Threat Detection & Response Engineer -- Senior Expert

AllstateMcCullom Lake, IL
$151,700 - $222,400Remote

About The Position

The Threat Detection & Response Engineer -- Senior Expert defines and builds the technical foundation of that rebuild. This is a hands-on, build-heavy role for an engineer who treats detections as software that is version-controlled, peer-reviewed, tested, and shipped through a pipeline, and above all one who can design and build the AI/ML pipelines that let a global team investigate and respond at machine speed. The role leads the technical projects that stand up this capability and owns accountability for their delivery, sets the technical bar for how detection content is written, validated, and deployed, and builds the tooling and intelligence pipelines that make high-quality detection engineering repeatable rather than heroic. This is an individual-contributor role that carries technical leadership and delivery ownership.

Requirements

  • AI/ML builder. You can design and build AI/ML pipelines that create real leverage by selecting and applying industry-leading models to security data, engineering the data and enrichment foundations they depend on, and putting them into production with clear evaluation and guardrails. You have a grounded point of view on where AI genuinely accelerates detection and response versus where it adds risk.
  • Builder-first. Detection and response as software: you write, version, test, and ship detections like code, and you have built the tooling, APIs, or pipelines that let others do the same.
  • Detection depth. Deep, hands-on detection engineering experience across SIEM and EDR/XDR platforms, authoring high-fidelity analytics, tuning for signal, and reasoning about telemetry and data sources. Fluency in KQL / SQL / Sigma or equivalent, and strong scripting/development skills (e.g., Python, Go).
  • Threat-informed. You map detections to adversary behavior (ATT&CK), partner naturally with hunting and intel, and think in terms of coverage, exploitability, and containment rather than just rule counts.
  • Delivery ownership. You lead technical projects to completion and own the outcome, setting standards, resolving hard engineering problems, and lifting the quality of everyone around you, comfortable being the deepest technical voice in the room.
  • Communication. You can explain a detection strategy, an AI/ML design choice, or an engineering trade-off clearly to both engineers and senior leaders.

Nice To Haves

  • Hands-on experience building or operating within an AI-assisted / agentic SOC model.
  • Security data engineering / streaming pipeline experience (telemetry normalization, parsing, ETL) that feeds ML workflows.
  • Experience across enterprise SIEM, XDR, and EDR platforms.
  • Purple-team, adversary-emulation, or breach-and-attack-simulation partnership experience.
  • Financial services, insurance, or other regulated, high-scale environment exposure.

Responsibilities

  • Define, design, and build the AI/ML pipelines at the center of our next-generation D&R capability, applying industry-leading models to investigation, triage, enrichment, and detection generation where they genuinely add leverage.
  • Own the technical delivery of AI-assisted investigation and triage, spanning data foundations and feature/enrichment pipelines through model selection, evaluation, and safe production deployment.
  • Set the standard for how AI/ML outputs are validated, explained, and trusted within detection and response workflows, and lead the projects that move promising pilots into durable, measurable production capability.
  • Design and own the detection-as-code pipeline, including repository structure, detection schema, peer-review model, automated testing, and staged (CI/CD) deployment across our SIEM, XDR, and endpoint detection surfaces.
  • Define the technical standards, reusable patterns, and quality bar for detection content, and build the guardrails that keep quality consistent as the team scales across the US, Ireland, and India.
  • Build tooling and APIs that let engineers author, test, and debug detections quickly, turning detection engineering into a repeatable software practice rather than console-by-console work.
  • Design automation and SOAR-style workflows, increasingly AI-driven, that collapse high-volume alert categories such as automated phishing campaign clustering and detonation, DLP risk-based routing, enrichment, and auto-closure of verified-benign reports.
  • Build the response automation, including playbooks, containment actions, and integrations, that shrinks dwell time and mean-time-to-respond.
  • Establish and maintain a MITRE ATT&CK coverage baseline; use it to identify real gaps and redundant coverage and to prioritize engineering effort.
  • Partner with Threat Intelligence and Threat Hunting to convert PIR-driven hunt findings and intel into durable, tested detections through a formal feedback loop.
  • Stand up continuous validation, such as breach-and-attack simulation and a purple-team cadence, so coverage claims are proven against real adversary techniques rather than asserted on paper.
  • Lead the technical projects that build out this capability end-to-end and own accountability for their delivery by scoping the work, driving execution, and being answerable for completion and outcomes.
  • Serve as the senior-most individual-contributor technical authority for detection engineering, acting as the final technical escalation point before management, setting direction and raising the capability of D&R engineers across regions.
  • Influence roadmap and tooling decisions with internal platform partners, and help shape the operating model as the function grows across a global follow-the-sun, detection-as-code model.

Benefits

  • Compensation offered for this role is $151,700 – 222,400 annually and is based on experience and qualifications.
  • Allstate provides a comprehensive technology setup, including a laptop, monitors, headset, keyboard, and mouse.
  • Employees eligible to work from home also receive a monthly connectivity reimbursement to help offset internet costs.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service