Data Management Risk Lead
AllstateAbout the role
At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection.
Job Description
Led by Allstate’s Senior Vice President of Risk and Resilience, the Data Risk and Resilience team ensures that every data-driven business outcome is well-governed, trusted and resilient. The team partners across the Enterprise including all Family of Companies to proactively manage data risk and return, strengthen intelligent data governance and support resilient, responsible data management practices.As a Data Management Risk Lead, you'll shape the enterprise data risk posture by designing policies, standards, and data governance frameworks. These will be used to communicate risk insights surrounding data in a way that drives action, clarity, and alignment across the organization. You will operate at the intersection of policy design, risk governance and executive influence with enterprise storytelling. You'll be responsible for implementing and influencing the Enterprise Risk and Return Management frameworks across Allstate. This role is ideal for a professional who can translate complex risks into clear, compelling narratives and advising executives on the risks that matter most. Your passion for data and your understanding of its importance as a critical business asset that needs to be protected and proactively managed will also help in achieving success.
Data Policy, Standards & Governance
Lead the creation, update, and governance of enterprise data risk policies, standards, and control frameworks.
Ensure documents are clear, actionable, aligned to regulatory requirements, and practical for business teams to implement.
Partner with Legal, Compliance, Security, Technology, and Business Architecture to ensure cross-functional alignment.
Risk Reporting & Communication
Develop and deliver enterprise risk reports, dashboards, and heat maps.
Facilitate discussions with business leaders, risk owners, and governance committees.
Make complex ideas simple, memorable, and aligned with the organization’s strategy.
Executive Storytelling & Persuasion
Craft and pitch executive-ready storylines for CEO, ERRC, ORRC, Board, and senior stakeholders.
Translate technical or operational risk topics into compelling narratives that illuminate impact, urgency, and value.
Build crisp visuals, briefs, and talking points that drive real decision-making.
Assist in the development of a holistic view of risk and return, apprised of business strategies, results and challenges.
Risk Strategy, Assessment & Advisory
Identify, assess, and prioritize enterprise risks across operational, technology, data, regulatory, financial, and emerging AI/automation domains with 1st Line leadership.
Advise senior leaders on top risks, root causes, exposure levels, and recommended controls.
Monitor risk trends and emerging threats; synthesize complex information into actionable insights.
Cross-Functional Collaboration
Work closely with 1st line leadership including support areas (Technology, Legal, Compliance, HR)
Support risk workshops, tabletop exercises, and scenario planning activities.
Strengthen data risk culture by coaching teams on frameworks, controls, and good risk hygiene.
Experience
5 or more years of experience in Enterprise Risk Management, Risk & Resilience, Operational Risk, Compliance, Internal Audit, or related field. (Preferred)
Strong technical and regulatory writing skills as it relates to writing policies, standards, and governance frameworks.
Exceptional verbal and written communication skills; demonstrated ability to build executive-ready storylines
Experience translating complex risks into actionable strategies and clear recommendations.
Familiarity with risk registers, control frameworks, regulatory expectations, and risk taxonomies.
Experience with data, technology, cyber, or AI-related risks is a plus (but not required)
Professional certification (e.g., CRISC, CISA, PMP, GRC certifications) are considered a plus
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s