Jobs Companies Allstate Senior Threat Hunting (Lead)

Über diese Senior Threat Hunting (Lead) Stelle bei Allstate

Allstate · Vor Ort · Ind – Blr Sez 1 (3Rd, 6Th & 7Th Floor)

At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection. 

Job Description

We are seeking a Senior Threat Hunter to lead hypothesis-driven, intelligence-led hunts across enterprise, cloud, and OT/IoT environments. This role proactively identifies adversary tradecraft that evades existing detections, operationalizes findings into durable detection logic, and partners with Threat Intelligence, Detection Engineering, IR, Exposure Management, and REM to reduce dwell time and shrink the enterprise exposure plane. The hunter will leverage MITRE ATT&CK, the Pyramid of Pain, and the Diamond Model to drive measurable risk reduction.

Key Responsibilities

  • Lead hypothesis-driven, intelligence-led hunt campaigns from formulation through reporting, mapped to MITRE ATT&CK
  • Design and execute custom analytics against large-scale security telemetry (SIEM, EDR/XDR, identity, cloud, network) to uncover adversary tradecraft that evades existing detections
  • Perform identity-centric hunting across Entra ID, Active Directory, and SaaS platforms - token theft, session hijacking, MFA bypass, OAuth abuse, and conditional access circumvention.
  • Conduct cloud-native hunting across AWS, Azure, M365, and SaaS control planes, including audit logs, identity events, and workload telemetry.
  • Convert hunt findings into durable detections, signatures, and SOAR playbooks in partnership with Detection Engineering, closing the hunt-to-detect loop
  • Perform Deception Operations by defining adversary-aligned use cases, authoring detection requirements for deception-generated activity, and tuning signal vs. noise thresholds
  • Leverage AI and LLM-assisted tooling to accelerate hunting - including query generation, log summarization, entity pivoting, anomaly clustering, and large-scale pattern discovery across disparate telemetry sources
  • Hunt within AI and LLM environments - including enterprise copilots, internal/external LLM deployments, AI agents, RAG pipelines, model endpoints, and AI/ML infrastructure - for threats such as prompt injection, model abuse, data exfiltration via AI channels, agent hijacking, supply-chain compromise of models, and unauthorized model access
  • Produce post-hunt reports with explicit evidence and measurable outcomes tied to exposure reduction
  • Partner with Threat Intelligence to operationalize finished intel into targeted hunt missions and feed collection requirements upstream
  • Support purple-team exercises and validate detection efficacy against adversary emulation campaigns (Atomic Red Team, CALDERA, Stratus Red Team)
  • Develop and maintain custom tooling and automation to support hunting, investigation, and analyst efficiency
  • Mentor junior hunters; contribute to internal knowledge bases, hunt libraries, and team training
  • Support Incident Response, Forensics, and Insider Threat / Fraud investigations as a senior technical resource when adversary expertise is needed
  • Serve as a liaison for Threat Services across Cyber Operations, communicating findings clearly to technical peers and executive leadership
  • Identify needs, drive solutions, and operate autonomously within strategic priorities

Required Qualifications

  • 7+ years of experience in security operations, with 4+ of those dedicated to threat hunting
  • Deep experience hunting in large, complex enterprise environments
  • Demonstrable experience executing MITRE ATT&CK-aligned hunts with documented outcomes and detection handoffs
  • Hands-on experience with modern SIEM (Splunk, Sentinel, Elastic) and EDR/XDR (CrowdStrike, Defender, SentinelOne, Tanium)
  • Demonstrated experience using AI/LLM-assisted tooling (e.g., Security Copilot, custom GPTs, agentic workflows, embeddings-based analytics) to accelerate hunting, triage, and analytic development.
  • Working knowledge of hunting in AI/LLM environments - familiarity with the MITRE ATLAS framework, OWASP Top 10 for LLM Applications, and common AI-specific threats (prompt injection, model theft, training data poisoning, agent abuse, sensitive data leakage through AI channels)
  • Working knowledge of threat intelligence frameworks: Diamond Model, Kill Chain, and the Pyramid of Pain
  • Strong scripting and automation skills in Python, PowerShell, GO, and/or Bash
  • Deep understanding of common network and application stack protocols: TCP/IP, DNS, TLS, HTTP, SMTP, etc.
  • Experience with signature and analytic development: CQL/KQL/SPL analytics, Sigma, YARA, Snort/Suricata
  • Excellent analytical and problem-solving skills, with a research mindset and a passion for puzzles
  • Strong written and verbal communication, including the ability to produce executive-ready summaries of technical findings
  • Demonstrated leadership and mentorship capability
  • Strong motivation to understand and train in new technologies, techniques, and a self-starter
  • Bachelor's or Master's degree in IT Security, Computer Science, Engineering, or equivalent experience and certifications

