վýý

Allstate

Software Engineer - Product Security

Posted on Apr 24 Remote, IL 33 views

At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection.

Job Description

**For this opportunity, the business is flexible to hire at Sr Consultant II, Lead Consultant, and Expert level depending on qualifications & interview evaluation.**

The Product Security Engineering organization is responsible for designing, building, and operating enterprise security controls as software products. The group applies modern software engineering practices to create scalable, reliable, and developer friendly security capabilities that are embedded directly into the enterprise technology ecosystem, enabling secure by default behaviors while minimizing friction for product and platform teams.

Product Security Engineers are software engineers who own the full software development lifecycle — from design and implementation through deployment and production support. They write and maintain production code, operate their services in real world environments, and are accountable for the reliability, adoption, and effectiveness of the security controls they deliver. Success in this role is measured through outcomes such as control adoption, system reliability, and meaningful reduction of security risk.

Key Responsibilities


  • Design, build, andoperateenterprise security controls as software products that integrate directly into the SDLC and core enterprise platforms



  • Own security control capabilitiesend‑to‑end, including architecture, implementation, deployment, and ongoing operational support in production



  • Write, test, andmaintainhigh‑qualityproduction code while meeting delivery and reliability expectations as a software engineer



  • Apply engineering best practices such astest‑drivendevelopment, paired programming, and continuous integration and deployment



  • Contribute tohigh‑levelandlow‑levelsystem andcomponentdesigns with a focus on scalability, reliability, and security outcomes



  • Continuously evaluate and adoptnew technologies, frameworks, and patterns to improve the effectiveness and usability of security controls



  • Collaborate closely with product managers, platform teams, and partner engineering groups to align security control capabilities with enterprise needs



  • Participate in agile delivery ceremonies and contribute to a culture of fast feedback, incremental delivery, and continuous improvement


Essential Skills:


  • 3+ years of software engineering experience, with demonstrated ownership of production systems throughout the full software development lifecycle which must include proficiency in one or more modern programming languages (e.g., Java, JavaScript)



  • Hands-onexperience designing, building, andoperatingscalable distributed systems andcloud‑basedapplications, including microservices architectures



  • Demonstrated ability to design, develop, and integrate APIs and backend services, includingREST‑basedinterfaces



  • Familiarity with modern development workflows and engineering practices such astest-drivendevelopment, paired programming, and continuous integration and deployment



  • Experiencecollaboratingeffectively within agile delivery models, working closely withproductmanagers, engineers, and partner teams to deliver outcomes



Additional Criteria for Lead and Expert Levels:


  • Minimum of 1 year demonstratedexperiencecoaching or mentoring engineers, with evidence of improving individual or team technical capability over time



  • Proven ability tolead technical design and architecture decisionsfor complex, distributed systems, resulting in measurable improvements to scalability, security, reliability, or performance



  • Track recordofdrivingcross teamcollaborationto deliver integrated solutions, achieving alignment across multiple product portfolios and stakeholder group


Desirable Skills:


  • Working knowledge of application and API security concepts, including common vulnerability classes (e.g., OWASP Top 10) and attack techniques (e.g., MITRE ATT&CK)



  • Experience implementing or integrating security mechanisms such as authentication, authorization, andidentity-basedaccess controls within applications and services



  • Knowledgeable in secure software development practices and techniques, includingbehavior drivendevelopment orsecurity focusedtesting patterns



  • Practical exposure to containerized andcloud nativeenvironments, including Docker, Kubernetes, and public cloud platforms such as AWS and/or Azure



  • Exposure to large language models (LLMs), machine learning concepts, or systems that incorporateAI drivencapabilities



  • Ability toleverageAI assisteddevelopment tools (e.g., Copilot, Cursor) responsibly to improve developer productivity and code quality



  • Demonstrated commitment to building solutions that balance robust security guarantees with an excellent developer experience, without compromising one for the other


Supervisory Responsibilities:


  • This job does not have supervisory duties.



#LI-JJ1


Skills

API Development, Application Security, Artificial Intelligence (AI), Cloud Based Solutions, Collaboration, Distributed Systems, Java, JavaScript, Large Language Models (LLMs), Microservices Architecture, Product Security, Security Controls, Software Engineering, Test Driven Development (TDD)

Compensation

Compensation offered for this role ranges from $90,700 - 195,700 annually and is based on experience and qualifications.

The candidate(s) offered this position will be required to submit to a background investigation.

Joining our team isn’t just a job — it’s an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact.

Allstate generally does not sponsor individuals for employment-based visas for this position.

Effective July 1, 2014, under Indiana House Enrolled Act (HEA) 1242, it is against public policy of the State of Indiana and a discriminatory practice for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component.

For jobs in San Francisco, please click “” for information regarding the San Francisco Fair Chance Ordinance.

For jobs in Los Angeles, please click “” for information regarding the Los Angeles Fair Chance Initiative for Hiring Ordinance.

To view the “EEO Know Your Rights” poster click “”. This poster provides information concerning the laws and procedures for filing complaints of violations of the laws with the Office of Federal Contract Compliance Programs.

To view the FMLA poster, click “”. This poster summarizing the major provisions of the Family and Medical Leave Act (FMLA) and telling employees how to file a complaint.

It is the Company’s policy to employ the best qualified individuals available for all jobs. Therefore, any discriminatory action taken on account of an employee’s ancestry, age, color, disability, genetic information, gender, gender identity, gender expression, sexual and reproductive health decision, marital status, medical condition, military or veteran status, national origin, race (include traits historically associated with race, including, but not limited to, hair texture and protective hairstyles), religion (including religious dress), sex, or sexual orientation that adversely affects an employee's terms or conditions of employment is prohibited. This policy applies to all aspects of the employment relationship, including, but not limited to, hiring, training, salary administration, promotion, job assignment, benefits, discipline, and separation of employment.

More From Allstate

Lead Digital Product Manager-PPS (Remote)

Posted on Mar 23 Illinois, IL

Field Auto Claims Estimator

Posted on Nov 19 Oregon, OR

Data and Reporting Analyst Apprentice

Posted on Mar 18 Illinois, IL

Lead Digital Product Manager (Platform integration)

Posted on Feb 18 Remote, IL

Property Adjuster - Field Estimating - Howard County, MD

Posted on Feb 8 Maryland, MD

Related Job Listings

Allstate

Data and Reporting Analyst Apprentice

Posted on Mar 18 Illinois, IL

The Travelers Companies, Inc.

Sr Software Engineer

Posted on Mar 3 Hartford, CT

The Travelers Companies, Inc.

VP, Enterprise Data Enablement

Posted on Mar 4 Hartford, CT

The Travelers Companies, Inc.

Data Engineer I (Databricks, MLOps)

Posted on Mar 6 Hartford, CT

The Travelers Companies, Inc.

Senior Architect

Posted on Mar 26 Hartford, CT