Senior Associate - Security Engineer
New York Life Insurance CoAbout the role
Location Designation: Hybrid - 3 days per quarter
As part of Technology, you'll have the opportunity to contribute to groundbreaking initiatives that shape New York Life's digital landscape. Leverage cutting-edge technologies like Generative AI to increase productivity, streamline processes, and create seamless experiences for clients, agents, and employees. Your expertise fuels innovation, agility, and growth — driving the company's success.
The Security Engineer will play a key role in designing, engineering, and maintaining NYL’s cloud and network security capabilities across hybrid environments. This role blends hands-on engineering with solution architecture, ensuring that network and cloud controls are robust, scalable, and aligned with enterprise standards.
The engineer will support both on-premises and cloud platforms—primarily AWS—integrating modern security solutions into NYL’s infrastructure and application ecosystems. The ideal candidate will bring technical depth across cloud networking, zero trust, and automation, with a strong learning mindset and enthusiasm for innovation. NYL is building the foundation for a secure, AI-enabled, technology-driven future—so curiosity, adaptability, and an eagerness to master emerging tools are essential.
What You’ll Do:
- Engineer, configure, and maintain enterprise network and cloud security solutions.
- Design and implement cloud-native network architectures in AWS using services such as VPC, Transit Gateway, PrivateLink, Network Firewall, WAF, and GuardDuty.
- Develop and manage segmentation strategies (e.g., Illumio, microsegmentation, Zero Trust principles) to prevent lateral movement and contain threats.
- Engineer and maintain secure connectivity solutions, including Zscaler, SWG, ZTNA, VPN, and enterprise firewalls (e.g., Palo Alto, Fortinet).
- Implement and tune cloud security posture management (CSPM), cloud workload protection (CWPP), and AWS Config Guardrails.
- Integrate network telemetry and cloud logs into enterprise SIEM and threat detection systems.
- Automate security control deployment using Infrastructure as Code (IaC) tools (e.g., Terraform, CloudFormation).
- Collaborate with architecture and application teams to embed security into cloud and network design patterns.
- Support data protection objectives through encryption, tokenization, and secure network routing for sensitive data flows.
- Contribute to the development of Zero Trust architectures, secure edge connectivity, and hybrid network modernization initiatives.
- Stay informed about emerging threats, technologies, and AWS security capabilities; recommend improvements to evolve NYL’s security posture.
What You’ll Bring:
- Bachelor’s degree in Computer Science, Information Systems, or equivalent experience.
- 5+ years of hands-on experience in network or cloud security engineering roles.
- Proven ability to design, deploy, and operate secure hybrid network environments (on-premises + AWS).
- Deep understanding of AWS security services (IAM, VPC, NACLs, Security Groups, WAF, Network Firewall, GuardDuty, CloudTrail, KMS).
- Experience with secure connectivity platforms (Zscaler, SWG, ZTNA, VPN, firewalls) and segmentation technologies (Illumio, VLANs, SDN).
- Strong grasp of Zero Trust networking concepts, PKI, and modern security protocols (SPIFFE, DCR, PKCE).
- Experience automating security operations through scripting or infrastructure-as-code (Python, PowerShell, Terraform).
- Understanding of regulatory frameworks and compliance requirements (NYS DFS, NIST CSF, CIS, ISO 27001).
- Preferred Qualifications
- Experience designing and implementing Zero Trust architectures at scale.
- Proficiency with AWS networking and security architecture design patterns, including Transit Gateway, Control Tower, and multi-account segmentation.
- Familiarity with CSPM and CWPP platforms (e.g., Prisma Cloud, Wiz, Orca).
- Experience integrating security into CI/CD pipelines and DevSecOps workflows.
- Knowledge of encryption technologies, HSMs, and key management systems.
- Exposure to securing containers, serverless, and edge environments.
- Experience with AI-assisted security tools
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s