Threat Detection & Response Engineer -- Senior Expert
$151.7k - $222.4kAllstate Insurance Company
At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection. Job Description The Threat Detection & Response Engineer -- Senior Expert defines and builds the technical foundation of that rebuild. This is a hands‑on, build‑heavy role for an engineer who treats detections as software that is version‑controlled, peer‑reviewed, tested, and shipped through a pipeline, and above all one who can design and build the AI/ML pipelines that let a global team investigate and respond at machine speed. The role leads the technical projects that stand up this capability and owns accountability for their delivery, sets the technical bar for how detection content is written, validated, and deployed, and builds the tooling and intelligence pipelines that make high‑quality detection engineering repeatable rather than heroic. This is an individual‑contributor role that carries technical leadership and delivery ownership. Why This Role Exists To stand up a detection‑as‑code workflow with version control, peer review, staged deployment, and measurable coverage, designed and owned by a principal engineer rather than inherited. To design and build the AI/ML pipelines that accelerate investigation, triage, and detection generation, the capability area we are most focused on developing. To prioritize automation and AI‑assisted triage for high‑volume, low‑judgment work such as phishing and DLP, so human attention goes to the investigations that need judgment. To close the loop between threat intelligence, threat hunting, and detection engineering so that intel and hunt findings reliably become durable detections. What You’ll Contribute AI/ML Pipelines for Detection & Response Define, design, and build the AI/ML pipelines at the center of our next‑generation D&R capability, applying industry‑leading models to investigation, triage, enrichment, and detection generation where they genuinely add leverage. Own the technical delivery of AI‑assisted investigation and triage, spanning data foundations and feature/enrichment pipelines through model selection, evaluation, and safe production deployment. Set the standard for how AI/ML outputs are validated, explained, and trusted within detection and response workflows, and lead the projects that move promising pilots into durable, measurable production capability. Detection-as-Code & Engineering Standards Design and own the detection‑as‑code pipeline, including repository structure, detection schema, peer‑review model, automated testing, and staged (CI/CD) deployment across our SIEM, XDR, and endpoint detection surfaces. Define the technical standards, reusable patterns, and quality bar for detection content, and build the guardrails that keep quality consistent as the team scales across the US, Ireland, and India. Build tooling and APIs that let engineers author, test, and debug detections quickly, turning detection engineering into a repeatable software practice rather than console‑by‑console work. Automation & Response Engineering Design automation and SOAR‑style workflows, increasingly AI‑driven, that collapse high‑volume alert categories such as automated phishing campaign clustering and detonation, DLP risk‑based routing, enrichment, and auto‑closure of verified‑benign reports. Build the response automation, including playbooks, containment actions, and integrations, that shrinks dwell time and mean‑time‑to‑respond. Coverage, Validation & the Intelligence Loop Establish and maintain a MITRE ATT&CK coverage baseline; use it to identify real gaps and redundant coverage and to prioritize engineering effort. Partner with Threat Intelligence and Threat Hunting to convert PIR‑driven hunt findings and intel into durable, tested detections through a formal feedback loop. Stand up continuous validation, such as breach‑and‑attack simulation and a purple‑team cadence, so coverage claims are proven against real adversary techniques rather than asserted on paper. Technical Project Leadership Lead the technical projects that build out this capability end‑to‑end and own accountability for their delivery by scoping the work, driving execution, and being answerable for completion and outcomes. Serve as the senior‑most individual‑contributor technical authority for detection engineering, acting as the final technical escalation point before management, setting direction and raising the capability of D&R engineers across regions. Influence roadmap and tooling decisions with internal platform partners, and help shape the operating model as the function grows across a global follow‑the‑sun, detection‑as‑code model. What You Bring AI/ML builder. You can design and build AI/ML pipelines that create real leverage by selecting and applying industry‑leading models to security data, engineering the data and enrichment foundations they depend on, and putting them into production with clear