[Remote] Cloud Product Security Engineer
Note: The job is a remote job and is open to candidates in USA. Allstate Insurance Co. is dedicated to protecting families and their belongings from life’s uncertainties. They are seeking a Cloud Product Security Engineer who will be responsible for building, integrating, and operating security controls within cloud environments, focusing on engineering preventative and responsive security capabilities across cloud infrastructure and application services.ResponsibilitiesDesign, build, and operate cloud‑native security controls as software products across cloud infrastructure, data platforms, and application servicesEngineer and maintain cloud security posture management (CSPM) and data loss prevention (DLP) capabilities to continuously detect, assess, and reduce risk in cloud environmentsBuild preventative, detective, and responsive security controls that integrate directly into cloud platforms, CI/CD pipelines, and shared enterprise servicesIntegrate cloud security controls with SIEM and security tooling to generate high‑quality signals for detection, investigation, and incident responseSupport incident handling and response by engineering detection logic, automation, and response mechanisms that improve containment and recoveryApply modern cloud and software engineering practices (e.g., infrastructure as code, automated testing, CI/CD) to ensure security controls are reliable, scalable, and maintainableCollaborate with platform engineers, application teams, and Digital Product Managers to align cloud security controls with architectures and developer workflowsSkills3+ years of professional software or security engineering experience, with hands on ownership of production systems deployed in cloud environmentsStrong proficiency in one or more modern programming languages (such as Python, Java, or JavaScript), and a proven ability to design, write, review, and maintain robust production grade codeHands-on experience engineering security controls within public cloud platforms (e.g., AWS and/or Azure), spanning infrastructure, platform services, or application-level integrationsBackground building or integrating cloud security posture management (CSPM), data protection, or data loss prevention (DLP) capabilities as engineered solutionsUnderstanding of cloud-native architectures and services (e.g., identity, networking, storage, compute) and how security controls integrate into themExperience engineering preventative, detective, and responsive security capabilities, including detection logic, automation, or response workflows in cloud environmentsFamiliarity integrating security controls and signals with SIEM or security monitoring platforms to support detection and incident responsePractical application of modern engineering practices such as infrastructure as code, automated testing, CI/CD, and operational feedback loopsWorking knowledge of cloud service provider security services and patterns (e.g., identity, networking, encryption, logging) and their use in real-world cloud architecturesPractical exposure to advanced CSPM techniques, including policy-as-code, drift detection, and automated remediationExperience with data classification, data handling, or data protection strategies that support DLP in cloud-hosted systemsFamiliarity with security telemetry, logging pipelines, and SIEM platforms used for detection, investigation, and incident responseHands-on involvement in incident response or post-incident analysis from an engineering perspective (e.g., improving detections, controls, or recovery mechanisms)Exposure to infrastructure-as-code and cloud automation tooling used to deploy, configure, and secure cloud resources at scaleUnderstanding of secure design principles for cloud-native and distributed systems, including identity-centric and least-privilege approachesDemonstrated interest in continuously improving cloud security controls through learning, experimentation, and collaborationCompany OverviewAllstate is an insurance company that offers car, home, and life insurance services. It is a sub-organization of Allstate. It was founded in 1931, and is headquartered in Northbrook, Illinois, USA, with a workforce of 10001+ employees. Its website is http://www.allstate.com.