Turn this role into an interview — a resume and cover letter built around what this employer wants.
Allstate is seeking a Senior Threat Hunter in Bengaluru to lead hypothesis-driven, intelligence-led hunts across enterprise, cloud, and OT/IoT environments.
You will operationalize findings into durable detection logic, partner with threat intel, IR, and Detection Engineering, and reduce dwell time with AI/LLM-assisted tooling. Shift B (India) applies, with strong leadership and mentoring duties.
At Allstate, great things happen when our people work together to protect families and their belongings from life's uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers' evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection.
Job Description
We are seeking a Senior Threat Hunter to lead hypothesis-driven, intelligence-led hunts across enterprise, cloud, and OT/IoT environments. This role proactively identifies adversary tradecraft that evades existing detections, operationalizes findings into durable detection logic, and partners with Threat Intelligence, Detection Engineering, IR, Exposure Management, and REM to reduce dwell time and shrink the enterprise exposure plane. The hunter will leverage MITRE ATT&CK, the Pyramid of Pain, and the Diamond Model to drive measurable risk reduction.
Lead hypothesis-driven, intelligence-led hunt campaigns from formulation through reporting, mapped to MITRE ATT&CK
Design and execute custom analytics against large-scale security telemetry (SIEM, EDR/XDR, identity, cloud, network) to uncover adversary tradecraft that evades existing detections
Perform identity-centric hunting across Entra ID, Active Directory, and SaaS platforms - token theft, session hijacking, MFA bypass, OAuth abuse, and conditional access circumvention.
Conduct cloud-native hunting across AWS, Azure, M365, and SaaS control planes, including audit logs, identity events, and workload telemetry.
Convert hunt findings into durable detections, signatures, and SOAR playbooks in partnership with Detection Engineering, closing the hunt-to-detect loop
Perform Deception Operations by defining adversary-aligned use cases, authoring detection requirements for deception-generated activity, and tuning signal vs. noise thresholds
Leverage AI and LLM-assisted tooling to accelerate hunting - including query generation, log summarization, entity pivoting, anomaly clustering, and large-scale pattern discovery across disparate telemetry sources
Hunt within AI and LLM environments - including enterprise copilots, internal/external LLM deployments, AI agents, RAG pipelines, model endpoints, and AI/ML infrastructure - for threats such as prompt injection, model abuse, data exfiltration via AI channels, agent hijacking, supply-chain compromise of models, and unauthorized model access
Produce post-hunt reports with explicit evidence and measurable outcomes tied to exposure reduction
Partner with Threat Intelligence to operationalize finished intel into targeted hunt missions and feed collection requirements upstream
Support purple-team exercises and validate detection efficacy against adversary emulation campaigns (Atomic Red Team, CALDERA, Stratus Red Team)
Develop and maintain custom tooling and automation to support hunting, investigation, and analyst efficiency
Mentor junior hunters; contribute to internal knowledge bases, hunt libraries, and team training
Support Incident Response, Forensics, and Insider Threat / Fraud investigations as a senior technical resource when adversary expertise is needed
Serve as a liaison for Threat Services across Cyber Operations, communicating findings clearly to technical peers and executive leadership
Identify needs, drive solutions, and operate autonomously within strategic priorities
Primary Skills
Customer Centricity, Digital Literacy, Inclusive Leadership, Learning Agility, Results-Oriented
Shift Time
Shift B (India)
About Allstate
Joining our team isn't just a job — it's an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact.
The Allstate Corporation is one of the largest publicly held insurance providers in the United States. Ranked No. 84 in the 2023 Fortune 500 list of the largest United States corporations by total revenue, The Allstate Corporation owns and operates 18 companies in the United States, Canada, Northern Ireland, and India. Allstate India Private Limited, also known as Allstate India, is a subsidiary of The Allstate Corporation. The India talent center was set up in 2012 and operates under the corporation’s Good Hands promise. As it innovates operations and technology, Allstate India has evolved beyond its technology functions to be the critical strategic business services arm of the corporation. With offices in Bengaluru and Pune, the company offers expertise to the parent organization’s business areas including technology and innovation, accounting and imaging services, policy administration, transformation solution design and support services, transformation of property liability service design, global operations and integration, and training and transition.
Learn more about Allstate India here.