Allstate
Senior Threat Hunter (Lead)
Key aspects of the role:
- Drive sales growth by engaging with interested prospective customers- all while working remote
- No cold calling— Connect through inbound calls and proactive outbound calls with active insurance shoppers
- Enjoy competitive compensation with a base salary + uncapped commissions
- Sell reputable products from Allstate and our family of brands
At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection.
Job Description
The Threat Assessment and Incident Response Expert leads the development and execution of cybersecurity threat assessments, penetration testing, and incident response plans and procedures for multiple areas; directs forensic and technical investigations, and advises governance, technical, and business leadership on results, vulnerabilities, and solutions to mitigate.
The Allstate Information Security (AIS) department is responsible for managing cyber security at Allstate. This includes Governance/Risk/Compliance, Access Management, Network Security, and Threat Response Services. The department is responsible for ensuring confidentiality, integrity, and availability of Allstate systems.
We are seeking an experienced Threat Hunter to perform intelligence-driven network defense supporting the monitoring and incident response capabilities. The role will involve analysis of large amounts of data from vendors and internal sources, including various indicator feeds, Splunk, and several threat intelligence tools, etc. The candidate will perform the functions of threat hunting and serve as a liaison for Threat Services for the Global Security Fusion Center, and mentor the incident handling and forensics teams.
Primary Responsibilities:
- Design and run custom analysis models on security event information to discover active threats
- Identify (hunting) security nuances and abnormalities in the environment
- Providing mentorship and support to teammates to help enrich and develop others in the team and within other areas of the GSFC regarding threat hunting
- Develop use cases and actionable content to identify security variants that are currently not alerted within the environment
- Lead projects and assignments
- Custom tool design to assist in analysis and investigations
- Perform as an Information Security SME in four of the following areas:
- Threat Intelligence
- Incident Response
- Log analysis (statistical modeling, correlation, pattern recognition, etc.)
- Microsoft platform (Server, workstation, applications)
- Open Systems platforms (Linux, UNIX, VM Ware ESX)
- Web Application
- Networking (firewalls, IDS/IPS, packet capture)
- Databases (Oracle, SQL Server, DB2, IMS)
- SIEM
- Reverse Engineering / Malware analysis
- Collaborate and support outside teams and organizations to enhance the threat hunting service offering
- Communication/rapport with other divisions and various peers
- Capable of identifying need & driving solutions, and providing guidance, in an autonomous manner
- Assist with compiling metrics and reporting of the service offering
- Lead projects and deliverables with limited oversight and day to day guidance
Qualifications
Essential Criteria
- Bachelors and/or Masters Degree in Engineering, Computers Science, or related field/experience (4+ years)
- 4+ years overall technical experience in either threat hunting, threat intelligence, incident response, security operations, or related information security field
- Deep understanding of common network and application stack protocols, including but not limited to TCP/IP, SMTP, DNS, TLS, XML, HTTP, etc.
- Advanced experience with security operations tools, including but not limited to:
- SIEM (e.g. Splunk, ArcSight, Sentinel)
- Network analysis/information (e.g. NetWitness, PaloAlto, Shodan, Censys)
- Signature development/management (e.g. Spunk rules, Snort rules, Yara rules)
- EDR solutions (e.g. CrowdStrike, Tanium, Carbon Black)
- Malware Analysis (e.g. Sandbox, Disassembler, IDA Pro, Ghidra, Debugger, OllyDbg, ReversingLabs, Secure Malware Analytics)
- Threat Intelligence (RecordedFuture, ThreatConnect, Maltego, ZeroFox)
- Broad experience with various common security infrastructure tools (NIDS, HIPS, EDR, etc.)
- Experience hunting in AWS and/or Azure environments
Desirable Criteria
- Excellent analytical and problem-solving skills, a passion for research and puzzle-solving
- Strong communication (oral, written, presentation), interpersonal and consultative skills
- Deep understanding of large, complex corporate network environments
- Knowledge or experience in penetration testing, ethical hacking, exploit writing, and/or vulnerability management
- Knowledge or experience in application design/engineering, including but not limited to programming/scripting, Windows/Linux system administration, RDBMS/NoSQL database administration, etc.
