Senior Threat Detection & Response Engineer
Posted 15hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior threat detection engineer building AI/ML pipelines and detection-as-code workflows. Automating response and strengthening cybersecurity for Allstate’s insurance business.
Responsibilities:
- Define, design, and build AI/ML pipelines for investigation, triage, enrichment, and detection generation
- Own delivery of AI-assisted investigation and triage from data foundations and feature/enrichment pipelines through model selection, evaluation, and safe production deployment
- Set standards for validating, explaining, and trusting AI/ML outputs in detection and response workflows
- Design and own the detection-as-code pipeline, including repository structure, detection schema, peer review, automated testing, and staged CI/CD deployment across SIEM, XDR, and endpoint detection surfaces
- Define technical standards, reusable patterns, and quality controls for detection content
- Build tooling and APIs for authoring, testing, and debugging detections
- Design AI-driven automation and SOAR-style workflows for phishing, DLP, enrichment, routing, and verified-benign report closure
- Build response automation, playbooks, containment actions, and integrations to reduce dwell time and mean time to respond
- Establish and maintain a MITRE ATT&CK coverage baseline
- Partner with Threat Intelligence and Threat Hunting to convert findings into durable, tested detections
- Establish continuous validation through breach-and-attack simulation and purple-team activities
- Lead technical projects end-to-end, including scoping, execution, delivery accountability, and outcome ownership
- Serve as the senior-most individual-contributor technical authority and final technical escalation point for detection engineering
- Influence roadmap and tooling decisions with internal platform partners and help shape a global follow-the-sun operating model
Requirements:
- Hands-on experience designing and building AI/ML pipelines for security data, including data and enrichment foundations, model evaluation, production deployment, and guardrails
- Experience writing, versioning, testing, and shipping detections as code
- Deep hands-on detection engineering experience across SIEM and EDR/XDR platforms
- Fluency in KQL, SQL, Sigma, or equivalent
- Strong scripting/development skills, such as Python or Go
- Experience mapping detections to MITRE ATT&CK and partnering with threat hunting and threat intelligence
- Experience leading technical projects to completion and owning delivery outcomes
- Ability to explain detection strategies, AI/ML design choices, and engineering trade-offs to engineers and senior leaders
- Background investigation required
- Allstate generally does not sponsor individuals for employment-based visas for this position
- Dedicated, private workspace free from distractions when working from home
- Reliable internet with minimum speeds of 50 MB download and 5 MB upload
- Nice to have: AI-assisted/agentic SOC experience; security data engineering or streaming pipeline experience; enterprise SIEM, XDR, and EDR experience; purple-team, adversary-emulation, or breach-and-attack-simulation experience; financial services, insurance, or regulated, high-scale environment exposure
Benefits:
- Comprehensive technology setup, including a laptop, monitors, headset, keyboard, and mouse
- Monthly connectivity reimbursement for employees eligible to work from home















