At a Glance
- Tasks: Design and operate cloud-native security controls, integrating them into CI/CD pipelines and enterprise services.
- Company: Allstate focuses on building security controls for cloud platforms and enterprise services.
- Benefits: The role offers hybrid working arrangements and opportunities for professional growth.
- Other info: This position has supervisory responsibilities over a team of engineers.
- Why this job: Join a team that engineers scalable security solutions for cloud-hosted workloads.
- Qualifications: Minimum 3+ years in software or security engineering with hands-on cloud experience required.
The predicted salary is between 60000 - 80000 £ per year.
A Cloud Product Security Engineer at Allstate builds, integrates, and operates security controls as software products that integrate directly into cloud platforms, CI/CD pipelines, and core enterprise services. The role focuses on engineering preventative, detective, and responsive security capabilities across cloud infrastructure, data platforms, and application services, ensuring reliable and scalable security for cloud-hosted workloads.
Key Responsibilities
- Design, build, and operate cloud-native security controls as software products across cloud infrastructure, data platforms, and application services.
- Engineer and maintain cloud security posture management (CSPM) and data loss prevention (DLP) capabilities to continuously detect, assess, and reduce risk in cloud environments.
- Build preventative, detective, and responsive security controls that integrate directly into cloud platforms, CI/CD pipelines, and shared enterprise services.
- Integrate cloud security controls with SIEM and security tooling to generate high-quality signals for detection, investigation, and incident response.
- Support incident handling and response by engineering detection logic, automation, and response mechanisms that improve containment and recovery.
- Apply modern cloud and software engineering practices such as infrastructure as code, automated testing, and CI/CD to ensure security controls are reliable, scalable, and maintainable.
- Collaborate with platform engineers, application teams, and Digital Product Managers to align cloud security controls with architectures and developer workflows.
Essential Skills
- All applicants must demonstrate a legal right to work in the UK. Allstate is not providing sponsorship for this vacancy.
- Minimum of 3+ years of professional software or security engineering experience, including ownership of production systems in cloud environments.
- Hands‑on experience engineering security controls within public cloud platforms (e.g., AWS and/or Azure) across infrastructure, platform services, or application-level integrations.
- Background building or integrating CSPM, data protection, or DLP capabilities as engineered solutions.
- Understanding of cloud-native architectures and services and how security controls integrate into them.
- Capability to engineer preventative, detective, and responsive security capabilities, including detection logic, automation, or response workflows.
- Practical application of modern engineering practices such as infrastructure as code, automated testing, CI/CD, and operational feedback loops.
- Ability to collaborate effectively with platform engineers, application teams, and security partners to deliver cloud security outcomes.
Desirable Skills
- Working knowledge of cloud service provider security services and patterns.
- Practical exposure to advanced CSPM techniques, including policy-as-code, drift detection, and automated remediation.
- Experience with data classification, data handling, or data protection strategies supporting DLP in cloud-hosted systems.
- Familiarity with security telemetry, logging pipelines, and SIEM platforms for detection, investigation, and incident response.
- Hands‑on involvement in incident response or post‑incident analysis from an engineering perspective.
- Exposure to infrastructure-as-code and cloud automation tooling for deploying, configuring, and securing cloud resources at scale.
- Understanding of secure design principles for cloud-native and distributed systems, including identity-centric and least-privilege approaches.
- Proficiency in one or more modern programming languages (e.g., Python, Java, JavaScript) with the ability to write, review, and maintain production-quality code.
Supervisory Responsibilities
This role has supervisory responsibilities and serves as the first-level manager for a team of engineers.
Closing Date
Monday 22nd June 2026 11:59pm
Product Engineers -Cloud (Multiple Levels) Hybrid employer: Allstate NI
Allstate is committed to enhancing cloud security through innovative engineering practices. Located in the UK, they offer hybrid work options and focus on developing cutting-edge security solutions. The team collaborates closely with platform engineers and application teams to ensure robust security outcomes.