Senior Incident Handler

Allstate

Confirmed live yesterday High trust
Remote

Quick summary

Work type
Remote
Location
IL
Salary
$120,000–$193,725 / yr
Posted
59 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $164k
This role $157k
$111k most similar roles pay here $206k

This role pays less than 56% of similar roles. Most pay $135,000–$193,000 — the shaded band above. At the midpoint, this role pays about $157k versus about $164k for comparable roles.

Based on 240 similar postings.

Employer

About Allstate

The Allstate Corporation is one of the largest publicly held personal lines insurers in the US, widely recognized for its "You're In Good Hands With Allstate®" slogan.

Allstate currently has 36 open roles on FindRole.

Listed pay typically runs $100,000–$170,500 across 36 roles with salary data.

Most-posted roles

View all roles at Allstate

At a glance

TL;DR · Senior Incident Handler

As a Senior Incident Handler, you will serve as the technical anchor for critical security events within a next-generation Security Operations program. You will lead the full lifecycle of incident handling, from detection through containment and recovery, while coordinating cross-functional teams including legal, infrastructure, and application owners. Your daily responsibilities involve conducting advanced investigations into malware, ransomware, and identity compromise by analyzing logs, network data, and forensic evidence to uncover attacker tradecraft. To succeed, you must possess expertise in EDR, XDR, SIEM, and cloud telemetry, alongside proficiency in Python and PowerShell for automation. You will also drive the integration of AI-assisted tooling and SOAR workflows to accelerate triage. This role addresses the challenge of maturing a scalable incident command model to defend against sophisticated threats within a complex enterprise environment.

What you'll do

  • Lead the full lifecycle of critical incidents from detection through containment, eradication, and recovery.
  • Act as the primary technical anchor and incident commander during high-severity security events.
  • Coordinate cross-functional teams including infrastructure, legal, communications, and third-party partners during active responses.
  • Translate complex technical realities into clear business impact reports for executive leadership and stakeholders.
  • Conduct advanced investigations into malware, identity compromise, ransomware, and targeted attacks using EDR/XDR and SIEM tools.
  • Analyze network and forensic data to identify attacker tradecraft such as lateral movement and exfiltration.
  • Implement AI-driven tooling and automation to accelerate triage and enrichment processes within the SOC.
  • Improve team capabilities by developing playbooks, refining detections, and conducting after-action reviews.

What we're looking for

  • Must have at least 5 years of experience in cybersecurity operations or incident response.
  • Proven track record of leading complex, enterprise-scale incidents from detection through recovery.
  • Demonstrated ability to act as an incident commander and technical lead during high-stakes events.
  • Proficiency in network security, EDR/XDR, log analysis, forensic investigation, and threat hunting.
  • Skilled in using SIEM tools and scripting for automation with Python or PowerShell.
  • Ability to communicate complex technical information clearly to both engineers and executive leadership.
  • Experience with SOAR, machine learning-based tooling, and LLMs to enhance response workflows.
  • Preferred certifications include CISSP, GCIA, GCIH, GCFA, or OSCP.

More like this

Similar roles

Security Engineer, Incident Response

F5 Inc

Remote 7 days ago $132,000$198,000
Incident Response Security Operations (SOC) Threat Hunting Digital Forensics AWS Azure GCP Kubernetes NGINX WAF WAAP CrowdStrike SIEM EDR NIST SP 800-61 ISO 27001 FedRAMP PCI-DSS
5+ yrs exp Remote

Senior Incident Responder, Global CSIRT

Salesforce

Remote (Mclean, VA) 7 days ago $148,500$223,900
Incident Response SOAR CI/CD AWS Azure GCP Windows macOS Linux Malware Analysis Detection Engineering Forensics AI LLM Salesforce Platform SaaS
5+ yrs exp Remote

Senior Incident Commander

Microsoft

46 days ago $119,800$234,700
Cybersecurity Incident Response SIEM Threat Modeling Anomaly Detection Security Operations Center (SOC) Software Development Lifecycle Large-scale Computing Vulnerability Triage Information Security CISSP CISA CISM SANS OSCP Security+
4+ yrs exp

Principal Security Engineer, Incident Response

F5 Inc

Remote 7 days ago $182,200$273,200
Incident Response Cybersecurity AWS Azure GCP Kubernetes WAF WAAP API Gateways DDoS Mitigation SIEM EDR CrowdStrike MITRE ATT&CK FedRAMP NIST SP 800-61 ISO 27001 PCI-DSS
10+ yrs exp Remote

Senior Manager - Response Threat Operations

Pfizer

Collegeville, PA 7 days ago $139,100$231,900
Incident Response Threat Intelligence Digital Forensics Malware Analysis Splunk Wireshark Snort Kali Linux Sift REMnux Python Java C TCP/IP Windows Agile Network Security Cybersecurity
6+ yrs exp Hybrid