Allstate
Threat Detection & Response Engineer — Senior Expert
Key aspects of the role:
- Drive sales growth by engaging with interested prospective customers- all while working remote
- No cold calling— Connect through inbound calls and proactive outbound calls with active insurance shoppers
- Enjoy competitive compensation with a base salary + uncapped performance-based incentives
- Sell reputable products from Allstate and our family of brands
At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection.
Job Description
The Threat Detection & Response Engineer — Senior Expert defines and builds the technical foundation of that rebuild. This is a hands-on, build-heavy role for an engineer who treats detections as software that is version-controlled, peer-reviewed, tested, and shipped through a pipeline, and above all one who can design and build the AI/ML pipelines that let a global team investigate and respond at machine speed.
The role leads the technical projects that stand up this capability and owns accountability for their delivery, sets the technical bar for how detection content is written, validated, and deployed, and builds the tooling and intelligence pipelines that make high-quality detection engineering repeatable rather than heroic. This is an individual-contributor role that carries technical leadership and delivery ownership.
Why This Role Exists
-
To stand up a detection-as-code workflow with version control, peer review, staged deployment, and measurable coverage, designed and owned by a principal engineer rather than inherited.
-
To design and build the AI/ML pipelines that accelerate investigation, triage, and detection generation, the capability area we are most focused on developing.
-
To prioritize automation and AI-assisted triage for high-volume, low-judgment work such as phishing and DLP, so human attention goes to the investigations that need judgment.
-
To close the loop between threat intelligence, threat hunting, and detection engineering so that intel and hunt findings reliably become durable detections.
What You’ll Contribute
AI/ML Pipelines for Detection & Response
-
Define, design, and build the AI/ML pipelines at the center of our next-generation D&R capability, applying industry-leading models to investigation, triage, enrichment, and detection generation where they genuinely add leverage.
-
Own the technical delivery of AI-assisted investigation and triage, spanning data foundations and feature/enrichment pipelines through model selection, evaluation, and safe production deployment.
-
Set the standard for how AI/ML outputs are validated, explained, and trusted within detection and response workflows, and lead the projects that move promising pilots into durable, measurable production capability.
Detection-as-Code & Engineering Standards
-
Design and own the detection-as-code pipeline, including repository structure, detection schema, peer-review model, automated testing, and staged (CI/CD) deployment across our SIEM, XDR, and endpoint detection surfaces.
-
Define the technical standards, reusable patterns, and quality bar for detection content, and build the guardrails that keep quality consistent as the team scales across the US, Ireland, and India.
-
Build tooling and APIs that let engineers author, test, and debug detections quickly, turning detection engineering into a repeatable software practice rather than console-by-console work.
Automation & Response Engineering
-
Design automation and SOAR-style workflows, increasingly AI-driven, that collapse high-volume alert categories such as automated phishing campaign clustering and detonation, DLP risk-based routing, enrichment, and auto-closure of verified-benign reports.
-
Build the response automation, including playbooks, containment actions, and integrations, that shrinks dwell time and mean-time-to-respond.
Coverage, Validation & the Intelligence Loop
-
Establish and maintain a MITRE ATT&CK coverage baseline; use it to identify real gaps and redundant coverage and to prioritize engineering effort.
-
Partner with Threat Intelligence and Threat Hunting to convert PIR-driven hunt findings and intel into durable, tested detections through a formal feedback loop.
-
Stand up continuous validation, such as breach-and-attack simulation and a purple-team cadence, so coverage claims are proven against real adversary techniques rather than asserted on paper.
Technical Project Leadership
-
Lead the technical projects that build out this capability end-to-end and own accountability for their delivery by scoping the work, driving execution, and being answerable for completion and outcomes.
-
Serve as the senior-most individual-contributor technical authority for detection engineering, acting as the final technical escalation point before management, setting direction and raising the capability of D&R engineers across regions.
-
Influence roadmap and tooling decisions with internal platform partners, and help shape the operating model as the function grows across a global follow-the-sun, detection-as-code model.
What You Bring
-
AI/ML builder. You can design and build AI/ML pipelines that create real leverage by selecting and applying industry-leading models to security data, engineering the data and enrichment foundations they depend on, and putting them into production with clear evaluation and guardrails. You have a grounded point of view on where AI genuinely accelerates detection and response versus where it adds risk.
