Cloud Product Security Engineer
This is the employer's own posting, not a copy on a job board.
What we know
Is it still open?
Confirmed still open
Last checked 10h ago — checked against the employer's own applicant tracking system, which is the company answering directly.
We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.
How old is it?
Posted 16d ago
The date the source published, not the day we noticed it (2026-09-15). Last seen at its source just now.
We have tracked this listing since 21 Sep 2026 (10 days). The employer's own board has carried it every time we have read it, most recently just now.
Is it remote?
The listing says yes
The location field doesn't say remote, so our assessment is based on the title or the description. Read the listing before applying.
Who may apply?
United States
The description states no restriction of its own. This is the source's own tag.
Pay
$90.7k–195.7k/yr
Read out of the job description by us, not from a structured field. Shown in the posting's own currency and period; we never convert.
Skills named in the ad
Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.
Carried by 1 source
-
workday employer's own board first seen 10d ago · last seen just now
- location not stated
The listing
At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection.
Job Description
Product Security Engineering designs, builds, and operates enterprise security controls as software products that integrate directly into cloud platforms, the SDLC, and core enterprise services. The organization applies modern software and cloud engineering practices to deliver scalable, reliable, and developer friendly security capabilities for cloud hosted workloads.The Cloud Product Security Engineer is a hands-on security engineer responsible for building, integrating, and operating security controls within cloud environments. This role focuses on engineering preventative, detective, and responsive security capabilities across cloud infrastructure, data platforms, and application services. It includes building and operating cloud security posture management (CSPM) and data loss prevention (DLP) capabilities to continuously detect, assess, and reduce risk in cloud environments.
Engineers in this role own the full software development lifecycle from design and implementation through deployment and production support and are accountable for the reliability, adoption, and effectiveness of cloud security controls, including their role in incident detection, response, and recovery.
Key Responsibilities
Design, build, and operate cloud‑native security controls as software products across cloud infrastructure, data platforms, and application services
Engineer and maintain cloud security posture management (CSPM) and data loss prevention (DLP) capabilities to continuously detect, assess, and reduce risk in cloud environments
Build preventative, detective, and responsive security controls that integrate directly into cloud platforms, CI/CD pipelines, and shared enterprise services
Integrate cloud security controls with SIEM and security tooling to generate high‑quality signals for detection, investigation, and incident response
Support incident handling and response by engineering detection logic, automation, and response mechanisms that improve containment and recovery
Apply modern cloud and software engineering practices (e.g., infrastructure as code, automated testing, CI/CD) to ensure security controls are reliable, scalable, and maintainable
Collaborate with platform engineers, application teams, and Digital Product Managers to align cloud security controls with architectures and developer workflows
Essential Skills:
3+ years of professional software or security engineering experience, with hands on ownership of production systems deployed in cloud environments. Strong proficiency in one or more modern programming languages (such as Python, Java, or JavaScript), and a proven ability to design, write, review, and maintain robust production grade code.
Hands‑on experience engineering security controls within public cloud platforms (e.g., AWS and/or Azure), spanning infrastructure, platform services, or application‑level integrations
Background building or integrating cloud security posture management (CSPM), data protection, or data loss prevention (DLP) capabilities as engineered solutions
Understanding of cloud‑native architectures and services (e.g., identity, networking, storage, compute) and how security controls integrate into them
Experience engineering preventative, detective, and responsive security capabilities, including detection logic, automation, or response workflows in cloud environments
Familiarity integrating security controls and signals with SIEM or security monitoring platforms to support detection and incident response
Practical application of modern engineering practices such as infrastructure as code, automated testing, CI/CD, and operational feedback loops
Desirable Skills:
Working knowledge of cloud service provider security services and patterns (e.g., identity, networking, encryption, logging) and their use in real‑world cloud architectures
Practical exposure to advanced CSPM techniques, including policy‑as‑code, drift detection, and automated remediation
Experience with data classification, data handling, or data protection strategies that support DLP in cloud‑hosted systems
Familiarity with security telemetry, logging pipelines, and SIEM platforms used for detection, investigation, and incident response
Hands‑on involvement in incident response or post‑incident analysis from an engineering perspective (e.g., improving detections, controls, or recovery mechanisms)
Exposure to infrastructure‑as‑code and cloud automation tooling used to deploy, configure, and secure cloud resources at scale
Understanding of secure design principles for cloud‑native and distributed systems, including identity‑centric and least‑privilege approaches
Demonstrated interest in continuously improving cloud security controls through learning, experimentation, and collaboration
#LI-JJ1
Skills
CI/CD, Cloud Platform, Cloud Security, Collaboration, Data Loss Prevention (DLP), Infrastructure As Code (IaC), Java (Programming Language), JavaScript, Python (Programming Language), Security Engineering, Software Development Life Cycle (SDLC), Software EngineeringCompensation
Compensation offered for this role ranges from $90,700 - 195,700 annually and is based on experience and qualifications.The candidate(s) offered this position will be required to submit to a background investigation.
Joining our team isn’t just a job — it’s an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact.
Allstate generally does not sponsor individuals for employment-based visas for this position.
Effective July 1, 2014, under Indiana House Enrolled Act (HEA) 1242, it is against public policy of the State of Indiana and a discriminatory practice for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component.
For jobs in San Francisco, please click “here” for information regarding the San Francisco Fair Chance Ordinance.
For jobs in Los Angeles, please click “here” for information regarding the Los Angeles Fair Chance Initiative for Hiring Ordinance.
To view the “EEO Know Your Rights” poster click “here”. This poster provides information concerning the laws and procedures for filing complaints of violations of the laws with the Office of Federal Contract Compliance Programs.
To view the FMLA poster, click “here”. This poster summarizing the major provisions of the Family and Medical Leave Act (FMLA) and telling employees how to file a complaint.
It is the Company’s policy to employ the best qualified individuals available for all jobs. Therefore, any discriminatory action taken on account of an employee’s ancestry, age, color, disability, genetic information, gender, gender identity, gender expression, sexual and reproductive health decision, marital status, medical condition, military or veteran status, national origin, race (include traits historically associated with race, including, but not limited to, hair texture and protective hairstyles), religion (including religious dress), sex, or sexual orientation that adversely affects an employee's terms or conditions of employment is prohibited. This policy applies to all aspects of the employment relationship, including, but not limited to, hiring, training, salary administration, promotion, job assignment, benefits, discipline, and separation of employment.
Allstate provides a comprehensive technology setup, including a laptop, monitors, headset, keyboard, and mouse. Employees eligible to work from home also receive a monthly connectivity reimbursement to help offset internet costs.
When working from home, you must have a dedicated, private workspace free from distractions, along with appropriate desk and seating. Reliable internet is required, with minimum speeds of 50 MB download and 5 MB upload.
To help create a more personal and engaging experience, we ask that you join with your camera on if your interview is virtual. Please also have a Valid Photo Identification available at the start of your interview. If you require any accommodations or have questions ahead of your interview please reach out to your recruiter.
Note: Internal candidates are only asked to join on video; a Valid Photo Identification is not needed for the interview.