At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. For more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs, from advocating for seat belts and airbags to pioneering pricing sophistication, telematics, and, more recently, device and identity protection.
Your role in the team
Product Security Engineering designs, builds, and operates enterprise security controls as software products that integrate directly into cloud platforms, the SDLC, and core enterprise services. The organization applies modern software and cloud engineering practices to deliver scalable, reliable, and developer‑friendly security capabilities for cloud-hosted workloads.
The Cloud Product Security Engineer is a hands‑on security engineer responsible for building, integrating, and operating security controls within cloud environments. This role focuses on engineering preventative, detective, and responsive security capabilities across cloud infrastructure, data platforms, and application services. It includes building and operating CSPM and DLP capabilities to continuously detect, assess, and reduce risk in cloud environments. Engineers in this role own the full software development lifecycle from design and implementation through deployment and production support and are accountable for the reliability, adoption, and effectiveness of cloud security controls, including their role in incident detection, response, and recovery.
Key Responsibilities
* Design, build, and operate cloud‑native security controls as software products across cloud infrastructure, data platforms, and application services
* Engineer and maintain CSPM and DLP capabilities to continuously detect, assess, and reduce risk in cloud environments
* Build preventative, detective, and responsive security controls that integrate directly into cloud platforms, CI/CD pipelines, and shared enterprise services
* Integrate cloud security controls with SIEM and security tooling to generate high‑quality signals for detection, investigation, and incident response
* Support incident handling and response by engineering detection logic, automation, and response mechanisms that improve containment and recovery
* Apply modern cloud and software engineering practices (e.g., infrastructure as code, automated testing, CI/CD) to ensure security controls are reliable, scalable, and maintainable
* Collaborate with platform engineers, application teams, and digital product managers to align cloud security controls with architectures and developer workflows
Essential Skills
* All applicants must demonstrate a legal right to work in the UK; this vacancy does not sponsor visas
* Minimum of 3 years professional software or security engineering experience with ownership of production systems in cloud environments; proficiency in at least one modern programming language (Python, Java, or JavaScript) and ability to design, write, review, and maintain production‑grade code
* Hands‑on experience engineering security controls within public cloud platforms (AWS and/or Azure), spanning infrastructure, platform services, or application-level integrations
* Background building or integrating CSPM, data protection, or DLP capabilities as engineered solutions
* Understanding of cloud‑native architectures and services (identity, networking, storage, compute) and how security controls integrate into them
* Experience engineering preventative, detective, and responsive security capabilities, including detection logic, automation, or response workflows in cloud environments
* Familiarity with integrating security controls and signals into SIEM or security monitoring platforms to support detection and incident response
* Practical application of modern engineering practices such as infrastructure as code, automated testing, CI/CD, and operational feedback loops
Desirable Skills
* Working knowledge of cloud provider security services and patterns (identity, networking, encryption, logging) and their use in real‑world cloud architectures
* Practical exposure to advanced CSPM techniques, including policy‑as‑code, drift detection, and automated remediation
* Experience with data classification, handling, or protection strategies that support DLP in hosted systems
* Familiarity with security telemetry, logging pipelines, and SIEM platforms for detection, investigation, and incident response
* Hands‑on involvement in incident response or post‑incident analysis from an engineering perspective
* Exposure to infrastructure‑as‑code and cloud automation tooling used to deploy, configure, and secure cloud resources at scale
* Understanding of secure design principles for cloud‑native and distributed systems, including identity‑centric and least‑privilege approaches
* Demonstrated interest in continuously improving cloud security controls through learning, experimentation, and collaboration
Supervisory Responsibilities
This role has supervisory responsibilities and serves as the first-level manager for a team of engineers.
Benefits
* A generous, flexible benefits package including annual leave, healthcare and dental cover, pension, and lifestyle discounts
* Access to world‑class learning platforms and award‑winning learning & development
* Clear career paths, internal mobility, and a strong focus on growth
* People‑first culture with flexible working options
Statement on Fair Employment and Equal Opportunities
Allstate NI wishes to ensure equal opportunity is given to all job applicants. This company will not discriminate on the grounds of race, gender (including gender reassignment status), sexual orientation, religious belief, political opinion, marital status, age or disability. All appointments will be made on merit. Applicants should note Allstate NI completes AccessNI background checks on all candidates offered a position.
#J-18808-Ljbffr