-
Builder-first. Detection and response as software: you write, version, test, and ship detections like code, and you have built the tooling, APIs, or pipelines that let others do the same.
-
Detection depth. Deep, hands-on detection engineering experience across SIEM and EDR/XDR platforms, authoring high-fidelity analytics, tuning for signal, and reasoning about telemetry and data sources. Fluency in KQL / SQL / Sigma or equivalent, and strong scripting/development skills (e.g., Python, Go).
-
Threat-informed. You map detections to adversary behavior (ATT&CK), partner naturally with hunting and intel, and think in terms of coverage, exploitability, and containment rather than just rule counts.
-
Delivery ownership. You lead technical projects to completion and own the outcome, setting standards, resolving hard engineering problems, and lifting the quality of everyone around you, comfortable being the deepest technical voice in the room.
-
Communication. You can explain a detection strategy, an AI/ML design choice, or an engineering trade-off clearly to both engineers and senior leaders.
Nice to Have
-
Hands-on experience building or operating within an AI-assisted / agentic SOC model.
-
Security data engineering / streaming pipeline experience (telemetry normalization, parsing, ETL) that feeds ML workflows.
-
Experience across enterprise SIEM, XDR, and EDR platforms.
-
Purple-team, adversary-emulation, or breach-and-attack-simulation partnership experience.
-
Financial services, insurance, or other regulated, high-scale environment exposure.
#LI-JJ1
Skills
API Development, Decision Making, Endpoint Detection and Response (EDR), Machine Learning (ML), MITRE ATT&CK Framework, Scalable AI Pipelines, Security Automation, Security Information and Event Management (SIEM), Security Orchestration, Automation, and Response (SOAR), Stakeholder Influence, Technical Project Leadership, Threat Detection
Compensation
Compensation offered for this role is $151,700 – 222,400 annually and is based on experience and qualifications.
The candidate(s) offered this position will be required to submit to a background investigation.
Joining our team isn’t just a job — it’s an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact.
Allstate generally does not sponsor individuals for employment-based visas for this position.
Effective July 1, 2014, under Indiana House Enrolled Act (HEA) 1242, it is against public policy of the State of Indiana and a discriminatory practice for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component.
For jobs in San Francisco, please click “here” for information regarding the San Francisco Fair Chance Ordinance.
For jobs in Los Angeles, please click “here” for information regarding the Los Angeles Fair Chance Initiative for Hiring Ordinance.
To view the “EEO Know Your Rights” poster click “here”. This poster provides information concerning the laws and procedures for filing complaints of violations of the laws with the Office of Federal Contract Compliance Programs.
To view the FMLA poster, click “here”. This poster summarizing the major provisions of the Family and Medical Leave Act (FMLA) and telling employees how to file a complaint.
It is the Company’s policy to employ the best qualified individuals available for all jobs. Therefore, any discriminatory action taken on account of an employee’s ancestry, age, color, disability, genetic information, gender, gender identity, gender expression, sexual and reproductive health decision, marital status, medical condition, military or veteran status, national origin, race (include traits historically associated with race, including, but not limited to, hair texture and protective hairstyles), religion (including religious dress), sex, or sexual orientation that adversely affects an employee's terms or conditions of employment is prohibited. This policy applies to all aspects of the employment relationship, including, but not limited to, hiring, training, salary administration, promotion, job assignment, benefits, discipline, and separation of employment.
Allstate provides a comprehensive technology setup, including a laptop, monitors, headset, keyboard, and mouse. Employees eligible to work from home also receive a monthly connectivity reimbursement to help offset internet costs.
When working from home, you must have a dedicated, private workspace free from distractions, along with appropriate desk and seating. Reliable internet is required, with minimum speeds of 50 MB download and 5 MB upload.
To help create a more personal and engaging experience, we ask that you join with your camera on if your interview is virtual. Please also have a Valid Photo Identification available at the start of your interview. If you require any accommodations or have questions ahead of your interview please reach out to your recruiter.
Note: Internal candidates are only asked to join on video; a Valid Photo Identification is not needed for the interview.
At Allstate, it’s all about teamwork, flexibility, and thinking ahead. We all contribute to the bigger picture, combining unique ideas to design innovative, more affordable protection solutions for customers.
