yoinka

Threat Detection & Response Engineer -- Senior Expert

Allstate

RemoteUS - RemoteSenior
Sign in to applyVerified 1h ago
Location
US - Remote
Work model
Remote
Level
Senior
Posted
Aug 28, 2026

Skills

CI/CDCybersecurityMachine Learning

About this role

At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection.

Job Description

The Threat Detection & Response Engineer -- Senior Expert defines and builds the technical foundation of that rebuild. This is a hands-on, build-heavy role for an engineer who treats detections as software that is version-controlled, peer-reviewed, tested, and shipped through a pipeline, and above all one who can design and build the AI/ML pipelines that let a global team investigate and respond at machine speed. The role leads the technical projects that stand up this capability and owns accountability for their delivery, sets the technical bar for how detection content is written, validated, and deployed, and builds the tooling and intelligence pipelines that make high-quality detection engineering repeatable rather than heroic. This is an individual-contributor role that carries technical leadership and delivery ownership. Why This Role Exists To stand up a detection-as-code workflow with version control, peer review, staged deployment, and measurable coverage, designed and owned by a principal engineer rather than inherited. To design and build the AI/ML pipelines that accelerate investigation, triage, and detection generation, the capability area we are most focused on developing. To prioritize automation and AI-assisted triage for high-volume, low-judgment work such as phishing and DLP, so human attention goes to the investigations that need judgment. To close the loop between threat intelligence, threat hunting, and detection engineering so that intel and hunt findings reliably become durable detections. What You’ll Contribute AI/ML Pipelines for Detection & Response Define, design, and build the AI/ML pipelines at the center of our next-generation D&R capability, applying industry-leading models to investigation, triage, enrichment, and detection generation where they genuinely add leverage. Own the technical delivery of AI-assisted investigation and triage, spanning data foundations and feature/enrichment pipelines through model selection, evaluation, and safe production deployment. Set the standard for how AI/ML outputs are validated, explained, and trusted within detection and response workflows, and lead the projects that move promising pilots into durable, measurable production capability. Detection-as-Code & Engineering Standards Design and own the detection-as-code pipeline, including repository structure, detection schema, peer-review model, automated testing, and staged (CI/CD) deployment across our SIEM, XDR, and endpoint detection surfaces. Define the technical standards, reusable patterns, and quality bar for detection content, and build the guardrails that keep quality consistent as the team scales across the US, Ireland, and India. Build tooling and APIs that let engineers author, test, and debug detections quickly, turning detection engineering into a repeatable software practice rather than console-by-console work. Automation & Response Engineering Design automation and SOAR-style workflows, increasingly AI-driven, that collapse high-volume alert categories such as automated phishing campaign clustering and detonation, DLP risk-based routing, enrichment, and auto-closure of verified-benign reports. Build the response automation, including playbooks, containment actions, and integrations, that shrinks dwell time and mean-time-to-respond. Coverage, Validation & the Intelligence Loop Establish and maintain a MITRE ATT&CK coverage baseline; use it to identify real gaps and redundant coverage and to prioritize engineering effort. Partner with Threat Intelligence

Listing verified 1h ago. Applications go through the company's official careers site.

← Back to Yoinka

Threat Detection & Response Engineer -- Senior Expert at Allstate, US - Remote | Yoinka