Allstate

Allstate

Senior Incident Handler

US - Remote · Senior

No sponsorship$120k-$194kDetected 8 days ago
PythonPowerShellMachine LearningLLMsCybersecurityPenetration TestingNetwork SecuritySIEMSOARSOC OperationsIncident ResponseLeadershipCommunicationCollaborationMentoringCISSP

About the role

  • At Allstate, great things happen when our people work together to protect families and their belongings from life's uncertainties.
  • This is a chance to bring your hard-won expertise into a next-generation Security Operations program at Fortune 100 scale, where rapid response, automation, and AI-driven investigation are core to how we operate.
  • What You Bring - Battle-tested IR experience: 5+ years in cybersecurity operations or incident response, with a track record of leading complex, enterprise-scale incidents end-to-end.

Responsibilities

  • We're rebuilding incident response from the ground up-and we want a proven responder to help lead the way.
  • As our Senior Incident Handler, you'll be the technical anchor for our most significant security events-driving the response, raising the bar on how we work, and helping mature the team toward a formal, scalable incident command model we're building for the future.
  • What You''ll Own
  • You build calm and confidence when it matters most.

Requirements

  • Battle-tested IR experience: 5+ years in cybersecurity operations or incident response, with a track record of leading complex, enterprise-scale incidents end-to-end.
  • The candidate(s) offered this position will be required to submit to a background investigation.
  • When working from home, you must have a dedicated, private workspace free from distractions, along with appropriate desk and seating.
  • Battle-tested IR experience: 5+ years in cybersecurity operations or incident response, with a track record of leading complex, enterprise-scale incidents end-to-end. Financial services or insurance experience is a plus-but great responders come from everywhere.
  • Command-level instincts: Demonstrated ability to act as an incident commander or technical lead in high-stakes moments-running major bridge calls and making decisive calls fast. You bring the judgment that helps a team operate like a mature command function.
  • Technical depth: Strong command of network security, EDR/XDR, log and forensic analysis, and threat hunting across on-prem and cloud. Comfortable with SIEM, forensics tooling, and scripting/automation (Python, PowerShell).
  • Communication range: Exceptional written and verbal skills
  • equally credible with engineers and executives.
  • Automation mindset: Enthusiasm for SOAR, ML-based tooling, and LLMs to elevate response workflows.
  • Why This Role
  • You'll join at a pivotal moment-bringing your expertise to a team that's actively maturing, with the opportunity to help shape the incident command function we're building next. This is a role for someone who wants their fingerprints on how a Fortune 100 responds to the threats ahead. If you're ready to lead through crisis, outthink sophisticated adversaries, and elevate a team around you- let's talk.
  • Cross-Functional Collaboration, Cyber Incident Response, Cyber Investigations, Cybersecurity Operations, Cyber Threat Hunting, Decision Making, Endpoint Detection and Response (EDR), Executive Communications, Forensic Analysis, Incident Handling, IT Automation, IT Security Architecture, Malware Analysis, Network Security, Penetration Testing, Scripting, Security Incident Response, Technical Leadership, Technical Mentoring, Technology Leadership
  • Compensation offered for this role is 120,000.00 - 193,725.00 annually and is based on experience and qualifications.

Nice to have

  • 5+ years in cybersecurity operations or incident response, with a track record of leading complex, enterprise-scale incidents end-to-end.
  • Financial services or insurance experience is a plus-but great responders come from everywhere.
  • CISSP, GCIA, GCIH, GCFA, OSCP or other certifications preferred.
  • This is a role for someone who wants their fingerprints on how a Fortune 100 responds to the threats ahead.
  • Credentials: CISSP, GCIA, GCIH, GCFA, OSCP or other certifications preferred.

Skills

  • Compensation
  • One that takes your skills and pushes them to the next level.
  • Allstate generally does not sponsor individuals for employment-based visas for this position.
  • For jobs in San Francisco, please click " here " for information regarding the San Francisco Fair Chance Ordinance.
  • For jobs in Los Angeles, please click " here " for information regarding the Los Angeles Fair Chance Initiative for Hiring Ordinance.
  • To view the "EEO Know Your Rights" poster click " here ".
  • To view the FMLA poster, click " here ".
  • This poster summarizing the major provisions of the Family and Medical Leave Act (FMLA) and telling employees how to file a complaint.
  • It is the Company's policy to employ the best qualified individuals available for all jobs.
  • Allstate provides a comprehensive technology setup, including a laptop, monitors, headset, keyboard, and mouse.
  • Employees eligible to work from home also receive a monthly connectivity reimbursement to help offset internet costs.
  • Reliable internet is required, with minimum speeds of 50 MB download and 5 MB upload.

Compensation

  • Compensation offered for this role is 120,000.00 - 193,725.00 annually and is based on experience and qualifications.
  • This policy applies to all aspects of the employment relationship, including, but not limited to, hiring, training, salary administration, promotion, job assignment, benefits, discipline, and separation of employment.

Company info

  • And for more than 90 years, our innovative drive has kept us a step ahead of our customers' evolving needs.

Visa & Work Authorization

  • Allstate generally does not sponsor individuals for employment-based visas for this position

This listing is sourced directly from Allstate's careers page and normalized into a canonical job model.