Senior Data Security Engineer

Allstate Private Limited

United States

Hybrid

USD 91,000 - 190,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Allstate is seeking a Senior Data Protection Security Engineer to lead modern data protection initiatives across cloud, SaaS, endpoint, email, and collaboration environments. You will drive automated, policy-as-code driven DLP and governance programs, advancing the organization’s data protection strategy while delivering measurable security improvements.

The role emphasizes engineering-driven security, automation, and collaboration with cross-functional teams to reduce risk and enable business

Qualifications

  • 4+ years delivering enterprise Data Protection, Information Protection, Cloud Security, or Security Engineering capabilities within complex organizations.
  • Policy-as-Code, Security-as-Code, and DevSecOps methodologies, automating security at scale.
  • Automation, APIs, IaC, platform engineering to modernize data protection.
  • Advanced knowledge of DLP, data classification, information protection, and governance.
  • Hands-on with Microsoft Purview, Microsoft Information Protection, Defender for Cloud Apps, and Microsoft 365 security ecosystem.
  • Understanding of cloud, SaaS, CASB, and enterprise data protection architectures.
  • Proficient in PowerShell, Python, REST APIs, Terraform, Bicep, YAML, JSON.
  • Experience modernizing Data Protection programs through automation and engineering.
  • Ability to scale DevOps/DevSecOps within security teams.
  • Proven track record leading large security initiatives.
  • Experience supporting enterprise-scale Microsoft 365 environments.
  • Knowledge of regulatory and privacy requirements for scalable controls.

Responsibilities

  • Engineer enterprise DLP controls across endpoint, email, SaaS, cloud storage, collaboration platforms, network, and web channels.
  • Modernize DLP policy deployment with policy-as-code workflows.
  • Build CI/CD pipelines for data protection policy lifecycle management.
  • Develop reusable policy templates, detection logic, and deployment standards across DLP/CASB platforms.
  • Automate operational tasks like policy promotion, drift detection, and health checks.
  • Integrate DLP, CASB, data classification, cloud security, identity, SIEM, SOAR, and workflow platforms.
  • Tune detection logic to reduce false positives and improve policy enforcement.
  • Design guardrails for sensitive data usage across Microsoft 365 and cloud environments.
  • Partner with engineering, cloud, compliance, and privacy teams to design practical data protection solutions.
  • Investigate data protection events and derive automated prevention patterns.
  • Define metrics, KPIs, dashboards, and control evidence for risk reduction.
  • Support platform upgrades and vendor integrations with disciplined engineering.

Skills

API
Cloud Security
Cybersecurity
Data Governance
Data Loss Prevention
Data Protection
Data Security
DevSecOps
Information Security Engineering
Microsoft 365 Security
Microsoft Defender for Cloud
Scripting
Infrastructure as Code
IT Automation
IT Security Architecture
IT Security Operations
SaaS

Job description

At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection.

Job Description

**For this opportunity, the business is flexible to hire at Senior Consultant, Lead Consultant, and Expert level depending on qualifications & interview evaluation.**

The Senior Data Protection Security Engineer will lead the evolution of enterprise data protection from a traditional tool administration model to an engineering-driven security capability.

This role is responsible for building scalable, automated, and measurable data protection solutions across cloud, SaaS, endpoint, email, and collaboration environments using Policy-as-Code, Security-as-Code, DevOps, and DevSecOps practices.

The successful candidate will bring a proven track record of modernizing Data Protection, DLP, CASB, or Information Protection programs by reducing manual processes, increasing automation, and implementing repeatable governance and deployment models.

This individual will serve as a key contributor in advancing the organization's data protection strategy while driving operational excellence, security effectiveness, and business enablement.

