Senior Threat Hunter

1 day ago


Ind Blr Sez Rd Th Th Floor, India Allstate Full time ₹ 12,00,000 - ₹ 36,00,000 per year

At Allstate, great things happen when our people work together to protect families and their belongings from life's uncertainties. And for more than 90 years our innovative drive has kept us a step ahead of our customers' evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection. 

Job Description

The Threat Assessment and Incident Response Expert leads the development and execution of cybersecurity threat assessments, penetration testing, and incident response plans and procedures for multiple areas; directs forensic and technical investigations, and advises governance, technical, and business leadership on results, vulnerabilities, and solutions to mitigate.

The Allstate Information Security (AIS) department is responsible for managing cyber security at Allstate.  This includes Governance/Risk/Compliance, Access Management, Network Security, and Threat Response Services.  The department is responsible for ensuring confidentiality, integrity, and availability of Allstate systems.

We are seeking an experienced Threat Hunter to perform intelligence-driven network defense supporting the monitoring and incident response capabilities. The role will involve analysis of large amounts of data from vendors and internal sources, including various indicator feeds, Splunk, and several threat intelligence tools, etc. The candidate will perform the functions of threat hunting and serve as a liaison for Threat Services for the Global Security Fusion Center, and mentor the incident handling and forensics teams. 

Primary Responsibilities:

  • Design and run custom analysis models on security event information to discover active threats
  • Identify (hunting) security nuances and abnormalities in the environment
  • Providing mentorship and support to teammates to help enrich and develop others in the team and within other areas of the GSFC regarding threat hunting
  • Develop use cases and actionable content to identify security variants that are currently not alerted within the environment
  • Lead projects and assignments
  • Custom tool design to assist in analysis and investigations
  • Perform as an Information Security SME in four of the following areas:
    • Threat Intelligence
    • Incident Response
    • Log analysis (statistical modeling, correlation, pattern recognition, etc.)
    • Microsoft platform (Server, workstation, applications)
    • Open Systems platforms (Linux, UNIX, VM Ware ESX)
    • Web Application
    • Networking (firewalls, IDS/IPS, packet capture)
    • Databases (Oracle, SQL Server, DB2, IMS)
    • SIEM
    • Reverse Engineering / Malware analysis
  • Collaborate and support outside teams and organizations to enhance the threat hunting service offering
  • Communication/rapport with other divisions and various peers
  • Capable of identifying need & driving solutions, and providing guidance, in an autonomous manner
  • Assist with compiling metrics and reporting of the service offering
  • Lead projects and deliverables with limited oversight and day to day guidance

Qualifications

Essential Criteria

  • Bachelors and/or Masters Degree in Engineering, Computers Science, or related field/experience (4+ years)
  • 4+ years overall technical experience in either threat hunting, threat intelligence, incident response, security operations, or related information security field
  • Deep understanding of common network and application stack protocols, including but not limited to TCP/IP, SMTP, DNS, TLS, XML, HTTP, etc.
  • Advanced experience with security operations tools, including but not limited to:
    • SIEM (e.g. Splunk, ArcSight, Sentinel)
    • Network analysis/information (e.g. NetWitness, PaloAlto, Shodan, Censys)
    • Signature development/management (e.g. Spunk rules, Snort rules, Yara rules)
    • EDR solutions (e.g. CrowdStrike, Tanium, Carbon Black)
    • Malware Analysis (e.g. Sandbox, Disassembler, IDA Pro, Ghidra, Debugger, OllyDbg, ReversingLabs, Secure Malware Analytics)
    • Threat Intelligence (RecordedFuture, ThreatConnect, Maltego, ZeroFox)
  • Broad experience with various common security infrastructure tools (NIDS, HIPS, EDR, etc.)
  • Experience hunting in AWS and/or Azure environments

Desirable Criteria

  • Excellent analytical and problem-solving skills, a passion for research and puzzle-solving
  • Strong communication (oral, written, presentation), interpersonal and consultative skills
  • Deep understanding of large, complex corporate network environments
  • Knowledge or experience in penetration testing, ethical hacking, exploit writing, and/or vulnerability management
  • Knowledge or experience in application design/engineering, including but not limited to programming/scripting, Windows/Linux system administration, RDBMS/NoSQL database administration, etc.
  • Scripting experience related to system administration and security operations (Python, Bash, PowerShell, Perl, C/C++)
  • Recent experience with malware analysis and reverse engineering
  • Strong organization and documentation skills
  • Obtained certifications in several of the following: SANS GIAC courses, CEH, CISSP, OSCP, or tool-specific certifications

Primary Skills

Customer Centricity, Digital Literacy, Inclusive Leadership, Learning Agility, Results-Oriented

Shift Time

Recruiter Info

Yateesh

About Allstate

Joining our team isn't just a job — it's an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo. One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact.

