6 days ago
Remote, WorldwideSenior
Base Salary
$152k - $222k/yr
Responsibilities
- Design and build AI/ML pipelines for investigation, triage, enrichment, and detection generation.
- Own the technical delivery of AI-assisted investigation and triage from data and feature pipelines through model evaluation and production deployment.
- Design and own detection-as-code pipelines, including repository structure, schemas, peer review, automated testing, and staged deployment.
- Define detection engineering standards, reusable patterns, quality controls, and guardrails for global teams.
- Build tooling and APIs for authoring, testing, and debugging detections.
- Design SOAR-style response automation, including phishing clustering and detonation, DLP routing, enrichment, playbooks, containment actions, integrations, and auto-closure.
- Establish MITRE ATT&CK coverage baselines and continuous validation through breach-and-attack simulation and purple-team activities.
- Convert threat intelligence and threat-hunting findings into durable, tested detections.
- Lead technical projects end to end and own delivery outcomes, roadmap influence, technical escalations, and engineering direction.
Requirements
- Hands-on ability to design and build AI/ML pipelines, engineer their data and enrichment foundations, apply models to security data, and deploy them with evaluation and guardrails.
- Experience treating detection and response as software through version control, testing, deployment, and supporting tooling, APIs, or pipelines.
- Deep hands-on detection engineering experience across SIEM and EDR/XDR platforms, including high-fidelity analytics, tuning, telemetry, and data-source analysis.
- Fluency in KQL, SQL, Sigma, or equivalent, plus strong scripting or development skills such as Python or Go.
- Experience mapping detections to adversary behavior using MITRE ATT&CK and partnering with threat hunting and threat intelligence.
- Ability to lead technical projects to completion, set standards, resolve difficult engineering problems, and act as a senior technical authority.
- Ability to communicate detection strategies, AI/ML design decisions, and engineering trade-offs to engineers and senior leaders.
- Preferred experience with AI-assisted or agentic SOC models, security data engineering and streaming pipelines, enterprise SIEM/XDR/EDR platforms, purple teaming, adversary emulation, breach-and-attack simulation, or regulated high-scale environments.
Benefits
- Allstate provides a laptop, monitors, headset, keyboard, and mouse as part of its technology setup.
- Employees eligible to work from home receive a monthly connectivity reimbursement.
- Work-from-home employees must have a dedicated private workspace, appropriate desk and seating, and reliable internet with at least 50 MB download and 5 MB upload speeds.
- Employment is subject to a background investigation.
Categories
About Allstate
At Allstate, we're advocates for peace of mind and a good life. And that comes through in everything we do. From building innovative teams that truly understand our customers' needs, to challenging each other to develop our careers in a meaningful way, and finally to the incredible results we're able to achieve together. See how we’re creating a better future through innovation, advocacy, and empowering people and communities.