Cloud Product Security Engineer

Allstate Allstate · Insurance · United States · Remote

Product Security Engineer responsible for building, integrating, and operating security controls within cloud environments, focusing on CSPM and DLP capabilities. The role involves engineering preventative, detective, and responsive security capabilities across cloud infrastructure, data platforms, and application services, integrating with SIEM and security tooling, and supporting incident response.

What you'd actually do

  1. Design, build, and operate cloud‑native security controls as software products across cloud infrastructure, data platforms, and application services
  2. Engineer and maintain cloud security posture management (CSPM) and data loss prevention (DLP) capabilities to continuously detect, assess, and reduce risk in cloud environments
  3. Build preventative, detective, and responsive security controls that integrate directly into cloud platforms, CI/CD pipelines, and shared enterprise services
  4. Integrate cloud security controls with SIEM and security tooling to generate high‑quality signals for detection, investigation, and incident response
  5. Support incident handling and response by engineering detection logic, automation, and response mechanisms that improve containment and recovery

Skills

Required

  • 3+ years of professional software or security engineering experience
  • Strong proficiency in one or more modern programming languages (such as Python, Java, or JavaScript)
  • Hands‑on experience engineering security controls within public cloud platforms (e.g., AWS and/or Azure)
  • Background building or integrating cloud security posture management (CSPM), data protection, or data loss prevention (DLP) capabilities as engineered solutions
  • Understanding of cloud‑native architectures and services
  • Experience engineering preventative, detective, and responsive security capabilities
  • Familiarity integrating security controls and signals with SIEM or security monitoring platforms
  • Practical application of modern engineering practices such as infrastructure as code, automated testing, CI/CD, and operational feedback loops

Nice to have

  • Working knowledge of cloud service provider security services and patterns
  • Practical exposure to advanced CSPM techniques
  • Experience with data classification, data handling, or data protection strategies
  • Familiarity with security telemetry, logging pipelines, and SIEM platforms
  • Hands‑on involvement in incident response or post‑incident analysis from an engineering perspective
  • Exposure to infrastructure‑as‑code and cloud automation tooling
  • Understanding of secure design principles for cloud‑native and distributed systems
  • Demonstrated interest in continuously improving cloud security controls

What the JD emphasized

  • hands on ownership of production systems deployed in cloud environments
  • Hands‑on experience engineering security controls within public cloud platforms
  • Background building or integrating cloud security posture management (CSPM), data protection, or data loss prevention (DLP) capabilities as engineered solutions
  • Experience engineering preventative, detective, and responsive security capabilities