Senior Associate - Security Operations Center (SOC) Analyst
New York Life Insurance CoAbout the role
Location Designation: Hybrid - 3 days per quarter
Business Unit
Technology, Data, AI and Ventures (TDAV)
Business Unit Overview
Within the Tech, Data, AI, Ventures (TDAV) organization, our work is guided by a shared vision: deploying the power of technology, data, AI and ventures to accelerate sustainable competitive advantage for New York Life's businesses. We build solutions that power how we serve policy owners, agents, advisors and employees while delivering measurable business outcomes.
Across technology, data, AI, cyber, product, digital experience, architecture and infrastructure, TDAV combines the scale and investment of an industry leader, access to leading-edge technologies and the opportunity to help shape how a world-class financial services company competes in the AI era — all backed by the stability and purpose of a mutual company built to last.
Role Overview
The Cyber Security Operations team is seeking a Security Operations Center (SOC) Analyst to help protect New York Life's enterprise technology environment by monitoring, detecting, investigating, and responding to cyber threats across hybrid and cloud environments. This role combines hands-on incident response, cloud security operations, and threat detection to identify and mitigate evolving cyber risks while strengthening the organization's overall security posture.
As a member of the Security Operations Center, you will leverage SIEM, EDR/XDR, cloud-native security technologies, and threat intelligence to investigate security events, conduct threat hunting, and coordinate incident response activities. You will collaborate with security engineering, cloud platform, infrastructure, and application teams to improve detection capabilities, automate response processes, and support a resilient, secure technology environment.
What You'll Do
-
Monitor, investigate, and respond to security alerts and incidents across cloud and on-premises environments using SIEM, EDR/XDR, and cloud-native security platforms, ensuring timely detection, containment, and resolution of cyber threats.
-
Perform threat hunting, malware analysis, and incident investigations involving phishing, ransomware, identity compromise, unauthorized access, and other advanced attack techniques while documenting findings and recommending remediation actions.
-
Analyze security telemetry and logs from cloud platforms, including AWS, Google Cloud Platform (GCP), and cloud security services, to identify indicators of compromise, emerging threats, and opportunities to strengthen security controls.
-
Develop and maintain incident response playbooks, standard operating procedures, and automation workflows while participating in tabletop exercises, security assessments, and continuous improvement initiatives to enhance operational readiness.
-
Collaborate with cross-functional technology and cybersecurity teams to improve cloud security posture, reduce operational risk, leverage AI-enabled security capabilities, and provide actionable reporting to technical and business stakeholders.
What You'll Bring
Required Skills
-
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent practical experience) with 3–4 years of experience in Security Operations, Incident Response, Cyber Defense, or a related cybersecurity discipline.
-
Hands-on experience securing cloud environments using Amazon Web Services (AWS) and/or Google Cloud Platform (GCP), including familiarity with cloud-native security services such as AWS GuardDuty, AWS Security Hub, Microsoft Defender for Cloud, or Google Security Command Center.
-
Experience working with SIEM platforms such as Elastic, Splunk, or Google Chronicle, along with EDR/XDR technologies including CrowdStrike Falcon, SentinelOne, or Palo Alto Cortex XDR.
-
Strong understanding of incident response methodologies, threat detection, log analysis, cloud identity security, MITRE ATT&CK, Cyber Kill Chain, Zero Trust principles, and identity and access management (IAM).
-
Knowledge of networking fundamentals, including TCP/IP, DNS, HTTP/S, VPNs, firewalls, IDS/IPS, proxy technologies, and the ability to investigate cloud-based attacks, privilege escalation, and lateral movement.
-
Experience with scripting or automation using Python, PowerShell, or Bash, strong analytical and communication sk
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s