Principal Engineer, Workforce, Customer & Agentic Identity

Allstate Insurance Company

Northern (KY)

On-site

USD 199,000 - 274,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Laptop provided
Monthly connectivity reimbursement for
Home office setup guidance

Job summary

Allstate Insurance Company seeks a Principal Engineer to lead identity strategy across workforce, customer, machine, and agentic identities. You will guide architecture, governance, and modernize identity platforms while partnering with engineering, product, and security teams to deliver secure experiences.

You will drive Zero Trust initiatives, implement MFA and fine-grained access controls, and mentor teams to achieve enterprise-wide identity excellence.

Qualifications

  • 12+ years of experience designing and implementing enterprise IAM solutions.
  • Working knowledge of Ping Identity, SailPoint, or similar IAM platforms.
  • Strong knowledge of customer identity, workforce identity, federation, SSO, MFA, privileged access management, identity governance, and access certification.
  • Experience designing and implementing Zero Trust identity architectures, including conditional access, risk-based authentication, fine-grained authorization, and least-privilege access controls.
  • Experience supporting machine identities, workload identities, service accounts, certificates, secrets management, and cloud-native identity models.
  • Familiarity with emerging AI and agentic identity concepts, governance models, and authorization frameworks.
  • Proven ability to influence senior leaders, drive enterprise adoption, and communicate complex technical strategies across diverse stakeholder groups.

Responsibilities

  • Define and drive the technical strategy and architecture for workforce, customer, machine, and agentic identity platforms across the enterprise.
  • Champion identity as a business enabler by improving customer authentication experiences while maintaining strong security, governance, and compliance standards.
  • Partner directly with engineers, architects, product teams, and security leaders to design, implement, and modernize identity solutions.
  • Provide technical leadership for authentication, authorization, federation, identity governance, lifecycle management, privileged access management, and access certification capabilities.
  • Lead the evaluation, design, and adoption of identity platforms and technologies, including Ping Identity, SailPoint, and emerging identity standards.
  • Drive Zero Trust initiatives through implementation of MFA, risk-based authentication, fine-grained authorization, identity governance, and least-privilege access controls.
  • Define identity strategies and governance models for machine identities, service accounts, workload identities, and emerging AI agents.
  • Establish identity controls and lifecycle processes for autonomous and agentic systems, including delegated authority, ownership, governance, and privileged access management.
  • Influence and drive enterprise adoption of identity modernization initiatives by clearly articulating business value, customer impact, and security outcomes.
  • Collaborate with digital product teams to create seamless, secure, and scalable customer identity experiences that improve engagement, trust, and retention.
  • Remain actively involved in architecture, troubleshooting, integration design, and implementation efforts while mentoring engineering teams and driving technical excellence.
  • Establish engineering standards, reference architectures, and best practices that advance Allstate's long-term identity roadmap and Zero Trust strategy.

Skills

Access Management
Artificial Intelligence (AI)
Identity Access Management (IAM)
Identity Governance
Multi-Factor Authentication (MFA)
Ping Identity
SailPoint IdentityNow
Single Sign-On (SSO)
Stakeholder Influence
Zero Trust Architecture

Education

Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related technical field
Preferred: Relevant IAM or security certifications such as CISSP, CCSP, SailPoint, Ping Identity, Microsoft Security, or equivalent

Job description

At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection.

Job Description

The Principal Engineer, Workforce, Customer & Agentic Identity, leads the technical strategy, architecture, and modernization of identity capabilities across workforce, customer, machine, and emerging AI agent identities. This hands-on technical leader champions secure, frictionless customer and employee experiences by partnering closely with engineering, product, and security teams to evolve authentication, authorization, governance, and access management capabilities. Leveraging deep expertise in modern identity platforms, Zero Trust principles, and emerging agentic identity models, the Principal Engineer influences enterprise strategy, drives adoption of transformative solutions, and helps shape the future of identity across Allstate\'s digital ecosystem.