We look for candidates with these skills to help us achieve that goal:
Learning agility
Quickly adapt to new situations, continually build new skills, experiment, and embrace new ways of doing things
Customer centricity
Deliver exceptional experience with a customer-first mindset and human-centered design
Digital literacy
Discover and apply emerging digital technology tools, data and insights.
Results-oriented
Start with measurable outcomes and drive results with speed
Inclusive leadership
Integrate diverse viewpoints into decision-making processes to enhance creativity and innovation
Together, we’re all working toward Our Shared Purpose, using our strengths to make a real difference for our people, our customers, our company, and the world around us.
What We Do:
As an expert on our products and services, you can give customers personalized attention and innovative solutions to make their lives easier.
How We Support You:
Starting day one, you’ll have access to resources and incentives to keep you feeling challenged and excited about your careers.
Make An Impact:
As a member of our sales team, you’ll bring a sense of ease and support to customers looking for a better understanding of their protection options. Whether in the field or talking to customers over the phone, you’ll continue to build trust in who we are and what we do.
You’re in Good Hands® is more than a promise we make to our customers. It’s a promise we make to our employees, too.
We want you to love where you work. That starts with the freedom to be yourself. Our workplace flexibility and focus on individuality means everyone is seen, heard and respected.
When you join us, you’ll have the opportunity to push your skills to the next level with access to development programs to support your career aspirations – whatever that means for you. Because as you learn and grow, so do we.
Working here also means getting the chance to make a real impact in your community. We have been driving change for over 90 years, but the mark we leave on the world can be even greater when we work together.
At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection.
Job Description
The Threat Detection & Response Engineer — Senior Expert defines and builds the technical foundation of that rebuild. This is a hands-on, build-heavy role for an engineer who treats detections as software that is version-controlled, peer-reviewed, tested, and shipped through a pipeline, and above all one who can design and build the AI/ML pipelines that let a global team investigate and respond at machine speed.
The role leads the technical projects that stand up this capability and owns accountability for their delivery, sets the technical bar for how detection content is written, validated, and deployed, and builds the tooling and intelligence pipelines that make high-quality detection engineering repeatable rather than heroic. This is an individual-contributor role that carries technical leadership and delivery ownership.
Why This Role Exists
-
To stand up a detection-as-code workflow with version control, peer review, staged deployment, and measurable coverage, designed and owned by a principal engineer rather than inherited.
-
To design and build the AI/ML pipelines that accelerate investigation, triage, and detection generation, the capability area we are most focused on developing.
-
To prioritize automation and AI-assisted triage for high-volume, low-judgment work such as phishing and DLP, so human attention goes to the investigations that need judgment.
-
To close the loop between threat intelligence, threat hunting, and detection engineering so that intel and hunt findings reliably become durable detections.
What You’ll Contribute
AI/ML Pipelines for Detection & Response
-
Define, design, and build the AI/ML pipelines at the center of our next-generation D&R capability, applying industry-leading models to investigation, triage, enrichment, and detection generation where they genuinely add leverage.
-
Own the technical delivery of AI-assisted investigation and triage, spanning data foundations and feature/enrichment pipelines through model selection, evaluation, and safe production deployment.
-
Set the standard for how AI/ML outputs are validated, explained, and trusted within detection and response workflows, and lead the projects that move promising pilots into durable, measurable production capability.
Detection-as-Code & Engineering Standards
-
Design and own the detection-as-code pipeline, including repository structure, detection schema, peer-review model, automated testing, and staged (CI/CD) deployment across our SIEM, XDR, and endpoint detection surfaces.
-
Define the technical standards, reusable patterns, and quality bar for detection content, and build the guardrails that keep quality consistent as the team scales across the US, Ireland, and India.
-
Build tooling and APIs that let engineers author, test, and debug detections quickly, turning detection engineering into a repeatable software practice rather than console-by-console work.
Automation & Response Engineering
-
Design automation and SOAR-style workflows, increasingly AI-driven, that collapse high-volume alert categories such as automated phishing campaign clustering and detonation, DLP risk-based routing, enrichment, and auto-closure of verified-benign reports.
-
Build the response automation, including playbooks, containment actions, and integrations, that shrinks dwell time and mean-time-to-respond.
