Senior Incident Handler
Allstate
At Allstate, great things happen when our people work together to protect families and their belongings from life's uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers' evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection. Job Description We're rebuilding incident response from the ground up-and we want a proven responder to help lead the way. This is a chance to bring your hard-won expertise into a next-generation Security Operations program at Fortune 100 scale, where rapid response, automation, and AI-driven investigation are core to how we operate. As our Senior Incident Handler, you'll be the technical anchor for our most significant security events-driving the response, raising the bar on how we work, and helping mature the team toward a formal, scalable incident command model we're building for the future. If you've handled the incidents that make headlines (or quietly prevented them from becoming headlines), bring the instincts of a seasoned incident commander, and can move seamlessly from the server room to the boardroom, this is where your experience turns into real influence. What You''ll Own Incident Handling & Response Leadership: Serve as the lead responder during critical incidents-owning the full lifecycle from detection through containment, eradication, and recovery. You'll help run the war room, coordinate responders, and make confident calls with incomplete information. Cross-Functional Coordination: Unify analysts, infrastructure, application owners, legal, comms, and third-party partners into a single, fast-moving response. Relentless focus on reducing dwell time and mean-time-to-respond. Executive Communication: Be a trusted voice during high-severity events-translating fast-moving technical realities into clear business impact for stakeholders up to the C-suite. You build calm and confidence when it matters most. Deep Threat Investigation: Lead advanced investigations into malware, identity compromise, ransomware, and targeted attacks. Analyze logs, network, and forensic data to expose attacker tradecraft (lateral movement, persistence, exfiltration) and hunt down what others miss-leveraging EDR/XDR, SIEM, and cloud telemetry. AI & Automation Leadership: Help modernize our SOC by putting cutting-edge automation and AI-assisted tooling to work-accelerating triage and enrichment without sacrificing human judgment. Team Uplevel & Continuous Improvement: Raise the standard of how the team responds-sharpening detections, playbooks, and controls through meaningful after-action reviews, and helping shape the practices that will underpin our future incident command function. What You Bring Battle-tested IR experience: 5+ years in cybersecurity operations or incident response, with a track record of leading complex, enterprise-scale incidents end-to-end. Financial services or insurance experience is a plus-but great responders come from everywhere. Command-level instincts: Demonstrated ability to act as an incident commander or technical lead in high-stakes moments-running major bridge calls and making decisive calls fast. You bring the judgment that helps a team operate like a mature command function. Technical depth: Strong command of network security, EDR/XDR, log and forensic analysis, and threat hunting across on-prem and cloud. Comfortable with SIEM, forensics tooling, and scripting/automation (Python, PowerShell). Communication range: Exceptional written and verbal skills; equally credible with engineers and executives. Automation mindset: Enthusiasm for SOAR, ML-based tooling, and LLMs to elevate response workflows. Credentials: CISSP, GCIA, GCIH, GCFA, OSCP or other certifications preferred. Why This Role You'll join at a pivotal moment-bringing your expertise to a team that's actively maturing, with the opportunity to help shape the incident command function we're building next. This is a role for someone who wants their fingerprints on how a Fortune 100 responds to the threats ahead. If you're ready to lead through crisis, outthink sophisticated adversaries, and elevate a team around you-let's talk.
