Product Security Engineer (Multiple Levels) in Lisburn

Product Security Engineer (Multiple Levels) in Lisburn

Lisburn Full-Time 60000 - 80000 € / year (est.) Home office (partial)
Allstate Northern Ireland

At a Glance

  • Tasks: Design and build security solutions to protect against cyber threats.
  • Company: Join Allstate, a leader in innovative protection for over 90 years.
  • Benefits: Flexible benefits, career growth, and access to world-class learning platforms.
  • Other info: Be part of a socially responsible team that values your growth.
  • Why this job: Make a real impact in cybersecurity while working with cutting-edge technology.
  • Qualifications: 3+ years in cybersecurity risk management and familiarity with regulatory frameworks.

The predicted salary is between 60000 - 80000 € per year.

At Allstate, great things happen when our people work together to protect families and their belongings from life's uncertainties. For more than 90 years, our innovative drive has kept us a step ahead of our customers' evolving needs.

Your role in the team: The Product Security Engineer partners in designing and building security solutions that will balance the need for speed and flexibility of the infrastructure and IaaS/PaaS/SaaS applications, with the need to protect Allstate against ongoing and potential security threats. This role needs to have the aptitude to understand new security strategies. This position has been opened at Senior Consultant II and Lead Consultant.

Key responsibilities:

  • Cyber Risk Assessment & Governance: Lead and execute enterprise, business-unit, and technology-specific cyber risk assessments, including inherent risk identification, control adequacy evaluation, residual risk determination, and risk prioritization. Develop, enhance, and operationalize cyber risk assessment methodologies, frameworks, and assessment artifacts aligned to recognized standards (e.g., NIST CSF, NIST SP 800-53, ISO/IEC 27001, CIS, COBIT). Translate business and technical risks into clear, actionable risk statements, supported by evidence-based control evaluation and impact analysis. Drive risk-based decision-making by clearly articulating risk exposure, control gaps, and mitigation options to stakeholders.
  • Regulatory, Compliance & Standards Alignment: Research, interpret, and apply global and regional cybersecurity regulations and requirements (e.g., NYDFS 500, GLBA, PCI DSS, SOX ITGCs, data protection and privacy regulations, contractual security requirements). Analyze regulatory guidance, enforcement actions, and industry advisories to inform governance programs and risk posture.
  • Program Development & Continuous Improvement: Design, enhance, and execute cybersecurity governance programs, policies, standards, procedures, and control requirements aligned to business and regulatory needs. Identify process gaps, control deficiencies, and maturity weaknesses; recommend risk-based remediation strategies and pragmatic control improvements. Contribute to the evolution of enterprise cybersecurity risk assessment (ECRA) capabilities, including risk taxonomies, metrics, and reporting. Support continuous monitoring and re-assessment of cyber risks as business, technology, and threat landscapes evolve.
  • Stakeholder Communication & Advisory: Act as a trusted risk advisor to technology, engineering, and business leaders by explaining complex cybersecurity and regulatory topics in a practical, business-relevant manner. Develop and deliver risk assessment summaries, executive briefings, and governance reports tailored for senior leadership, risk committees, and audit stakeholders. Provide guidance and mentorship to less-experienced team members on cyber risk assessment techniques, regulatory interpretation, and governance best practices.

Essential Skills:

  • All applicants must demonstrate they have a legal right to work in the UK for employment at Allstate. Allstate is not providing sponsorship for this vacancy.
  • A minimum of 3+ years of experience working with Cybersecurity risk management concepts (threats, vulnerabilities, impact, likelihood, controls).
  • Cloud, SaaS, and third-party risk considerations.
  • Identity & access management, data protection, network security, vulnerability management, and secure SDLC concepts.
  • A minimum of 1 year working with one of either NIST CSF, NIST SP 800-53, ISO, CIS Controls, COBIT Regulatory frameworks relevant to financial services, insurance, or regulated industries.

Desirable Skills:

  • Certified in CRISC, CISM, CISSP, CISA.
  • Experienced in large, complex, and regulated environments.

Supervisory Responsibilities: This job does not have supervisory duties.

