Software Engineer - Security

Security EngineerSecurity EngineerFull TimeRemoteMid LevelTeam 10,001+Since 1931H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

39 days ago

Salary

$90.7K - $199K / year

Seniority

Mid Level

Job Description

Software Engineer - Security

Allstate

At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection. Job Description **For this opportunity, the business is flexible to hire at Sr Consultant II, Lead Consultant, and Expert level depending on qualifications & interview evaluation.** Allstate Cybersecurity & Controls (ACC) is advancing its embedded security product strategy by launching three new engineering teams dedicated to building security controls seamlessly integrated into Allstate’s technology ecosystem. This is an opportunity for an engineer to build tools for other product engineers to improve the security and developer experience of Allstate's SDLC and platforms. The Software Engineer architects and designs their digital products using modern tools, technologies, frameworks, and systems. This individual will apply a systematic application of scientific and technological knowledge, methods, and experience to the design, implementation, testing, and documentation of software. Software Engineers take pride in building solutions without compromise—demonstrating an unwavering commitment to both developer friendliness and security. The Security Engineering group this position would be a part of is tasked with developing security controls as digital products that enhance or contribute to the enhancement of security within Allstate. Key Responsibilities - Participate in the ideation of security controls that challenge the status quo and push the organization to a higher level of embedded security - Demonstrate technical skills and aptitude needed to meet/exceed delivery velocity expectations as a full stack developer - Actively learn different technologies as needed for delivery of stories - Deliver on all phases of development work from initial kick-off, technical setup, application development, and support - Embrace approach of making collaborative, fast, local decisions; then course correct as/if needed (test/learn/iterate) - Participate in regular agile meetings (e.g., site standup, product team standup, iteration planning meeting, retrospective, lunch & learns) - Utilize Paired programming - Leverage Test-Driven Development - Establish continuous integration, continuous delivery, and continuous deployment pipelines and practices - Participate in high-level and low-level component and system designs - Partner in collaboration and strategy alignment across product portfolios (cross-product) in partnership with product managers, other peers and key stakeholders Essential Skills - Minimum of 3 years’ experience delivering production grade applications using (Java, Python, .NET, JavaScript etc.) with measurable impact (e.g., improved performance, reduced incidents) - Familiarity with the tools such as, Intellij-IDE or equivalent, Git, and REST APIs - Experience building and maintaining CI/CD pipelines that reduced deployment time and increased release frequency without compromising quality - Knowledge of Agile methodologies (especially Agile XP), including paired programming and test-driven development - Hands on experience architecting and deploying distributed systems in the cloud including MicroServices architectures, achieving scalability and uptime targets Additional Criteria for Lead & Expert Levels: - Minimum of 1 year of experience coaching or mentoring engineers with evidence of improving team capability - Proven ability to lead technical design and architecture decisions for complex, distributed systems, resulting in measurable improvements in scalability, security, or performance - Track record of driving cross-team collaboration to deliver integrated solutions, achieving alignment across multiple product portfolios Desirable Skills - Familiarity with OWASP top 10 and MITRE attack framework - Experience and knowledge in web and API security including authentication, authorization, OAuth, OWASP, OpenID, and SAML - Experience with behavioral driven development - Knowledge of LLMs and Machine Learning - Knowledge of AI-assisted development tools (Copilot, Cursor) and ability to leverage them for productivity gains Supervisory Responsibilities - There are no supervisory responsibilities for this role #LI-JJ1 Skills Agile Methodology, CI/CD, Java, JavaScript, Microservices Architecture, Microsoft .NET, Python (Programming Language), Software Engineering, Test Driven Development (TDD) Compensation Compensation offered for this role ranges from $90,700 - 199,910 annually and is based on experience and qualifications. The candidate(s) offered this position will be required to submit to a background investigation. Joining our team isn’t just a job — it’s an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact. Allstate generally does not sponsor individuals for employment-based visas for this position. Effective July 1, 2014, under Indiana House Enrolled Act (HEA) 1242, it is against public policy of the State of Indiana and a discriminatory practice for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component. For jobs in San Francisco, please click “here” for information regarding the San Francisco Fair Chance Ordinance. For jobs in Los Angeles, please click “here” for information regarding the Los Angeles Fair Chance Initiative for Hiring Ordinance. To view the “EEO Know Your Rights” poster click “here”. This poster provides information concerning the laws and procedures for filing complaints of violations of the laws with the Office of Federal Contract Compliance Programs. To view the FMLA poster, click “here”. This poster summarizing the major provisions of the Family and Medical Leave Act (FMLA) and telling employees how to file a complaint. It is the Company’s policy to employ the best qualified individuals available for all jobs. Therefore, any discriminatory action taken on account of an employee’s ancestry, age, color, disability, genetic information, gender, gender identity, gender expression, sexual and reproductive health decision, marital status, medical condition, military or veteran status, national origin, race (include traits historically associated with race, including, but not limited to, hair texture and protective hairstyles), religion (including religious dress), sex, or sexual orientation that adversely affects an employee's terms or conditions of employment is prohibited. This policy applies to all aspects of the employment relationship, including, but not limited to, hiring, training, salary administration, promotion, job assignment, benefits, discipline, and separation of employment.

