Platform Consultant - Product Security

Allstate Allstate · Insurance · United States · Remote

Allstate is seeking a Platform Consultant with deep engineering and security architecture experience to guide engineering teams in building secure enterprise-wide solutions. The role focuses on AI Security, SaaS Security, API Security, Threat Modeling Agents, and embedding secure-by-design principles. The consultant will act as a strategic advisor, make architectural decisions, communicate security posture to leadership, and mentor teams on modern engineering practices and emerging technologies.

What you'd actually do

  1. Serve as a trusted consultant to engineering teams and organizations, guiding secure platform design and implementation across diverse product domains
  2. Communicate clearly and effectively ensuring business and engineering needs are met
  3. Foster effective collaborative sessions with teams from different disciplines and leadership levels
  4. Embed secure-by-design principles and deep threat modeling practices into the development lifecycle, ensuring security is foundational—not bolted on
  5. Define and communicate Allstate’s security posture clearly to technical and business leadership, enabling informed decision-making

Skills

Required

  • Extensive experience (8+ years) in software engineering, platform development, or architecture roles, with increasing technical leadership responsibilities in complex enterprise environments
  • Demonstrated success as a high-impact technical advisor to multiple engineering teams, with proven ability to influence architecture direction and mentor engineers in best practices
  • Expert-level knowledge of Agile/XP and DevOps methodologies, including paired programming, test-driven development (TDD), and CI/CD automation, with a track record of using these practices to accelerate delivery and improve quality
  • Hands-on expertise in architecting and delivering large-scale distributed systems, such as cloud-native microservices on Docker/Kubernetes, deployed on modern cloud platforms (AWS, Azure, or equivalent), ensuring scalability, high availability, and performance
  • Broad technical proficiency across multiple programming languages and frameworks (especially Java and JavaScript ecosystems), and comfort with modern development tools (e.g., IntelliJ or VS Code, Git/GitHub, Spring Boot) and designing robust RESTful APIs
  • Exceptional analytical and problem-solving skills, combined with excellent communication abilities to clearly convey complex technical and security concepts to both engineering teams and senior business leaders

Nice to have

  • In-depth knowledge of industry security frameworks and web/API security standards – e.g., OWASP Top 10, MITRE ATT&CK, OAuth 2.0, OpenID Connect, SAML – to guide secure design and development practices
  • Deep expertise in security architecture and secure-by-design practices, including advanced threat modeling, robust identity and access management (IAM) strategies, and Zero Trust architectures – with a proven ability to embed these controls at all stages of the development lifecycle
  • Broad technical proficiency across multiple programming paradigms – in addition to Java and JavaScript experience, deep experience with procedural (e.g., Go, Rust) and functional (e.g., F#, Elixir, Haskell, Clojure) programming languages is a strong signal of architectural proficiency
  • Technical proficiency with AI tools such as runnin

What the JD emphasized

  • AI Security
  • Threat Modeling Agents
  • rigorous threat modeling
  • secure-by-design principles
  • security architecture
  • security integrity