Jobedly Post a Job

Senior Incident Handler

Allstate · Remote
RemoteFull-timeGeneralSenior$120,000–$193,725/yr
Apply on Jobedly ⚡ One-click AI Apply

About the Senior Incident Handler role

Senior Incident Handler positions focus on delivering results in their domain. This page aggregates open Senior Incident Handler roles and what employers typically expect.

At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection. **Job Description** We're rebuilding incident response from the ground up—and we want a proven responder to help lead the way. This is a chance to bring your hard-won expertise into a next-generation Security Operations program at Fortune 100 scale, where rapid response, automation, and AI-driven investigation are core to how we operate. As our Senior Incident Handler, you'll be the technical anchor for our most significant security events—driving the response, raising the bar on how we work, and helping mature the team toward a formal, scalable incident command model we're building for the future. If you've handled the incidents that make headlines (or quietly prevented them from becoming headlines), bring the instincts of a seasoned incident commander, and can move seamlessly from the server room to the boardroom, this is where your experience turns into real influence. ## **What You''ll Own** - **Incident Handling & Response Leadership:** Serve as the lead responder during critical incidents—owning the full lifecycle from detection through containment, eradication, and recovery. You'll help run the war room, coordinate responders, and make confident calls with incomplete information. - **Cross-Functional Coordination:** Unify analysts, infrastructure, application owners, legal, comms, and third-party partners into a single, fast-moving response. Relentless focus on reducing dwell time and mean-time-to-respond. - **Executive Communication:** Be a trusted voice during high-severity events—translating fast-moving technical realities into clear business impact for stakeholders up to the C-suite. You build calm and confidence when it matters most. - **Deep Threat Investigation:** Lead advanced investigations into malware, identity compromise, ransomware, and targeted attacks. Analyze logs, network, and forensic data to expose attacker tradecraft (lateral movement, persistence, exfiltration) and hunt down what others miss—leveraging EDR/XDR, SIEM, and cloud telemetry. - **AI & Automation Leadership:** Help modernize our SOC by putting cutting-edge automation and AI-assisted tooling to work—accelerating triage and enrichment without sacrificing human judgment. - **Team Uplevel & Continuous Improvement:** Raise the standard of how the team responds—sharpening detections, playbooks, and controls through meaningful after-action reviews, and helping shape the practices that will underpin our future incident command function. ## **What You Bring** - **Battle-tested IR experience:** 5+ years in cybersecurity operations or incident response, with a track record of leading complex, enterprise-scale incidents end-to-end. Financial services or insurance experience is a plus—but great responders come from everywhere. - **Command-level instincts:** Demonstrated ability to act as an incident commander or technical lead in high-stakes moments—running major bridge calls and making decisive calls fast. You bring the judgment that helps a team operate like a mature command function. - **Technical depth:** Strong command of network security, EDR/XDR, log and forensic analysis, and threat hunting across on-prem and cloud. Comfortable with SIEM, forensics tooling, and scripting/automation (Python, PowerShell). - **Communication range:** Exceptional written and verbal skills; equally credible with engineers and executives. - **Automation mindset:** Enthusiasm for SOAR, ML-based tooling, and LLMs to elevate response workflows. - **Credentials:** CISSP, GCIA, GCIH, GCFA, OSCP or other certifications preferred. ## **Why This Role** Yo…

Salary estimate

$120,000 – $193,725/yr
Provided by the employer.

Skills for this role

PythonCommunicationLeadershipSecurityAutomation

Resume tips for Senior Incident Handler applicants

Interview preparation

Prepare concrete STAR-format stories that show Senior Incident Handler outcomes you drove.

Research the employer's product and recent news before the interview.

Be ready to explain how you'd approach a typical Senior Incident Handler problem end to end.

Have thoughtful questions ready about the team, tools and success metrics.

About Allstate

Allstate is actively hiring on Jobedly. Explore their open roles and what it's like to work there.

Apply on Jobedly ⚡ One-click AI Apply

Similar jobs

Companies hiring for similar roles