Related Categories

Related Job Pages

More Security Engineer Jobs

Zensar logo

DIGITAL SECURITY - IAM - MICROSOFT

Zensar

At Zensar, we’re “experience-led everything”. We are committed to conceptualizing, designing, engineering, marketing, and managing digital solutions and experiences for over 130 leading enterprises. We are a company driven by a bold purpose: Together, we shape experiences for better futures. Whether for our clients, our people, or the world around us, this belief powers everything we do. At the heart of our culture is ONE with Client - a set of four core values that reflect who we are and how we work: One Zensar, Nurturing, Empowering, and Client Focus. Part of the $4.8 billion RPG Group, we’re a community of 10,000+ innovators across 30+ global locations, including Milpitas, Seattle, Princeton, Cape Town, London, Zurich, Singapore, and Mexico City. We believe the best work happens when individuality is celebrated, growth is encouraged, and well-being is prioritized. We are an equal employment opportunity (EEO) and affirmative action employer, committed to creating an inclusive workplace. All qualified applicants will be considered without regard to race, creed, color, ancestry, religion, sex, national origin, citizenship, age, sexual orientation, gender identity, disability, marital status, family medical leave status, or protected veteran status.

Full TimeRemoteTeam 10,001

Deliverables (SOW-ready) - Target and transition-state architecture pack (AD/Entra, 0365, PAM, IGA, SCIM, APIs, key integrations). - Migration sequencing design (waves, cutover, rollback considerations, operational readiness gates). - Application onboarding blueprint for auth/provisioning changes (prioritisation and dependency mapping). - Security-by-design artefacts and audit evidence approach. - Architecture Decision Records (ADRs) and maintained decision log entries. - Runbook requirements and support model inputs for Day-2 operations. At Zensar, we’re “experience-led everything”. We are committed to conceptualizing, designing, engineering, marketing, and managing digital solutions and experiences for over 130 leading enterprises. We are a company driven by a bold purpose: Together, we shape experiences for better futures. Whether for our clients, our people, or the world around us, this belief powers everything we do. At the heart of our culture is ONE with Client - a set of four core values that reflect who we are and how we work: One Zensar, Nurturing, Empowering, and Client Focus. Part of the $4.8 billion RPG Group, we’re a community of 10,000+ innovators across 30+ global locations, including Milpitas, Seattle, Princeton, Cape Town, London, Zurich, Singapore, and Mexico City. Explore Life at Zensar and join us to Grow. Own. Achieve. Learn. to be the best version of yourself. We believe the best work happens when individuality is celebrated, growth is encouraged, and well-being is prioritized. We are an equal employment opportunity (EEO) and affirmative action employer, committed to creating an inclusive workplace. All qualified applicants will be considered without regard to race, creed, color, ancestry, religion, sex, national origin, citizenship, age, sexual orientation, gender identity, disability, marital status, family medical leave status, or protected veteran status.

India
BeyondTrust logo

Identity Security Sales Specialist

BeyondTrust

Protect identities, stop threats, and deliver dynamic access to empower and secure a work-from-anywhere world.

