Risk Partner Senior Manager - Technology & Cybersecurity

Allstate Allstate · Insurance · IL · Remote

Senior Manager role focused on operational and cybersecurity risk within Enterprise Shared Services Technology at Allstate. This role acts as a second line of defense, providing independent oversight and risk assessment for technology and cybersecurity functions, including sensitive data, regulatory compliance, and third-party ecosystems. The position requires deep cybersecurity expertise and the ability to translate complex risk signals into business impact for executive leadership.

What you'd actually do

  1. Serve as the primary risk partner and advisor to senior business and technology leaders for Enterprise Shared Services Technology (ATS) and the supported shared services functions (Human Resources, Legal, Finance, and Law & Regulation) providing an integrated view of operational risk across cybersecurity, technology, resilience, third‑party, and compliance domains.
  2. Provide cybersecurity risk leadership for enterprise platforms supporting shared services, including risks related to sensitive employee data, financial systems, legal information, regulatory data, and privileged access.
  3. Operate as a second line of defense function, providing independent oversight, challenge, and guidance to first line teams without owning controls or delivery execution.
  4. Plan and oversee risk assessments and thematic reviews, synthesizing outputs into executive‑level insights and trend analysis.
  5. Prepare and deliver concise risk briefings for senior leaders, councils, and committees.

Skills

Required

  • 10+ years of experience in cybersecurity, technology risk, operational risk, or related disciplines within a large, complex organization.
  • Demonstrated deep cybersecurity expertise equivalent to a Business Information Security Officer, Security Risk Lead, or similar senior cyber risk role.
  • Proven experience operating in or alongside a second line of defense function within a Three or Four Lines of Defense model.
  • Ability to engage credibly with senior engineers, architects, and security teams while maintaining independence from first‑line delivery ownership.
  • Strong executive communication skills with the ability to translate technical risk into business impact.

Nice to have

  • Experience in highly regulated environments and familiarity with regulatory expectations impacting technology and cybersecurity risk.
  • Experience with operational resilience, third‑party risk, or enterprise risk management functions.
  • Relevant professional certifications (e.g., CISSP, CISM, CRISC, or equivalent).

What the JD emphasized

  • deep cybersecurity knowledge and expertise
  • cybersecurity risk leadership
  • second line of defense
  • highly regulated environments