We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
Remote New

Governance Engineer II - Remote

CSAA
401(k), remote work
United States, North Carolina
Oct 06, 2026

External candidates: In order for your application to be correctly processed please sign-in before you apply

Internal candidates: Please go to Workday and click "Find Jobs" link under Career

Thank you for considering opportunities with us!

Job Title

Governance Engineer II - Remote

Requisition Number

R7942 Governance Engineer II - Remote (Open)

Location

Arizona - Home Teleworkers

Additional Locations

Alabama - Home Teleworkers, Alabama - Home Teleworkers, Arkansas - Home Teleworkers, California - Home Teleworkers, Colorado - Home Teleworkers, Connecticut - Home Teleworkers, Delaware - Home Teleworker, District of Columbia - Home Teleworkers, Florida - Home Teleworkers, Georgia - Home Teleworkers, Idaho - Home Teleworkers, Illinois - Home Teleworkers, Indiana - Home Teleworkers, Iowa - Home Teleworkers, Kansas - Home Teleworker, Kentucky - Home Teleworkers, Louisiana - Home Teleworkers, Maine Home Teleworkers, Maryland - Home Teleworkers, Massachusetts - Home Teleworkers, Michigan - Home Teleworkers, Minnesota - Home Teleworkers, Mississippi - Home Teleworker, Missouri - Home Teleworker, Montana - Home Teleworkers {+ 21 more}

Job Information

CSAA Insurance Group (CSAA IG), a AAA insurer, is one of the leading personal lines property and casualty insurance groups in the United States. Here, every employee shapes our mission. We build innovative, human-centered solutions that help AAA members prevent, prepare for, and recover from life's uncertainties. You will join a collaborative, inclusive culture where your strengths have room to grow and your ideas can drive real impact. Step into a role where you can contribute to our shared success through meaningful work.

We are actively hiring for a Governance Engineer II - Remote

Your Role: The Governance Engineer will play a hands-on role in turning enterprise API, data, security, and responsible AI policies into practical, automated engineering solutions. This position will develop governance-as-code, reusable standards, and automated guardrails that enable APIs and emerging AI agents to securely access enterprise data, tools, and MCP resources. Working closely with architecture, security, risk, data, and engineering teams, the Governance Engineer will strengthen API and AI security, automate compliance and approval processes, improve lifecycle management and monitoring, and create self-service solutions that make governance easier to follow while enabling teams to innovate responsibly.

Your Work:

API Governance Standards


  • Review API specifications and data contracts for alignment with enterprise REST, security, and data standards.
  • Translate enterprise policies into implementable standards, controls, templates, and reusable patterns.
  • Promote consistent API design, data definitions, schemas, metadata, error models, and access patterns.
  • Maintain governance artifacts, including standards, reference implementations, reusable components, and technical guidance.
  • Track compliance, exceptions, adoption, and remediation across engineering teams.
  • Agentic AI Governance & Responsible AI
  • Establish engineering guardrails for how AI agents discover, access, and invoke APIs, tools, and enterprise data.
  • Implement controls for agent identity, authentication, authorization, least-privilege access, approvals, and human oversight.
  • Define technical practices for agent evaluations, tool-use validation, traceability, auditability, and monitoring.
  • Review agent workflows and AI-generated artifacts for security, quality, compliance, and alignment with approved policies.
  • Partner with security, architecture, data, and responsible AI teams to operationalize enterprise policy without independently setting that policy.
  • Support safe adoption of AI-assisted development tools and agentic capabilities across engineering teams.


Agentic AI Governance & Responsible AI


  • Establish engineering guardrails for how AI agents discover, access, and invoke APIs, tools, and enterprise data.
  • Implement controls for agent identity, authentication, authorization, least-privilege access, approvals, and human oversight.
  • Define technical practices for agent evaluations, tool-use validation, traceability, auditability, and monitoring.
  • Review agent workflows and AI-generated artifacts for security, quality, compliance, and alignment with approved policies.
  • Partner with security, architecture, data, and responsible AI teams to operationalize enterprise policy without independently setting that policy.
  • Support safe adoption of AI-assisted development tools and agentic capabilities across engineering teams.


API Lifecycle Management


  • Support API lifecycle activities, including design, review, publishing, versioning, deployment, monitoring, deprecation, and retirement.
  • Onboard APIs to enterprise catalogs, repositories, developer portals, and governance platforms.
  • Maintain API inventory, ownership, dependencies, lifecycle status, and supporting documentation.
  • Implement lifecycle controls for breaking changes, backward compatibility, versioning, and retirement.
  • Monitor API usage, health, security, compliance, and adoption metrics.
  • Automation, Platform Enablement & Developer Adoption
  • Integrate API and agent governance controls into CI/CD pipelines and development workflows.
  • Build or configure API linting, contract testing, security scanning, policy validation, and compliance checks.
  • Develop scripts, reusable pipeline components, and governance-as-code solutions to reduce manual review.
  • Support API catalogs, developer portals, Postman workspaces, governance repositories, and reporting capabilities.
  • Create self-service templates, documentation, training materials, and onboarding guidance.
  • Partner with development teams to resolve findings and drive adoption of governance standards and tools.


