{"id":1210846,"url":"https://alion.io/job/allstate-corporation-senior-data-security-engineer","title":"Senior Data Security Engineer","company":{"id":1921602,"name":"Allstate Corporation","domain":"allstatecorporation.com","url":"https://alion.io/company/allstatecorporation","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":{"grade":"B","score":80,"open_postings":19,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":16,"computed_at":"2026-09-27T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":90700,"max":190000,"currency":"USD","period":"year","gross":null,"usd_annual":190000},"salary_estimate":null,"experience_years_min":null,"visa_sponsorship":true,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Bicep","optional":false},{"name":"CI/CD","optional":false},{"name":"DLP","optional":false},{"name":"Microsoft Defender","optional":false},{"name":"Microsoft Defender for Cloud","optional":false},{"name":"Platform Engineering","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"Rest API","optional":false},{"name":"SIEM","optional":false},{"name":"Terraform","optional":false},{"name":"Azure","optional":true}],"status":"live","first_seen_at":"2026-08-18T00:00:00Z","employer_posted_date":"2026-08-18","last_verified_at":"2026-09-27T20:31:39Z","board_verified":true,"closed_at":null,"days_open":41,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":41},"description":"At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection.\nJob Description\n**For this opportunity, the business is flexible to hire at Senior Consultant, Lead Consultant, and Expert level depending on qualifications & interview evaluation.**The Senior Data Protection Security Engineer will lead the evolution of enterprise data protection from a traditional tool administration model to an engineering-driven security capability. This role is responsible for building scalable, automated, and measurable data protection solutions across cloud, SaaS, endpoint, email, and collaboration environments using Policy-as-Code, Security-as-Code, DevOps, and DevSecOps practices.\nThe successful candidate will bring a proven track record of modernizing Data Protection, DLP, CASB, or Information Protection programs by reducing manual processes, increasing automation, and implementing repeatable governance and deployment models. This individual will serve as a key contributor in advancing the organization's data protection strategy while driving operational excellence, security effectiveness, and business enablement.\nKey Responsibilities\nEngineer enterprise DLP controls across endpoint, email, SaaS, cloud storage, collaboration platforms, network, and web channels.\n\nModernize DLP policy deployment by moving from manual console-based changes to version-controlled, automated, and repeatable policy-as-code workflows.\n\nBuild CI/CD pipelines for data protection policy lifecycle management, including peer review, automated validation, testing, approval, deployment, and rollback.\n\nDevelop reusable policy templates, detection logic, exception patterns, configuration baselines, and deployment standards across multiple DLP and CASB platforms.\n\nAutomate operational tasks such as policy promotion, configuration drift detection, control validation, reporting, alert enrichment, and recurring health checks.\n\nIntegrate DLP, CASB, data classification, cloud security, identity, SIEM, SOAR, and workflow platforms to improve visibility, response, and enforcement.\n\nTune detection logic using data-driven analysis to reduce false positives, improve signal quality, and increase confidence in policy enforcement.\n\nDesign guardrails for sensitive data usage across Microsoft 365, cloud platforms, source code repositories, collaboration tools, SaaS applications, and enterprise endpoints.\n\nPartner with engineering, cloud, infrastructure, network, compliance, privacy, legal, and business teams to design practical data protection solutions.\n\nInvestigate data protection events, identify root cause, recommend control improvements, and convert lessons learned into automated prevention patterns.\n\nDefine and maintain metrics, KPIs, dashboards, and control evidence that demonstrate risk reduction, policy effectiveness, deployment quality, and operational maturity.\n\nSupport platform upgrades, capability expansions, vendor integrations, and new data protection control patterns using disciplined engineering practices.\n\n Key Qualifications\n4+ years delivering enterprise Data Protection, Information Protection, Cloud Security, or Security Engineering capabilities within complex organizations.\n\nProven experience in Policy-as-Code, Security-as-Code, and DevSecOps methodologies, with a demonstrated ability to automate security control deployment and governance at enterprise scale.\n\nTrack record of replacing manual operational processes with engineering-driven solutions through automation, APIs, Infrastructure-as-Code, and platform engineering practices.\n\nAdvanced knowledge of Data Loss Prevention (DLP), data classification, information protection, and data governance principles.