Senior Incident Handler
Allstate · United States · 6 days ago
RemoteRemoteManufacturingFull-time
About the role
We're rebuilding incident response from the ground up—and we want a proven responder to help lead the way. This is a chance to bring your hard-won expertise into a next-generation Security Operations program at Fortune 100 scale, where rapid response, automation, and AI-driven investigation are core to how we operate.
Responsibilities
- Serve as the lead responder during critical incidents—owning the full lifecycle from detection through containment, eradication, and recovery.
- Help run the war room, coordinate responders, and make confident calls with incomplete information.
- Unify analysts, infrastructure, application owners, legal, comms, and third-party partners into a single, fast-moving response.
- Relentlessly focus on reducing dwell time and mean-time-to-respond.
- Be a trusted voice during high-severity events—translating fast-moving technical realities into clear business impact for stakeholders up to the C-suite.
- Lead advanced investigations into malware, identity compromise, ransomware, and targeted attacks. Analyze logs, network, and forensic data to expose attacker tradecraft (lateral movement, persistence, exfiltration) and hunt down what others miss—leveraging EDR/XDR, SIEM, and cloud telemetry.
- Help modernize our SOC by putting cutting-edge automation and AI-assisted tooling to work—accelerating triage and enrichment without sacrificing human judgment.
- Team Uplevel & Continuous Improvement: Raise the standard of how the team responds—sharpening detections, playbooks, and controls through meaningful after-action reviews, and helping shape the practices that will underpin our future incident command function.
Requirements
- Battle-tested IR experience: 5+ years in cybersecurity operations or incident response, with a track record of leading complex, enterprise-scale incidents end-to-end.
- Financial services or insurance experience is a plus—but great responders come from everywhere.
- Command-level instincts: Demonstrated ability to act as an incident commander or technical lead in high-stakes moments—running major bridge calls and making decisive calls fast. You bring the judgment that helps a team operate like a mature command function.
- Technical depth: Strong command of network security, EDR/XDR, log and forensic analysis, and threat hunting across on-prem and cloud. Comfortable with SIEM, forensics tooling, and scripting/automation (Python, PowerShell).
Qualifications
- Deep Threat Investigation: Lead advanced investigations into malware, identity compromise, ransomware, and targeted attacks. Analyze logs, network, and forensic data to expose attacker tradecraft (lateral movement, persistence, exfiltration) and hunt down what others miss—leveraging EDR/XDR, SIEM, and cloud telemetry.
- AI & Automation Leadership: Help modernize our SOC by putting cutting-edge automation and AI-assisted tooling to work—accelerating triage and enrichment without sacrificing human judgment.
- Team Uplevel & Continuous Improvement: Raise the standard of how the team responds—sharpening detections, playbooks, and controls through meaningful after-action reviews, and helping shape the practices that will underpin our future incident command function.
Skills
- Cross-Functional Collaboration
- Cyber Incident Response
- Cyber Investigations
- Cybersecurity Operations
- Cyber Threat Hunting
- Decision Making
- Endpoint Detection and Response (EDR)
- Executive Communications
- Forensic Analysis
- Incident Handling
- IT Automation
- IT Security Architecture
- Malware Analysis
- Network Security
- Penetration Testing
- Scripting
- Security Incident Response
- Technical Leadership
- Technical Mentoring
- Technology Leadership
Benefits
- Compensation offered for this role is 120,000.00 - 193,725.00 annually and is based on experience and qualifications.
- The candidate(s) offered this position will be required to submit to a background investigation.
Pay
Compensation offered for this role is 120,000.00 - 193,725.00 annually and is based on experience and qualifications.
Schedule
Not specified.