Allstate

Threat Detection & Response Engineer -- Senior Expert

Allstate
Apply
6 days ago
Remote, WorldwideSenior

Base Salary

$152k - $222k/yr

Responsibilities

  • Design and build AI/ML pipelines for investigation, triage, enrichment, and detection generation.
  • Own the technical delivery of AI-assisted investigation and triage from data and feature pipelines through model evaluation and production deployment.
  • Design and own detection-as-code pipelines, including repository structure, schemas, peer review, automated testing, and staged deployment.
  • Define detection engineering standards, reusable patterns, quality controls, and guardrails for global teams.
  • Build tooling and APIs for authoring, testing, and debugging detections.
  • Design SOAR-style response automation, including phishing clustering and detonation, DLP routing, enrichment, playbooks, containment actions, integrations, and auto-closure.
  • Establish MITRE ATT&CK coverage baselines and continuous validation through breach-and-attack simulation and purple-team activities.
  • Convert threat intelligence and threat-hunting findings into durable, tested detections.
  • Lead technical projects end to end and own delivery outcomes, roadmap influence, technical escalations, and engineering direction.

Requirements

  • Hands-on ability to design and build AI/ML pipelines, engineer their data and enrichment foundations, apply models to security data, and deploy them with evaluation and guardrails.
  • Experience treating detection and response as software through version control, testing, deployment, and supporting tooling, APIs, or pipelines.
  • Deep hands-on detection engineering experience across SIEM and EDR/XDR platforms, including high-fidelity analytics, tuning, telemetry, and data-source analysis.
  • Fluency in KQL, SQL, Sigma, or equivalent, plus strong scripting or development skills such as Python or Go.
  • Experience mapping detections to adversary behavior using MITRE ATT&CK and partnering with threat hunting and threat intelligence.
  • Ability to lead technical projects to completion, set standards, resolve difficult engineering problems, and act as a senior technical authority.
  • Ability to communicate detection strategies, AI/ML design decisions, and engineering trade-offs to engineers and senior leaders.
  • Preferred experience with AI-assisted or agentic SOC models, security data engineering and streaming pipelines, enterprise SIEM/XDR/EDR platforms, purple teaming, adversary emulation, breach-and-attack simulation, or regulated high-scale environments.

Benefits

  • Allstate provides a laptop, monitors, headset, keyboard, and mouse as part of its technology setup.
  • Employees eligible to work from home receive a monthly connectivity reimbursement.
  • Work-from-home employees must have a dedicated private workspace, appropriate desk and seating, and reliable internet with at least 50 MB download and 5 MB upload speeds.
  • Employment is subject to a background investigation.
Allstate

About Allstate

10,000+ employees

At Allstate, we're advocates for peace of mind and a good life. And that comes through in everything we do. From building innovative teams that truly understand our customers' needs, to challenging each other to develop our careers in a meaningful way, and finally to the incredible results we're able to achieve together. See how we’re creating a better future through innovation, advocacy, and empowering people and communities.

Contact me