As a Director you won’t just deliver results – you drive our culture and shared purpose. At Allstate, we value in person connected experiences not just with your team but also other Allstaters. This may require travel within your local area or to one of our offices on a regular basis.

Key Responsibilities

  • Define and drive the technical strategy and architecture for workforce, customer, machine, and agentic identity platforms across the enterprise.

  • Champion identity as a business enabler by improving customer authentication experiences while maintaining strong security, governance, and compliance standards.

  • Partner directly with engineers, architects, product teams, and security leaders to design, implement, and modernize identity solutions.

  • Provide technical leadership for authentication, authorization, federation, identity governance, lifecycle management, privileged access management, and access certification capabilities.

  • Lead the evaluation, design, and adoption of identity platforms and technologies, including Ping Identity, SailPoint, and emerging identity standards.

  • Drive Zero Trust initiatives through implementation of MFA, risk-based authentication, fine-grained authorization, identity governance, and least-privilege access controls.

  • Define identity strategies and governance models for machine identities, service accounts, workload identities, and emerging AI agents.

  • Establish identity controls and lifecycle processes for autonomous and agentic systems, including delegated authority, ownership, governance, and privileged access management.

  • Influence and drive enterprise adoption of identity modernization initiatives by clearly articulating business value, customer impact, and security outcomes.

  • Collaborate with digital product teams to create seamless, secure, and scalable customer identity experiences that improve engagement, trust, and retention.

  • Remain actively involved in architecture, troubleshooting, integration design, and implementation efforts while mentoring engineering teams and driving technical excellence.

  • Establish engineering standards, reference architectures, and best practices that advance Allstate\'s long-term identity roadmap and Zero Trust strategy.

Skills & Capabilities

  • Ability to influence enterprise strategy and drive adoption of identity modernization initiatives.

  • Strong change leadership and stakeholder management skills across engineering, security, product, and business teams.

  • Proven ability to communicate the value of identity solutions and build consensus around technical decisions.

  • Technical leadership experience guiding architectures, engineering standards, and best practices.

  • Customer-centric mindset focused on balancing security, usability, and business outcomes.

  • Ability to lead through influence, navigate ambiguity, and drive enterprise-wide change without direct authority.

  • Experience influencing vendor roadmaps and product strategies to align with evolving business objectives and operational priorities.

Experience

  • 12+ years of experience designing and implementing enterprise Identity and Access Management (IAM) solutions.

  • Working knowledge of Ping Identity, SailPoint, or similar identity and access management platforms.

  • Strong knowledge of customer identity, workforce identity, federation, SSO, MFA, privileged access management, identity governance, and access certification.

  • Experience designing and implementing Zero Trust identity architectures, including conditional access, risk-based authentication, fine-grained authorization, and least-privilege access controls.

  • Experience supporting machine identities, workload identities, service accounts, certificates, secrets management, and cloud-native identity models.

  • Familiarity with emerging AI and agentic identity concepts, governance models, and authorization frameworks.

  • Proven ability to influence senior leaders, drive enterprise adoption, and communicate complex technical strategies across diverse stakeholder groups.

Education

  • Bachelor\'s degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related technical field.

  • Preferred: Relevant IAM or security certifications such as CISSP, CCSP, SailPoint, Ping Identity, Microsoft Security, or equivalent.

Supervisory Responsibilities

  • This job has supervisory duties.

Skills Access Management, Artificial Intelligence (AI), Identity Access Management (IAM), Identity Governance, Multi-Factor Authentication (MFA), Ping Identity, SailPoint IdentityNow, Single Sign-On (SSO), Stakeholder Influence, Zero Trust Architecture

Compensation

Compensation offered for this role is 199,000.00 - 274,000.00 annually and is based on experience and qualifications.

The candidate(s) offered this position will be required to submit to a background investigation.

Joining our team isn’t just a job — it’s an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact.

