Allstate Logo

Allstate

Software Engineer - Product Security

Posted 6 Hours Ago
Remote
Hiring Remotely in US
91K-196K Annually
Mid level
Remote
Hiring Remotely in US
91K-196K Annually
Mid level
Design, build, deploy, and operate enterprise security controls as software products. Develop production code, APIs, backend services, and scalable cloud-based distributed systems while integrating security capabilities into development platforms. Apply test-driven development, continuous integration and deployment, and agile practices. Collaborate with product and engineering teams, evaluate emerging technologies, and improve security, reliability, adoption, and developer experience.
The summary above was generated by AI

At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection. 

Job Description

The Product Security Engineering organization is responsible for designing, building, and operating enterprise security controls as software products. The group applies modern software engineering practices to create scalable, reliable, and developer friendly security capabilities that are embedded directly into the enterprise technology ecosystem, enabling secure by default behaviors while minimizing friction for product and platform teams.
Product Security Engineers are software engineers who own the full software development lifecycle — from design and implementation through deployment and production support. They write and maintain production code, operate their services in real world environments, and are accountable for the reliability, adoption, and effectiveness of the security controls they deliver. Success in this role is measured through outcomes such as control adoption, system reliability, and meaningful reduction of security risk.

Key Responsibilities  
  • Design, build, and operate enterprise security controls as software products that integrate directly into the SDLC and core enterprise platforms 

  • Own security control capabilities end‑to‑end, including architecture, implementation, deployment, and ongoing operational support in production 

  • Write, test, and maintain high‑quality production code while meeting delivery and reliability expectations as a software engineer 

  • Apply engineering best practices such as test‑driven development, paired programming, and continuous integration and deployment 

  • Contribute to high‑level and low‑level system and component designs with a focus on scalability, reliability, and security outcomes 

  • Continuously evaluate and adopt new technologies, frameworks, and patterns to improve the effectiveness and usability of security controls 

  • Collaborate closely with product managers, platform teams, and partner engineering groups to align security control capabilities with enterprise needs 

  • Participate in agile delivery ceremonies and contribute to a culture of fast feedback, incremental delivery, and continuous improvement 


Essential Skills  
  • 3+ years of software engineering experience, with demonstrated ownership of production systems throughout the full software development lifecycle which must include proficiency in one or more modern programming languages (e.g., Java, JavaScript)

  • Hands-on experience designing, building, and operating scalable distributed systems and cloud‑based applications, including microservices architectures 

  • Demonstrated ability to design, develop, and integrate APIs and backend services, including REST‑based interfaces 

  • Familiarity with modern development workflows and engineering practices such as test-driven development, paired programming, and continuous integration and deployment 

  • Experience collaborating effectively within agile delivery models, working closely with product managers, engineers, and partner teams to deliver outcomes 

Desirable Skills
  • Working knowledge of application and API security concepts, including common vulnerability classes (e.g., OWASP Top 10) and attack techniques (e.g., MITRE ATT&CK) 

  • Experience implementing or integrating security mechanisms such as authentication, authorization, and identity-based access controls within applications and services 

  • Knowledgeable in secure software development practices and techniques, including behavior driven development or security focused testing patterns 

  • Practical exposure to containerized and cloud native environments, including Docker, Kubernetes, and public cloud platforms such as AWS and/or Azure 

  • Exposure to large language models (LLMs), machine learning concepts, or systems that incorporate AI driven capabilities 

  • Ability to leverage AI assisted development tools (e.g., Copilot, Cursor) responsibly to improve developer productivity and code quality 

  • Demonstrated commitment to building solutions that balance robust security guarantees with an excellent developer experience, without compromising one for the other 
     

Additional Criteria for Lead and Expert Levels
  • Minimum of 1 year demonstrated experience coaching or mentoring engineers, with evidence of improving individual or team technical capability over time 

  • Proven ability to lead technical design and architecture decisions for complex, distributed systems, resulting in measurable improvements to scalability, security, reliability, or performance 

  • Track record of driving cross team collaboration to deliver integrated solutions, achieving alignment across multiple product portfolios and stakeholder group 


Supervisory Responsibilities
  • This job does not have supervisory duties.

#LI-JJ1
 

Skills

API Development, Application Security, Artificial Intelligence (AI), Cloud Based Solutions, Collaboration, Distributed Systems, Java (Programming Language), JavaScript, Large Language Models (LLMs), Microservices Architecture, Product Security, Security Controls, Software Engineering, Test Driven Development (TDD)

Compensation

Compensation offered for this role ranges from $90,700 - 195,700 annually and is based on experience and qualifications.

