Senior Data Security Engineer
Listed on 2026-08-26
-
IT/Tech
Cybersecurity, Information Security & Data Protection
At Allstate, great things happen when our people work together to protect families and their belongings from life's uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers' evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection.
Job Description
For this opportunity, the business is flexible to hire at Senior Consultant, Lead Consultant, and Expert level depending on qualifications & interview evaluation.
The Senior Data Protection Security Engineer will lead the evolution of enterprise data protection from a traditional tool administration model to an engineering-driven security capability. This role is responsible for building scalable, automated, and measurable data protection solutions across cloud, SaaS, endpoint, email, and collaboration environments using Policy-as-Code, Security-as-Code, Dev Ops, and Dev Sec Ops practices.
The successful candidate will bring a proven track record of modernizing Data Protection, DLP, CASB, or Information Protection programs by reducing manual processes, increasing automation, and implementing repeatable governance and deployment models. This individual will serve as a key contributor in advancing the organization's data protection strategy while driving operational excellence, security effectiveness, and business enablement.
Key ResponsibilitiesEngineer enterprise DLP controls across endpoint, email, SaaS, cloud storage, collaboration platforms, network, and web channels.
Modernize DLP policy deployment by moving from manual console-based changes to version-controlled, automated, and repeatable policy-as-code workflows.
Build CI/CD pipelines for data protection policy lifecycle management, including peer review, automated validation, testing, approval, deployment, and rollback.
Develop reusable policy templates, detection logic, exception patterns, configuration baselines, and deployment standards across multiple DLP and CASB platforms.
Automate operational tasks such as policy promotion, configuration drift detection, control validation, reporting, alert enrichment, and recurring health checks.
Integrate DLP, CASB, data classification, cloud security, identity, SIEM, SOAR, and workflow platforms to improve visibility, response, and enforcement.
Tune detection logic using data-driven analysis to reduce false positives, improve signal quality, and increase confidence in policy enforcement.
Design guardrails for sensitive data usage across Microsoft 365, cloud platforms, source code repositories, collaboration tools, SaaS applications, and enterprise endpoints.
Partner with engineering, cloud, infrastructure, network, compliance, privacy, legal, and business teams to design practical data protection solutions.
Investigate data protection events, identify root cause, recommend control improvements, and convert lessons learned into automated prevention patterns.
Define and maintain metrics, KPIs, dashboards, and control evidence that demonstrate risk reduction, policy effectiveness, deployment quality, and operational maturity.
Support platform upgrades, capability expansions, vendor integrations, and new data protection control patterns using disciplined engineering practices.
4+ years delivering enterprise Data Protection, Information Protection, Cloud Security, or Security Engineering capabilities within complex organizations.
Proven experience in Policy-as-Code, Security-as-Code, and Dev Sec Ops methodologies, with a demonstrated ability to automate security control deployment and governance at enterprise scale.
Track record of replacing manual operational processes with engineering-driven solutions through automation, APIs, Infrastructure-as-Code, and platform engineering practices.
Advanced knowledge of Data Loss Prevention (DLP), data classification, information protection, and data governance principles.
Hands-on expertise with Microsoft Purview, Microsoft Information Protection, Defender for Cloud Apps, and the Microsoft 365 security ecosystem.
Comprehensive understanding of cloud, SaaS, CASB, and enterprise data protection architectures.
Proficiency in scripting and automation technologies including Power Shell, Python, REST APIs, Terraform, Bicep, YAML, JSON, or comparable tools.
Demonstrated success in modernizing Data Protection, DLP, CASB, or Information Protection programs through automation, standardization, and engineering-driven operating models.
Proven ability to implement and scale Dev Ops, Dev Sec Ops , or Platform Engineering practices within security organizations.
Track record of leading large-scale security initiatives that improve control effectiveness, operational efficiency, and measurable risk reduction.
Background supporting enterprise-scale cloud, SaaS, or Microsoft 365 environments.
Knowledge of regulatory, privacy, and compliance requirements and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).