Key Responsibilities
  • Engineer enterprise DLP controls across endpoint, email, SaaS, cloud storage, collaboration platforms, network, and web channels.
  • Modernize DLP policy deployment by moving from manual console-based changes to version-controlled, automated, and repeatable policy-as-code workflows.
  • Build CI/CD pipelines for data protection policy lifecycle management, including peer review, automated validation, testing, approval, deployment, and rollback.
  • Develop reusable policy templates, detection logic, exception patterns, configuration baselines, and deployment standards across multiple DLP and CASB platforms.
  • Automate operational tasks such as policy promotion, configuration drift detection, control validation, reporting, alert enrichment, and recurring health checks.
  • Integrate DLP, CASB, data classification, cloud security, identity, SIEM, SOAR, and workflow platforms to improve visibility, response, and enforcement.
  • Tune detection logic using data-driven analysis to reduce false positives, improve signal quality, and increase confidence in policy enforcement.
  • Design guardrails for sensitive data usage across Microsoft 365, cloud platforms, source code repositories, collaboration tools, SaaS applications, and enterprise endpoints.
  • Partner with engineering, cloud, infrastructure, network, compliance, privacy, legal, and business teams to design practical data protection solutions.
  • Investigate data protection events, identify root cause, recommend control improvements, and convert lessons learned into automated prevention patterns.
  • Define and maintain metrics, KPIs, dashboards, and control evidence that demonstrate risk reduction, policy effectiveness, deployment quality, and operational maturity.
  • Support platform upgrades, capability expansions, vendor integrations, and new data protection control patterns using disciplined engineering practices.
Key Qualifications
  • 4+ years delivering enterprise Data Protection, Information Protection, Cloud Security, or Security Engineering capabilities within complex organizations.
  • Proven experience in Policy-as-Code, Security-as-Code, and DevSecOps methodologies, with a demonstrated ability to automate security control deployment and governance at enterprise scale.
  • Track record of replacing manual operational processes with engineering-driven solutions through automation, APIs, Infrastructure-as-Code, and platform engineering practices.
  • Advanced knowledge of Data Loss Prevention (DLP), data classification, information protection, and data governance principles.
  • Hands-on expertise with Microsoft Purview, Microsoft Information Protection, Defender for Cloud Apps, and the Microsoft 365 security ecosystem.
  • Comprehensive understanding of cloud, SaaS, CASB, and enterprise data protection architectures.
  • Proficiency in scripting and automation technologies including PowerShell, Python, REST APIs, Terraform, Bicep, YAML, JSON, or comparable tools.
  • Demonstrated success in modernizing Data Protection, DLP, CASB, or Information Protection programs through automation, standardization, and engineering-driven operating models.
  • Proven ability to implement and scale DevOps, DevSecOps, or Platform Engineering practices within security organizations.
  • Track record of leading large-scale security initiatives that improve control effectiveness, operational efficiency, and measurable risk reduction.
  • Background supporting enterprise-scale cloud, SaaS, or Microsoft 365 environments.
  • Knowledge of regulatory, privacy, and compliance requirements and their implementation through scalable technical controls.

#LI-JJ1

Skills Application Programming Interface (API), Cloud Security, Cybersecurity Strategies, Data Governance, Data Loss Prevention (DLP), Data Protection, Data Security, DevSecOps, Information Security Engineering, Information Technology Training, Infrastructure As Code (IaC), IT Automation, IT Security Architecture, IT Security Operations, Microsoft 365 Security & Compliance, Microsoft Defender for Cloud, Scripting, Secure Code, Security Engineering, Software as a Service (SaaS)

Compensation

Compensation offered for this role is $90,700 – 190,000 annually and is based on experience and qualifications.

The candidate(s) offered this position will be required to submit to a background investigation.

Joining our team isn’t just a job — it’s an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact.

Allstate generally does not sponsor individuals for employment-based visas for this position.

Effective July 1, 2014, under Indiana House Enrolled Act (HEA) 1242, it is against public policy of the State of Indiana and a discriminatory practice for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component.

Allstate provides a comprehensive technology setup, including a laptop, monitors, headset, keyboard, and mouse. Employees eligible to work from home also receive a monthly connectivity reimbursement to help offset internet costs.

When working from home, you must have a dedicated, private workspace free from distractions, along with appropriate desk and seating. Reliable internet is required, with minimum speeds of 50 MB download and 5 MB upload.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Data Security Engineer
Senior Data Security Engineer

Allstate Northern Ireland Limited • Northern (KY)

On-site
USD 91,000 - 190,000
Laptop provided
Monitors
Headset, keyboard & mouse
+2
Managing Engineer - Data Security Engineering
Managing Engineer - Data Security Engineering

Allstate Insurance • Illinois

On-site
USD 120,000 - 195,000
Security Engineering Senior Manager
Security Engineering Senior Manager

Allstate • United States

On-site
USD 152,000 - 210,000
Tech setup provided
Connectivity reimbursement
Managing Engineer - Data Security Engineering
Managing Engineer - Data Security Engineering

Allstate Insurance Company • Springfield (IL)

On-site
USD 120,000 - 195,000
DAE Consultant I
DAE Consultant I

Allstate Private Limited • New York (NY)

On-site
USD 75,000 - 126,000
DAE Consultant I
DAE Consultant I

Allstate Private Limited • United States

Remote
USD 75,000 - 126,000
Data Scientist Associate Manager - Remote
Data Scientist Associate Manager - Remote

Allstate Foundation • Illinois

Remote
USD 146,000 - 190,000
Laptop provided and peripherals
Monthly connectivity reimbursement
DAE Consultant I
DAE Consultant I

Allstate • United States

Remote
USD 75,000 - 126,000
Laptop provided
Monitors provided
Connectivity reimbursement
DAE Consultant I
DAE Consultant I

Allstate Foundation • New York (NY)

Remote
USD 75,000 - 126,000
Managing Engineer - Cloud Security Engineering
Managing Engineer - Cloud Security Engineering

Allstate Insurance • Illinois

On-site
USD 120,000 - 195,000