The Allstate Corporation is one of the largest publicly held insurance providers in the United States. Ranked No. 84 in the 2023 Fortune 500 list of the largest United States corporations by total revenue, The Allstate Corporation owns and operates 18 companies in the United States, Canada, Northern Ireland, and India. Allstate India Private Limited, also known as Allstate India, is a subsidiary of The Allstate Corporation. The India talent center was set up in 2012 and operates under the corporation's Good Hands promise. As it innovates operations and technology, Allstate India has evolved beyond its technology functions to be the critical strategic business services arm of the corporation. With offices in Bengaluru and Pune, the company offers expertise to the parent organization's business areas including technology and innovation, accounting and imaging services, policy administration, transformation solution design and support services, transformation of property liability service design, global operations and integration, and training and transition.

Learn more about Allstate India here.


  • Threat Hunter

    2 weeks ago


    Ind – Pune Sez (All Floors Except Th And Th), India Allstate Solutions Pvt Ltd Full time ₹ 6,00,000 - ₹ 18,00,000 per year

    Threat Hunter At Allstate, great things happen when our people work together to protect families and their belongings from life's uncertainties. And for more than 90 years our innovative drive has kept us a step ahead of our customers' evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in...

  • Senior Consultant

    1 day ago


    th Floor- Mumbai (Ruby), India Legal operations Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Requisition Id : As a global leader in assurance, tax, transaction and advisory services, we hire and develop the most passionate people in their field to help build a better working world. This starts with a culture that believes in giving you the training, opportunities and creative freedom. At EY, we don't just focus on who you are now, but who you can...

  • Senior Consultant

    1 day ago


    th Floor- Mumbai (Ruby), India Legal operations Full time ₹ 45,00,000 - ₹ 70,00,000 per year

    Requisition Id : As a global leader in assurance, tax, transaction and advisory services, we hire and develop the most passionate people in their field to help build a better working world. This starts with a culture that believes in giving you the training, opportunities and creative freedom. At EY, we don't just focus on who you are now, but who you can...


  • Gera Commerzone SEZ, Pune, India Barclays Full time ₹ 1,50,00,000 - ₹ 3,00,00,000 per year

    Job DescriptionPurpose of the roleTo monitor the performance of operational controls, implement and manage security controls and consider lessons learnt in order to protect the bank from potential cyber-attacks and respond to threats. AccountabilitiesManagement of security monitoring systems, including intrusive prevention and detection systems, to alert,...


  • IND-BLR-Divyasree Technopolis, India London Stock Exchange Group Full time ₹ 6,50,000 - ₹ 8,00,000 per year

    Role PurposeThe Cyber Security Engineering Vulnerability & Threat Management (VTM) team are looking for an independent, pro-active, and aspiring individual who is committed to making a meaningful contribution, as a VTM Analyst. They will play a supporting role utilising their technical experience to enhance VTM solutions that best fit our business...


  • Bangalore, IND; Mohali, IND, India Zscaler Softech Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Senior Security Researcher - Automation About Zscaler Serving thousands of enterprise customers around the world including 45% of Fortune 500 companies, Zscaler (NASDAQ: ZS) was founded in 2007 with a mission to make the cloud a safe place to do business and a more enjoyable experience for enterprise users. As the operator of the world's largest security...


  • Bangalore, IND, India Zscaler Softech Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Senior Security Researcher - RSH Tickets/Evening Shift (6pm to 3 am IST) About Zscaler Serving thousands of enterprise customers around the world including 45% of Fortune 500 companies, Zscaler (NASDAQ: ZS) was founded in 2007 with a mission to make the cloud a safe place to do business and a more enjoyable experience for enterprise users. As the...


  • IND-Bangalore, India Ecolab Food Safety & Hygiene Solutions Private Limited Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Sr Security Engineer - Product Security Job Position Senior Security Engineer – Product SecurityLocation: Bangalore, KarnatakaExperience: 6–8 YearsDepartment: Information SecurityEmployment Type: Full-Time Overview Ecolab's Information Security team is seeking a Senior Security Engineer with strong expertise in Product Security to lead and...


  • th Floor, Tower -, Phoenix Equinox, Telangana, Hyderabad, India Experian Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Company Description Experian is a global data and technology company, powering opportunities for people and businesses around the world. We help to redefine lending practices, uncover and prevent fraud, simplify healthcare, create marketing solutions, and gain deeper insights into the automotive market, all using our unique combination of data, analytics and...


  • Bangalore, IND, India Zscaler Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Our Engineering team built the world's largest cloud security platform from the ground up, and we keep building. With more than 100 patents and big plans for enhancing services and increasing our global footprint, the team has made us and our multitenant architecture today's cloud security leader, with more than 15 million users in 185 countries. Bring your...