Senior Data Security Engineer - (Hybrid)
Allstate Belfast, Northern Ireland, United Kingdom
Insurance · 10,001+ employees
About the role
The Senior Data Protection Security Engineer will lead the evolution of enterprise data protection by implementing automated, engineering-driven security capabilities across cloud and collaboration environments. This role involves building CI/CD pipelines for policy management, integrating security platforms, and designing guardrails to protect sensitive data.
What they look for
Requirements
Applicants must have at least 4 years of experience in enterprise data protection or security engineering with a strong background in automation and DevSecOps methodologies. Proficiency in Microsoft security ecosystems, scripting languages, and infrastructure-as-code tools is essential for this role.
Benefits
Full description
At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection.
Your role in the team
The Senior Data Protection Security Engineer will lead the evolution of enterprise data protection from a traditional tool administration model to an engineering-driven security capability. This role is responsible for building scalable, automated, and measurable data protection solutions across cloud, SaaS, endpoint, email, and collaboration environments using Policy-as-Code, Security-as-Code, DevOps, and DevSecOps practices.
The successful candidate will bring a proven track record of modernising Data Protection, DLP, CASB, or Information Protection programs by reducing manual processes, increasing automation, and implementing repeatable governance and deployment models. This individual will serve as a key contributor in advancing the organisation's data protection strategy while driving operational excellence, security effectiveness, and business enablement.
For this opportunity, the business is flexible to hire at Senior Consultant, Lead Consultant, and Expert level depending on qualifications & interview evaluation.
Key responsibilities:
- Engineer enterprise DLP controls across endpoint, email, SaaS, cloud storage, collaboration platforms, network, and web channels.
- Modernise DLP policy deployment by moving from manual console-based changes to version-controlled, automated, and repeatable policy-as-code workflows.
- Build CI/CD pipelines for data protection policy lifecycle management, including peer review, automated validation, testing, approval, deployment, and rollback.
- Develop reusable policy templates, detection logic, exception patterns, configuration baselines, and deployment standards across multiple DLP and CASB platforms.
- Automate operational tasks such as policy promotion, configuration drift detection, control validation, reporting, alert enrichment, and recurring health checks.
- Integrate DLP, CASB, data classification, cloud security, identity, SIEM, SOAR, and workflow platforms to improve visibility, response, and enforcement.
- Tune detection logic using data-driven analysis to reduce false positives, improve signal quality, and increase confidence in policy enforcement.
- Design guardrails for sensitive data usage across Microsoft 365, cloud platforms, source code repositories, collaboration tools, SaaS applications, and enterprise endpoints.
- Partner with engineering, cloud, infrastructure, network, compliance, privacy, legal, and business teams to design practical data protection solutions.
- Investigate data protection events, identify root cause, recommend control improvements, and convert lessons learned into automated prevention patterns.
- Define and maintain metrics, KPIs, dashboards, and control evidence that demonstrate risk reduction, policy effectiveness, deployment quality, and operational maturity.
- Support platform upgrades, capability expansions, vendor integrations, and new data protection control patterns using disciplined engineering practices.
Essential Skills:
- All applicants must demonstrate they have a legal right to work in the UK for employment at Allstate. Allstate is not providing sponsorship for this vacancy.
- A minimum of 4 years delivering enterprise Data Protection, Information Protection, Cloud Security, or Security Engineering capabilities within complex organisations.
- Proven experience in Policy-as-Code, Security-as-Code, and DevSecOps methodologies, with a demonstrated ability to automate security control deployment and governance at enterprise scale.
- Track record of replacing manual operational processes with engineering-driven solutions through automation, APIs, Infrastructure-as-Code, and platform engineering practices.
- Advanced knowledge of Data Loss Prevention (DLP), data classification, information protection, and data governance principles.
- Hands-on expertise with Microsoft Purview, Microsoft Information Protection, Defender for Cloud Apps, and the Microsoft 365 security ecosystem.
- Comprehensive understanding of cloud, SaaS, CASB, and enterprise data protection architectures.
- Proficiency in scripting and automation technologies including PowerShell, Python, REST APIs, Terraform, Bicep, YAML, JSON, or comparable tools.
- Demonstrated success in modernising Data Protection, DLP, CASB, or Information Protection programs through automation, standardization, and engineering-driven operating models.
- Proven ability to implement and scale DevOps, DevSecOps, or Platform Engineering practices within security organisations.
- Track record of leading large-scale security initiatives that improve control effectiveness, operational efficiency, and measurable risk reduction.
- Background supporting enterprise-scale cloud, SaaS, or Microsoft 365 environments.
Desirable Skills:
- Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Engineering, or equivalent practical experience.
- Knowledge of regulatory, privacy, and compliance requirements and their implementation through scalable technical controls.
#LI-TR3
#LI-Hybrid
Skills
Cybersecurity, Cyber Security, Data Leakage Prevention Operations, Data Loss Prevention (DLP), Data Loss Prevention (DLP) Operations and Management, Data Loss Protection, Data Security, GRC Platform, GRC Software, IT Governance Risk and Compliance (GRC), Software Development
Shape the Future of Insurance with Cutting-Edge Tech and a People-First Culture
Why join us? Allstate NI is proud to be Allstate’s European Digital Centre of Excellence, a hub for innovation and engineering excellence. We’re recent winners of Best Place to Work in IT (100+ employees) and Best Use of Cloud Services at the Belfast Telegraph IT Awards, and we’ve been recognised for our community and sustainability impact with Platinum in the Northern Ireland Environmental Benchmarking Survey.
We’re a product-driven, cloud-first organisation delivering real outcomes through modern technology, a digital product-centric talent model, and a culture rooted in engineering excellence. Our teams work in cross-functional structures, guided by an outcome-based delivery approach that accelerates speed, agility, and value.
We also invest in you. At Allstate NI, your career growth matters. You’ll have access to our Continuous Learning Hub, designed to support skills development and professional advancement through tailored learning paths, certifications, and mentoring opportunities. Whether you’re deepening technical expertise or exploring leadership roles, we provide the tools and support to help you thrive.
What do you get in return?
As well as receiving a competitive annual salary, our reward package includes:
- Corporate bonus scheme
- Pension scheme
- Annual performance-related pay reviews
- Life assurance and income protection
- Flexible working options
- Hybrid working
- Private medical and dental insurance
- Access to an employee assistance programme
- Discounted gym membership
- Two paid volunteering days each year
- Cycle to work scheme
Be part of a high-performing, socially responsible organisation where your work has purpose, and your growth is supported every step of the way.
Similar roles
-
Lead Strategic Services Consultant (Application Security)
Black Duck Software, Inc. Burlington, Massachusetts, United States · $124K–$185K/yr
-
Cybersecurity & Governance Engineer
CALIBRE Systems, Inc. Washington, District of Columbia, United States · $125K–$145K/yr
-
Cybersecurity Project Manager
Sancorp Consulting LLC Arlington, Virginia, United States · $110K–$170K/yr
-
Lead Application Security/Information Security Engineer
VBest Software Inc Charlotte, North Carolina, United States · $156K–$166K/yr
-
Cybersecurity Specialist (RMF/IL-6) - ACWS
Data Systems Analysts, Inc. Fort Dix, New Jersey, United States · $160K–$170K/yr
-
College Co-Op Cybersecurity
Synovus Columbus, Georgia, United States