- Scripting experience related to system administration and security operations (Python, Bash, PowerShell, Perl, C/C++)
- Recent experience with malware analysis and reverse engineering
- Strong organization and documentation skills
- Obtained certifications in several of the following: SANS GIAC courses, CEH, CISSP, OSCP, or tool-specific certifications
Primary Skills
Customer Centricity, Digital Literacy, Inclusive Leadership, Learning Agility, Results-Oriented
Shift Time
Recruiter Info
Yateesh
ybgaa@allstate.com
About Allstate
Joining our team isn’t just a job — it’s an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact.
The Allstate Corporation is one of the largest publicly held insurance providers in the United States. Ranked No. 84 in the 2023 Fortune 500 list of the largest United States corporations by total revenue, The Allstate Corporation owns and operates 18 companies in the United States, Canada, Northern Ireland, and India. Allstate India Private Limited, also known as Allstate India, is a subsidiary of The Allstate Corporation. The India talent center was set up in 2012 and operates under the corporation's Good Hands promise. As it innovates operations and technology, Allstate India has evolved beyond its technology functions to be the critical strategic business services arm of the corporation. With offices in Bengaluru and Pune, the company offers expertise to the parent organization’s business areas including technology and innovation, accounting and imaging services, policy administration, transformation solution design and support services, transformation of property liability service design, global operations and integration, and training and transition.
Learn more about Allstate India here.
At Allstate, it’s all about teamwork, flexibility, and thinking ahead. We all contribute to the bigger picture, combining unique ideas to design innovative, more affordable protection solutions for customers.
We look for candidates with these skills to help us achieve that goal:
Learning agility
Quickly adapt to new situations, continually build new skills, experiment, and embrace new ways of doing things
Customer centricity
Deliver exceptional experience with a customer-first mindset and human-centered design
Digital literacy
Discover and apply emerging digital technology tools, data and insights.
Results-oriented
Start with measurable outcomes and drive results with speed
Inclusive leadership
Integrate diverse viewpoints into decision-making processes to enhance creativity and innovation
Together, we’re all working toward Our Shared Purpose, using our strengths to make a real difference for our people, our customers, our company, and the world around us.
What We Do:
As an expert on our products and services, you can give customers personalized attention and innovative solutions to make their lives easier.
How We Support You:
Starting day one, you’ll have access to resources and incentives to keep you feeling challenged and excited about your careers.
Make An Impact:
As a member of our sales team, you’ll bring a sense of ease and support to customers looking for a better understanding of their protection options. Whether in the field or talking to customers over the phone, you’ll continue to build trust in who we are and what we do.
You’re in Good Hands® is more than a promise we make to our customers. It’s a promise we make to our employees, too.
We want you to love where you work. That starts with the freedom to be yourself. Our workplace flexibility and focus on individuality means everyone is seen, heard and respected.
When you join us, you’ll have the opportunity to push your skills to the next level with access to development programs to support your career aspirations – whatever that means for you. Because as you learn and grow, so do we.
Working here also means getting the chance to make a real impact in your community. We have been driving change for over 90 years, but the mark we leave on the world can be even greater when we work together.
At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection.
Job Description
The Threat Assessment and Incident Response Expert leads the development and execution of cybersecurity threat assessments, penetration testing, and incident response plans and procedures for multiple areas; directs forensic and technical investigations, and advises governance, technical, and business leadership on results, vulnerabilities, and solutions to mitigate.
The Allstate Information Security (AIS) department is responsible for managing cyber security at Allstate. This includes Governance/Risk/Compliance, Access Management, Network Security, and Threat Response Services. The department is responsible for ensuring confidentiality, integrity, and availability of Allstate systems.
We are seeking an experienced Threat Hunter to perform intelligence-driven network defense supporting the monitoring and incident response capabilities. The role will involve analysis of large amounts of data from vendors and internal sources, including various indicator feeds, Splunk, and several threat intelligence tools, etc. The candidate will perform the functions of threat hunting and serve as a liaison for Threat Services for the Global Security Fusion Center, and mentor the incident handling and forensics teams.
Primary Responsibilities:
- Design and run custom analysis models on security event information to discover active threats
- Identify (hunting) security nuances and abnormalities in the environment
- Providing mentorship and support to teammates to help enrich and develop others in the team and within other areas of the GSFC regarding threat hunting
- Develop use cases and actionable content to identify security variants that are currently not alerted within the environment
- Lead projects and assignments
- Custom tool design to assist in analysis and investigations
- Perform as an Information Security SME in four of the following areas:
- Threat Intelligence
- Incident Response
- Log analysis (statistical modeling, correlation, pattern recognition, etc.)
