Lead Platform Consultant (hybrid)

Allstate Allstate · Insurance · Belfast, United Kingdom +1

Lead Platform Consultant at Allstate focused on engineering enterprise-wide security solutions, including AI Security and Threat Modeling Agents. The role involves acting as a strategic advisor to engineering teams, guiding secure platform design, embedding secure-by-design principles, and leveraging AI for enhanced platform capabilities. The candidate will also mentor teams and influence cross-functional engagements.

What you'd actually do

  1. Serve as a trusted consultant to engineering teams and organizations, guiding secure platform design and implementation across diverse product domains
  2. Communicate clearly and effectively ensuring business and engineering needs are met
  3. Foster effective collaborative sessions with teams from different disciplines and leadership levels
  4. Embed secure-by-design principles and deep threat modeling practices into the development lifecycle, ensuring security is foundational—not bolted on
  5. Define and communicate Allstate’s security posture clearly to technical and business leadership, enabling informed decision-making

Skills

Required

  • 5 years software engineering experience
  • Object-oriented programming (Java & Javascript required)
  • Procedural / systems programming (e.g. Go, Rust, C)
  • Functional programming (e.g. F#, Elixir, Clojure, Haskell)
  • modern development tools (e.g., IntelliJ or VS Code, Git/GitHub, Spring Boot)
  • designing robust RESTful APIs
  • 3 years hands on expertise in architecting and delivering large scale distributed systems
  • cloud native microservices on Docker/Kubernetes
  • modern cloud platforms (AWS, Azure, or equivalent)
  • high impact technical advisor to multiple engineering teams
  • influence architecture direction
  • mentor engineers in best practices
  • leadership responsibilities
  • Agile/XP and DevOps methodologies
  • paired programming
  • test driven development (TDD)
  • CI/CD automation

Nice to have

  • In-depth knowledge of industry security frameworks and web/API security standards e.g., OWASP Top 10, MITRE ATT&CK, OAuth 2.0, OpenID Connect, SAML
  • Deep expertise in security architecture and secure-by-design practices
  • advanced threat modeling
  • robust identity and access management (IAM) strategies
  • Zero Trust architectures
  • Technical proficiency with AI tools such as running local models, developing MCP servers, using AI powered development tools like cursor/copilot/claude code/codex/etc
  • test for effective model deployment strategies
  • API-first design
  • specification-driven development (e.g., OpenAPI, Swagger)
  • shape developer experience
  • accelerate delivery through contract-first approaches

What the JD emphasized

  • deep engineering expertise
  • strong security architecture experience
  • rigorous threat modeling
  • security-focused engineering leader
  • forward-thinking technical leader
  • developer experience or security integrity