Security Engineering Senior Manager

AllstateMcCullom Lake, IL
3d

About The Position

Allstate Information Security (AIS) is advancing its embedded security product strategy by launching three new engineering teams dedicated to building security controls seamlessly integrated into Allstate’s technology ecosystem. The Security Engineering Senior Manager will be the direct leader responsible for the day-to-day development, implementation, and support of security controls across multiple product security engineering teams, working with global stakeholders. This position requires a strong, well-rounded technical leader who can quickly learn the overall business and technology processes supported by the teams, and who is eager to grow skills within the security engineering landscape, including secure software development, cloud security, application security, and modern DevSecOps practices. The role demands hands-on expertise in security engineering, along with solid integration and compliance knowledge. This senior leader will be expected to build relationships throughout the organization to ensure whole-company alignment and support for their goals, and vice-versa. This individual architects and designs secure digital products using modern tools, technologies, frameworks, and systems. This role applies a systematic application of scientific and technological knowledge, methods, and experience to the design, implementation, testing, and documentation of secure software. This leader owns and manages running their applications in production and is accountable for the success of their digital products through achieving KPIs, including security metrics.

Requirements

  • 10+ years of experience preferred in security engineering, with at least 3 years in a technical leadership or managerial role.
  • Deep understanding of secure software development, vulnerability management, cloud security, application security, and modern security engineering practices.
  • Experience with secure software configuration and development, including secure APIs, authentication/authorization, encryption, and threat modeling.
  • Experience working with modern security frameworks, tools, and methodologies (e.g., DevSecOps, CI/CD security, cloud-native security).
  • Deep understanding of technology best practices in areas of secure development and compliance.
  • Experience in Test Driven Development (TDD), Agile SCRUM methodologies, and secure SDLC.
  • Excellent problem-solving skills and a passion for continuous learning in security.
  • Strong team player with well-developed verbal, written, and interpersonal communication skills.
  • Dedicated, self-directed, motivated, proactive, and inquisitive.

Responsibilities

  • Frequently advise others on complex security engineering matters.
  • Build foundation to translate security strategy into challenging and meaningful goals.
  • Manage teams responsible for strategic and critical security architecture or provide functions that are of key strategic value to the business.
  • Act as an authority in secure software best practices and propagate these throughout the broader organization, beyond their individual team.
  • Display expertise in viewing the organization as a whole, especially in terms of risk and security posture.
  • Leverage and influence key stakeholders to drive adoption of security controls and practices.
  • Designing, implementing, and productizing security controls to address complex business and technology challenges.
  • Working directly with business and technical teams to assess and provide security technology support.
  • Understanding multiple end-to-end business and technology processes, with a focus on security risks and mitigations.
  • Displaying deep knowledge of technical details, integration, and functions of security tools and platforms (e.g., IAM, SIEM, vulnerability management, cloud security).
  • Evaluating potential system enhancements and upgrades, influencing the security product roadmap.
  • Identifying and implementing process improvements and product simplification opportunities, especially in security operations.
  • Providing technical or functional leadership for team members in security engineering.
  • Ensuring industry and technology best practices are followed for secure development and operations.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service