Senior Manager, Global Security Operations
Allstate · US - Remote
Job description
At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection. Job Description "You're in good hands" is more than a promise to our customers. It's how we run cyber defense at Allstate. We are hiring a Senior Manager to join the leadership team of our Security Operations Center (SOC) and provide senior management support across our 24x7x365 detection and response operations. This is a senior leadership role, operating during US business hours in matrixed collaboration with our operations leaders across the Americas and international teams. You will operate at both the tactical and strategic level, embedded directly with the analysts and incident handlers who run the floor, while owning the metrics, processes, and improvement projects that raise the performance of the entire operation. You will be empowered to drive initiatives that increase the effectiveness of our monitoring, triage, and response, and to develop the next generation of security operations talent. This role is ideal for a proven operational leader who is ready to grow their management career at a Fortune 100 company. What You'll DoLead from the floor. Partner directly with frontline security operations — analysts, shift leads, and incident handlers to measure, manage, and continuously improve the day-to-day performance of the US SOC across all shifts. Own the metrics. Serve as the owner of the SOC’s operational metrics program to define, track, and interpret KPIs and service outcomes (e.g., MTTD, MTTR, alert quality, false-positive rates, detection coverage, and SLA adherence) that reveal how the operation is truly performing. Turn data into action. Use data across SOC operations to drive decisions on resource allocation, workflow, and threat mitigation, and to lead the improvement projects that close identified gaps and increase overall operational efficiency. Uplevel talent. Coach, mentor, and develop existing analysts and incident handlers — building clear career paths (L1→L2→L3), raising technical and operational capability, and fostering a high-performance, low-burnout culture. Drive operational excellence. Establish and maintain the operating rhythms — shift turnover, quality reviews, and performance reporting that keep the team consistent, accountable, and aligned to established processes, procedures, and standards. Improve the machine. Identify recurring pain points and champion process improvement, tooling optimization, and automation opportunities (SIEM/SOAR) that reduce analyst fatigue and accelerate response. Support the global mission. Provide global senior management support to the broader Global Security Operations team, contributing to consistency, continuity, and effective handoffs across US, Ireland, and India operations. Communicate outcomes. Translate operational performance and improvement outcomes into clear, actionable reporting and dashboards for both technical teams and senior leadership. Outcomes You'll DriveA consistently fast and effective SOC, with strong Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) sustained across all shifts. High-quality operations, with dependable detection coverage, precise alerting, and reliable SLA performance. A skilled and engaged team, with clear career growth, strong retention, and a healthy pipeline of talent ready for advancement. A metrics-driven operation that anticipates opportunities early and delivers high-impact improvement projects. Key QualificationsPrior leadership experience within a Security Operations Center (SOC) — you have run the floor and understand security operations firsthand. 6+ years of experience in security operations, incident response, or a related cybersecurity discipline. 4+ years of people management experience, including managing analysts and coordinating a global team. Demonstrated experience developing, maintaining, and interpreting operational metrics (KPIs/SLAs) to measure performance and drive improvement. Proven ability to lead operational improvement projects from identification through delivery of measurable results. Advanced technical knowledge of network and endpoint security, common attacker techniques, and SIEM/SOAR detection-and-response tooling. Preferred QualificationsA security operations background with a clear ambition to grow their management capability within a Fortune 100 enterprise. Experience defining and operating metrics, dashboards, and reporting for a 24x7 operational service. Experience supporting or coordinating operations across a global footprint, including scheduling, turnover, and team cohesion. Familiarity with automation and process-improvement approaches that reduce analyst toil and improve response speed. History of developing individual contributors into stronger operators and future leaders. One or more industry certifications, such as CISSP, CISM, GCIH, GCIA, or equivalent. #LI-JJ1 Skills Automation Tools, Cybersecurity Operations, Data-Driven Decision Making, Executive Presence, Global Team Leadership, Mentorship, Operational Metrics, People Leadership, Process Improvement, Security Incident Response, Security Information and Event Management (SIEM), Security Orchestration, Automation, and Response (SOAR), Technical Leadership, Threat Detection Compensation Compensation offered for this role is $151,700 – 210,000 annually and is based on experience and qualifications. The candidate(s) offered this position will be required to submit to a background investigation. Joining our team isn’t just a job — it’s an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact. Allstate generally does not sponsor individuals for employment-based visas for this position. Effective July 1, 2014, under Indiana House Enrolled Act (HEA) 1242, it is against public policy of the State of Indiana and a discriminatory practice for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component. For jobs in San Francisco, please click “here” for information regarding the San Francisco Fair Chance Ordinance. For jobs in Los Angeles, please click “here” for information regarding the Los Angeles Fair Chance Initiative for Hiring Ordinance. To view the “EEO Know Your Rights” poster click “here”. This poster provides information concerning the laws and procedures for filing complaints of violations of the laws with the Office of Federal Contract Compliance Programs. To view the FMLA poster, click “here”. This poster summarizing the major provisions of the Family and Medical Leave Act (FMLA) and telling employees how to file a complaint. It is the Company’s policy to employ the best qualified individuals available for all jobs. Therefore, any discriminatory action taken on account of an employee’s ancestry, age, color, disability, genetic information, gender, gender identity, gender expression, sexual and reproductive health decision, marital status, medical condition, military or veteran status, national origin, race (include traits historically associated with race, including, but not limited to, hair texture and protective hairstyles), religion (including religious dress
Verified and listed by ActiveJobs. Applications are made directly on Allstate's own career page — we never sit in the middle.