Allstate Information Security Cloud Governance Consultant in Irving, Texas
Information Security Cloud Governance Consultant
Apply Now at https://www.applytracking.com/tp/rj6-40ftT_e-K
Job ID :
Irving, TX US
Job Category :
Where good people build rewarding careers.
Think that working in the insurance field can’t be exciting, rewarding and challenging? Think again. You’ll help us reinvent protection and retirement to improve customers’ lives. We’ll help you make an impact with our training and mentoring offerings. Here, you’ll have the opportunity to expand and apply your skills in ways you never thought possible. And you’ll have fun doing it. Join a company of individuals with hopes, plans and passions, all using and developing our talents for good, at work and in life.
**In addition to Irving, TX, we are open to candidates in the Chicago, IL and Charlotte, NC markets to work in our offices in those locations. Strong qualified candidates in other US geographic markets will also be given consideration as potential home-based professionals.
This is your chance to join the team responsible for helping to integrate security into the development of Allstate’s cloud based applications that run and support the largest publicly held personal-lines insurer, which insures more than 17 million households with over 32 billion in annual revenues and 37,000+ employees internationally. The Information Security Cloud Governance Consultant will be part of the Allstate Information Security - Assurance, Policy, Monitoring & Reporting (AIS-APMR) team and lead Cloud Information Security Governance activities. This includes working closely with the product, software, and infrastructure development teams to implement best practices within the cloud based environments. As well as working closely with developers and system architects to diagnose, document, solution, and remediate any deviations from governance standards. Addition responsibility includes but not limited to contributing to the evaluation, recommendations and implementations of cloud security controls in an automated continuous integration/deployment environment.
In addition, this individual will have extensive client interactions relating to technical security controls with a wide range of technology-based functions and business groups. Relevant skills include an understanding of business/technology risk, thought leadership in designing and executing cloud / technology controls that mitigate those risks, and ability to keep up-to date with the latest technologies and potential cyber-threats.
A broad range of professional skills along with strong interpersonal skills will be required for problem-solving, collaboration with virtual cross-functional work groups, along with tracking and reporting of critical gaps to closure & final resolution. This resource is expected serve as a trusted advisor that can clearly articulate Allstate security policies, standards, and guidelines to both technical and business audiences alike.
• Work closely with Application Development, Cloud, Governance, and Compliance teams to help formulate and implement a strategy for cloud based security that is tailored to the specific risks facing the organization, including threat modeling and applications security advisement services.
• Develop and maintain a balanced cloud security governance framework based on industry standards.
• Ensure compliance with society, regulatory, and industry standards for cloud based security.
• Continuously evaluate the organization’s existing cloud security practices, define and measure security-related activities, and demonstrating improvements to the cloud programs within the organization.
• Evaluate business strategies, requirements, and user needs, existing usage cloud platforms, technical capabilities, and overall cloud application maturity, and provides strategic guidance and best-practices based recommendations for implementing governance boards and proven best practices for cloud based application/platform development, deployment, and support.
• Support lead security consultants in promoting and consulting on the positions that help strengthen and secure the organization by either following standards or helping direct others on technology positions.
• Help facilitate review of changes in company processes, standards and technology to ensure the effectiveness of security controls to meet compliance requirements.
• Help consult with stakeholders on requirements for new and existing business / technology solutions to assure compliance to compliance frameworks and internal standards and governing policies and procedures.
• Responsible for building effective working relationships, making sound decisions, successfully making changes, initiating action and achieving results as a trusted advisor.
• Minimum 5 years of experience in secure application/platform development and security
• Minimum 3 years of project management, consulting, and/or application security analyst experience
• Relevant postsecondary education and/or industry standard certifications preferred (i.e., CompTIA, Microsoft, EC-Council, ISACA, ISC2, SANS Institute/GIAC, EMC, Amazon, VMware), AWS Certified Solutions Architect, CompTIA Cloud+ Certification, CISSP, Certificate of Cloud Security Knowledge (CCSK)
• A strong understanding of cloud security governance
• Practical understanding and use of cloud computing and cloud security tools
• Experience with establishing cloud security governance across an organization
• Thorough knowledge of common application vulnerabilities (e.g. OWASP Top 10), attack techniques and remediation tactics/strategies
• A demonstrable passion for application security, general understanding of SDLC processes and key security checkpoints along with software development methodologies
• Must be fluent in reviewing technical reports based on findings
• Strong a self-starter who has the ability to operate independently and demonstrates complete ownership over assigned objectives in a "semi-structured" environment, but also recognizes when guidance is needed
• Strong understanding of IT security best practices by applying depth and breadth of expertise in multiple related disciplines
• Understanding and Passion for Agile/XP/Scrum/Kanban, Test Driven Development built on User Stories and Continuous Integration/Testing/Delivery
• Ability to effectively work with technical and non-technical resources
• Demonstrated success at leading cross-functional projects leveraging SDLC methodology. Basic knowledge of Security Analysis (manual and leveraging automated scanning tools). Familiarity with both static analysis and/or dynamic scanning tools
• Excellent oral/written presentation skills with ability to communicate effectively with senior executive leadership; proficiency in preparation of presentations, analytical reports, and documents regarding program operational status, achievement and performance
• Strong organizational skills, ability to effectively manage multiple, competing projects/priorities while achieving targeted completion results
• Effective written, verbal communication skills - Ability to tailor communication style to audience at hand and write "high quality" documentation and/or presentations is a must
• Ability to stay up to date with the current cybersecurity threat landscape to account for changing circumstances when evaluating security risks
• Ability to develop/enhance partnerships with key stakeholders
• Ability to maintain technical proficiency via self or formal training
• Proficient in MS Office Suite (Word, Excel, PowerPoint, OneNote, Project, Access, Visio) and SharePoint
Good Work. Good Life. Good Hands®.
As a Fortune 100 company and industry leader, we provide a competitive salary – but that’s just the beginning. Our Total Rewards package also offers benefits like tuition assistance, medical and dental insurance, as well as a robust pension and 401(k). Plus, you’ll have access to a wide variety of programs to help you balance your work and personal life -- including a generous paid time off policy.
Learn more about life at Allstate. Connect with us on Twitter at http://jb.al.st/BWGk6 , Facebook at http://jb.al.st/BWGka , Instagram at http://jb.al.st/BWGlO and LinkedIn at https://www.linkedin.com/company/allstate/careers or watch a video at http://jb.al.st/BWGpG .
Allstate generally does not sponsor individuals for employment-based visas for this position.
Effective July 1, 2014, under Indiana House Enrolled Act (HEA) 1242, it is against public policy of the State of Indiana and a discriminatory practice for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component.
For jobs in San Francisco, please click "here" at http://sfgov.org/olse/sites/default/files/FileCenter/Documents/11600-Art%20%2049%20Official%20Notice%20Final%20091114.pdf for information regarding the San Francisco Fair Chance Ordinance.
For jobs in Los Angeles, please click "here" at http://bca.lacity.org/fair-chance for information regarding the Los Angeles Fair Chance Initiative for Hiring Ordinance.
It is the policy of Allstate to employ the best qualified individuals available for all jobs without regard to race, color, religion, sex, age, national origin, sexual orientation, gender identity/gender expression, disability, and citizenship status as a veteran with a disability or veteran of the Vietnam Era.