Product Security Engineer (Multiple Levels)

Company: Allstate NI
Apply for the Product Security Engineer (Multiple Levels)
Location: Belfast
Job Description:

At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection.

Your role in the team

The Product Security Engineer partners in designing and building security solutions that will balance the need for speed and flexibility of the infrastructure and IaaS/PaaS/SaaS applications, with the need to protect Allstate against ongoing and potential security threats. This role needs to have the aptitude to understand new security strategies. This position has been opened at Senior Consultant II and Lead Consultant.

Key responsibilities

  • Cyber Risk Assessment & Governance Lead: execute enterprise, business-unit, and technology-specific cyber risk assessments, including inherent risk identification, control adequacy evaluation, residual risk determination, and risk prioritization. Develop, enhance, and operationalize cyber risk assessment methodologies, frameworks, and assessment artifacts aligned to recognized standards (e.g., NIST CSF, NIST SP 800-53, ISO/IEC 27001, CIS, COBIT). Translate business and technical risks into clear, actionable risk statements, supported by evidence-based control evaluation and impact analysis. Drive risk‑based decision‑making by clearly articulating risk exposure, control gaps, and mitigation options to stakeholders.
  • Regulatory, Compliance & Standards Alignment: research, interpret, and apply global and regional cybersecurity regulations and requirements (e.g., NYDFS 500, GLBA, PCI DSS, SOX ITGCs, data protection and privacy regulations, contractual security requirements). Analyze regulatory guidance, enforcement actions, and industry advisories to inform governance programs and risk posture.
  • Program Development & Continuous Improvement: design, enhance, and execute cybersecurity governance programs, policies, standards, procedures, and control requirements aligned to business and regulatory needs. Identify process gaps, control deficiencies, and maturity weaknesses; recommend risk‑based remediation strategies and pragmatic control improvements. Contribute to the evolution of enterprise cybersecurity risk assessment (ECRA) capabilities, including risk taxonomies, metrics, and reporting. Support continuous monitoring and re‑assessment of cyber risks as business, technology, and threat landscapes evolve.
  • Stakeholder Communication & Advisory: act as a trusted risk advisor to technology, engineering, and business leaders by explaining complex cybersecurity and regulatory topics in a practical, business‑relevant manner. Develop and deliver risk assessment summaries, executive briefings, and governance reports tailored for senior leadership, risk committees, and audit stakeholders. Provide guidance and mentorship to less‑experienced team members on cyber risk assessment techniques, regulatory interpretation, and governance best practices.

Essential Skills

  • Legal right to work in the UK; sponsorship not provided.
  • Minimum 3+ years experience in cybersecurity risk management concepts.
  • Experience with Cloud, SaaS, third‑party risk, identity & access management, data protection, network security, vulnerability management, and secure SDLC.
  • Minimum 1 year with one of NIST CSF, NIST SP 800-53, ISO 27001/27002, CIS Controls, COBIT, relevant regulatory frameworks.
  • Experience in large, complex, regulated environments.

Desirable Skills

  • Certifications: CRISC, CISM, CISSP, CISA.

Supervisory Responsibilities

This job does not have supervisory duties.

Posting Closing date

Thursday 4th June 2026 {11.59pm}

Benefits and Skills

Skills: Information Security Engineering, IT Security Operations, Risk Management, Security Tools, Stakeholder Engagement.

As part of Allstate, you will receive a competitive annual salary. The reward package includes corporate bonus scheme, pension scheme, annual performance‑related pay reviews, life assurance and income protection, flexible working options, hybrid working, private medical and dental insurance, employee assistance programme, discounted gym membership, two paid volunteering days each year, cycle to work scheme.

#J-18808-Ljbffr…

Posted: May 31st, 2026