Jobs and Careers
NE

Senior Associate - Security Engineer

New York Life Insurance Co
Remote, any state, US, United StatesRemotefull_timeVerifiedPosted 9 Nov 2025
💰 $172,500/yr($121,000/yr$172,500/yr)

About the role

 

Location Designation: Hybrid - 3 days per quarter 

 

 

As part of Technology, you'll have the opportunity to contribute to groundbreaking initiatives that shape New York Life's digital landscape. Leverage cutting-edge technologies like Generative AI to increase productivity, streamline processes, and create seamless experiences for clients, agents, and employees. Your expertise fuels innovation, agility, and growth — driving the company's success.

 

 

The Security Engineer will play a key role in designing, engineering, and maintaining NYL’s cloud and network security capabilities across hybrid environments. This role blends hands-on engineering with solution architecture, ensuring that network and cloud controls are robust, scalable, and aligned with enterprise standards.

 

 

The engineer will support both on-premises and cloud platforms—primarily AWS—integrating modern security solutions into NYL’s infrastructure and application ecosystems. The ideal candidate will bring technical depth across cloud networking, zero trust, and automation, with a strong learning mindset and enthusiasm for innovation. NYL is building the foundation for a secure, AI-enabled, technology-driven future—so curiosity, adaptability, and an eagerness to master emerging tools are essential.

 

 

What You’ll Do:

  • Engineer, configure, and maintain enterprise network and cloud security solutions.
  • Design and implement cloud-native network architectures in AWS using services such as VPC, Transit Gateway, PrivateLink, Network Firewall, WAF, and GuardDuty.
  • Develop and manage segmentation strategies (e.g., Illumio, microsegmentation, Zero Trust principles) to prevent lateral movement and contain threats.
  • Engineer and maintain secure connectivity solutions, including Zscaler, SWG, ZTNA, VPN, and enterprise firewalls (e.g., Palo Alto, Fortinet).
  • Implement and tune cloud security posture management (CSPM), cloud workload protection (CWPP), and AWS Config Guardrails.
  • Integrate network telemetry and cloud logs into enterprise SIEM and threat detection systems.
  • Automate security control deployment using Infrastructure as Code (IaC) tools (e.g., Terraform, CloudFormation).
  • Collaborate with architecture and application teams to embed security into cloud and network design patterns.
  • Support data protection objectives through encryption, tokenization, and secure network routing for sensitive data flows.
  • Contribute to the development of Zero Trust architectures, secure edge connectivity, and hybrid network modernization initiatives.
  • Stay informed about emerging threats, technologies, and AWS security capabilities; recommend improvements to evolve NYL’s security posture.

 

 

What You’ll Bring:

  • Bachelor’s degree in Computer Science, Information Systems, or equivalent experience.
  • 5+ years of hands-on experience in network or cloud security engineering roles.
  • Proven ability to design, deploy, and operate secure hybrid network environments (on-premises + AWS).
  • Deep understanding of AWS security services (IAM, VPC, NACLs, Security Groups, WAF, Network Firewall, GuardDuty, CloudTrail, KMS).
  • Experience with secure connectivity platforms (Zscaler, SWG, ZTNA, VPN, firewalls) and segmentation technologies (Illumio, VLANs, SDN).
  • Strong grasp of Zero Trust networking concepts, PKI, and modern security protocols (SPIFFE, DCR, PKCE).
  • Experience automating security operations through scripting or infrastructure-as-code (Python, PowerShell, Terraform).
  • Understanding of regulatory frameworks and compliance requirements (NYS DFS, NIST CSF, CIS, ISO 27001).
  • Preferred Qualifications
  • Experience designing and implementing Zero Trust architectures at scale.
  • Proficiency with AWS networking and security architecture design patterns, including Transit Gateway, Control Tower, and multi-account segmentation.
  • Familiarity with CSPM and CWPP platforms (e.g., Prisma Cloud, Wiz, Orca).
  • Experience integrating security into CI/CD pipelines and DevSecOps workflows.
  • Knowledge of encryption technologies, HSMs, and key management systems.
  • Exposure to securing containers, serverless, and edge environments.
  • Experience with AI-assisted security tools

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

New York Life Insurance Co

View company profile →