Allstate generally does not sponsor individuals for employment-based visas for this position.

Effective July 1, 2014, under Indiana House Enrolled Act (HEA) 1242, it is against public policy of the State of Indiana and a discriminatory practice for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component.

For jobs in San Francisco, please click “here” for information regarding the San Francisco Fair Chance Ordinance.

For jobs in Los Angeles, please click “here” for information regarding the Los Angeles Fair Chance Initiative for Hiring Ordinance.

To view the “EEO Know Your Rights” poster click “here”. This poster provides information concerning the laws and procedures for filing complaints of violations of the laws with the Office of Federal Contract Compliance Programs.

To view the FMLA poster, click “here”. This poster summarizing the major provisions of the Family and Medical Leave Act (FMLA) and telling employees how to file a complaint.

It is the Company’s policy to employ the best qualified individuals available for all jobs. Therefore, any discriminatory action taken on account of an employee’s ancestry, age, color, disability, genetic information, gender, gender identity, gender expression, sexual and reproductive health decision, marital status, medical condition, military or veteran status, national origin, race, religion, sex, or sexual orientation that adversely affects an employee\'s terms or conditions of employment is prohibited. This policy applies to all aspects of the employment relationship, including, but not limited to, hiring, training, salary administration, promotion, job assignment, benefits, discipline, and separation of employment.

Allstate provides a comprehensive technology setup, including a laptop, monitors, headset, keyboard, and mouse. Employees eligible to work from home also receive a monthly connectivity reimbursement to help offset internet costs.

When working from home, you must have a dedicated, private workspace free from distractions, along with appropriate desk and seating. Reliable internet is required, with minimum speeds of 50 MB download and 5 MB upload.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Engineer, Workforce, Customer & Agentic Identity
Principal Engineer, Workforce, Customer & Agentic Identity

Allstate Insurance • Illinois

On-site
USD 199,000 - 274,000
Connectivity reimbursement
Tech equipment provided
Home office setup guidance
Principal Engineer, Developer Experience
Principal Engineer, Developer Experience

Allstate Insurance Company • Northern (KY)

Hybrid
USD 199,000 - 274,000
Laptop & monitors provided
Connectivity reimbursement
Lead Engineer, Authentication Engineering, (Sr Mgr Level) - Remote
Lead Engineer, Authentication Engineering, (Sr Mgr Level) - Remote

Allstate • United States

On-site
USD 152,000 - 222,000
Principal Engineer, Workforce, Customer & Agentic Identity
Principal Engineer, Workforce, Customer & Agentic Identity

Allstate Northern Ireland Limited • Northern (KY)

Hybrid
USD 199,000 - 274,000
Laptop provision
Home-office connectivity reimbursement
Workspace setup guidance
Workforce Identity Service Lead Consultant
Workforce Identity Service Lead Consultant

allstate • Illinois

On-site
USD 98,100 - 167,850
Security Engineering Senior Manager
Security Engineering Senior Manager

Allstate Insurance • Illinois

On-site
USD 152,000 - 210,000
Connectivity reimbursement
Principal, Strategic Planning & Integration
Principal, Strategic Planning & Integration

Allstate Insurance • Illinois

On-site
USD 177,000 - 244,000
Laptop & monitors provided
Connectivity reimbursement for remote/
Principal Engineer, Developer Experience
Principal Engineer, Developer Experience

Allstate • Illinois

On-site
USD 199,000 - 274,000
Managing Engineer – (Software Development/Container Workloads)
Managing Engineer – (Software Development/Container Workloads)

allstate • United States

Hybrid
USD 120,000 - 193,725
Laptop, monitors, headset, keyboard, &
Connectivity reimbursement for home办公
Microsoft Azure Cloud Lead Consultant
Microsoft Azure Cloud Lead Consultant

Allstate • United States

On-site
USD 120,000 - 185,000
Laptop provided
Connectivity reimbursement
Home office setup