Senior Data Security Engineer
Allstate · US - Remote
Job description
At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection. Job Description **For this opportunity, the business is flexible to hire at Senior Consultant, Lead Consultant, and Expert level depending on qualifications & interview evaluation.** The Senior Data Protection Security Engineer will lead the evolution of enterprise data protection from a traditional tool administration model to an engineering-driven security capability. This role is responsible for building scalable, automated, and measurable data protection solutions across cloud, SaaS, endpoint, email, and collaboration environments using Policy-as-Code, Security-as-Code, DevOps, and DevSecOps practices. The successful candidate will bring a proven track record of modernizing Data Protection, DLP, CASB, or Information Protection programs by reducing manual processes, increasing automation, and implementing repeatable governance and deployment models. This individual will serve as a key contributor in advancing the organization's data protection strategy while driving operational excellence, security effectiveness, and business enablement. Key ResponsibilitiesEngineer enterprise DLP controls across endpoint, email, SaaS, cloud storage, collaboration platforms, network, and web channels. Modernize DLP policy deployment by moving from manual console-based changes to version-controlled, automated, and repeatable policy-as-code workflows. Build CI/CD pipelines for data protection policy lifecycle management, including peer review, automated validation, testing, approval, deployment, and rollback. Develop reusable policy templates, detection logic, exception patterns, configuration baselines, and deployment standards across multiple DLP and CASB platforms. Automate operational tasks such as policy promotion, configuration drift detection, control validation, reporting, alert enrichment, and recurring health checks. Integrate DLP, CASB, data classification, cloud security, identity, SIEM, SOAR, and workflow platforms to improve visibility, response, and enforcement. Tune detection logic using data-driven analysis to reduce false positives, improve signal quality, and increase confidence in policy enforcement. Design guardrails for sensitive data usage across Microsoft 365, cloud platforms, source code repositories, collaboration tools, SaaS applications, and enterprise endpoints. Partner with engineering, cloud, infrastructure, network, compliance, privacy, legal, and business teams to design practical data protection solutions. Investigate data protection events, identify root cause, recommend control improvements, and convert lessons learned into automated prevention patterns. Define and maintain metrics, KPIs, dashboards, and control evidence that demonstrate risk reduction, policy effectiveness, deployment quality, and operational maturity. Support platform upgrades, capability expansions, vendor integrations, and new data protection control patterns using disciplined engineering practices. Key Qualifications4+ years delivering enterprise Data Protection, Information Protection, Cloud Security, or Security Engineering capabilities within complex organizations. Proven experience in Policy-as-Code, Security-as-Code, and DevSecOps methodologies, with a demonstrated ability to automate security control deployment and governance at enterprise scale. Track record of replacing manual operational processes with engineering-driven solutions through automation, APIs, Infrastructure-as-Code, and platform engineering practices. Advanced knowledge of Data Loss Prevention (DLP), data classification, information protection, and data governance principles. Hands-on expertise with Microsoft Purview, Microsoft Information Protection, Defender for Cloud Apps, and the Microsoft 365 security ecosystem. Comprehensive understanding of cloud, SaaS, CASB, and enterprise data protection architectures. Proficiency in scripting and automation technologies including PowerShell, Python, REST APIs, Terraform, Bicep, YAML, JSON, or comparable tools. Demonstrated success in modernizing Data Protection, DLP, CASB, or Information Protection programs through automation, standardization, and engineering-driven operating models. Proven ability to implement and scale DevOps, DevSecOps, or Platform Engineering practices within security organizations. Track record of leading large-scale security initiatives that improve control effectiveness, operational efficiency, and measurable risk reduction. Background supporting enterprise-scale cloud, SaaS, or Microsoft 365 environments. Knowledge of regulatory, privacy, and compliance requirements and their implementation through scalable technical controls. #LI-JJ1 Skills Application Programming Interface (API), Cloud Security, Cybersecurity Strategies, Data Governance, Data Loss Prevention (DLP), Data Protection, Data Security, DevSecOps, Information Security Engineering, Information Technology Training, Infrastructure As Code (IaC), IT Automation, IT Security Architecture, IT Security Operations, Microsoft 365 Security & Compliance, Microsoft Defender for Cloud, Scripting, Secure Code, Security Engineering, Software as a Service (SaaS) Compensation Compensation offered for this role is $90,700 – 190,000 annually and is based on experience and qualifications. The candidate(s) offered this position will be required to submit to a background investigation. Joining our team isn’t just a job — it’s an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact. Allstate generally does not sponsor individuals for employment-based visas for this position. Effective July 1, 2014, under Indiana House Enrolled Act (HEA) 1242, it is against public policy of the State of Indiana and a discriminatory practice for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component. For jobs in San Francisco, please click “here” for information regarding the San Francisco Fair Chance Ordinance. For jobs in Los Angeles, please click “here” for information regarding the Los Angeles Fair Chance Initiative for Hiring Ordinance. To view the “EEO Know Your Rights” poster click “here”. This poster provides information concerning the laws and procedures for filing complaints of violations of the laws with the Office of Federal Contract Compliance Programs. To view the FMLA poster, click “here”. This poster summarizing the major provisions of the Family and Medical Leave Act (FMLA) and telling employees how to file a complaint. It is the Company’s policy to employ the best qualified individuals available for all jobs. Therefore, any discriminatory action taken on account of an employee’s ancestry, age, color, disability, genetic information, gender, gender identity, gender expression, sexual and reproductive health decision, marital status, medical condition, military or veteran status, national origin, race (include traits historically associated with race, including, but not limited to, hair texture and protective hairstyles), religion (including religious dress), sex, or sexual orientation that adve
Verified and listed by ActiveJobs. Applications are made directly on Allstate's own career page — we never sit in the middle.