Coverage, Validation & the Intelligence Loop
-
Establish and maintain a MITRE ATT&CK coverage baseline; use it to identify real gaps and redundant coverage and to prioritize engineering effort.
-
Partner with Threat Intelligence and Threat Hunting to convert PIR-driven hunt findings and intel into durable, tested detections through a formal feedback loop.
-
Stand up continuous validation, such as breach-and-attack simulation and a purple-team cadence, so coverage claims are proven against real adversary techniques rather than asserted on paper.
Technical Project Leadership
-
Lead the technical projects that build out this capability end-to-end and own accountability for their delivery by scoping the work, driving execution, and being answerable for completion and outcomes.
-
Serve as the senior-most individual-contributor technical authority for detection engineering, acting as the final technical escalation point before management, setting direction and raising the capability of D&R engineers across regions.
-
Influence roadmap and tooling decisions with internal platform partners, and help shape the operating model as the function grows across a global follow-the-sun, detection-as-code model.
What You Bring
-
AI/ML builder. You can design and build AI/ML pipelines that create real leverage by selecting and applying industry-leading models to security data, engineering the data and enrichment foundations they depend on, and putting them into production with clear evaluation and guardrails. You have a grounded point of view on where AI genuinely accelerates detection and response versus where it adds risk.
-
Builder-first. Detection and response as software: you write, version, test, and ship detections like code, and you have built the tooling, APIs, or pipelines that let others do the same.
-
Detection depth. Deep, hands-on detection engineering experience across SIEM and EDR/XDR platforms, authoring high-fidelity analytics, tuning for signal, and reasoning about telemetry and data sources. Fluency in KQL / SQL / Sigma or equivalent, and strong scripting/development skills (e.g., Python, Go).
-
Threat-informed. You map detections to adversary behavior (ATT&CK), partner naturally with hunting and intel, and think in terms of coverage, exploitability, and containment rather than just rule counts.
-
Delivery ownership. You lead technical projects to completion and own the outcome, setting standards, resolving hard engineering problems, and lifting the quality of everyone around you, comfortable being the deepest technical voice in the room.
-
Communication. You can explain a detection strategy, an AI/ML design choice, or an engineering trade-off clearly to both engineers and senior leaders.
Nice to Have
-
Hands-on experience building or operating within an AI-assisted / agentic SOC model.
-
Security data engineering / streaming pipeline experience (telemetry normalization, parsing, ETL) that feeds ML workflows.
-
Experience across enterprise SIEM, XDR, and EDR platforms.
-
Purple-team, adversary-emulation, or breach-and-attack-simulation partnership experience.
-
Financial services, insurance, or other regulated, high-scale environment exposure.
#LI-JJ1
Skills
API Development, Decision Making, Endpoint Detection and Response (EDR), Machine Learning (ML), MITRE ATT&CK Framework, Scalable AI Pipelines, Security Automation, Security Information and Event Management (SIEM), Security Orchestration, Automation, and Response (SOAR), Stakeholder Influence, Technical Project Leadership, Threat Detection
Compensation
Compensation offered for this role is $151,700 – 222,400 annually and is based on experience and qualifications.
The candidate(s) offered this position will be required to submit to a background investigation.
Joining our team isn’t just a job — it’s an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact.
Allstate generally does not sponsor individuals for employment-based visas for this position.
Effective July 1, 2014, under Indiana House Enrolled Act (HEA) 1242, it is against public policy of the State of Indiana and a discriminatory practice for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component.
For jobs in San Francisco, please click “here” for information regarding the San Francisco Fair Chance Ordinance.
For jobs in Los Angeles, please click “here” for information regarding the Los Angeles Fair Chance Initiative for Hiring Ordinance.
To view the “EEO Know Your Rights” poster click “here”. This poster provides information concerning the laws and procedures for filing complaints of violations of the laws with the Office of Federal Contract Compliance Programs.
To view the FMLA poster, click “here”. This poster summarizing the major provisions of the Family and Medical Leave Act (FMLA) and telling employees how to file a complaint.