- Microsoft platform (Server, workstation, applications)
- Open Systems platforms (Linux, UNIX, VM Ware ESX)
- Web Application
- Networking (firewalls, IDS/IPS, packet capture)
- Databases (Oracle, SQL Server, DB2, IMS)
- SIEM
- Reverse Engineering / Malware analysis
- Collaborate and support outside teams and organizations to enhance the threat hunting service offering
- Communication/rapport with other divisions and various peers
- Capable of identifying need & driving solutions, and providing guidance, in an autonomous manner
- Assist with compiling metrics and reporting of the service offering
- Lead projects and deliverables with limited oversight and day to day guidance
Qualifications
Essential Criteria
- Bachelors and/or Masters Degree in Engineering, Computers Science, or related field/experience (4+ years)
- 4+ years overall technical experience in either threat hunting, threat intelligence, incident response, security operations, or related information security field
- Deep understanding of common network and application stack protocols, including but not limited to TCP/IP, SMTP, DNS, TLS, XML, HTTP, etc.
- Advanced experience with security operations tools, including but not limited to:
- SIEM (e.g. Splunk, ArcSight, Sentinel)
- Network analysis/information (e.g. NetWitness, PaloAlto, Shodan, Censys)
- Signature development/management (e.g. Spunk rules, Snort rules, Yara rules)
- EDR solutions (e.g. CrowdStrike, Tanium, Carbon Black)
- Malware Analysis (e.g. Sandbox, Disassembler, IDA Pro, Ghidra, Debugger, OllyDbg, ReversingLabs, Secure Malware Analytics)
- Threat Intelligence (RecordedFuture, ThreatConnect, Maltego, ZeroFox)
- Broad experience with various common security infrastructure tools (NIDS, HIPS, EDR, etc.)
- Experience hunting in AWS and/or Azure environments
Desirable Criteria
- Excellent analytical and problem-solving skills, a passion for research and puzzle-solving
- Strong communication (oral, written, presentation), interpersonal and consultative skills
- Deep understanding of large, complex corporate network environments
- Knowledge or experience in penetration testing, ethical hacking, exploit writing, and/or vulnerability management
- Knowledge or experience in application design/engineering, including but not limited to programming/scripting, Windows/Linux system administration, RDBMS/NoSQL database administration, etc.
- Scripting experience related to system administration and security operations (Python, Bash, PowerShell, Perl, C/C++)
- Recent experience with malware analysis and reverse engineering
- Strong organization and documentation skills
- Obtained certifications in several of the following: SANS GIAC courses, CEH, CISSP, OSCP, or tool-specific certifications
Primary Skills
Customer Centricity, Digital Literacy, Inclusive Leadership, Learning Agility, Results-Oriented
Shift Time
Recruiter Info
Yateesh
ybgaa@allstate.com
About Allstate
Joining our team isn’t just a job — it’s an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact.
The Allstate Corporation is one of the largest publicly held insurance providers in the United States. Ranked No. 84 in the 2023 Fortune 500 list of the largest United States corporations by total revenue, The Allstate Corporation owns and operates 18 companies in the United States, Canada, Northern Ireland, and India. Allstate India Private Limited, also known as Allstate India, is a subsidiary of The Allstate Corporation. The India talent center was set up in 2012 and operates under the corporation's Good Hands promise. As it innovates operations and technology, Allstate India has evolved beyond its technology functions to be the critical strategic business services arm of the corporation. With offices in Bengaluru and Pune, the company offers expertise to the parent organization’s business areas including technology and innovation, accounting and imaging services, policy administration, transformation solution design and support services, transformation of property liability service design, global operations and integration, and training and transition.
Learn more about Allstate India here.
At Allstate, it’s all about teamwork, flexibility, and thinking ahead. We all contribute to the bigger picture, combining unique ideas to design innovative, more affordable protection solutions for customers.
We look for candidates with these skills to help us achieve that goal:
Learning agility
Quickly adapt to new situations, continually build new skills, experiment, and embrace new ways of doing things
Customer centricity
Deliver exceptional experience with a customer-first mindset and human-centered design
Digital literacy
Discover and apply emerging digital technology tools, data and insights.