\n\nHands-on expertise with Microsoft Purview, Microsoft Information Protection, Defender for Cloud Apps, and the Microsoft 365 security ecosystem.\n\nComprehensive understanding of cloud, SaaS, CASB, and enterprise data protection architectures.\n\nProficiency in scripting and automation technologies including PowerShell, Python, REST APIs, Terraform, Bicep, YAML, JSON, or comparable tools.\n\nDemonstrated success in modernizing Data Protection, DLP, CASB, or Information Protection programs through automation, standardization, and engineering-driven operating models.\n\nProven ability to implement and scale DevOps, DevSecOps, or Platform Engineering practices within security organizations.\n\nTrack record of leading large-scale security initiatives that improve control effectiveness, operational efficiency, and measurable risk reduction.\n\nBackground supporting enterprise-scale cloud, SaaS, or Microsoft 365 environments.\n\nKnowledge of regulatory, privacy, and compliance requirements and their implementation through scalable technical controls.\n\n#LI-JJ1\nSkills\nApplication Programming Interface (API), Cloud Security, Cybersecurity Strategies, Data Governance, Data Loss Prevention (DLP), Data Protection, Data Security, DevSecOps, Information Security Engineering, Information Technology Training, Infrastructure As Code (IaC), IT Automation, IT Security Architecture, IT Security Operations, Microsoft 365 Security & Compliance, Microsoft Defender for Cloud, Scripting, Secure Code, Security Engineering, Software as a Service (SaaS)Compensation\nCompensation offered for this role is $90,700 - 190,000 annually and is based on experience and qualifications.The candidate(s) offered this position will be required to submit to a background investigation.\nJoining our team isn’t just a job - it’s an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger - a winning team making a meaningful impact.\nAllstate generally does not sponsor individuals for employment-based visas for this position.\nEffective July 1, 2014, under Indiana House Enrolled Act (HEA) 1242, it is against public policy of the State of Indiana and a discriminatory practice for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component.\nFor jobs in San Francisco, please click “here ” for information regarding the San Francisco Fair Chance Ordinance.\nFor jobs in Los Angeles, please click “here ” for information regarding the Los Angeles Fair Chance Initiative for Hiring Ordinance.\nTo view the “EEO Know Your Rights” poster click “here ”. This poster provides information concerning the laws and procedures for filing complaints of violations of the laws with the Office of Federal Contract Compliance Programs.\nTo view the FMLA poster, click “ here ”. This poster summarizing the major provisions of the Family and Medical Leave Act (FMLA) and telling employees how to file a complaint.\nIt is the Company’s policy to employ the best qualified individuals available for all jobs. Therefore, any discriminatory action taken on account of an employee’s ancestry, age, color, disability, genetic information, gender, gender identity, gender expression, sexual and reproductive health decision, marital status, medical condition, military or veteran status, national origin, race (include traits historically associated with race, including, but not limited to, hair texture and protective hairstyles), religion (including religious dress), sex, or sexual orientation that adversely affects an employee's terms or conditions of employment is prohibited. This policy applies to all aspects of the employment relationship, including, but not limited to, hiring, training, salary administration, promotion, job assignment, benefits, discipline, and separation of employment.\nAllstate provides a comprehensive technology setup, including a laptop, monitors, headset, keyboard, and mouse. Employees eligible to work from home also receive a monthly connectivity reimbursement to help offset internet costs.\nWhen working from home, you must have a dedicated, private workspace free from distractions, along with appropriate desk and seating. Reliable internet is required, with minimum speeds of 50 MB download and 5 MB upload.","description_format":"text","description_chars":8695,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"phd","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Nonprofits & Foundations"],"lifecycle":[{"event":"open","at":"2026-09-25T04:12:39Z"}],"liveness":{"score":11,"band":"cold","label":"Long shot","p_open":1,"p_active":0.391,"p_room":0.28,"age_days":40,"expected_fill_days":16,"reasons":["conf:9","stale_co","velocity","win:tail","crowd:brand"],"computed_at":"2026-09-27T05:45:00Z"},"pay":{"stated_usd_annual":190000,"is_top_pay":true},"html_url":"https://alion.io/job/allstate-corporation-senior-data-security-engineer","json_url":"https://alion.io/job/allstate-corporation-senior-data-security-engineer.json","meta":{"generated_at":"2026-09-28T05:17:17Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3511,"day_limit":5000,"remaining_today":1489,"minute_limit":60,"resets_at":"2026-09-29T00:00:00Z"}}}