#LI-JJ1
Skills Cross-Functional Collaboration, Cyber Incident Response, Cyber Investigations, Cybersecurity Operations, Cyber Threat Hunting, Decision Making, Endpoint Detection and Response (EDR), Executive Communications, Forensic Analysis, Incident Handling, IT Automation, IT Security Architecture, Malware Analysis, Network Security, Penetration Testing, Scripting, Security Incident Response, Technical Leadership, Technical Mentoring, Technology Leadership Compensation Compensation offered for this role is 120,000.00 - 193,725.00 annually and is based on experience and qualifications. The candidate(s) offered this position will be required to submit to a background investigation. Joining our team isn't just a job - it's an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger - a winning team making a meaningful impact. Allstate generally does not sponsor individuals for employment-based visas for this position. Effective July 1, 2014, under Indiana House Enrolled Act (HEA) 1242, it is against public policy of the State of Indiana and a discriminatory practice for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component. For jobs in San Francisco, please click "here" for information regarding the San Francisco Fair Chance Ordinance. For jobs in Los Angeles, please click "here" for information regarding the Los Angeles Fair Chance Initiative for Hiring Ordinance. To view the "EEO Know Your Rights" poster click "here". This poster provides information concerning the laws and procedures for filing complaints of violations of the laws with the Office of Federal Contract Compliance Programs. To view the FMLA poster, click "here". This poster summarizing the major provisions of the Family and Medical Leave Act (FMLA) and telling employees how to file a complaint. It is the Company's policy to employ the best qualified individuals available for all jobs. Therefore, any discriminatory action taken on account of an employee's ancestry, age, color, disability, genetic information, gender, gender identity, gender expression, sexual and reproductive health decision, marital status, medical condition, military or veteran status, national origin, race (include traits historically associated with race, including, but not limited to, hair texture and protective hairstyles), religion (including religious dress), sex, or sexual orientation that adversely affects an employee's terms or conditions of employment is prohibited. This policy applies to all aspects of the employment relationship, including, but not limited to, hiring, training, salary administration, promotion, job assignment, benefits, discipline, and separation of employment. Allstate provides a comprehensive technology setup, including a laptop, monitors, headset, keyboard, and mouse. Employees eligible to work from home also receive a monthly connectivity reimbursement to help offset internet costs. When working from home, you must have a dedicated, private workspace free from distractions, along with appropriate desk and seating. Reliable internet is required, with minimum speeds of 50 MB download and 5 MB upload. Allstate Insurance Company- Anthropic is seeking a senior Technical Program Manager to own and evolve the D&R incident management lifecycle, from detection to post-incident review. You will drive cross-functional improvements, act as incident commander for security events, and lead rotations and KPI...Senior
- ...'s, Incorporated, seeks an experienced Security Operations Center (SOC) Manager to lead monitoring, detection, investigation, and incident response across the organization's locations. You will oversee day-to-day SOC operations, manage a team of specialists, develop and...Senior
- Zelis Healthcare Inc. is seeking a Senior Security Operations Center (SOC) Analyst to lead investigations and mitigate security incidents. This role involves triaging alerts, performing digital forensics, and guiding team members through complex security challenges. The...Senior
- BlueVoyant is seeking a Senior Director, Digital Forensics & Incident Response to spearhead cyber investigations in a client-facing leadership role. This position requires managing complex security incidents while advising executives and legal teams. The ideal candidate...SeniorRemote job
- Managing Security Information and Event Management (SIEM) systems, the full-time Senior Cybersecurity Incident Response Administrator will deploy, install, and monitor infrastructure while creating dashboards for real-time detection of security anomalies, with the flexibility...SeniorFull timeRemote work
$87.32k
...designation reflects the company’s commitment to hiring and supporting active-duty and veteran employees. Responsibilities The Senior Cybersecurity Incident Response Administrator manages Security Information and Event Management (SIEM) systems, including deployment,...SeniorFor contractorsLocal areaRemote work$190k - $240k
Senior Staff Security Engineer, Incident Response Houston; New York; San Francisco; Seattle About Nscale Nscale is the GPU cloud engineered for AI. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers. Nscale enables...SeniorPermanent employmentFlexible hours- SCAYLE is seeking an experienced enterprise support engineer to investigate complex B2B SaaS issues, using Datadog and logs to diagnose distributed systems. You will read code, query SQL, and manage tickets through a full lifecycle while communicating clearly with major...Senior
- .... About the Role We're looking for a AI/ML Engineer (Senior/Staff/Principal) - Threat Detection who will design, build, and... ...containment and response for high-confidence security incidents. • Design and implement detection algorithms spanning authentication...SeniorFull timeFor contractorsWorldwide
$18.1 - $28 per hour
Job Details The Senior Warehouse Operator is responsible for executing material handling operations, ensuring the efficient movement... ...procedures, as well as the ability to mentor and assist Material Handlers in daily tasks. The Senior Warehouse Operator must efficiently...SeniorHourly payPermanent employmentContract workTemporary workMonday to FridayFlexible hours$157k - $210k