evaluation and guardrails. You have a grounded point of view on where AI genuinely accelerates detection and response versus where it adds risk. Builder‑first. Detection and response as software: you write, version, test, and ship detections like code, and you have built the tooling, APIs, or pipelines that let others do the same. Detection depth. Deep, hands‑on detection engineering experience across SIEM and EDR/XDR platforms, authoring high‑fidelity analytics, tuning for signal, and reasoning about telemetry and data sources. Fluency in KQL / SQL / Sigma or equivalent, and strong scripting/development skills (e.g., Python, Go). Threat‑informed. You map detections to adversary behavior (ATT&CK), partner naturally with hunting and intel, and think in terms of coverage, exploitability, and containment rather than rule counts. Delivery ownership. You lead technical projects to completion and own the outcome, setting standards, resolving hard engineering problems, and lifting the quality of everyone around you, comfortable being the deepest technical voice in the room. Communication. You can explain a detection strategy, an AI/ML design choice, or an engineering trade‑off clearly to both engineers and senior leaders. Nice to Have Hands‑on experience building or operating within an AI‑assisted / agentic SOC model. Security data engineering / streaming pipeline experience (telemetry normalization, parsing, ETL) that feeds ML workflows. Experience across enterprise SIEM, XDR, and EDR platforms. Purple‑team, adversary‑emulation, or breach‑and‑attack‑simulation partnership experience. Financial services, insurance, or other regulated, high‑scale environment exposure. Skills API Development, Decision Making, Endpoint Detection and Response (EDR), Machine Learning (ML), MITRE ATT&CK Framework, Scalable AI Pipelines, Security Automation, Security Information and Event Management (SIEM), Security Orchestration, Automation, and Response (SOAR), Stakeholder Influence, Technical Project Leadership, Threat Detection Compensation Compensation offered for this role is $151,700 – 222,400 annually and is based on experience and qualifications. The candidate(s) offered this position will be required to submit to a background investigation. Joining our team isn’t just a job — it’s an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact. Allstate generally does not sponsor individuals for employment‑based visas for this position. Effective July 1, 2014, under Indiana House Enrolled Act (HEA) 1242, it is against public policy of the State of Indiana and a discriminatory practice for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component. For jobs in San Francisco, please click “here” for information regarding the San Francisco Fair Chance Ordinance. For jobs in Los Angeles, please click “here” for information regarding the Los Angeles Fair Chance Initiative for Hiring Ordinance. To view the “EEO Know Your Rights” poster click “here”. This poster provides information concerning the laws and procedures for filing complaints of violations of the laws with the Office of Federal Contract Compliance Programs. To view the FMLA poster, click “here”. This poster summarizing the major provisions of the Family and Medical Leave Act (FMLA) and telling employees how to file a complaint. It is the Company’s policy to employ the best qualified individuals available for all jobs. Therefore, any discriminatory action taken on account of an employee’s ancestry, age, color, disability, genetic information, gender, gender identity, gender expression, sexual and reproductive health decision, marital status, medical condition, military or veteran status, national origin, race (include traits historically associated with race, including, but not limited to, hair texture and protective hairstyles), religion (including religious dress), sex, or sexual orientation that adversely affects an employee’s terms or conditions of employment is prohibited. This policy applies to all aspects of the employment relationship, including, but not limited to, hiring, training, salary administration, promotion, job assignment, benefits, discipline, and separation of employment. Allstate provides a comprehensive technology setup, including a laptop, monitors, headset, keyboard, and mouse. Employees eligible to work from home also receive a monthly connectivity reimbursement to help offset internet costs. When working from home, you must have a dedicated, private workspace free from distractions, along with appropriate desk and seating. Reliable internet is required, with minimum speeds of 50 MB download and 5 MB upload. To help create a more personal and engaging experience, we ask that you join with your camera on if your interview is virtual. Please also have a Valid Photo Identification available at the start of your interview. If you require any accommodations or have questions ahead of your interview please reach out to your recruiter. Note: Internal candidates are only asked to join on video; a Valid Photo Identification is not needed for the interview. #J-18808-Ljbffr Allstate Insurance Company
