Business Information Security Officer (hybrid or remote)
AllstateAbout the role
About Us
The world isn’t standing still, and neither is Allstate. We’re moving quickly, looking across our businesses and brands and taking bold steps to better serve customers’ evolving needs. That’s why now is an exciting time to join our team. You’ll have opportunities to take risks, challenge the status quo and shape the future for the greater good.
You’ll do all this in an environment of excellence and the highest ethical standards – a place where values such as integrity, inclusive diversity and accountability are paramount. We empower every employee to lead, drive change and give back where they work and live. Our people are our greatest strength, and we work as one team in service of our customers and communities.
Allstate operate a very flexible hybrid working policy that will allow you to design your working week in collaboration with your manager with a blend of remote and office working for NI based employees as well as condensed working patterns (4 day week/9 day fortnight). Employees based in GB will be employed on a permanent remote working contract.
Join our team and you’ll find challenge and reward in a culture of innovation, support and balance.
Location
Northern Ireland/ Remote, GB
Your role in the team
The Business Information Security Officer (BISO) functions as the security leader for an Area of Responsibility (AOR) the associated product portfolio and technology resources. This role will have dual reporting structure, one reporting to the AoR and one into Allstate Information Security. This individual establishes and drives a business specific Information Security program aligned with the business area risks and the Allstate Corporation Information Security Program.
The BISO serves as the trusted advisor, both to the business and to the Chief Information Security Officer (CISO). This role will liaise between the business and Allstate Information Security (AIS), keeping clear lines of communication including but not limited to; transparency to the business on upcoming security initiatives, reporting of security risks to the CISO and appropriate committees, as well as a key player in the information security incident response process, from identifying impact to the business and to consumers, to helping shape remediation, and developing external and internal message points. In addition, this role will ensure business compliance with the Information Security Policy and Standards while continuously monitoring and reporting on risks and documented exceptions.
Responsibilities include (but are not limited to):
- Establish a documented Information Security Program and supporting strategy for the AoR
- Ensure program is aligned with the AIS Information Security Program, Policies and Standards
- Ensure inclusion of all applicable regulatory, legal and contractual obligations
- Leverage the Enterprise and AoR specific Information Security Risk Assessments to establish and monitor the program
- Update the program annually
- Provide input into the Allstate Corporation Information Security Program, Security Policy and Standards
- Ensure clear lines of communication between AoR and the Chief Information Security Officer
- Provide reporting on the state and efficacy of security controls for their projects and platforms
- Secure ongoing security funding for special/complex projects and evangelize security awareness across the AoR
- Within the AoR, drive Information Security risk management, policy compliance, access management, data protection, education, and awareness
The successful candidate must also demonstrate the following competencies:
- Ability to manage multiple complex priorities and competing agendas without express authority over delivery teams
- Ability to interpret and apply policies and regulations across a large, complex business
- Analytical aptitude with an emphasis on investigative, methodical critical questioning and logical thinking; a data-driven decision maker
- High level of interpersonal skills to interact with leaders at multiple levels and facilitate team interactions
So, what are the essential criteria to apply?
- All applicants must demonstrate they have a legal right to work in the UK for employment at Allstate. Allstate is not providing sponsorship for this vacancy.
- At minimum 5 years’ experience in audit or information security related role
- A minimum of 2 years’ leadership or management experience
- Either achieved or already be in the process of obtaining Security/Risk certification
- Advanced working knowle
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s