At a Glance
- Tasks: Lead cybersecurity governance projects and mentor team members while ensuring compliance with regulations.
- Company: Join Allstate, a leader in protecting families for over 90 years with innovative solutions.
- Benefits: Enjoy flexible working options, generous benefits, and access to world-class learning platforms.
- Why this job: Be part of a socially responsible organisation where your work has purpose and growth is supported.
- Qualifications: 5+ years in security/technology audit; knowledge of NIST standards; strong communication skills required.
- Other info: Allstate values diversity and encourages applications from under-represented groups.
The predicted salary is between 48000 - 72000 £ per year.
At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. For more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs.
Your role in the team:
The Security Governance Lead Consultant develops and evaluates compliance with programs, processes, and procedures to mitigate cybersecurity risk and ensure protection of company information and assets; researches and develops interpretations of industry and government regulations, standards, and contract requirements for application to assigned area of operations.
Key responsibilities:
- Provides leadership and mentoring for less experienced team members on assigned projects and in area of expertise.
- Reviews and validates with Legal resources and communicates interpretations of regulatory, contract, and industry requirements for business and technical managers for cybersecurity governance and suggests application to assigned area; oversees the creation, organization, and maintenance of required filings and documentation.
- Performs ongoing and forensic audits of governance process and procedure compliance; tracks metrics, analyzes results, and develops recommendations for changes and enhancements; communicates to business and technical leadership.
- Works with business and technical leaders to develop governance plan and metrics for assigned area; develops, communicates, and executes programs and processes that provide guidance and promote cybersecurity risk awareness and management in alignment with operational needs.
This job does not have supervisory responsibilities.
Essential Skills:
- All applicants must demonstrate they have a legal right to work in the UK for employment at Allstate. Allstate is not providing sponsorship for this vacancy.
- 5+ years of security/technology audit experience, including development of control test plans/scripts.
- Working knowledge of NIST CSF 2.0 and/or NIST 800.53 rev. 5.
- Experience in automating control testing processes.
- Experience managing multiple assignments and projects at once.
Desirable Skills:
- 8+ years of security/technology audit experience, including development of control test plans/scripts.
- CISA, CRISC, CISSP, CISM, or other relevant certifications (preferred).
- Experience communicating effectively with resources of all levels (analyst to executive).
- Proven experience challenging ideas, asserting your expertise, and being comfortable making recommendations in a professional manner.
- Experience working in a role that requires strong attention to detail.
Supervisory Responsibilities:
This job does not have supervisory duties.
Why join us?
Allstate NI is proud to be Allstate’s European Digital Centre of Excellence—recent winners of ‘Best Use of Cloud Services’ at the Belfast Telegraph IT Awards 2024, and recognised for our community and sustainability impact at the 2024 Business in the Community Awards and Gold accreditation for Environmental Responsibility. We’re a product-driven, cloud-first organisation delivering real outcomes through modern technology, a digital product-centric talent model, and a culture rooted in engineering excellence. Our teams work in cross-functional structures, guided by an outcome-based delivery approach that accelerates speed, agility, and value.
We offer:
- A generous, flexible benefits package including annual leave, healthcare and dental cover, pension, and lifestyle discounts.
- Access to world-class learning platforms and award-winning L&D.
- Clear career paths, internal mobility, and a strong focus on growth.
- A people-first culture with flexible working options.
Be part of a high-performing, socially responsible organisation where your work has purpose, and your growth is supported every step of the way.
Statement on Fair Employment and Equal Opportunities:
Allstate NI wishes to ensure equal opportunity is given to all job applicants. This company will not discriminate on the grounds of race, gender (including gender reassignment status), sexual orientation, religious belief, political opinion, marital status, age or disability. We are an equal opportunities employer. We welcome applications from all suitably qualified persons. However, as women are currently under-represented in our workforce, we would particularly welcome applications from women. All appointments will be made on merit. Applicants should note Allstate NI complete AccessNI background checks on all candidates offered a position.
Security Governance - Lead Consultant (hybrid/remote) employer: Allstate Insurance Company
Contact Detail:
Allstate Insurance Company Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Security Governance - Lead Consultant (hybrid/remote)
✨Tip Number 1
Familiarise yourself with NIST CSF 2.0 and NIST 800.53 rev. 5, as these are crucial for the role. Understanding these frameworks will not only help you in interviews but also demonstrate your commitment to cybersecurity governance.
✨Tip Number 2
Network with professionals in the cybersecurity field, especially those who have experience in security governance. Engaging in discussions or attending relevant webinars can provide insights and potentially lead to referrals.
✨Tip Number 3
Showcase your ability to manage multiple projects by discussing past experiences where you successfully juggled various assignments. This will highlight your organisational skills and readiness for the demands of the role.
✨Tip Number 4
Prepare to discuss how you've communicated complex regulatory requirements to different stakeholders. This skill is essential for the position, so having specific examples ready will set you apart from other candidates.
We think you need these skills to ace Security Governance - Lead Consultant (hybrid/remote)
Some tips for your application 🫡
Understand the Role: Before applying, make sure you fully understand the responsibilities and requirements of the Security Governance Lead Consultant position. Tailor your application to highlight relevant experience in cybersecurity governance and compliance.
Highlight Relevant Experience: In your CV and cover letter, emphasise your 5+ years of security/technology audit experience. Include specific examples of how you've developed control test plans or automated control testing processes, as these are key aspects of the role.
Showcase Your Skills: Mention any relevant certifications such as CISA, CRISC, CISSP, or CISM. Also, demonstrate your ability to communicate effectively with various stakeholders, as this is crucial for the position.
Craft a Strong Cover Letter: Use your cover letter to express your passion for cybersecurity and your alignment with Allstate's values. Discuss how your expertise can contribute to their mission of protecting families and assets, and mention your interest in their community and sustainability initiatives.
How to prepare for a job interview at Allstate Insurance Company
✨Understand the Role and Responsibilities
Make sure you thoroughly understand the key responsibilities of the Security Governance Lead Consultant role. Familiarise yourself with compliance programs, cybersecurity risk management, and the specific regulations mentioned in the job description, such as NIST CSF 2.0 and NIST 800.53.
✨Showcase Your Experience
Prepare to discuss your relevant experience in security and technology audits. Highlight any specific projects where you've developed control test plans or automated testing processes, as these are crucial for the role.
✨Demonstrate Leadership Skills
Even though this position does not have supervisory responsibilities, it's important to showcase your ability to mentor and lead less experienced team members. Share examples of how you've provided guidance in past roles.
✨Communicate Effectively
Practice articulating complex cybersecurity concepts in a way that can be understood by both technical and non-technical stakeholders. This will demonstrate your ability to communicate effectively across different levels of an organisation.