Governance Engineer II - Remote

CSAA Insurance Group, a AAA Insurer
•$85,410 - $113,901•Remote

About The Position

CSAA Insurance Group (CSAA IG), a AAA insurer, is one of the leading personal lines property and casualty insurance groups in the United States. Here, every employee shapes our mission. We build innovative, human-centered solutions that help AAA members prevent, prepare for, and recover from life's uncertainties. You will join a collaborative, inclusive culture where your strengths have room to grow and your ideas can drive real impact. Step into a role where you can contribute to our shared success through meaningful work. We are actively hiring for a Governance Engineer II - Remote Your Role: The Governance Engineer will play a hands-on role in turning enterprise API, data, security, and responsible AI policies into practical, automated engineering solutions. This position will develop governance-as-code, reusable standards, and automated guardrails that enable APIs and emerging AI agents to securely access enterprise data, tools, and MCP resources. Working closely with architecture, security, risk, data, and engineering teams, the Governance Engineer will strengthen API and AI security, automate compliance and approval processes, improve lifecycle management and monitoring, and create self-service solutions that make governance easier to follow while enabling teams to innovate responsibly.

Requirements

  • 2 + years of experience in software engineering, API development, systems integration, platform engineering, DevSecOps, or a related technical field.
  • Demonstrated experience with designing, developing, testing, and supporting REST APIs and integrations, including OpenAPI/Swagger specifications, API testing, and lifecycle management.
  • Experience implementing engineering controls within CI/CD pipelines, including automated testing, API validation, contract testing, security scanning, or other governance-as-code practices.
  • Working knowledge of API security concepts, including OAuth, authentication, authorization, access controls, and secure API design principles.
  • Experience with modern API lifecycle and governance tools such as Postman, SwaggerHub, API catalogs, developer portals, API gateways, or similar platforms.
  • Familiarity with AI-assisted engineering, agentic AI concepts, and the application of governance controls, traceability, approvals, and monitoring for AI-enabled solutions.
  • Strong scripting or programming skills and the ability to translate governance, security, and compliance requirements into practical engineering solutions and automation.
  • Strong analytical, communication, collaboration, and problem-solving skills.

Nice To Haves

  • Experience implementing governance-as-code, policy-as-code, reusable pipeline controls, or automated compliance and quality checks.
  • Knowledge of API security best practices, OWASP API Security Top 10, secure software development, and cloud-native architectures.
  • Experience with microservices, event-driven architectures, enterprise integration patterns, and platform engineering practices.
  • Experience building governance, compliance, operational, or adoption metrics and dashboards.
  • Insurance industry experience is a plus.
  • Actively shapes our company culture (e.g., participating in employee resource groups, volunteering, etc.)
  • Lives into cultural norms (e.g., willing to have cameras when it matters: helping onboard new team members, building relationships, etc.)
  • Travels as needed for role, including divisional / team meetings and other in-person meetings
  • Fulfills business needs, which may include investing extra time, helping other teams, etc

Responsibilities

  • Review API specifications and data contracts for alignment with enterprise REST, security, and data standards.
  • Translate enterprise policies into implementable standards, controls, templates, and reusable patterns.
  • Promote consistent API design, data definitions, schemas, metadata, error models, and access patterns.
  • Maintain governance artifacts, including standards, reference implementations, reusable components, and technical guidance.
  • Track compliance, exceptions, adoption, and remediation across engineering teams.
  • Establish engineering guardrails for how AI agents discover, access, and invoke APIs, tools, and enterprise data.
  • Implement controls for agent identity, authentication, authorization, least-privilege access, approvals, and human oversight.
  • Define technical practices for agent evaluations, tool-use validation, traceability, auditability, and monitoring.
  • Review agent workflows and AI-generated artifacts for security, quality, compliance, and alignment with approved policies.
  • Partner with security, architecture, data, and responsible AI teams to operationalize enterprise policy without independently setting that policy.
  • Support safe adoption of AI-assisted development tools and agentic capabilities across engineering teams.
  • Support API lifecycle activities, including design, review, publishing, versioning, deployment, monitoring, deprecation, and retirement.
  • Onboard APIs to enterprise catalogs, repositories, developer portals, and governance platforms.
  • Maintain API inventory, ownership, dependencies, lifecycle status, and supporting documentation.
  • Implement lifecycle controls for breaking changes, backward compatibility, versioning, and retirement.
  • Monitor API usage, health, security, compliance, and adoption metrics.
  • Integrate API and agent governance controls into CI/CD pipelines and development workflows.
  • Build or configure API linting, contract testing, security scanning, policy validation, and compliance checks.
  • Develop scripts, reusable pipeline components, and governance-as-code solutions to reduce manual review.
  • Support API catalogs, developer portals, Postman workspaces, governance repositories, and reporting capabilities.
  • Create self-service templates, documentation, training materials, and onboarding guidance.
  • Partner with development teams to resolve findings and drive adoption of governance standards and tools.

Benefits

  • total compensation package
  • annual bonus eligibility for most roles
  • 401(k) with a company match
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service