All jobs

Exposure Intelligence Analyst – Cloud Platforms (AWS / Azure / GCP / Cloud Posture)

Allstate9h ago
United StatesRemote$100K–$170.5KFull-timeMid Level3+ yrs exp

Top focus

Cloud EngineerAws EngineerAzure EngineerGcp EngineerCloud Architect

At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection.

Job Description Exposure Intelligence Analyst – Cloud Platforms (AWS / Azure / GCP / Cloud Posture) Business Title: Lead Consultant- Threat & Incident Response Team and overall work scope The team operates within a newly established Exposure Management function in the broader cybersecurity organization, focused on modernizing how the enterprise identifies, prioritizes, and mitigates security vulnerabilities shifting from traditional patch approaches to a more strategic focus on true business risk and exploitability Individual Contributor/ Lead Consultant roles are designed to bring in deep domain expertise (network, endpoint, cloud, identity, infrastructure, etc.) to bridge the gap between security insights and practical remediation strategies The Exposure Intelligence Analyst – Cloud Platforms is the SME responsible for identifying and prioritizing exposure risk across cloud services (AWS, Azure, GCP), including cloud IAM, posture misconfigurations, insecure architectures, and cloud-native control gaps.

The role applies CTEM principles to identify exploitable conditions and collaborate with cloud engineering teams to drive rapid and durable exposure reduction. What’s exciting about this role: Help secure modern cloud environments by identifying exploitable misconfigurations and attack paths across AWS, Azure, and GCP, using AI‑enhanced insights to prioritize and remediate the exposures that matter most.

Ideal Candidate: Experienced cloud security or engineering professional with deep expertise across AWS, Azure, or GCP environments. Has spent years building or securing cloud platforms and understands identity, misconfigurations, and cloud architecture risks, able to identify, validate, and reduce high-impact cloud exposures.

Success Measures Reduced cloud misconfiguration-driven exposure and improved guardrail compliance. Faster closure of exploitable cloud attack paths. Improved signal quality and prioritization accuracy for cloud findings. Key Responsibilities (Core + Domain) Exposure Intelligence (Core) Correlate vulnerability and posture signals into actionable exposure intelligence.

Identify attack paths spanning cloud control planes, identity privileges, and data access pathways. Create clear prioritization and remediation guidance; track closure outcomes. Cloud Platforms (Domain) Own SME coverage for cloud exposure: IAM misconfigurations, excessive privileges, insecure storage, network exposure, workload security, and posture drift.

Identify systemic patterns: role sprawl, weak guardrails, misconfigured service endpoints, risky trust relationships, insecure defaults. Partner with cloud platform teams to validate fixes and reduce repeated exposure creation. Required Qualifications 3+ years in cloud security, cloud engineering, security operations, or exposure management.

Experience with at least one major cloud provider (AWS/Azure/GCP) and cloud security fundamentals. Ability to translate technical cloud findings into business risk prioritization. Preferred Qualifications Cloud posture management and architecture security Hands-on experience with cloud posture management, cloud IAM security, and cloud logging/telemetry.

Experience evaluating cloud attack paths and privilege escalation scenarios. Scripting/query skills for validation (Python/KQL/SQL). Skills Cloud Application Security, Cloud Security, Cyber Incident Response, Exposure Management, IT Security Operations, Penetration Testing, Root Cause Analysis (RCA), Threat Assessment Compensation Compensation offered for this role is 100,000.00 - 170,500.00 annually and is based on experience and qualifications.

The candidate(s) offered this position will be required to submit to a background investigation. Joining our team isn’t just a job — it’s an opportunity. One that takes your skills and pushes them to the next level. One that encourages you to challenge the status quo.

One where you can shape the future of protection while supporting causes that mean the most to you. Joining our team means being part of something bigger – a winning team making a meaningful impact. Allstate generally does not sponsor individuals for employment-based visas for this position.

Effective July 1, 2014, under Indiana House Enrolled Act (HEA) 1242, it is against public policy of the State of Indiana and a discriminatory practice for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component.

For jobs in San Francisco, please click “ here ” for information regarding the San Francisco Fair Chance Ordinance. For jobs in Los Angeles, please click “ here ” for information regarding the Los Angeles Fair Chance Initiative for Hiring Ordinance.

To view the “EEO Know Your Rights” poster click “ here ”. This poster provides information concerning the laws and procedures for filing complaints of violations of the laws with the Office of Federal Contract Compliance Programs. To view the FMLA poster, click “ here ”.

This poster summarizing the major provisions of the Family and Medical Leave Act (FMLA) and telling employees how to file a complaint. It is the Company’s policy to employ the best qualified individuals available for all jobs. Therefore, any discriminatory action taken on account of an employee’s ancestry, age, color, disability, genetic information, gender, gender identity, gender expression, sexual and reproductive health decision, marital status, medical condition, military or veteran status, national origin, race (include traits historically associated with race, including, but not limited to, hair texture and protective hairstyles), religion (including religious dress), sex, or sexual orientation that adversely affects an employee's terms or conditions of employment is prohibited.

This policy applies to all aspects of the employment relationship, including, but not limited to, hiring, training, salary administration, promotion, job assignment, benefits, discipline, and separation of employment. Allstate provides a comprehensive technology setup, including a laptop, monitors, headset, keyboard, and mouse.

Employees eligible to work from home also receive a monthly connectivity reimbursement to help offset internet costs. When working from home, you must have a dedicated, private workspace free from distractions, along with appropriate desk and seating.

Reliable internet is required, with minimum speeds of 50 MB download and 5 MB upload.

Required skills

Cloud Application SecurityCloud SecurityCyber Incident ResponseExposure ManagementIT Security OperationsPenetration TestingRoot Cause AnalysisThreat AssessmentPython
Posted on JobRush — the end-to-end AI job-search platform.