Full TimeRemoteTeam 1,001-5,000Since 1985H1B Sponsor

BeyondTrust is a place where you can bring your purpose to life through the work that you do, creating a safer world through our cybersecurity SaaS portfolio. Our culture of flexibility, trust, and continual learning means you will be recognized for your growth, and for the impact you make on our success. You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself. The Role We are seeking a high-performing Commercial Identity Security Sales Specialist to drive net-new revenue for BeyondTrust’s Entitle solution within a defined U.S. territory. This is a strategic hunter role focused on acquiring and expanding commercial accounts within complex, multi-stakeholder environments. In addition to owning direct sales opportunities end-to-end, this role will operate in an overlay capacity across other Commercial Account Executives’ territories. You will serve as the Identity Security subject matter expert, partnering with aligned sellers to identify, influence, and close opportunities where Entitle is a strategic fit. Success in this role requires strong cross-functional collaboration, influence without authority, and the ability to drive urgency across a matrixed sales organization. Entitle is a foundational component of BeyondTrust’s privilege-centric Identity Security strategy, enabling organizations to eliminate excessive and standing privileges—commonly referred to as Paths to Privilege™—across cloud and hybrid environments. You will lead consultative engagements that help organizations reduce their attack surface through least-privilege and just-in-time access models while maintaining operational efficiency. What You’ll Do - Own and execute a strategic territory plan focused on net-new commercial acquisition. - Drive full-cycle sales motions from prospecting through close within your assigned accounts. - Operate as an overlay specialist across aligned Commercial Account Executives, identifying and advancing Entitle opportunities within their territories. - Build strong internal partnerships with Commercial AEs to create joint account plans and pipeline acceleration strategies. - Generate pipeline through proactive prospecting, executive outreach, partner collaboration, and targeted account strategies. - Lead complex, multi-threaded sales engagements within commercial organizations. - Engage C-level and senior security stakeholders (CISO, CIO, VP Security, Cloud Security leaders) in outcome-driven security conversations. - Deliver consultative discovery centered on privilege risk reduction, identity governance, and cloud security posture. - Coordinate cross-functional resources (Sales Engineering, Channel, Marketing, Professional Services, Customer Success) to accelerate deal progression and ensure successful outcomes. - Develop compelling business cases and ROI-driven proposals aligned to customer security initiatives. - Accurately forecast and manage pipeline using Salesforce, maintaining disciplined deal inspection and territory hygiene. - Consistently meet and exceed quarterly and annual revenue targets across both direct and overlay motions. - Represent the company at industry events, executive briefings, and partner engagements. What You’ll Bring - 5+ years of experience selling commercial SaaS, cybersecurity, or cloud security solutions. - Experience operating in both direct quota-carrying and overlay/specialist sales models. - Demonstrated success closing complex deals in competitive markets. - Proven ability to influence peer sellers and drive alignment across a matrixed sales organization. - Experience selling into security organizations and engaging C-level stakeholders. - Strong understanding of Identity & Access Management (IAM), Privileged Access Management (PAM), Cloud Security, Endpoint Security, or related domains. - Skilled in consultative selling, executive alignment, and value-based positioning. - Experience building and executing territory and account-based sales strategies. - Proficiency with Salesforce (SFDC) and disciplined forecasting practices. - Exceptional communication, negotiation, and stakeholder management skills. - High integrity, resilience, and comfort operating in a performance-driven environment. Better Together Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected. We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together. About Us BeyondTrust is the global identity security leader protecting Paths to Privilege™. Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders. BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies. We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners. Learn more at www.beyondtrust.com. #LI-JC1

United States

Industrial Security Specialist

Allied Universal

Allied Universal, founded in 2016 with the merger of AlliedBarton Security Services and Universal Services of America, is now a widely-recognized industry leader and North America�

