Cloud Product Security Engineer

Allstate Corporation
Springfield, IL, United States
18 days ago
Apply on find.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$155,000.0 - $185,000.0
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Application Programming Interfaces (APIs) Amazon Web Services Microsoft Azure Cloud Computing Cloud Computing Security Continuous Integration Identity and Access Management Key Management Network Segmentation Security Information and Event Management Software Vulnerability Management
+7 more
Google Cloud Spring Cloud Software Security Terraform Data Pipelines Static Application Security Testing Dynamic Application Security Testing

Job description

Allstate is seeking a Cloud Product Security Engineer to secure cloud-native insurance and financial products in a dynamic, customer-focused environment. You’ll partner with product, engineering, and DevOps teams to design secure architectures, conduct threat modeling, and embed security controls across AWS/Azure/GCP. Responsibilities include automating security via CI/CD and IaC, managing vulnerabilities and misconfigurations, and leading incident response. You’ll shape security standards, mentor teams, and help advance Allstate’s mission of protecting customers and communities through resilient digital solutions., * Design and implement secure architectures for Allstate’s cloud-hosted insurance and financial products across AWS/Azure/GCP environments.

  • Embed security into the product lifecycle by partnering with engineering, product, and Dev
  • Ops teams from design through deployment.
  • Conduct threat modeling, risk assessments, and security reviews for cloud-native applications, APIs, and data pipelines.
  • Implement and manage security controls including IAM, encryption, key management, secrets management, and network segmentation.
  • Automate security testing and policy enforcement using CI/CD pipelines, infrastructure as code, and security-as-code practices.
  • Monitor cloud environments for vulnerabilities and misconfigurations, and drive timely remediation with engineering teams.
  • Evaluate and integrate cloud security tools such as CSPM, CWPP, SIEM, and SAST/DAST solutions.
  • Develop and maintain secure coding standards, reference architectures, and best practices for cloud product teams.
  • Lead incident response for cloud product security events, including investigation, containment, and lessons learned.
  • Mentor engineers on cloud security principles and contribute to a culture of security, learning, and continuous improvement.

Requirements

  • Cloud security architecture
  • AWS/Azure/GCP security services
  • Identity and Access Management (IAM)
  • Threat modeling
  • Application and API security
  • Infrastructure as Code (Terraform/Cloud
  • Formation)
  • CI/CD pipeline security
  • Container and Kubernetes security
  • Vulnerability management and remediation
  • Security incident response

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on find.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

2:07 min

Implementing business logic leveraging the Spring Cloud framework

Ingo Weichsel · World Congress 2023

6:10 min

Unlocking free learning credits via Google Cloud Innovators

Asrar Asrar · World Congress 2024

1:39 min

Understanding the four Cs of cloud native security

Rico Komenda Rico Komenda · World Congress 2025

1:26 min

Selecting open source technologies for multi-cloud capability

Ingo Weichsel · World Congress 2023

2:32 min

Overview of Terraform and Terraform Cloud features

Devlin Duldulao · LIVE

Videos

See all

Related articles

See all