Results-oriented
Start with measurable outcomes and drive results with speed
Inclusive leadership
Integrate diverse viewpoints into decision-making processes to enhance creativity and innovation
Together, we’re all working toward Our Shared Purpose, using our strengths to make a real difference for our people, our customers, our company, and the world around us.
What We Do:
Your ability to quickly and calmly make smart decisions can make a huge difference in how confident customers feel throughout the claims process. And as you support our customers, we’re there to support you.
How We Support You:
We empower your success starting day one. You’ll have access to everything you need to grow professionally while helping our customers get their lives back on track.
Make An Impact:
Helping customers with their claims is about learning their stories, not just processing their paperwork. You can take pride in the fact that you’re providing invaluable guidance and helping to build continued trust in our company.
You’re in Good Hands® is more than a promise we make to our customers. It’s a promise we make to our employees, too.
We want you to love where you work. That starts with the freedom to be yourself. Our workplace flexibility and focus on individuality means everyone is seen, heard and respected.
When you join us, you’ll have the opportunity to push your skills to the next level with access to development programs to support your career aspirations – whatever that means for you. Because as you learn and grow, so do we.
Working here also means getting the chance to make a real impact in your community. We have been driving change for over 90 years, but the mark we leave on the world can be even greater when we work together.
At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection.
Job Description
The Threat Assessment and Incident Response Expert leads the development and execution of cybersecurity threat assessments, penetration testing, and incident response plans and procedures for multiple areas; directs forensic and technical investigations, and advises governance, technical, and business leadership on results, vulnerabilities, and solutions to mitigate.
The Allstate Information Security (AIS) department is responsible for managing cyber security at Allstate. This includes Governance/Risk/Compliance, Access Management, Network Security, and Threat Response Services. The department is responsible for ensuring confidentiality, integrity, and availability of Allstate systems.
We are seeking an experienced Threat Hunter to perform intelligence-driven network defense supporting the monitoring and incident response capabilities. The role will involve analysis of large amounts of data from vendors and internal sources, including various indicator feeds, Splunk, and several threat intelligence tools, etc. The candidate will perform the functions of threat hunting and serve as a liaison for Threat Services for the Global Security Fusion Center, and mentor the incident handling and forensics teams.
Primary Responsibilities:
- Design and run custom analysis models on security event information to discover active threats
- Identify (hunting) security nuances and abnormalities in the environment
- Providing mentorship and support to teammates to help enrich and develop others in the team and within other areas of the GSFC regarding threat hunting
- Develop use cases and actionable content to identify security variants that are currently not alerted within the environment
- Lead projects and assignments
- Custom tool design to assist in analysis and investigations
- Perform as an Information Security SME in four of the following areas:
- Threat Intelligence
- Incident Response
- Log analysis (statistical modeling, correlation, pattern recognition, etc.)
- Microsoft platform (Server, workstation, applications)
- Open Systems platforms (Linux, UNIX, VM Ware ESX)
- Web Application
- Networking (firewalls, IDS/IPS, packet capture)
- Databases (Oracle, SQL Server, DB2, IMS)
- SIEM
- Reverse Engineering / Malware analysis
- Collaborate and support outside teams and organizations to enhance the threat hunting service offering
- Communication/rapport with other divisions and various peers
- Capable of identifying need & driving solutions, and providing guidance, in an autonomous manner
- Assist with compiling metrics and reporting of the service offering
- Lead projects and deliverables with limited oversight and day to day guidance
Qualifications
Essential Criteria
- Bachelors and/or Masters Degree in Engineering, Computers Science, or related field/experience (4+ years)
- 4+ years overall technical experience in either threat hunting, threat intelligence, incident response, security operations, or related information security field
- Deep understanding of common network and application stack protocols, including but not limited to TCP/IP, SMTP, DNS, TLS, XML, HTTP, etc.
