Allstate
Insurance
See how your profile stacks up against this role.
We compared the job requirements to your profile to show where you're strong and where you fall short.
At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection.
Job Description
The Supplier Security Due Diligence & Monitoring Service operates at the intersection of Cybersecurity, Legal, Procurement, Supplier Management, and Enterprise Risk Management. The team is responsible for helping the enterprise navigate information security requirements within supplier contracts by providing first-line support during contract negotiations and redline reviews.Provide subject matter expertise and consultation on information security requirements within supplier contracts during contract negotiations and redline reviews.
Translate supplier risk assessment outcomes into practical contractual security positions and recommend risk-aligned solutions for business stakeholders.
Review supplier-proposed contractual language and determine alignment with established security requirements, standards, and enterprise risk expectations.
Apply approved fallback language and assist stakeholders in navigating contractual negotiations involving security controls and requirements.
Document security control exceptions, risk acceptance decisions, contractual deviations, and non-standard positions in accordance with established governance processes.
Facilitate escalation and governance review of contractual positions that fall outside approved standards or risk tolerances.
Partner closely with Cybersecurity, Legal, Procurement, Supplier Management, Enterprise Risk Management, and business stakeholders to support timely and informed contracting decisions.
Serve as a senior resource for complex supplier security due diligence engagements and contractual risk discussions.
Support development and maintenance of service procedures, operating guidelines, knowledge articles, templates, and training materials.
Identify trends, recurring issues, and opportunities for process optimization to improve service effectiveness and stakeholder experience.
Contribute to service metrics, reporting, quality assurance activities, and continuous improvement initiatives.
Preferred Experience
Experience supporting third-party risk management, supplier security assessments, cybersecurity governance, technology risk management, procurement, legal operations, or contract management activities.
Demonstrated ability to interpret complex security requirements and translate technical risk concepts into practical business and contractual guidance.
Experience working with cross-functional stakeholders including Legal, Procurement, Enterprise Risk Management, and Cybersecurity teams.
Strong analytical, communication, negotiation, and stakeholder management skills.
Experience supporting governance processes, exception management, policy interpretation, and control assessment activities.
Ability to influence decisions, build consensus, and navigate ambiguity in a complex enterprise environment.
Success in this role
Success in this position is demonstrated through the delivery of consistent, risk-aligned contractual security guidance; effective support of supplier negotiations; timely resolution of stakeholder inquiries; thorough documentation of contractual exceptions and decisions; and meaningful contributions to the ongoing maturity, scalability, and effectiveness of the Supplier Security Due Diligence & Monitoring Service. The role helps ensure the enterprise can confidently engage suppliers while maintaining alignment with information security requirements and enterprise risk expectations.
Skills
Analytical Thinking, Contract Negotiations, Cybersecurity Risk Management, Executive Communications, Information Security, Information Technology (IT) Risk Management, Process Governance, Reporting, Risk Mitigation Strategies, Risk Reporting, Supplier Governance, Supplier Management, Technical Risk Assessment, Third Party Risk Management, Threat and Vulnerability ManagementCompensation
Compensation offered for this role is 90,700.00 - 153,925.00 annually and is based on experience and qualifications.The candidate(s) offered this position will be required to submit to a background investigation.
Joining our team isn’t just a job — it’s an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact.
Allstate generally does not sponsor individuals for employment-based visas for this position.
Effective July 1, 2014, under Indiana House Enrolled Act (HEA) 1242, it is against public policy of the State of Indiana and a discriminatory practice for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component.
For jobs in San Francisco, please click “here” for information regarding the San Francisco Fair Chance Ordinance.
For jobs in Los Angeles, please click “here” for information regarding the Los Angeles Fair Chance Initiative for Hiring Ordinance.
To view the “EEO Know Your Rights” poster click “here”. This poster provides information concerning the laws and procedures for filing complaints of violations of the laws with the Office of Federal Contract Compliance Programs.
To view the FMLA poster, click “here”. This poster summarizing the major provisions of the Family and Medical Leave Act (FMLA) and telling employees how to file a complaint.
It is the Company’s policy to employ the best qualified individuals available for all jobs. Therefore, any discriminatory action taken on account of an employee’s ancestry, age, color, disability, genetic information, gender, gender identity, gender expression, sexual and reproductive health decision, marital status, medical condition, military or veteran status, national origin, race (include traits historically associated with race, including, but not limited to, hair texture and protective hairstyles), religion (including religious dress), sex, or sexual orientation that adversely affects an employee's terms or conditions of employment is prohibited. This policy applies to all aspects of the employment relationship, including, but not limited to, hiring, training, salary administration, promotion, job assignment, benefits, discipline, and separation of employment.
Allstate provides a comprehensive technology setup, including a laptop, monitors, headset, keyboard, and mouse. Employees eligible to work from home also receive a monthly connectivity reimbursement to help offset internet costs.
When working from home, you must have a dedicated, private workspace free from distractions, along with appropriate desk and seating. Reliable internet is required, with minimum speeds of 50 MB download and 5 MB upload.
After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.
Marcus Rivera
Chief Revenue Officer

Fiserv

AM53 Smart Solutions

Dale WorkForce Solutions

HumanIT Solutions

Harper James

Allstate

Allstate

Allstate