It is the Company’s policy to employ the best qualified individuals available for all jobs. Therefore, any discriminatory action taken on account of an employee’s ancestry, age, color, disability, genetic information, gender, gender identity, gender expression, sexual and reproductive health decision, marital status, medical condition, military or veteran status, national origin, race (include traits historically associated with race, including, but not limited to, hair texture and protective hairstyles), religion (including religious dress), sex, or sexual orientation that adversely affects an employee's terms or conditions of employment is prohibited. This policy applies to all aspects of the employment relationship, including, but not limited to, hiring, training, salary administration, promotion, job assignment, benefits, discipline, and separation of employment.
Allstate provides a comprehensive technology setup, including a laptop, monitors, headset, keyboard, and mouse. Employees eligible to work from home also receive a monthly connectivity reimbursement to help offset internet costs.
When working from home, you must have a dedicated, private workspace free from distractions, along with appropriate desk and seating. Reliable internet is required, with minimum speeds of 50 MB download and 5 MB upload.
To help create a more personal and engaging experience, we ask that you join with your camera on if your interview is virtual. Please also have a Valid Photo Identification available at the start of your interview. If you require any accommodations or have questions ahead of your interview please reach out to your recruiter.
Note: Internal candidates are only asked to join on video; a Valid Photo Identification is not needed for the interview.
At Allstate, it’s all about teamwork, flexibility, and thinking ahead. We all contribute to the bigger picture, combining unique ideas to design innovative, more affordable protection solutions for customers.
We look for candidates with these skills to help us achieve that goal:
Learning agility
Quickly adapt to new situations, continually build new skills, experiment, and embrace new ways of doing things
Customer centricity
Deliver exceptional experience with a customer-first mindset and human-centered design
Digital literacy
Discover and apply emerging digital technology tools, data and insights.
Results-oriented
Start with measurable outcomes and drive results with speed
Inclusive leadership
Integrate diverse viewpoints into decision-making processes to enhance creativity and innovation
Together, we’re all working toward Our Shared Purpose, using our strengths to make a real difference for our people, our customers, our company, and the world around us.
What We Do:
Your ability to quickly and calmly make smart decisions can make a huge difference in how confident customers feel throughout the claims process. And as you support our customers, we’re there to support you.
How We Support You:
We empower your success starting day one. You’ll have access to everything you need to grow professionally while helping our customers get their lives back on track.
Make An Impact:
Helping customers with their claims is about learning their stories, not just processing their paperwork. You can take pride in the fact that you’re providing invaluable guidance and helping to build continued trust in our company.
You’re in Good Hands® is more than a promise we make to our customers. It’s a promise we make to our employees, too.
We want you to love where you work. That starts with the freedom to be yourself. Our workplace flexibility and focus on individuality means everyone is seen, heard and respected.
When you join us, you’ll have the opportunity to push your skills to the next level with access to development programs to support your career aspirations – whatever that means for you. Because as you learn and grow, so do we.
Working here also means getting the chance to make a real impact in your community. We have been driving change for over 90 years, but the mark we leave on the world can be even greater when we work together.
At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection.
Job Description
The Threat Detection & Response Engineer — Senior Expert defines and builds the technical foundation of that rebuild. This is a hands-on, build-heavy role for an engineer who treats detections as software that is version-controlled, peer-reviewed, tested, and shipped through a pipeline, and above all one who can design and build the AI/ML pipelines that let a global team investigate and respond at machine speed.
The role leads the technical projects that stand up this capability and owns accountability for their delivery, sets the technical bar for how detection content is written, validated, and deployed, and builds the tooling and intelligence pipelines that make high-quality detection engineering repeatable rather than heroic. This is an individual-contributor role that carries technical leadership and delivery ownership.
Why This Role Exists
-
To stand up a detection-as-code workflow with version control, peer review, staged deployment, and measurable coverage, designed and owned by a principal engineer rather than inherited.
-
To design and build the AI/ML pipelines that accelerate investigation, triage, and detection generation, the capability area we are most focused on developing.
-
To prioritize automation and AI-assisted triage for high-volume, low-judgment work such as phishing and DLP, so human attention goes to the investigations that need judgment.
-
To close the loop between threat intelligence, threat hunting, and detection engineering so that intel and hunt findings reliably become durable detections.
What You’ll Contribute
AI/ML Pipelines for Detection & Response
-
Define, design, and build the AI/ML pipelines at the center of our next-generation D&R capability, applying industry-leading models to investigation, triage, enrichment, and detection generation where they genuinely add leverage.
