Senior Threat Detection & Response Engineer

Posted 15hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Senior threat detection engineer building AI/ML pipelines and detection-as-code workflows. Automating response and strengthening cybersecurity for Allstate’s insurance business.

Responsibilities:

  • Define, design, and build AI/ML pipelines for investigation, triage, enrichment, and detection generation
  • Own delivery of AI-assisted investigation and triage from data foundations and feature/enrichment pipelines through model selection, evaluation, and safe production deployment
  • Set standards for validating, explaining, and trusting AI/ML outputs in detection and response workflows
  • Design and own the detection-as-code pipeline, including repository structure, detection schema, peer review, automated testing, and staged CI/CD deployment across SIEM, XDR, and endpoint detection surfaces
  • Define technical standards, reusable patterns, and quality controls for detection content
  • Build tooling and APIs for authoring, testing, and debugging detections
  • Design AI-driven automation and SOAR-style workflows for phishing, DLP, enrichment, routing, and verified-benign report closure
  • Build response automation, playbooks, containment actions, and integrations to reduce dwell time and mean time to respond
  • Establish and maintain a MITRE ATT&CK coverage baseline
  • Partner with Threat Intelligence and Threat Hunting to convert findings into durable, tested detections
  • Establish continuous validation through breach-and-attack simulation and purple-team activities
  • Lead technical projects end-to-end, including scoping, execution, delivery accountability, and outcome ownership
  • Serve as the senior-most individual-contributor technical authority and final technical escalation point for detection engineering
  • Influence roadmap and tooling decisions with internal platform partners and help shape a global follow-the-sun operating model

Requirements:

  • Hands-on experience designing and building AI/ML pipelines for security data, including data and enrichment foundations, model evaluation, production deployment, and guardrails
  • Experience writing, versioning, testing, and shipping detections as code
  • Deep hands-on detection engineering experience across SIEM and EDR/XDR platforms
  • Fluency in KQL, SQL, Sigma, or equivalent
  • Strong scripting/development skills, such as Python or Go
  • Experience mapping detections to MITRE ATT&CK and partnering with threat hunting and threat intelligence
  • Experience leading technical projects to completion and owning delivery outcomes
  • Ability to explain detection strategies, AI/ML design choices, and engineering trade-offs to engineers and senior leaders
  • Background investigation required
  • Allstate generally does not sponsor individuals for employment-based visas for this position
  • Dedicated, private workspace free from distractions when working from home
  • Reliable internet with minimum speeds of 50 MB download and 5 MB upload
  • Nice to have: AI-assisted/agentic SOC experience; security data engineering or streaming pipeline experience; enterprise SIEM, XDR, and EDR experience; purple-team, adversary-emulation, or breach-and-attack-simulation experience; financial services, insurance, or regulated, high-scale environment exposure

Benefits:

  • Comprehensive technology setup, including a laptop, monitors, headset, keyboard, and mouse
  • Monthly connectivity reimbursement for employees eligible to work from home