- Peraton Labs is hiring a Senior Incident Response Analyst to lead hands-on incident response for the Covered California and CalHEERS environments, own detection engineering and threat hunting, and serve as backup incident manager in coordination with the client's Information...Senior
- Strava is seeking a Senior Manager, Detection & Response to own and scale security monitoring, incident response, recovery, and threat hunting across both our product surface and corporate... ..., and build a hands-on team of engineers in a fast-growing security program....Senior
- Pffcu in Bensalem, PA is seeking a Senior IT Security Analyst to oversee detection, investigation, and mitigation of advanced cybersecurity threats. The role involves high-level incident response, threat hunting, and continuous improvement of monitoring tools to protect...Senior
- Alteryx is seeking a Senior Security Operations Analyst in the United... ...will triage alerts, lead incident response, and improve detection across endpoints, identity,... ...The role emphasizes forensics, threat hunting, and detection engineering, with on-call responsibilities...Senior
- SecureTech is seeking a Malware Engineer to analyze and report on malicious code, develop detection strategies, and support CMSP objectives. You will perform dynamic and static analysis, explore data artifacts, and craft actionable mitigation steps. Ideal candidates have...Suggested
- ...million athletes worldwide. As threats against consumer platforms... ..., this team is responsible for detecting, investigating, and responding... ...confidently. We're looking for a Senior Manager, Detection &... ...and manage a small team of engineers, decide how to extend that...SeniorWork at officeWorldwideFlexible hours3 days per week
- Fullsteam is seeking a security incident response specialist to lead investigations, coordinate with cross-functional teams, and drive... ...organization. You will participate in 24x7 on-call rotations, perform threat hunting, tune alerts, and contribute to playbooks with a focus...Senior
- ...Senior Engineer Jersey City, New Jersey;Charlotte, North Carolina; Pennington, New Jersey... ...connection. We do this by driving Responsible Growth and delivering for our clients... ...a critical component of our SOC and threat-detection capabilities. The ideal candidate has...SeniorWork at officeShift workDay shift
- Welltower is actively seeking a Lead Contact Center Engineer to drive the design, configuration, and optimization of our contact center and support channels. You will lead voice routing, IVR flows, virtual agent experiences, and service desk integrations, partnering with...Senior
- Britive is seeking a Senior Customer Success Engineer to own the technical relationship with enterprise accounts from kickoff to maturity. You will lead deployment, drive adoption, and ensure measurable value while coordinating with Customer Success Managers on commercial...SeniorRemote job
- Allen Integrated Solutions, LLC seeks a Space Systems Engineer to provide advanced engineering across the system lifecycle for GEOINT-capable space programs within CAPs and SAPs. The role involves requirements engineering, integration, and sustainment of space-based capabilities...Senior
$134.5k - $265.1k
...navigate the ever-changing threat landscape. We simplify... ...Forward Deployed Engineer (FDE) Sr Consultant, you... ...-4o, Assistants API, Responses API, OpenAI Agents... ...experience working with senior client stakeholders to... ...cloud security, identity, detection engineering)....SeniorLocal areaVisa sponsorship- Sehlhorst Equipment Services seeks an experienced Layout Engineer to provide precise field layout, staking, GPS control, surface modeling and as-built documentation for civil construction projects. You will support underground utilities, grading, demolition and site work...SeniorFull time
- ...is seeking a Cybersecurity Operations Center Analyst, Senior to lead a SOC team and drive real-time threat analysis for critical infrastructure. You will oversee incident response, triage severity, develop detection rules, refine SOPs, and coordinate with senior leadership...Senior
- ...Job Title: Senior Engineer, Quantum Photonics Location: Hoboken, NJ Division: Technology... ...lab into scalable production. Key Responsibilities • Design nonlinear and quantum... ...measurements, including single-photon detection (e.g., SNSPD), coincidence and CAR measurements...Senior
$105.4k - $207.8k
...Recruiting for this role ends on 12/31/2026.Work you'll doAs a Senior Engineering Management Specialist on the Cyber Defense & Resilience Continuous Threat Exposure Management (CTEM) team, you will be responsible for…Leading day-to-day forward deployed engineering...SeniorLocal area$200k - $240k