-
Own the technical delivery of AI-assisted investigation and triage, spanning data foundations and feature/enrichment pipelines through model selection, evaluation, and safe production deployment.
-
Set the standard for how AI/ML outputs are validated, explained, and trusted within detection and response workflows, and lead the projects that move promising pilots into durable, measurable production capability.
Detection-as-Code & Engineering Standards
-
Design and own the detection-as-code pipeline, including repository structure, detection schema, peer-review model, automated testing, and staged (CI/CD) deployment across our SIEM, XDR, and endpoint detection surfaces.
-
Define the technical standards, reusable patterns, and quality bar for detection content, and build the guardrails that keep quality consistent as the team scales across the US, Ireland, and India.
-
Build tooling and APIs that let engineers author, test, and debug detections quickly, turning detection engineering into a repeatable software practice rather than console-by-console work.
Automation & Response Engineering
-
Design automation and SOAR-style workflows, increasingly AI-driven, that collapse high-volume alert categories such as automated phishing campaign clustering and detonation, DLP risk-based routing, enrichment, and auto-closure of verified-benign reports.
-
Build the response automation, including playbooks, containment actions, and integrations, that shrinks dwell time and mean-time-to-respond.
Coverage, Validation & the Intelligence Loop
-
Establish and maintain a MITRE ATT&CK coverage baseline; use it to identify real gaps and redundant coverage and to prioritize engineering effort.
-
Partner with Threat Intelligence and Threat Hunting to convert PIR-driven hunt findings and intel into durable, tested detections through a formal feedback loop.
-
Stand up continuous validation, such as breach-and-attack simulation and a purple-team cadence, so coverage claims are proven against real adversary techniques rather than asserted on paper.
Technical Project Leadership
-
Lead the technical projects that build out this capability end-to-end and own accountability for their delivery by scoping the work, driving execution, and being answerable for completion and outcomes.
-
Serve as the senior-most individual-contributor technical authority for detection engineering, acting as the final technical escalation point before management, setting direction and raising the capability of D&R engineers across regions.
-
Influence roadmap and tooling decisions with internal platform partners, and help shape the operating model as the function grows across a global follow-the-sun, detection-as-code model.
What You Bring
-
AI/ML builder. You can design and build AI/ML pipelines that create real leverage by selecting and applying industry-leading models to security data, engineering the data and enrichment foundations they depend on, and putting them into production with clear evaluation and guardrails. You have a grounded point of view on where AI genuinely accelerates detection and response versus where it adds risk.
-
Builder-first. Detection and response as software: you write, version, test, and ship detections like code, and you have built the tooling, APIs, or pipelines that let others do the same.
-
Detection depth. Deep, hands-on detection engineering experience across SIEM and EDR/XDR platforms, authoring high-fidelity analytics, tuning for signal, and reasoning about telemetry and data sources. Fluency in KQL / SQL / Sigma or equivalent, and strong scripting/development skills (e.g., Python, Go).
-
Threat-informed. You map detections to adversary behavior (ATT&CK), partner naturally with hunting and intel, and think in terms of coverage, exploitability, and containment rather than just rule counts.
-
Delivery ownership. You lead technical projects to completion and own the outcome, setting standards, resolving hard engineering problems, and lifting the quality of everyone around you, comfortable being the deepest technical voice in the room.
-
Communication. You can explain a detection strategy, an AI/ML design choice, or an engineering trade-off clearly to both engineers and senior leaders.
Nice to Have
-
Hands-on experience building or operating within an AI-assisted / agentic SOC model.
-
Security data engineering / streaming pipeline experience (telemetry normalization, parsing, ETL) that feeds ML workflows.
-
Experience across enterprise SIEM, XDR, and EDR platforms.
-
Purple-team, adversary-emulation, or breach-and-attack-simulation partnership experience.
-
Financial services, insurance, or other regulated, high-scale environment exposure.
#LI-JJ1
Skills
API Development, Decision Making, Endpoint Detection and Response (EDR), Machine Learning (ML), MITRE ATT&CK Framework, Scalable AI Pipelines, Security Automation, Security Information and Event Management (SIEM), Security Orchestration, Automation, and Response (SOAR), Stakeholder Influence, Technical Project Leadership, Threat Detection
Compensation
Compensation offered for this role is $151,700 – 222,400 annually and is based on experience and qualifications.
