Jobs and Careers
NE

Senior Associate - SOC Engineer

New York Life Insurance Co
Remote, any state, US, United StatesRemotefull_timeVerifiedPosted 9 Nov 2025
💰 $172,500/yr($121,000/yr$172,500/yr)

About the role

 

Location Designation: Hybrid - 3 days per quarter 

 

 

As part of Technology, you'll have the opportunity to contribute to groundbreaking initiatives that shape New York Life's digital landscape. Leverage cutting-edge technologies like Generative AI to increase productivity, streamline processes, and create seamless experiences for clients, agents, and employees. Your expertise fuels innovation, agility, and growth — driving the company's success. 

 

New York Life is seeking a skilled and motivated SOC Engineer to design, implement, and support the tools and integrations that enable the Security Operations Center (SOC). This role will focus on engineering and automation activities across the SOC technology stack, including SIEM, SOAR, log data pipelines, and integrations with security telemetry sources.

 

The SOC Engineer will work closely with SOC Analysts, Threat Intelligence, and Threat Hunting teams to translate operational requirements into engineering solutions. This includes developing SIEM parsers and use cases, building and deploying SOAR playbooks, enabling new log source integrations, and ensuring the SOC toolset is optimized for detection and response.

 

This position is ideal for a technically hands-on engineer who enjoys building and integrating security technologies that directly empower SOC operations.

 

 

What You'll Do:

Engineering & Integration

  • Design, implement, and maintain SIEM and SOAR platforms, ensuring scalability and reliability.
  • Build and maintain log source integrations and custom parsers to expand SOC visibility.
  • Develop and optimize SIEM use cases, correlation rules, and dashboards.
  • Engineer and automate SOAR playbooks to support incident response workflows.
  • Ensure secure and reliable operation of the log data pipeline, including ingestion, parsing, normalization, and enrichment.

Collaboration & Enablement

  • Partner with SOC Analysts, Threat Intel, and Threat Hunting teams to define detection and response requirements.
  • Translate operational requirements into technical implementations within SIEM and SOAR.
  • Collaborate with IT, application, and infrastructure teams to onboard new log sources and security telemetry.
  • Provide technical expertise and escalation support for SOC operations.

Continuous Improvement

  • Evaluate and implement enhancements to SOC tools and processes to improve detection fidelity and analyst efficiency.
  • Develop and maintain SOC engineering documentation, runbooks, and playbooks.
  • Stay up to date with emerging threats, attacker techniques, and security tool capabilities to evolve detection and response.
  • Identify opportunities for automation to reduce manual effort and accelerate response.

 

 

What You'll Bring:

  • 5+ years of experience in security engineering, SOC operations, or related IT security roles.
  • Hands-on experience with SIEM platforms (e.g., Splunk, Elastic, QRadar, Google SecOps, Azure Sentinel).
  • Strong experience with SOAR tools and playbook development (e.g., Splunk SOAR, Tines, Cortex XSOAR, Swimlane, ServiceNow Security Operations).
  • Proficiency in log data pipeline engineering, parsing, normalization, and enrichment.
  • Familiarity with scripting or automation (Python, PowerShell, Bash, etc.).
  • Familiarity with automating incident response in cloud and hybrid environments through SOAR platforms (Wiz Defend, Tines, etc.)
  • Understanding of detection engineering and use case development based on MITRE ATT&CK.
  • Solid understanding of common networking protocols (e.g., TCP/IP, DNS, HTTP) and infrastructure devices (e.g., routers, switches).
  • Strong experience working with cybersecurity tools such as SIEM, EDR, SOAR, Phishing Protection/Email Security, (Elastic, Splunk, Qradar, Google SecOps, Palo XSOAR, SentinelOne, Crowdstrike, Abnormal.AI, CISCO Ironport, Proofpoint)
  • Strong understanding of cybersecurity concepts such as DLP, IDS/IPS, firewalls, Proxies.
  • Solid understanding of Threat Intelligence, IOCs, and Threat Hunting concepts and procedures.
  • Strong understanding of cloud infrastructure and services, preferably in AWS and AZURE.

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

New York Life Insurance Co

View company profile →