Lead Engineering, Authentication Engineering (Senior Manager)
Allstate · Canadian Head Office (It)
Job description
At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection. Job Description Who is Allstate: Allstate Insurance Company of Canada is a leading home and auto insurer focused on providing its customers prevention and protection products and services for every stage of life. Serving Canadians since 1953, Allstate strives to reassure both customers and employees with its “You’re in Good Hands®” promise and is proud to have been named a Best Employer in Canada for nine consecutive years. Allstate is committed to making a positive difference in the communities in which it operates through partnerships with charitable organizations, employee giving and volunteerism. To learn more, visit www.allstate.ca. For safety tips and advice, visit www.goodhandsadvice.ca. Through our Employee Value Proposition, we have worked hard to develop and nurture a culture where employees feel valued, experience personal growth, have career options and truly enjoy the work they do. Role Designation: Remote Benefits to joining Allstate Flexible Work Arrangements. Employee discounts (15% on auto and property insurance, plus many other products and services). Good Office program (receive up to $400 back after purchasing office equipment). Student Loan Payment Matching Program for Government Student loans. Comprehensive Retirement Savings Program with employer matched contributions. Annual Wellness allowance to support employees with improving health and wellbeing. Personal days. Tuition Reimbursement. Working within the community and giving back. Job description: We are seeking a highly technical and innovative Lead Engineering, Authentication Engineering (Senior Manager) to lead the design, implementation, and advancement of enterprise authentication platforms. Multiple Managing Engineering’s for authentication teams will report to this role. This role will provide technical leadership for authentication solutions, including directory infrastructure, multi-factor authentication (MFA), PKI, privileged access management and vaulting solutions and an in-house developed application for password and MFA management. The successful candidate will partner closely with Product Management, Cybersecurity, Infrastructure Engineering, Application Teams, and Operations to deliver secure, scalable, and resilient authentication capabilities that align with strategic directions including AI enablement, Zero Trust, Infrastructure as Code, and automation. Accountabilities: Partner with Authentication Lead Product Manager for creation of strategy, roadmaps, prioritization, and implementation of solutions. Lead the strategy, architecture, and engineering of enterprise authentication solutions, ensuring they meet business needs while delivering a secure, seamless user experience. Design, implement, and modernize authentication solutions, including MFA,, PKI, SSO, privileged access management, vaulting, and cloud-native authentication platforms to enable Zero Trust capabilities including passwordless, phishing-resistant authentication, Just-In-Time (JIT) and Just-Enough (JEA) access. Drive increased automation and Infrastructure as Code including test driven development practices for validation and control testing Lead large-scale authentication migrations and technology transformations, while continuously improving platforms to reduce user friction and increase adoption. Partner with security, infrastructure, cloud, application, and AI teams to deliver scalable, resilient authentication services and support security integration into application d automation, AI workflows, agentic AI capabilities. Provide technical leadership and people development by coaching Managing Engineerings, leading technical product design reviews, and providing direction for engineering best practices. Influence clients and partners to prioritize for enterprise benefit and risk reduction and assist in driving the adoption of technology solutions that leverage existing patterns, practices, and reference architectures. Strengthen the organization’s security posture by implementing and enhancing controls to address gaps and vulnerabilities identified through audits, assessments, red team, penetration testing, vulnerability scanning, and proactive threat modeling. gaps identified through Own the reliability, resiliency, and operational excellence of authentication services by defining and achieving SLOs, improving service availability and performance, instrumenting and enhancing observability, and leading incident response efforts to reduce MTTR. Evaluate emerging technologies and industry trends, establish engineering standards and best practices, and provide technical leadership across authentication domains. Qualifications:. Experience 5-10+ years of Information Technology or Engineering experience with authentication engineering accountabilities. 3+ years management experience. Experience leading enterprise large-scale projects. Technical Skills Strong technical expertise and enterprise experience with majority of the following: Strong Expertise with Active Directory and Entra ID Experience with PKI solutions such as Active Directory Certificate Services (AD CS); Hashicorp, Entrust, Sectigo, DigiCert, etc. Experience with multifactor solutions such as Microsoft Authenticator, Duo, etc. Experience implementing on-prem and cloud authentication solutions (AWS, Azure, and/or GCP) Experience with automation of authentication solutions and processes Experience deploying configurations leveraging CI/CD pipelines utilizing technologies like GitHub, Jenkins, GitHub Actions, Teraform, Ansible, etc Bonus Qualifications: Experience with Privileged Access Management and Vaulting solutions (CyberArk, Hashicorp, Azure Key Vault, AWS Secrets Manager, GCP Secrets Manager, etc.) Experience with hardware tokens/smart cards for TOTP, FIDO2, PIV (Duo, Thales, Yubikey, etc.) Strong knowledge of authentication protocols such as SAML, OAuth 2.0, OpenID Connect, Kerberos, LDAP, certificate based authentication, etc. Understanding of authentication attack techniques, threat actors, and exploitation methods and controls to mitigate. Scripting experience (PowerShell, Python, etc.) Understanding of Full Stack Java development. Understanding security standards and compliance requirements (NIST, ISO, PCI, HIPPA, Sox, etc.). If you are applying for a position open to candidates across Canada, unless otherwise indicated, strong English communication skills are required, as the role involves regular interaction with clients, advisors, or employees across the country. Allstate Canada Group has policies and practices that provide workplace accommodations. If you require accommodation, please let us know and we will work with you to meet your needs. #LI_NJ1 À propos d’Allstate : Allstate du Canada, compagnie d’assurance est un chef de file dans le domaine des assurances automobile et habitation; elle offre à ses clients des produits et services de prévention et de protection qui conviennent à toutes les étapes de la vie. Au service des Canadiens depuis 1953, l’entreprise met tout en œuvre pour que non seulement ses clients, mais aussi ses employés soient en bonnes mainsMD, comme en fait foi sa présence au palmarès des Employeurs de choix au Canada pendant neuf années de suite. Allstate du Canada tient à contribuer au mieux-être des communautés dans lesquelles elle exerce ses activités au moyen de partenariats avec des organismes caritatifs et de programmes misant sur la générosité de ses employés. Pour en savoir plus, visitez le www.allstate.ca. Pour connaître nos con
Verified and listed by ActiveJobs. Applications are made directly on Allstate's own career page — we never sit in the middle.