The candidate(s) offered this position will be required to submit to a background investigation.
Joining our team isn’t just a job — it’s an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact.
Allstate generally does not sponsor individuals for employment-based visas for this position.
Effective July 1, 2014, under Indiana House Enrolled Act (HEA) 1242, it is against public policy of the State of Indiana and a discriminatory practice for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component.
For jobs in San Francisco, please click “here” for information regarding the San Francisco Fair Chance Ordinance.
For jobs in Los Angeles, please click “here” for information regarding the Los Angeles Fair Chance Initiative for Hiring Ordinance.
To view the “EEO Know Your Rights” poster click “here”. This poster provides information concerning the laws and procedures for filing complaints of violations of the laws with the Office of Federal Contract Compliance Programs.
To view the FMLA poster, click “here”. This poster summarizing the major provisions of the Family and Medical Leave Act (FMLA) and telling employees how to file a complaint.
It is the Company’s policy to employ the best qualified individuals available for all jobs. Therefore, any discriminatory action taken on account of an employee’s ancestry, age, color, disability, genetic information, gender, gender identity, gender expression, sexual and reproductive health decision, marital status, medical condition, military or veteran status, national origin, race (include traits historically associated with race, including, but not limited to, hair texture and protective hairstyles), religion (including religious dress), sex, or sexual orientation that adversely affects an employee's terms or conditions of employment is prohibited. This policy applies to all aspects of the employment relationship, including, but not limited to, hiring, training, salary administration, promotion, job assignment, benefits, discipline, and separation of employment.
Allstate provides a comprehensive technology setup, including a laptop, monitors, headset, keyboard, and mouse. Employees eligible to work from home also receive a monthly connectivity reimbursement to help offset internet costs.
When working from home, you must have a dedicated, private workspace free from distractions, along with appropriate desk and seating. Reliable internet is required, with minimum speeds of 50 MB download and 5 MB upload.
To help create a more personal and engaging experience, we ask that you join with your camera on if your interview is virtual. Please also have a Valid Photo Identification available at the start of your interview. If you require any accommodations or have questions ahead of your interview please reach out to your recruiter.
Note: Internal candidates are only asked to join on video; a Valid Photo Identification is not needed for the interview.
At Allstate, it’s all about teamwork, flexibility, and thinking ahead. We all contribute to the bigger picture, combining unique ideas to design innovative, more affordable protection solutions for customers.
We look for candidates with these skills to help us achieve that goal:
Learning agility
Quickly adapt to new situations, continually build new skills, experiment, and embrace new ways of doing things
Customer centricity
Deliver exceptional experience with a customer-first mindset and human-centered design
Digital literacy
Discover and apply emerging digital technology tools, data and insights.
Results-oriented
Start with measurable outcomes and drive results with speed
Inclusive leadership
Integrate diverse viewpoints into decision-making processes to enhance creativity and innovation
Together, we’re all working toward Our Shared Purpose, using our strengths to make a real difference for our people, our customers, our company, and the world around us.
You’re in Good Hands® is more than a promise we make to our customers. It’s a promise we make to our employees, too.
We want you to love where you work. That starts with the freedom to be yourself. Our workplace flexibility and focus on individuality means everyone is seen, heard and respected.
When you join us, you’ll have the opportunity to push your skills to the next level with access to development programs to support your career aspirations – whatever that means for you. Because as you learn and grow, so do we.
Working here also means getting the chance to make a real impact in your community. We have been driving change for over 90 years, but the mark we leave on the world can be even greater when we work together.
Benefits
Experience the benefits that make Allstate a great place to work.
*Benefits vary based on position.

- Medical, dental and vision coverage
- HSAs and FSAs
- Wellbeing programs
- Free therapy sessions

- 401(k) plan
- Pension plan
- Free financial counseling

- Paid time off
- Work flexibility

- Talent shares
- Tuition reimbursement
- Learning opportunities
For a full description of Allstate’s benefits visit our benefits page
Start making a difference
Realize your full potential by doing
work that matters.
Grow your career in meaningful ways.
We want to make sure you have every opportunity to grow, explore new horizons and follow your passion in a meaningful career. It’s an exciting time to join Allstate. Help us shape the future.