...Sr. Strategic Customer Success Engineer - Central US Remote- Central US Modern software... ...while approaching difficulties head-on. Responsibilities & Key Skills: Lead consulting... ...Working knowledge and understanding of threat modeling and how it applies to modern software...SeniorRemote work$135.8k - $203.6k
...anticipates a near-term need for a Senior Principal Systems Engineer to work as a deputy technical lead... ...program execution. Roles and Responsibilities: In coordination with the algorithm... ...the understanding of Physics-based detection methods for various phenomenologies...SeniorRelocation packageShift work$110k - $140k
...— this one's built for you. As the Senior Systems Engineer at Level99, you'll be the technical... ...running seamlessly across the country. RESPONSIBILITIES Network Administration: Design,... ...network from unauthorized access and threats. Hardware & Server Management: Manage...SeniorLocal areaFlexible hours- ...cybersecurity, combining technology, threat intelligence, and expert services. The people here chose... ...an experienced and dynamic Senior Systems Engineer to join our Network Collections... ...application for OT environments. Responsibilities Design and implement lightweight...SeniorLocal areaImmediate startRemote work
- ...Cape Fox Corporation seeks a skilled Subject Matter Expert III (FMS) to support Foreign Military Sales case development and pre-... ...and ensure alignment with USAF Security Assistance programs. Responsibilities include LOR/LOA processes, P&A data preparation, and coordination...Senior
- ...an Attack Surface Validation & Exposure Engineer to join the Vulnerability Management and... ...automated attack-path discovery, build scalable detection pipelines, and develop exploitation... .... You’ll collaborate with Red Team and Threat Intelligence, report findings with...Senior
$190k - $270k
...with resolve. As cyber threats grow faster and... ...Corelight helps teams to detect advanced threats and close... ...and driven Pre-Sales Engineer to join our SLED Team... ...Depending on the nature and seniority of the role, a... ...network detection and response platforms in the industry...SeniorLocal area$105.4k - $207.8k
...clients navigate the ever-changing threat landscape. Through powerful... ...Consulting, you will be responsible for delivering high-quality work... ...technical ownership with engineering expertise and governance.Work... ...From entry-level employees to senior leaders, we believe there’s always...SeniorLocal areaVisa sponsorship$135k - $216k
Responsibilities Peraton Labs is searching for a part time, on-call Senior Systems Engineer. This position presents an opportunity for candidates... ...(e.g., 3GPP, ATIS, IEEE). Expert knowledge in IMS Core Network... ...traditional and nontraditional threats across all domains: land,...SeniorContract workPart timeShift work- ...VA Information Technology Job Title Senior Systems Engineer Location Winchester, VA - REMOTE (4... ...Systems Engineer with following job responsibilities : Supervise, coordinate and/or... ...response time and primary support for detection and correction of operational problems...SeniorRemote jobFull timeImmediate start
$176k - $282k
Responsibilities We are seeking a candidate with a strong background in Network Engineering and Systems Engineering, supporting activities involving the latest technologies in... ...nexus between traditional and nontraditional threats across all domains: land, sea, space, air,...SeniorContract workShift work$104k - $166k
...Responsibilities **Position Is Contingent Upon Award** Peraton Labs is hiring a Senior Incident Response Analyst to lead hands‑on incident response for the Covered... ...and CalHEERS environments, own detection engineering and threat hunting, and serve as backup incident...SeniorContract workShift work- ..., mentor technical teams, partner with senior leadership, and define the future direction... ...employees. As the Senior Principal Expert, Manufacturing Science & Technology,... ...Leader or Project Contributor. Duties & Responsibilities Be the "go to" technical expert for Global...SeniorLocal area
- ...Ridge Automation is seeking to fill a full-time Senior Systems Engineer position. This position will be responsible for designing and implementing solutions for customers... ...that involve reviewing information, actively detecting problems, developing, and evaluating options,...SeniorFull time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Threat Detection & Response Engineer -- Senior Expert. Be the first to apply!
- subject matter expert Brooklyn, NY
- fulfillment expert Brooklyn, NY
- guest service support expert Brooklyn, NY
- sql expert Brooklyn, NY
- technology expert Brooklyn, NY
- senior network engineer remote Brooklyn, NY
- senior app developer Brooklyn, NY
- senior manager legal Brooklyn, NY
- senior retail sales associate Brooklyn, NY
- sr project manager Brooklyn, NY

