Jobs and Careers
NE

Senior Associate - Security Analyst

New York Life Insurance Co
United Statesfull_timeVerifiedPosted 18 Dec 2023
💰 $160,000/yr($105,000/yr$160,000/yr)

About the role

Location Designation: Hybrid 

 

 

When you join New York Life, you’re joining a company that values career development, collaboration, innovation, and inclusiveness. We want employees to feel proud about being part of a company that is committed to doing the right thing. You’ll have the opportunity to grow your career while developing personally and professionally through various resources and programs. New York Life is a relationship-based company and appreciates how both virtual and in-person interactions support our culture.

 

 

New York Life is seeking a Security Analyst role for within the Security Operations Center (SOC). The Security Analyst will be responsible for executing both New York Life’s cyber incident response procedures and assist with Security Information and Event Management (SIEM) operations in a 24/7/365 model.  This role will work with both internal, cross-organizational, and offshore security teams in monitoring, actioning, and improving upon incident response processes for the CTSO Organization. 

 

 

Responsibilities:

 

 

  • Monitor NYL sources of potential security incidents, health alerts with monitored solutions and requests for information. This includes the monitoring of real-time channels or dashboards, periodic reports, email inboxes, ServiceNow ticketing system, telephone calls, chat sessions.

 

  • Follow documented incident-specific procedures to perform triage of potential security incidents to validate and determine needed mitigation.

 

  • Escalate potential security incidents to Line 2 Personnel, implement countermeasures in response to others, and recommend operational improvements.

 

  • Maintain awareness of the NYL’s technology architecture, known weaknesses, the architecture of the security solutions used for monitoring, imminent and pervasive threats as identified by NYL threat intelligence, and recent security incidents.

 

  • Provide advanced analysis of the results of the monitoring solutions, asses escalated outputs and alerts from Level 1 Analysts

 

  • Perform peer reviews and consultations with Level 1 Analysts regarding potential security incidents.

 

  • Provide advice and guidance on the response action plans for information risk events and incidents based on incident type and severity.

 

  • Devise and document new procedures and runbooks/playbooks as directed.

 

  • Maintain compliance with processes, runbooks, templates and procedures-based experience and best practices.

 

  • Provide malware analysis (executables, scripts, documents) to determine indicators of compromise, and create signatures for future detection of similar samples.

 

  • Demonstrate knowledge of IBM QRadar SIEM navigation, administration, and implementation.

 

  • Continuously improve the vigilance service by identifying and correcting issues or gaps in knowledge (analysis procedures, playbooks, NYL network models), false positive tuning, identifying, and recommending new or updated tools, content, countermeasures, scripts, plug-ins, etc.

 

  • Scripting, regex, parser code writing to integrate various log sources along with SIEM tool for monitoring and analysis.

 

  • Developing actionable use cases to detect, triage, investigate and remediate based on latest threat actor trends, including actual technical implementation of parsing log sources creating, validating, and testing alerting queries to reduce false positives.

 

  • Leverage previous experiences, share best practices, and create innovative solutions to push user adoption and maximize the value of SIEM.

 

  • Have a pragmatic approach to dealing with situations where confidentiality is important or where our work is of a sensitive nature. Helping maintain our NYL’s strong professional relationships is integral to our business.

 

  • Maintain a solid understanding of the NYL’s culture, environment (people, process, technology), goals, and security initiatives and communicate all to the engagement team.

 

  • Identify and recommend operational improvements to the NYL, drawing on SOC operational experience and industry specific knowledge of risks.

 

  • Seek opportunities and offer guidance on how to improve SOC service delivery methodology including owning and driving internal improvement initiatives.

 

  • Perform the cyber threat research and knowledge acquisition activities (such as malware, zero-day exploits, botnets, phishing sites etc.)

 

  • Actively seek self-improvement thr

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

New York Life Insurance Co

View company profile →