The candidate(s) offered this position will be required to submit to a background investigation.


Joining our team isn’t just a job — it’s an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact.

Allstate generally does not sponsor individuals for employment-based visas for this position.

Effective July 1, 2014, under Indiana House Enrolled Act (HEA) 1242, it is against public policy of the State of Indiana and a discriminatory practice for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component.

For jobs in San Francisco, please click “here” for information regarding the San Francisco Fair Chance Ordinance.

For jobs in Los Angeles, please click “here” for information regarding the Los Angeles Fair Chance Initiative for Hiring Ordinance.

To view the “EEO Know Your Rights” poster click “here”. This poster provides information concerning the laws and procedures for filing complaints of violations of the laws with the Office of Federal Contract Compliance Programs.

To view the FMLA poster, click “here”. This poster summarizing the major provisions of the Family and Medical Leave Act (FMLA) and telling employees how to file a complaint.

It is the Company’s policy to employ the best qualified individuals available for all jobs. Therefore, any discriminatory action taken on account of an employee’s ancestry, age, color, disability, genetic information, gender, gender identity, gender expression, sexual and reproductive health decision, marital status, medical condition, military or veteran status, national origin, race (include traits historically associated with race, including, but not limited to, hair texture and protective hairstyles), religion (including religious dress), sex, or sexual orientation that adversely affects an employee's terms or conditions of employment is prohibited. This policy applies to all aspects of the employment relationship, including, but not limited to, hiring, training, salary administration, promotion, job assignment, benefits, discipline, and separation of employment.


Allstate provides a comprehensive technology setup, including a laptop, monitors, headset, keyboard, and mouse. Employees eligible to work from home also receive a monthly connectivity reimbursement to help offset internet costs.


When working from home, you must have a dedicated, private workspace free from distractions, along with appropriate desk and seating. Reliable internet is required, with minimum speeds of 50 MB download and 5 MB upload.

 

To help create a more personal and engaging experience, we ask that you join with your camera on if your interview is virtual. Please also have a Valid Photo Identification available at the start of your interview.  If you require any accommodations or have questions ahead of your interview please reach out to your recruiter.


Note: Internal candidates are only asked to join on video; a Valid Photo Identification is not needed for the interview.

Similar Jobs

7 Days Ago
Remote or Hybrid
USA
100K-145K Annually
Entry level
100K-145K Annually
Entry level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Secure CrowdStrike’s software supply chain and code-hosting environments by assessing GitHub organizations, open-source integrations, repositories, dependencies, and third-party packages. Implement repository guardrails, secret scanning, access controls, and automation; investigate supply-chain threats such as typosquatting and dependency confusion; promote secure coding and open-source compliance; and collaborate with engineering teams on security initiatives.
Top Skills: Amazon S3Argo CdArtifactoryBitbucketCi/CdDatadogGitGithub ActionsGitlabGoJavaScriptJenkinsLinuxLogscalePrometheusPythonSecret ScanningShellSoftware Composition Analysis (Sca)SplunkUnix
13 Days Ago
Remote or Hybrid
27 Locations
120K-180K Annually
Entry level
120K-180K Annually
Entry level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Build and operate scalable security tooling, applications, APIs, and automation for CrowdStrike’s global multi-cloud Product Security environment. Responsibilities include software supply chain security, AI-powered vulnerability discovery, platform visibility, risk assessments, CI/CD, SRE operations, datastore management, monitoring, and incident response support. The role partners across Product Security to define tooling strategy and maintain mission-critical security services.
Top Skills: Amazon SqsAngularAnsibleAWSChefCi/CdContainersGCPGenerative AiGoKafkaLarge Language ModelsLinuxOpensearchPostgresPuppetPythonReactSaltSoftware Cryptographic SigningTypescriptValkey
One Month Ago
In-Office or Remote
150K-350K Annually
Senior level
150K-350K Annually
Senior level
Artificial Intelligence • Information Technology • Software
Design and implement product-level authentication, authorization, multi-tenant isolation, and privacy-preserving data lifecycles. Ship security-sensitive changes end-to-end, own application and API security, threat modeling, telemetry for security events, and integrate conservative partner security controls.
Top Skills: GoHonoNext.JsPostgresPythonReactSpaceliftTerraformTypescriptVitest

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account