At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection.
Job Description
Product Security is growing. We are engineering enterprise-wide security solutions that start left instead of just shifting left. Our focus spans AI Security, SaaS Security, API Security, Threat Modeling Agents, Apex Threat Modeling, Code Security in the IDE/Pipelines, and more.Serve as a trusted consultant to engineering teams and organizations, guiding secure platform design and implementation across diverse product domains
Communicate clearly and effectively ensuring business and engineering needs are met
Foster effective collaborative sessions with teams from different disciplines and leadership levels
Embed secure-by-design principles and deep threat modeling practices into the development lifecycle, ensuring security is foundational—not bolted on
Define and communicate Allstate’s security posture clearly to technical and business leadership, enabling informed decision-making
Lead the ideation and implementation of innovative security controls that challenge the status quo and elevate Allstate’s embedded security maturity
Drive forward engineering practices that adapt to evolving technologies, enabling scalable, resilient, and efficient platforms
Mentor engineers and platform consultants in systems thinking, reusable design, and outcome-based delivery
Influence cross-functional teams through Discovery & Framing sessions, architectural reviews, and strategic planning
Promote and enforce architectural standards, simplification, and reuse across the enterprise
Actively participate in agile ceremonies and foster a culture of continuous learning and iterative delivery
Job Qualifications
Essential Skills:
Extensive experience (8+ years) in software engineering, platform development, or architecture roles, with increasing technical leadership responsibilities in complex enterprise environments
Demonstrated success as a high-impact technical advisor to multiple engineering teams, with proven ability to influence architecture direction and mentor engineers in best practices
Expert-level knowledge of Agile/XP and DevOps methodologies, including paired programming, test-driven development (TDD), and CI/CD automation, with a track record of using these practices to accelerate delivery and improve quality
Hands-on expertise in architecting and delivering large-scale distributed systems, such as cloud-native microservices on Docker/Kubernetes, deployed on modern cloud platforms (AWS, Azure, or equivalent), ensuring scalability, high availability, and performance
Broad technical proficiency across multiple programming languages and frameworks (especially Java and JavaScript ecosystems), and comfort with modern development tools (e.g., IntelliJ or VS Code, Git/GitHub, Spring Boot) and designing robust RESTful APIs
Exceptional analytical and problem-solving skills, combined with excellent communication abilities to clearly convey complex technical and security concepts to both engineering teams and senior business leaders
Desirable Skills:
In-depth knowledge of industry security frameworks and web/API security standards – e.g., OWASP Top 10, MITRE ATT&CK, OAuth 2.0, OpenID Connect, SAML – to guide secure design and development practices
Deep expertise in security architecture and secure-by-design practices, including advanced threat modeling, robust identity and access management (IAM) strategies, and Zero Trust architectures – with a proven ability to embed these controls at all stages of the development lifecycle
Broad technical proficiency across multiple programming paradigms – in addition to Java and JavaScript experience, deep experience with procedural (e.g., Go, Rust) and functional (e.g., F#, Elixir, Haskell, Clojure) programming languages is a strong signal of architectural proficiency
Technical proficiency with AI tools such as running local models, developing MCP servers, using AI powered development tools like cursor/copilot/claude code/codex/etc. to help drive your work more efficiently and test for effective model deployment strategies
Demonstrated expertise in API-first design and specification-driven development (e.g., OpenAPI, Swagger), enabling scalable, discoverable, and reusable services. Proven ability to shape developer experience and accelerate delivery through contract-first approaches, while laying the foundation for AI-assisted development and automated API governance
Deep understanding of modern cryptographic principles and protocols (e.g., AES, TLS, Argon2, elliptic curve cryptography), with the ability to evaluate, implement, and advise on secure data protection strategies. Skilled in applying cryptographic techniques to strengthen trust boundaries, safeguard sensitive data, and ensure compliance with enterprise and regulatory security standards
Experience with advanced development and testing practices, such as behavior-driven development (BDD) and integrating automated security checks into CI/CD pipelines
Familiarity with emerging technologies (e.g., AI/ML, knowledge graph solutions, advanced analytics) and their application to improve developer velocity, platform reliability, and security capabilities
Exposure to specialized security domains like AI Security, SaaS Security, and API Security, with an understanding of the unique challenges and tools in these areas
This job does not have supervisory duties.
#LI-JJ1
Skills
Agile Methodology, Analytical Thinking, CI/CD, Cloud-Native Architecture, Cybersecurity Controls, DevOps, Enterprise Software Architecture, Platform Development, Product Security, Software Engineering, Strategic Advisory, Technical Leadership, Zero Trust ArchitectureCompensation
Compensation offered for this role is $160,000 – 230,000 annually and is based on experience and qualifications.The candidate(s) offered this position will be required to submit to a background investigation.
Joining our team isn’t just a job — it’s an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact.
Allstate generally does not sponsor individuals for employment-based visas for this position.
Effective July 1, 2014, under Indiana House Enrolled Act (HEA) 1242, it is against public policy of the State of Indiana and a discriminatory practice for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component.
For jobs in San Francisco, please click “here” for information regarding the San Francisco Fair Chance Ordinance.
For jobs in Los Angeles, please click “here” for information regarding the Los Angeles Fair Chance Initiative for Hiring Ordinance.
To view the “EEO Know Your Rights” poster click “here”. This poster provides information concerning the laws and procedures for filing complaints of violations of the laws with the Office of Federal Contract Compliance Programs.
To view the FMLA poster, click “here”. This poster summarizing the major provisions of the Family and Medical Leave Act (FMLA) and telling employees how to file a complaint.
It is the Company’s policy to employ the best qualified individuals available for all jobs. Therefore, any discriminatory action taken on account of an employee’s ancestry, age, color, disability, genetic information, gender, gender identity, gender expression, sexual and reproductive health decision, marital status, medical condition, military or veteran status, national origin, race (include traits historically associated with race, including, but not limited to, hair texture and protective hairstyles), religion (including religious dress), sex, or sexual orientation that adversely affects an employee's terms or conditions of employment is prohibited. This policy applies to all aspects of the employment relationship, including, but not limited to, hiring, training, salary administration, promotion, job assignment, benefits, discipline, and separation of employment.

BCD Travel

Foundever

SupportYourApp

ConMendo GmbH

PartnerStack

Allstate Identity Protection

Allstate Identity Protection

Allstate Identity Protection