- Advanced experience with security operations tools, including but not limited to:
- SIEM (e.g. Splunk, ArcSight, Sentinel)
- Network analysis/information (e.g. NetWitness, PaloAlto, Shodan, Censys)
- Signature development/management (e.g. Spunk rules, Snort rules, Yara rules)
- EDR solutions (e.g. CrowdStrike, Tanium, Carbon Black)
- Malware Analysis (e.g. Sandbox, Disassembler, IDA Pro, Ghidra, Debugger, OllyDbg, ReversingLabs, Secure Malware Analytics)
- Threat Intelligence (RecordedFuture, ThreatConnect, Maltego, ZeroFox)
- Broad experience with various common security infrastructure tools (NIDS, HIPS, EDR, etc.)
- Experience hunting in AWS and/or Azure environments
Desirable Criteria
- Excellent analytical and problem-solving skills, a passion for research and puzzle-solving
- Strong communication (oral, written, presentation), interpersonal and consultative skills
- Deep understanding of large, complex corporate network environments
- Knowledge or experience in penetration testing, ethical hacking, exploit writing, and/or vulnerability management
- Knowledge or experience in application design/engineering, including but not limited to programming/scripting, Windows/Linux system administration, RDBMS/NoSQL database administration, etc.
- Scripting experience related to system administration and security operations (Python, Bash, PowerShell, Perl, C/C++)
- Recent experience with malware analysis and reverse engineering
- Strong organization and documentation skills
- Obtained certifications in several of the following: SANS GIAC courses, CEH, CISSP, OSCP, or tool-specific certifications
Primary Skills
Customer Centricity, Digital Literacy, Inclusive Leadership, Learning Agility, Results-Oriented
Shift Time
Recruiter Info
Yateesh
ybgaa@allstate.com
About Allstate
Joining our team isn’t just a job — it’s an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact.
The Allstate Corporation is one of the largest publicly held insurance providers in the United States. Ranked No. 84 in the 2023 Fortune 500 list of the largest United States corporations by total revenue, The Allstate Corporation owns and operates 18 companies in the United States, Canada, Northern Ireland, and India. Allstate India Private Limited, also known as Allstate India, is a subsidiary of The Allstate Corporation. The India talent center was set up in 2012 and operates under the corporation's Good Hands promise. As it innovates operations and technology, Allstate India has evolved beyond its technology functions to be the critical strategic business services arm of the corporation. With offices in Bengaluru and Pune, the company offers expertise to the parent organization’s business areas including technology and innovation, accounting and imaging services, policy administration, transformation solution design and support services, transformation of property liability service design, global operations and integration, and training and transition.
Learn more about Allstate India here.
At Allstate, it’s all about teamwork, flexibility, and thinking ahead. We all contribute to the bigger picture, combining unique ideas to design innovative, more affordable protection solutions for customers.
We look for candidates with these skills to help us achieve that goal:
Learning agility
Quickly adapt to new situations, continually build new skills, experiment, and embrace new ways of doing things
Customer centricity
Deliver exceptional experience with a customer-first mindset and human-centered design
Digital literacy
Discover and apply emerging digital technology tools, data and insights.
Results-oriented
Start with measurable outcomes and drive results with speed
Inclusive leadership
Integrate diverse viewpoints into decision-making processes to enhance creativity and innovation
Together, we’re all working toward Our Shared Purpose, using our strengths to make a real difference for our people, our customers, our company, and the world around us.
You’re in Good Hands® is more than a promise we make to our customers. It’s a promise we make to our employees, too.
We want you to love where you work. That starts with the freedom to be yourself. Our workplace flexibility and focus on individuality means everyone is seen, heard and respected.
When you join us, you’ll have the opportunity to push your skills to the next level with access to development programs to support your career aspirations – whatever that means for you. Because as you learn and grow, so do we.
Working here also means getting the chance to make a real impact in your community. We have been driving change for over 90 years, but the mark we leave on the world can be even greater when we work together.
Benefits
Experience the benefits that make Allstate a great place to work.
*Benefits vary based on position.
- Medical, dental and vision coverage
- HSAs and FSAs
- Wellbeing programs
- Free therapy sessions
- 401(k) plan
- Pension plan
- Free financial counseling
- Paid time off
- Work flexibility
- Talent shares
- Tuition reimbursement
- Learning opportunities
For a full description of Allstate’s benefits visit our benefits page
Start making a difference
Realize your full potential by doing
work that matters.
Grow your career in meaningful ways.
We want to make sure you have every opportunity to grow, explore new horizons and follow your passion in a meaningful career. It’s an exciting time to join Allstate. Help us shape the future.