Overview Company Overview: Allied Universal®, North America’s leading security and facility services company, offers rewarding careers that provide you a sense of purpose. While working in a dynamic, welcoming, and collaborative workplace, you will be part of a team that contributes to a culture that positively impacts the communities and customers we serve. Job Description Allied Universal® is hiring an Industrial Security Specialist. The position of Industrial Security Specialist entails administering electronic security clearance questionnaires (Standard Form 86 - SF86), conducting access indoctrinations and debriefings, and delivering security clearance-related training. Additionally, responsibilities include administrative Personnel Security (PerSec) procedures such as database management, file review, electronic form submission, and coordination of required security clearance briefings. The Industrial Security Specialist must undergo a federal government security investigation and meet the eligibility requirements for accessing classified information by either holding an active SECRET clearance or demonstrating the ability to obtain and retain one. This role is remote; therefore, the employee must ensure reliable internet access and a private workspace or work from the local branch office. - Help employees get and keep their security clearances by guiding them through background check paperwork, fixing issues, tracking deadlines, and making sure everything is accurate so people can work without delays. - Keep security records organized and compliant by coordinating with employees, managers, and government reviewers, answering questions, and ensuring all security rules are followed. - This is a remote role. RESPONSIBILITIES: - Organize and maintain employee information for clearance processing using Defense Information System for Security (DISS), National Background Investigation Services (NBIS), and eApp - Support security clearance applicants throughout the SF86 security application process and nomination packages - Receive and review DD254 packages; coordinate with client representatives to facilitate security clearances and manage classified visits to the assigned site(s) - Provide training to Allied Universal personnel on the Code of Federal Regulations Title 32 Part 117, NISPOM - Ensure that Allied Universal personnel adhere to company policies and government regulations - Troubleshoot issues and address inquiries from federal investigators, account managers, and cleared personnel - Manage electronic application (eApp) case files for initial personnel security investigations and continuous vetting - Provide employee assistance throughout the security application process - Conduct mandatory briefings and gather all necessary reporting information from employees - Use multiple internal and government security databases - Manage designated client account portfolios and collaborate with managers to coordinate processing visits and access for cleared personnel - Effectively engage with personnel at all levels, both internally and externally, through oral and written communication. QUALIFICATIONS (MUST HAVE): - High school diploma or equivalent - Must be a United States Citizen and possess a Department of Defense (DoD) SECRET security clearance, or be eligible to obtain one quickly PREFERRED QUALIFICATIONS (NICE TO HAVE): - Prior experience working in the industrial security program for a commercial or government entity - Comprehensive understanding of the Defense Counterintelligence Security Agency (DCSA) PerSec Program - Familiarity with legal, federal government, and National Industrial Security Program (NISP) terminology - Knowledge of the Department of Defense and the Intelligence Community BENEFITS: - Hourly wage range: $22.00 - $25.00 + internal advancement opportunities - Medical, dental, vision, basic life, AD&D, retirement plan and disability insurance - Eight paid holidays annually, five sick days, and four personal days - Vacation time offered at an accrual rate of 3.08 hours biweekly; unused vacation is only paid out where required by law Closing Allied Universal® is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race/ethnicity, age, color, religion, sex, sexual orientation, gender identity, national origin, genetic information, disability, protected veteran status or relationship/association with a protected veteran, or any other basis or characteristic protected by law. For more information: www.aus.com If you have difficulty using the online system and require an alternate method to apply or require an accommodation, please contact our local Human Resources department. To find an office near you, please visit: www.aus.com/offices. Requisition ID 2026-1557685

United States
$22 - $25 / hour

Application Security Architect

RGA - Reinsurance Group of America

Reinsurance Group of America (RGA), founded in 1973 and headquartered in Chesterfield, Missouri, is a global provider of health and life insurance. RGA has prov

