Cloud Product Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+7 more
Job description
Allstate is seeking a Cloud Product Security Engineer to secure cloud-native insurance and financial products in a dynamic, customer-focused environment. You’ll partner with product, engineering, and DevOps teams to design secure architectures, conduct threat modeling, and embed security controls across AWS/Azure/GCP. Responsibilities include automating security via CI/CD and IaC, managing vulnerabilities and misconfigurations, and leading incident response. You’ll shape security standards, mentor teams, and help advance Allstate’s mission of protecting customers and communities through resilient digital solutions., * Design and implement secure architectures for Allstate’s cloud-hosted insurance and financial products across AWS/Azure/GCP environments.
- Embed security into the product lifecycle by partnering with engineering, product, and Dev
- Ops teams from design through deployment.
- Conduct threat modeling, risk assessments, and security reviews for cloud-native applications, APIs, and data pipelines.
- Implement and manage security controls including IAM, encryption, key management, secrets management, and network segmentation.
- Automate security testing and policy enforcement using CI/CD pipelines, infrastructure as code, and security-as-code practices.
- Monitor cloud environments for vulnerabilities and misconfigurations, and drive timely remediation with engineering teams.
- Evaluate and integrate cloud security tools such as CSPM, CWPP, SIEM, and SAST/DAST solutions.
- Develop and maintain secure coding standards, reference architectures, and best practices for cloud product teams.
- Lead incident response for cloud product security events, including investigation, containment, and lessons learned.
- Mentor engineers on cloud security principles and contribute to a culture of security, learning, and continuous improvement.
Requirements
- Cloud security architecture
- AWS/Azure/GCP security services
- Identity and Access Management (IAM)
- Threat modeling
- Application and API security
- Infrastructure as Code (Terraform/Cloud
- Formation)
- CI/CD pipeline security
- Container and Kubernetes security
- Vulnerability management and remediation
- Security incident response
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
What Are The Top Skills Required For Azure Developers?
Highest Paying Tech Companies for Developers
Understanding and Mitigating Common Web Vulnerabilities