acceptances do not introduce aggregated risk and address root cause of cyber systemic exceptions.* Identify systemic control failures to identify root causes and partner with accountable owners to drive enterprise level remediation.* Establish governance for the cybersecurity controls, including ownership, design expectations, evidence requirements, effectiveness monitoring, deficiencies and remediation oversight, hold implementation owners accountable.* Drive control rationalization and harmonization across regulatory frameworks to reduce duplicative controls and create a common enterprise control framework.* Partner with Technology and Engineering teams to embed compliance requirements and automated controls into engineering workflows and the software development cycle.* Define cybersecurity governance KPIs, KRIs and compliance metrics covering compliance posture, control health, remediation progress and emerging risks.* Lead the development and delivery of monthly and quarterly business reviews, translating cybersecurity governance performance, compliance posture, emerging risks and strategic initiatives into executive-level insights, recommendations and actionable decisions.* Partner with Enterprise Risk and accountable risk owners to maintain accurate cyber risk records, escalation material exposure and oversee treatment commitments.* Set governance requirements and priorities for continuous compliance monitoring and automation across multi-cloud and data center environments, partner with engineering teams responsible for delivery.* Manage all cyber issues to closure.* Build, mentor and lead a high-performing governance function, with clear priorities, ownership, coaching, while fostering a culture of accountability, innovation and continuous improvement.* Lead monthly, quarterly annual priorities, resource planning, change adoption and performance management; establish an inclusive, accountable team culture and develop team members.* Influence cross-functional stakeholders, constructively challenge proposed risk decisions and lead complex discussions to resolution without relying on direct authority.**What you will need*** Deep expertise in cybersecurity governance, control frameworks, risk management and regulatory compliance, with the ability to connect requirements to technical implementation.* Demonstrated experience presenting to senior leadership, effectively communication performance, risks and strategic priorities while confidently addressing challenging questions and driving executive alignment.* Demonstrated credibility with senior leaders, translates complex cyber and regulatory matters into business implications, presents clear options and facilitates decision.* Exceptional written and verbal communication, including the ability to lead difficult, high-stakes discussions, challenge constructively and gain alignment without direct authority.* Sound judgement and accountability in ambiguous environments, balancing regulatory obligations, business priorities and risk.* Experience leading and developing technical governance, compliance or security engineering professionals, including performance management and coaching.* Proven delivery of enterprise scale governance transformation, cross functional change and measurable process improvement.* Working technical knowledge of multi-cloud and hybrid/data center security controls: MS Azure and AWS experience preferred. **Qualifications*** 7+ years of progressive experience in cybersecurity governance, risk and compliance, including at least 5 years leading teams and enterprise programs.* Experience establishing or maturing governance and compliance capabilities in large, complex, multi-cloud and hybrid environments.* Strong working knowledge of application security frameworks and standards such as ISO 27001, NIST 800-series, NY DFS, CPPA/CPRA, PCI DSS, NIST CSF, SOX is valuable as applicable to assigned scope.* Experience overseeing cybersecurity audits or regulatory examinations and coordinating control remediation with accountable owners.* Experience with strategic planning, program roadmaps, priorities and resource allocation* Bachelor’s degree in a related field or equivalent professional experience. CISSP, CISM, CISA or CRISC preferred.**Annual Salary**$120,000.00 - $260,000.00The above annual salary range is a general guideline. Multiple factors are taken into consideration to arrive at the final hourly rate/ annual salary to be offered to the selected candidate. Factors include, but are not limited to, the scope and responsibilities of the role, the selected candidate’s work experience, education and training, the work location as well as market and business considerations.GEICO will consider sponsoring a new qualified applicant for employment authorization for this position.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Manager Cybersecurity Governance & Assurance
Senior Manager Cybersecurity Governance & Assurance

Geico • Palo Alto (CA)

On-site
USD 120,000 - 260,000
Senior Manager Cybersecurity Governance & Assurance
Senior Manager Cybersecurity Governance & Assurance

Government Employees Insurance Company • East Palo Alto (CA)

On-site
USD 120,000 - 260,000
Sponsorship for work authorization
Competitive compensation & benefits
Third-Party Cyber Risk Management - Engineer II
Third-Party Cyber Risk Management - Engineer II

GEICO • Maryland

Hybrid
USD 60,000 - 215,000
Senior Director, Cyber Governance & Assurance
Senior Director, Cyber Governance & Assurance

GEICO • California (MD)

Hybrid
USD 120,000 - 260,000
Senior Cyber Governance & Assurance Leader
Senior Cyber Governance & Assurance Leader

Government Employees Insurance Company • East Palo Alto (CA)

On-site
USD 120,000 - 260,000
Sponsorship for work authorization
Competitive compensation & benefits
Cyber Governance & Assurance Leader
Cyber Governance & Assurance Leader

Geico • Palo Alto (CA)

On-site
USD 120,000 - 260,000
Cyber Security Identity Staff Engineer
Cyber Security Identity Staff Engineer

GEICO • Maryland

On-site
USD 110,000 - 230,000
Staff Portfolio Manager, Cybersecurity Operations
Staff Portfolio Manager, Cybersecurity Operations

Geico • Dallas (TX)

On-site
USD 110,000 - 230,000
Senior Staff Engineer - Java [Hybrid]
Senior Staff Engineer - Java [Hybrid]

GEICO • Bethesda (MD), Northern (KY)

Hybrid
USD 130,000 - 260,000
Staff Portfolio Manager, Cybersecurity Operations
Staff Portfolio Manager, Cybersecurity Operations

Cybersecurity Jobs • Seattle (WA)

On-site
USD 110,000 - 230,000
Competitive pay and benefits
Flexible work arrangements
Development programs & certification