You desire impactful work. You’re RGA ready RGA is a purpose-driven organization working to solve today’s challenges through innovation and collaboration. A Fortune 200 Company and listed among its World’s Most Admired Companies, we’re the only global reinsurance company to focus primarily on life- and health-related solutions. Join our multinational team of intelligent, motivated, and collaborative people, and help us make financial protection accessible to all. The Application Security Architect will partner with engineering teams to build secure software from design through delivery. This role is equal parts hands-on advisor and security design reviewer: you will help developers write secure code, efficiently triage and resolve false positives, and provide pragmatic guidance that improves security outcomes without slowing delivery. You will also perform Secure by Design reviews for new applications and material changes to existing applications to ensure solutions are secure, scalable, and compliant with company standards. Principle Duties Developer enablement & secure coding support - Coach and support developers in writing secure code, including secure patterns, common vulnerability classes, and secure use of frameworks and libraries. - Provide timely consulting on “how to do it right” (architecture, implementation details, and operational considerations) and help teams choose secure-by-default approaches. - Triage findings from SAST, SCA, DAST, container and IaC scanning; investigate, validate, and resolve false positives; and help teams prioritize true risk. - Partner with teams to tune security tools, reduce noise, and improve signal quality (rules, suppressions, baselines, and exception processes) while maintaining strong security posture. Secure by Design reviews - Conduct Secure by Design reviews for new applications and material changes to existing applications, validating security requirements and design decisions early. - Lead and facilitate threat modeling workshops; identify abuse cases, trust boundaries, and attack paths; and document mitigations and residual risk. - Review authentication/authorization design, data flows, secrets handling, logging/monitoring, and resiliency controls to ensure secure architectures. - Provide clear, actionable recommendations and track follow-through with engineering teams. CI/CD and SDLC security - Advise on the security of CI/CD practices: pipeline hardening, least privilege, artifact integrity, signing, provenance, and secure deployment patterns. - Advise on secure use of third-party dependencies and supply chain controls, including SCA governance and patch/vulnerability management workflows. - Collaborate with platform/tooling teams to integrate security controls into developer workflows with a focus on automation and self-service. AI/ML security guidance - Provide security architecture guidance for AI/ML and GenAI-enabled applications, including model/data risk, prompt/agent design considerations, and safe integration patterns. - Help teams implement appropriate controls for data protection, access control, monitoring, and abuse prevention in AI/ML features. Collaboration & communication - Act as a trusted partner to product, engineering, and leadership—translating security requirements into developer-friendly guidance. - Create and maintain secure coding guidance, reference architectures, and reusable patterns. - Support incident learnings by contributing to root cause analysis and preventative design improvements. Education - Bachelor’s Degree in Arts/Sciences (BA/BS) or equivalent experience - Required - Master’s degree in Arts/Sciences (MA/MS) or professional industry certification - Preferred Work Experience - 8+ years related IT experience; 5+ years experience in security application tools - 6+ years experience in application security reviews of new architecture; 4 + years of experience with public and hybrid cloud (AWS) environments. Required Qualifications & Skills - Strong software development background with the ability to read, understand, and advise on production code and design decisions. - Demonstrated expertise in threat modeling and secure architecture review for modern web and API-based applications. - Expertise securing CI/CD and SDLC processes (pipeline security, secrets management, artifact integrity, build/release controls, and automation). - Experience with application security tooling and processes, including managing findings and resolving false positives (SAST/SCA/DAST and related scanning in pipelines). - Working knowledge of AI/ML security risks and mitigations for applications that use ML models or GenAI components. - Strong collaborative and consulting skills: ability to influence without authority, communicate clearly, and deliver pragmatic, developer-friendly recommendations. #LI-CW1 #LI-Remote What you can expect from RGA: - Gain valuable knowledge from and experience with diverse, caring colleagues around the world. - Enjoy a respectful, welcoming environment that fosters individuality and encourages pioneering thought. - Join the bright and creative minds of RGA, and experience vast, endless career potential. We’re excited to get to know you and connect your unique skills with our global opportunities. To create a modern and seamless experience, we use artificial intelligence (AI) in parts of our preliminary screening process. This technology helps us personalize job recommendations, automate interview scheduling, evaluate candidates based solely on experience—without considering name, gender, or other personal details—and provide real-time answers through our chatbot. AI is used only during early screening and never makes hiring decisions. Your RGA recruiter will work closely with you every step of the way to ensure the process feels personal, thoughtful, and focused on you. Compensation Range: $150,770.00 - $224,640.00 Annual Base pay varies depending on job-related knowledge, skills, experience and market location. In addition, RGA provides an annual bonus plan that includes all roles and some positions are eligible for participation in our long-term equity incentive plan. RGA also maintains a full range of health, retirement, and other employee benefits. RGA is an equal opportunity employer. Qualified applicants will be considered without regard to race, color, age, gender identity or expression, sex, disability, veteran status, religion, national origin, or any other characteristic protected by applicable equal employment opportunity laws.

United States
$150K - $224K / year