Desirable Criteria

  • Proficiency in KQL/CQL/SPL; comfortable building complex queries and analytics across large datasets
  • Experience hunting in cloud environments (AWS, Azure, M365) using native telemetry such as CloudTrail, Azure Activity, M365 Unified Audit Log, and identity provider logs
  • Adversary emulation experience using Atomic Red Team, CALDERA, Stratus Red Team, or equivalent
  • Recent experience with malware analysis and reverse engineering
  • Hands-on experience securing or hunting within AI/ML pipelines, model registries, vector databases, and agentic systems
  • Hands-on experience with vulnerability research, penetration testing or exploit development (offensive mindset)
  • Experience with container and Kubernetes security telemetry (Falco, runtime security, cloud workload protection)
  • Experience consuming deception technology outputs as a hunting data source
  • Familiarity with threat hunting maturity models (e.g., Hunting Maturity Model - HMM) and capability of advancing program maturity
  • Experience with insider threat or fraud-adjacent hunting use cases
  • Published research, conference talks, CTF participation, or contributions to open-source detection content (Sigma rules, Atomic Red Team, hunt libraries)
  • Familiarity with OT/ICS or IoT environments
  • Relevant certifications such as:
    • GIAC: GCTD, GCTI, GCFA, GCFE, GNFA, GREM, GDAT, GCIA
    • Offensive: OSCP, OSCE, CRTO
    • Cloud: AWS Security Specialty, AZ-500, SC-200
    • AI Security: AI/ML security certifications, MITRE ATLAS training, AI red-team credentials
    • Foundational: CISSP, CEH
  • Tool-specific certifications in Splunk, Sentinel, CrowdStrike, or similar platforms

Primary Skills

Customer Centricity, Digital Literacy, Inclusive Leadership, Learning Agility, Results-Oriented

Shift Time

Shift B (India)

Recruiter Info

Yateesh B G

[email protected]

About Allstate

Joining our team isn’t just a job — it’s an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact.

The Allstate Corporation is one of the largest publicly held insurance providers in the United States. Ranked No. 84 in the 2023 Fortune 500 list of the largest United States corporations by total revenue, The Allstate Corporation owns and operates 18 companies in the United States, Canada, Northern Ireland, and India. Allstate India Private Limited, also known as Allstate India, is a subsidiary of The Allstate Corporation. The India talent center was set up in 2012 and operates under the corporation's Good Hands promise. As it innovates operations and technology, Allstate India has evolved beyond its technology functions to be the critical strategic business services arm of the corporation. With offices in Bengaluru and Pune, the company offers expertise to the parent organization’s business areas including technology and innovation, accounting and imaging services, policy administration, transformation solution design and support services, transformation of property liability service design, global operations and integration, and training and transition.

Learn more about Allstate India here.

Bereit, sich bei Allstate zu bewerben?
Bei Allstate bewerben

Über Allstate

At Allstate, we work hard to help people live a good life every day. Allstaters are dedicated to serving clients, customers, and communities, which allows employees to find meaning and value in their work. Allstate offers an environment that fosters innovative thinking where you’ll be able to explore your ideas and feel proud of the work you do. Allstate helps protect nearly 16 million households with auto, home, life, and retirement products. We want every professional connected to Allstate to be committed to giving our customers the best and that means finding the best talent. We want you to be our next great addition. It’s easy to search and apply for a new opportunity with Allstate. Simp

Alle Jobs bei Allstate ansehen →

Ähnliche Jobs

AL
Digital Product Manager
Allstate
⚡ Früh bewerben USA - IL (Remote) · standortgebunden
● Neu 👁 Gesehen ✓ Beworben vor 2 Std.
AL
Senior Trial Attorney (Remote - Connecticut)
Allstate
⚡ Früh bewerben USA - CT (Remote) Hybrid $120,000–$150,000
● Neu 👁 Gesehen ✓ Beworben vor 2 Std.
AL
Non-Attorney-Represented Bodily Injury Adjuster
Allstate
⚡ Früh bewerben USA - FL (Remote) · standortgebunden $53,500–$86,400
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
AL
Large Loss Risk Adjuster
Allstate
⚡ Früh bewerben USA - GA (Remote) · standortgebunden
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
AL
Inside Property Adjuster (Homeowners)
Allstate
⚡ Früh bewerben USA - AZ (Remote) · standortgebunden
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
AL
Senior Trial Attorney - Las Vegas, NV (Remote)
Allstate
⚡ Früh bewerben USA - NV (Remote) · standortgebunden
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
AL
Early Career Personal Injury Protection / SIU Attorney (Remote - Metro Area, NY)
Allstate
⚡ Früh bewerben USA - NY (Remote) · standortgebunden
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
AL
Trial Attorney - Dallas, TX (Hybrid)
Allstate
⚡ Früh bewerben USA - TX (Remote) · standortgebunden
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
AL
Reconciliations Associate III
Allstate
⚡ Früh bewerben Ind – Pune Sez 1 (All Floors E... Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei Allstate

Alle Jobs bei Allstate ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos