Cloud Product Security Engineer

Allstate Corporation
Chicago, United States of America
27 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Intermediate
Compensation
$ 196K

Job location

Chicago, United States of America

Tech stack

Java
JavaScript
Amazon Web Services (AWS)
Application Services
Automation of Tests
Azure
Cloud Computing
Cloud Computing Security
Cloud Engineering
Continuous Integration
Information Leak Prevention
DevOps
Distributed Systems
Python
Systems Development Life Cycle
Cloud Services
Security Information and Event Management
Software Engineering
Systems Integration
Data Logging
Data Processing
Cloud Platform System
Data Classification
Software Security
Infrastructure as Code (IaC)
Infrastructure Automation Frameworks
Data Management
Programming Languages

Job description

For this opportunity, the business is flexible to hire at Sr Consultant II, Lead Consultant, and Expert level depending on qualifications & interview evaluation.

Product Security Engineering designs, builds, and operates enterprise security controls as software products that integrate directly into cloud platforms, the SDLC, and core enterprise services. The organization applies modern software and cloud engineering practices to deliver scalable, reliable, and developer friendly security capabilities for cloud hosted workloads.

The Cloud Product Security Engineer is a hands-on security engineer responsible for building, integrating, and operating security controls within cloud environments. This role focuses on engineering preventative, detective, and responsive security capabilities across cloud infrastructure, data platforms, and application services. It includes building and operating cloud security posture management (CSPM) and data loss prevention (DLP) capabilities to continuously detect, assess, and reduce risk in cloud environments. Engineers in this role own the full software development lifecycle from design and implementation through deployment and production support and are accountable for the reliability, adoption, and effectiveness of cloud security controls, including their role in incident detection, response, and recovery.

Key Responsibilities

  • Design, build, andoperatecloudnativesecurity controls as software products across cloud infrastructure, data platforms, and application services
  • Engineer andmaintaincloud security posture management (CSPM) and data loss prevention (DLP) capabilities to continuously detect, assess, and reduce risk in cloud environments
  • Build preventative, detective, and responsive security controls that integrate directly into cloud platforms, CI/CD pipelines, and shared enterprise services
  • Integrate cloud security controls with SIEM and security tooling to generatehighqualitysignals for detection, investigation, and incident response
  • Support incident handling and response by engineering detection logic, automation, and response mechanisms that improve containment and recovery
  • Apply modern cloud and software engineering practices (e.g., infrastructure as code, automated testing, CI/CD) to ensure security controls are reliable, scalable, and maintainable
  • Collaborate with platform engineers, application teams, and Digital Product Managers to align cloud security controls with architectures and developer workflows, The candidate(s) offered this position will be required to submit to a background investigation.

Joining our team isn't just a job - it's an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger - a winning team making a meaningful impact.

Allstate generally does not sponsor individuals for employment-based visas for this position.

Effective July 1, 2014, under Indiana House Enrolled Act (HEA) 1242, it is against public policy of the State of Indiana and a discriminatory practice for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component.

Requirements

  • 3+ years of professional software or security engineering experience, with hands on ownership of production systems deployed in cloud environments. Strongproficiencyin one or more modern programming languages (such as Python, Java, or JavaScript), and a proven ability to design, write, review, andmaintainrobust production grade code.
  • Handsonexperience engineering security controls within public cloud platforms (e.g., AWS and/or Azure), spanning infrastructure, platform services, orapplicationlevelintegrations
  • Background building or integrating cloud security posture management (CSPM), data protection, or data loss prevention (DLP) capabilities as engineered solutions
  • Understanding ofcloudnativearchitectures and services (e.g., identity, networking, storage, compute) and how security controls integrate into them
  • Experience engineering preventative, detective, and responsive security capabilities, including detection logic, automation, or response workflows in cloud environments
  • Familiarity integrating security controls and signals with SIEM or security monitoring platforms to support detection and incident response
  • Practical application of modern engineering practices such as infrastructure as code, automated testing, CI/CD, and operational feedback loops

Desirable Skills:

  • Working knowledge of cloud service provider security services and patterns (e.g., identity, networking, encryption, logging) and their use inrealworldcloud architectures
  • Practical exposure to advanced CSPM techniques, includingpolicyascode, drift detection, and automated remediation
  • Experience with data classification, data handling, or data protection strategies that support DLP incloudhostedsystems
  • Familiarity with security telemetry, logging pipelines, and SIEM platforms used for detection, investigation, and incident response
  • Handsoninvolvement in incident response orpostincidentanalysis from an engineering perspective (e.g., improving detections, controls, or recovery mechanisms)
  • Exposure toinfrastructureascodeand cloud automation tooling used to deploy, configure, and secure cloud resources at scale
  • Understanding of secure design principles forcloudnativeand distributed systems, includingidentitycentricandleastprivilegeapproaches
  • Demonstrated interest in continuously improving cloud security controls through learning, experimentation, and collaboration

#LI-JJ1

Skills CI/CD, Cloud Platform, Cloud Security, Collaboration, Data Loss Prevention (DLP), Infrastructure As Code (IaC), Java (Programming Language), JavaScript, Python (Programming Language), Security Engineering, Software Development Life Cycle (SDLC), Software Engineering

Benefits & conditions

Compensation offered for this role ranges from $90,700 - 195,700 annually and is based on experience and qualifications

About the company

At Allstate, great things happen when our people work together to protect families and their belongings from life's uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers' evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection.

Apply for this position