Senior Incident Handler
Allstate - United States
Hiring: Senior Incident Handler Company: Allstate Location: United States Job Posted Time: 2026-09-17 09:38:12 Employment Type: Contract Target Skills & Keywords : LLM, Penetration Testing, PowerShell, Python, SIEM, SOC About the job Experience: •90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection. •5+ years in cybersecurity operations or incident response, with a track record of leading complex, enterprise-scale incidents end-to-end. Financial services or insurance experience is a plus—but great responders come from everywhere. Required Skills: •We're rebuilding incident response from the ground up—and we want a proven responder to help lead the way. •If you've handled the incidents that make headlines (or quietly prevented them from becoming headlines), bring the instincts of a seasoned incident commander, and can move seamlessly from the server room to the boardroom, this is where your experience turns into real influence. •Incident Handling & Response Leadership: Serve as the lead responder during critical incidents—owning the full lifecycle from detection through containment, eradication, and recovery. You'll help run the war room, coordinate responders, and make confident calls with incomplete information. •Cross-Functional Coordination: Unify analysts, infrastructure, application owners, legal, comms, and third-party partners into a single, fast-moving response. Relentless focus on reducing dwell time and mean-time-to-respond. •Executive Communication: Be a trusted voice during high-severity events—translating fast-moving technical realities into clear business impact for stakeholders up to the C-suite. You build calm and confidence when it matters most. •Deep Threat Investigation: Lead advanced investigations into malware, identity compromise, ransomware, and targeted attacks. Analyze logs, network, and forensic data to expose attacker tradecraft (lateral movement, persistence, exfiltration) and hunt down what others miss—leveraging EDR/XDR, SIEM, and cloud telemetry. •AI & Automation Leadership: Help modernize our SOC by putting cutting-edge automation and AI-assisted tooling to work—accelerating triage and enrichment without sacrificing human judgment. •Team Uplevel & Continuous Improvement: Raise the standard of how the team responds—sharpening detections, playbooks, and controls through meaningful after-action reviews, and helping shape the practices that will underpin our future incident command function. Qualifications: •Battle-tested IR experience: 5+ years in cybersecurity operations or incident response, with a track record of leading complex, enterprise-scale incidents end-to-end. Financial services or insurance experience is a plus—but great responders come from everywhere. •Command-level instincts: Demonstrated ability to act as an incident commander or technical lead in high-stakes moments—running major bridge calls and making decisive calls fast. You bring the judgment that helps a team operate like a mature command function. •Technical depth: Strong command of network security, EDR/XDR, log and forensic analysis, and threat hunting across on-prem and cloud. Comfortable with SIEM, forensics tooling, and scripting/automation (Python, PowerShell). •Communication range: Exceptional written and verbal skills; equally credible with engineers and executives. •Automation mindset: Enthusiasm for SOAR, ML-based tooling, and LLMs to elevate response workflows. •Credentials: CISSP, GCIA, GCIH, GCFA, OSCP or other certifications preferred. Compensation: •Flexible work environment (work from home / hybrid options) Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!