Automation, Platform Enablement & Developer Adoption


  • Integrate API and agent governance controls into CI/CD pipelines and development workflows.
  • Build or configure API linting, contract testing, security scanning, policy validation, and compliance checks.
  • Develop scripts, reusable pipeline components, and governance-as-code solutions to reduce manual review.
  • Support API catalogs, developer portals, Postman workspaces, governance repositories, and reporting capabilities.
  • Create self-service templates, documentation, training materials, and onboarding guidance.
  • Partner with development teams to resolve findings and drive adoption of governance standards and tools.


Expected Outcomes

The successful candidate will be expected to contribute to:


  • Increased automation of API, data contract, and agent governance controls.
  • Faster and more consistent governance reviews with fewer manual checkpoints.
  • Improved API lifecycle visibility, ownership, versioning, and retirement practices.
  • Stronger security for APIs and AI agents, including access controls, approvals, and traceability.
  • Earlier identification of API quality, contract compatibility, security, and compliance issues.
  • Broader adoption of reusable standards, governance-as-code, and self-service capabilities.
  • Measurable improvements in governance compliance and developer experience.

Required Experience, Education and Skills


  • 2 + years of experience in software engineering, API development, systems integration, platform engineering, DevSecOps, or a related technical field.
  • Demonstrated experience with designing, developing, testing, and supporting REST APIs and integrations, including OpenAPI/Swagger specifications, API testing, and lifecycle management.
  • Experience implementing engineering controls within CI/CD pipelines, including automated testing, API validation, contract testing, security scanning, or other governance-as-code practices.
  • Working knowledge of API security concepts, including OAuth, authentication, authorization, access controls, and secure API design principles.
  • Experience with modern API lifecycle and governance tools such as Postman, SwaggerHub, API catalogs, developer portals, API gateways, or similar platforms.
  • Familiarity with AI-assisted engineering, agentic AI concepts, and the application of governance controls, traceability, approvals, and monitoring for AI-enabled solutions.
  • Strong scripting or programming skills and the ability to translate governance, security, and compliance requirements into practical engineering solutions and automation.
  • Strong analytical, communication, collaboration, and problem-solving skills.

What would make us excited about you?


  • Experience implementing governance-as-code, policy-as-code, reusable pipeline controls, or automated compliance and quality checks.
  • Knowledge of API security best practices, OWASP API Security Top 10, secure software development, and cloud-native architectures.
  • Experience with microservices, event-driven architectures, enterprise integration patterns, and platform engineering practices.
  • Experience building governance, compliance, operational, or adoption metrics and dashboards.
  • Insurance industry experience is a plus.
  • Actively shapes our company culture (e.g., participating in employee resource groups, volunteering, etc.)
  • Lives into cultural norms (e.g., willing to have cameras when it matters: helping onboard new team members, building relationships, etc.)
  • Travels as needed for role, including divisional / team meetings and other in-person meetings
  • Fulfills business needs, which may include investing extra time, helping other teams, etc

Please note we are hiring for this role remote anywhere in the United States with the following exceptions: Hawaii and Alaska.

Why Choose a Career at CSAA IG?

At CSAA IG, we are a mission-driven organization proudly committed to empowering our members, our employees, and our communities to thrive.

Recognition: We offer a total compensation package, annual bonus eligibility for most roles, 401(k) with a company match, and so much more! Read more about what we offer and what it is like to be a part of our dynamic team at https://careers.csaainsurance.aaa.com/us/en/benefits.

Career Growth: We believe in growth for everyone. Here at CSAA IG, leaders and mentors partner with employees to align interests, unlock development opportunities, and support longterm success.

Flexible Workplace: We embrace a remote-first culture through our Flexible Workplace. Most employees hold Home-Flex roles, working primarily from home, often with the flexibility to work from various locations including CSAA offices. Our flexible workplace empowers you to balance remote work with intentional inperson moments that deepen connection and collaboration.

Inclusion and Belonging: An inclusive and welcoming workplace is the cornerstone of our success. By fostering an environment where people feel valued and heard, we deepen our ability to understand and meet the unique needs of our members. This strengthens innovation and enhances our products and services, giving us a competitive edge in the market.

Sustainability: As climate change leads to more frequent and severe weather events, we are taking bold action to build more resilient communities and reduce our environmental impact. Submit your application to be considered. We communicate via email, so check your inbox and/or your spam folder to ensure you don't miss important updates from us.

CSAA is committed to providing reasonable accommodations to qualified applicants and employees with disabilities or other limitations. If you would like to request an accommodation to participate in the job application or interview process, please contact TalentAcquistion@csaa.com

If you apply and are selected to continue in the recruiting process, we will schedule a preliminary call with you to discuss the role and will disclose during that call the available salary/hourly rate range based on your location. Factors used to determine the actual salary offered may include location, experience, or education.

CSAA does not provide visa sponsorship for this role. Applicants must have authorization to work indefinitely in the US. Please do not apply for this role if at any time (now or in the future) you will need immigration support (i.e., H-1B, TN, STEM OPT Training Plans, etc.).

CSAA Insurance Group is an equal opportunity employer.

#LI-JR1

.

The national average hourly rate for this position is $41.07-$45.63. However, we have a location-based compensation structure. Our salary ranges vary and are calculated based on work location. The starting pay range for this position across all the states we hire in is $41.07-$54.76. This role also includes an opportunity for a company-wide annual discretionary bonus, through our Annual Incentive Plan (AIP), of up to 7% of eligible pay.Colorado Specific Job Range :$85,410.00 - $104,350.00 This job posting will be unposted on Fri, 16 Oct 2026.
Applied = 0

(web-9db6c7984-whzc5)