Why join us? Allstate NI is proud to be Allstate's European Digital Centre of Excellence, recent winners of 'Best Use of Cloud Services' at the Belfast Telegraph IT Awards 2024, and recognised for our community and sustainability impact at the 2024 Business in the Community Awards and Gold accreditation for Environmental Responsibility. We're a product-driven, cloud-first organisation delivering real outcomes through modern technology, a digital product-centric talent model, and a culture rooted in engineering excellence. Our teams work in cross-functional structures, guided by an outcome-based delivery approach that accelerates speed, agility, and value.

We offer:

  • A generous, flexible benefits package including annual leave, healthcare and dental cover, pension, and lifestyle discounts.
  • Access to world-class learning platforms and award-winning L&D.
  • Clear career paths, internal mobility, and a strong focus on growth.
  • A people-first culture with flexible working options.
  • Be part of a high-performing, socially responsible organisation where your work has purpose, and your growth is supported every step of the way.

Statement on Fair Employment and Equal Opportunities: Allstate NI wishes to ensure equal opportunity is given to all job applicants. This company will not discriminate on the grounds of race, gender (including gender reassignment status), sexual orientation, religious belief, political opinion, marital status, age or disability. We are an equal opportunities employer. We welcome applications from all suitably qualified persons. However, as women are currently under-represented in our workforce, we would particularly welcome applications from women. All appointments will be made on merit. Applicants should note Allstate NI complete AccessNI background checks on all candidates offered a position.

Product Security Engineer (Multiple Levels) in Lisburn employer: Allstate Northern Ireland

At Allstate, we pride ourselves on fostering a collaborative and innovative work environment that empowers our employees to excel in their roles. As a Product Security Engineer, you will benefit from a generous and flexible benefits package, access to world-class learning platforms, and clear career paths that support your professional growth. Located in Belfast, our award-winning European Digital Centre of Excellence is committed to making a meaningful impact while prioritising employee well-being and development.

Allstate Northern Ireland

Contact Detail:

Allstate Northern Ireland Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Product Security Engineer (Multiple Levels) in Lisburn

Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Prepare for interviews by researching Allstate's values and recent projects. Show us that you’re not just another candidate but someone who genuinely cares about our mission to protect families and innovate in security solutions.

Tip Number 3

Practice your technical skills and be ready to discuss them in detail. We want to see how you approach problem-solving and risk assessment, so brush up on your knowledge of NIST CSF and other relevant frameworks.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows us you’re serious about joining our team at Allstate.

We think you need these skills to ace Product Security Engineer (Multiple Levels) in Lisburn

Cyber Risk Assessment
Governance Frameworks
NIST CSF
NIST SP 800-53
ISO/IEC 27001
CIS Controls
COBIT

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience with cybersecurity risk management and relevant frameworks. We want to see how your skills align with the role of Product Security Engineer!

Showcase Your Achievements:Don’t just list your responsibilities; share specific achievements that demonstrate your impact in previous roles. Use metrics where possible to show how you’ve contributed to security improvements or risk assessments.

Be Clear and Concise:When writing your application, keep it straightforward and to the point. We appreciate clarity, so avoid jargon unless it’s necessary to convey your expertise in cybersecurity.

Apply Through Our Website:Remember to submit your application through our careers page! It’s the best way for us to receive your details and ensure you’re considered for the role. We can’t wait to hear from you!

How to prepare for a job interview at Allstate Northern Ireland

Know Your Cybersecurity Frameworks

Familiarise yourself with key cybersecurity frameworks like NIST CSF, ISO/IEC 27001, and CIS Controls. Be ready to discuss how you've applied these in past roles, especially in risk assessments and compliance.

Showcase Your Risk Assessment Skills

Prepare to explain your experience with cyber risk assessments. Highlight specific methodologies you've used and be ready to provide examples of how you've identified and mitigated risks in previous positions.

Understand Regulatory Requirements

Brush up on relevant regulations such as PCI DSS and GLBA. Be prepared to discuss how you’ve interpreted and applied these regulations in your work, and how they impact security strategies.

Communicate Clearly and Confidently

Practice articulating complex cybersecurity concepts in a straightforward manner. During the interview, aim to convey your ideas clearly, especially when discussing risk exposure and mitigation options with stakeholders.