Security Engineering Senior Manager

Allstate Allstate · Insurance · United States · Remote

Senior Manager for Security Engineering at Allstate, leading teams to build and implement security controls within the company's technology ecosystem. Focuses on secure software development, cloud security, application security, and DevSecOps practices, ensuring alignment with business goals and security posture.

What you'd actually do

  1. Design, implement, and productize security controls to address complex business and technology challenges.
  2. Work directly with business and technical teams to assess and provide security technology support.
  3. Understand multiple end-to-end business and technology processes, with a focus on security risks and mitigations.
  4. Display deep knowledge of technical details, integration, and functions of security tools and platforms (e.g., IAM, SIEM, vulnerability management, cloud security).
  5. Evaluate potential system enhancements and upgrades, influencing the security product roadmap.

Skills

Required

  • Security Engineering
  • Technical Leadership
  • Secure Software Development
  • Cloud Security
  • Application Security
  • DevSecOps
  • Secure Software Configuration
  • Secure APIs
  • Authentication/Authorization
  • Encryption
  • Threat Modeling
  • Modern Security Frameworks
  • CI/CD Security
  • Cloud-Native Security
  • Compliance
  • Test Driven Development (TDD)
  • Agile SCRUM
  • Secure SDLC

Nice to have

  • Vulnerability Management
  • IAM
  • SIEM
  • Team Leadership
  • Technical Problem-Solving
  • CI/CD

What the JD emphasized

  • security engineering
  • technical leadership
  • secure software development
  • cloud security
  • application security
  • DevSecOps practices
  • compliance knowledge
  • secure software best practices
  • risk and security posture
  • security controls
  • security technology support
  • security risks and mitigations
  • security tools and platforms
  • security product roadmap
  • security operations
  • secure development and operations
  • secure software configuration and development
  • secure APIs
  • authentication/authorization
  • encryption
  • threat modeling
  • modern security frameworks
  • tools
  • methodologies
  • CI/CD security
  • cloud-native security
  • technology best practices
  • secure development
  • compliance
  • secure SDLC