Senior Incident Handler
Listed on 2026-07-18
-
IT/Tech
Cybersecurity
We're rebuilding incident response from the ground up—and we want a proven responder to help lead the way. This is a chance to bring your hard-won expertise into a next‑generation Security Operations program at Fortune 100 scale, where rapid response, automation, and AI‑driven investigation are core to how we operate. As our Senior Incident Handler, you’ll be the technical anchor for our most significant security events—driving the response, raising the bar on how we work, and helping mature the team toward a formal, scalable incident command model we’re building for the future.
If you’ve handled incidents that make headlines (or quietly prevented them from becoming headlines), bring the instincts of a seasoned incident commander and can move seamlessly from the server room to the boardroom. This is where your experience turns into real influence.
What You’ll Own- Incident Handling & Response Leadership: Serve as the lead responder during critical incidents—owning the full lifecycle from detection through containment, eradication, and recovery. Help run the war room, coordinate responders, and make confident calls with incomplete information.
- Cross‑Functional Coordination: Unify analysts, infrastructure, application owners, legal, communications, and third‑party partners into a single, fast‑moving response. Focus on reducing dwell time and mean‑time‑to‑respond.
- Executive Communication: Be a trusted voice during high‑severity events—translating fast‑moving technical realities into clear business impact for stakeholders up to the C‑suite. Build calm and confidence when it matters most.
- Deep Threat Investigation: Lead advanced investigations into malware, identity compromise, ransomware, and targeted attacks. Analyze logs, network, and forensic data to expose attacker tradecraft (lateral movement, persistence, exfiltration) and hunt down what others miss—leveraging EDR/XDR, SIEM, and cloud telemetry.
- AI & Automation Leadership: Help modernize our SOC by putting cutting‑edge automation and AI‑assisted tooling to work—accelerating triage and enrichment without sacrificing human judgment.
- Team Uplevel & Continuous Improvement: Raise the standard of how the team responds—sharpening detections, playbooks, and controls through meaningful after‑action reviews, and shaping the practices that will underpin our future incident command function.
- Battle‑tested IR experience: 5+ years in cybersecurity operations or incident response, with a track record of leading complex, enterprise‑scale incidents end‑to‑end. Financial services or insurance experience is a plus, but great responders come from everywhere.
- Command‑level instincts: Demonstrated ability to act as an incident commander or technical lead in high‑stakes moments—running major bridge calls and making decisive calls fast. Bring the judgment that helps a team operate like a mature command function.
- Technical depth: Strong command of network security, EDR/XDR, log and forensic analysis, and threat hunting across on‑prem and cloud. Comfortable with SIEM, forensics tooling, and scripting/automation (Python, Power Shell).
- Communication range: Exceptional written and verbal skills; equally credible with engineers and executives.
- Automation mindset: Enthusiasm for SOAR, ML‑based tooling, and LLMs to elevate response workflows.
- Credentials: CISSP, GCIA, GCIH, GCFA, OSCP, or other certifications preferred.
Skills Cross‑Functional Collaboration, Cyber Incident Response, Cyber Investigations, Cybersecurity Operations, Cyber Threat Hunting, Decision Making, Endpoint Detection and Response (EDR), Executive Communications, Forensic Analysis, Incident Handling, IT Automation, IT Security Architecture, Malware Analysis, Network Security, Penetration Testing, Scripting, Security Incident Response, Technical Leadership, Technical Mentoring, Technology Leadership.
Compensation Compensation offered for this role is – annually and is based on experience and qualifications.
The candidate(s) offered this position will be required to submit to a background investigation.
Equal Employment OpportunityAllstate generally does not sponsor individuals for employment‑based visas…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).