...strategic decision-making, with a strong emphasis on building trusted relationships across the organization. As Senior Counsel, Cybersecurity & Incident Response, you will serve as a key legal partner to Security and other cross-functional teams on cybersecurity...SeniorPermanent employmentFull timeTemporary workCasual workWork at officeFlexible hours- ...com. About the Role We're looking for a AI/ML Engineer (Senior/Staff/Principal) - Agentic AI Security who will design, build,... ...containment and response for high-confidence security incidents. • Train, evaluate, and deploy ML models on real-world...SeniorFor contractorsWorldwide
- ...About the Role We’re looking for an Observability Engineer (Senior/Staff/Principal level) who has shipped distributed tracing... ...Structured, semantically rich telemetry that future LLM-based incident analysis agents can reason over. The schema you design today is...SeniorFor contractorsWorldwide
- Senior Medical Writer/Principal Medical Writer Remote, United Kingdom Position Summary: The Senior Medical Writer/Principal Medical Writer... ...targeted by a recruitment scam, we encourage you to report the incident to your local law enforcement authorities, consumer protection...SeniorLocal areaRemote work
$165k - $185k
Cyber Hunt Senior Analyst Everforth ECS is seeking a Cyber Hunt Senior Analyst who lives in close proximity to the National Capital... ...Systems Security Professional (CISSP) GIAC Certified Incident Handler (GCIH) GIAC Certified Forensic Analyst (GCFA) Certified Ethical...SeniorLocal areaRemote work- Oracle is seeking a Data Platform Cloud Architect to join the North America Cloud Engineering team supporting the Healthcare industry. You will partner with customers, sales, engineering and product teams to design, demonstrate, and deploy Oracle Cloud architectures that...Senior
- A leading communication platform is seeking a Senior Principal Technical Program Manager to lead a portfolio of strategic programs. You will be responsible for orchestrating complex technical strategies, influencing high-level architectural decisions, and mentoring team...Senior
- HopHR is looking for a Senior Technical Recruiter to join their remote team. This role offers a unique opportunity to blend traditional recruiting with innovative AI tools. You will be responsible for conducting full-cycle searches and building relationships with candidates...SeniorRemote work
- ...Socure is seeking a Senior SDET to advance our quality engineering for distributed systems, DR, and production readiness. You will design... ...pipelines, and develop AI-driven failure analysis to reduce incident response time and improve observability. You will...Senior
- Jobtailor seeks an experienced leader in clinical risk management and pharmacovigilance to drive safety surveillance for investigational and marketed products. You will chair safety teams, develop risk management and pharmacovigilance plans, and collaborate with cross-functional...Senior
$138k - $200k
Collaborate with internal and customer teams to investigate and contain incidents.Recognize and codify attacker Tools, Tactics, and Procedures (TTPs) and Indicators of Compromise (IOCs) that can be applied to current and future investigations.Conduct host forensics, network...Senior- Via Transportation, Inc. in New York City is seeking a Principal Product Designer to shape the Transit Operations platform. You will lead design for complex workflows used by dispatchers and transit operators, turning business needs into clear, scalable experiences. You...Senior
- ...posture across our platform, infrastructure, and corporate environment. You will shape access control, vulnerability management, and incident response from the ground up, partnering with Engineering and Infrastructure to build scalable security systems protecting customer...Senior
$197.6k - $261.3k
Gen is seeking a Senior Principal Product Manager to steer ecosystem strategy across various platforms and partnerships. This role involves owning strategic direction, identifying key distribution opportunities, and representing the company in industry forums. Candidates...Senior- ...Santander Holdings USA Inc. is seeking a senior Murex MX.3 Application Developer in New York to lead strategic MX.3 initiatives across... ...production releases, and regulatory initiatives, with oversight of performance, resiliency, and incident resolution. #J-18808-Ljbffr...Senior
- Publicis Sapient is seeking a Senior Principal to help grow the Management Consulting and Strategy practice. You will lead goal-oriented Digital Business Transformations and deliver strategic guidance in the early stages of client initiatives. You will collaborate with...Senior
- Twilio is seeking a Senior Principal, Product Management to lead the Developer Platform's strategic vision, managing foundational services, APIs and infrastructure. You will drive the roadmap that enables internal teams and partners to scale confidently. You will treat...SeniorRemote job
$154k - $205k
Datadog Incident Response is an end-to-end incident operations solution native to Datadog’s unified observability and security platform... ...between disconnected monitoring, paging, and incident tools.As a Senior Product Marketing Manager (PMM) - Incident Response, you will...SeniorWork at office- ...Responsibilities In this role, you’ll lead high-impact incident response work in a complex cloud environment and help shape how... ..., Product Security, Legal, Crisis Communications, Support, and senior leadership to drive investigation, containment, recovery, and follow...SeniorWork at officeLocal area
- Inovalon is seeking a Senior Principal Product Manager to shape product strategy and roadmaps for critical healthcare solutions. You’ll work with Client Management, Product, Architecture, and design teams to align requirements with market needs and client goals. This role...SeniorRemote job
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Incident Handler. Be the first to apply!
- senior technical service engineer New York, NY
- senior technical consultant New York, NY
- senior director product management New York, NY
- senior vice president human resources New York, NY
- senior automation controls engineer New York, NY
- senior grant accountant New York, NY
- senior technical recruiter New York, NY
- senior compliance officer New York, NY
- senior tax New York, NY
- sr data modeler New York, NY



