Summary
New York Life is a financial services and insurance company focused on technology-, data-, and AI-enabled solutions. The Senior Associate will support cybersecurity regulatory compliance certifications, examinations, reporting, and regulatory requests by coordinating stakeholders, reviewing evidence, maintaining trackers and repositories, and supporting SEC and FINRA compliance reporting.
Responsibilities
- Maintaining a detailed tracker of state cybersecurity requirements, including aligned compliance documentation, evidence source, due dates, approval dates, and key decisions and year-over-year changes
- Reviewing the Tracker daily to ensure timely responses and reporting weekly to the CRC team on the overall status of the certification process
- Communicate and coordinate with all stakeholders involved in the annual certification process, including internal teams, evidence providers, reviewers, and approvers
- Reviewing all responses and evidence for accuracy, completeness, and alignment to state requirements and providing guidance to owners on applicable evidence, as needed
- Organizing all responses and evidence in the CRC SharePoint site for review and approval
- Managing the internal DocuSign sign-off process, including creating templates for executives to review and approve all evidence, tracking responses, and sending reminder notifications
- Collaborating with the CRC Lead on an analysis following completion of the certifications to identify and incorporate improvement opportunities to the procedures consulting with key stakeholders
- Serving as a liaison between state examiners, Legal and the Cybersecurity and Technology teams
- Assessing exam requests and assigning appropriate control owners for response
- Creating and maintaining a tracker of all requests, due dates, owners, and responses; follow-up with owners, as needed
- Reviewing all responses and evidence for accuracy, completeness, and consistency
- Collaborating internally to leverage evidence across various reviews and reporting activities
- Maintaining a repository of all regulatory responses and documents provided and sources/key contacts
- Organizing responses and evidence for review and approval by senior management and Legal teams
- Supporting quarterly compliance reporting activities by coordinating the collection, validation, and maintenance of cybersecurity documentation and evidence demonstrating adherence to SEC and FINRA requirements
Skills
- Bachelor's degree in Information Security/Technology, Cybersecurity, Risk Management, or a related field; or equivalent work experience
- 3+ years of experience in cybersecurity risk, technology risk, IT audit, regulatory compliance, or related Governance, Risk, and Compliance (GRC) functions, preferably within financial services or insurance environments
- Proven experience supporting IT / cybersecurity audits, regulatory examinations, MAR/SOX compliance activities, or related reviews
- Demonstrated knowledge of Information Security principles, controls, and technology risk management sufficient to independently assess compliance evidence, identify gaps or inconsistencies, and recommend documentation that more effectively demonstrates compliance
- Demonstrated ability to analyze complex information, manage competing priorities, and work independently with limited oversight
- Strong organizational, project management, written communication, and stakeholder management skills
- Proficiency using Microsoft 365, particularly Teams and SharePoint
- Familiarity with AI Generative tools, such as ChatGPT and Copilot
- Experience with DocuSign administration and workflow management
Qualifications
Must Haves
- Bachelor's degree in Information Security/Technology, Cybersecurity, Risk Management, or a related field; or equivalent work experience
- 3+ years of experience in cybersecurity risk, technology risk, IT audit, regulatory compliance, or related Governance, Risk, and Compliance (GRC) functions, preferably within financial services or insurance environments
- Proven experience supporting IT / cybersecurity audits, regulatory examinations, MAR/SOX compliance activities, or related reviews
- Demonstrated knowledge of Information Security principles, controls, and technology risk management sufficient to independently assess compliance evidence, identify gaps or inconsistencies, and recommend documentation that more effectively demonstrates compliance
- Demonstrated ability to analyze complex information, manage competing priorities, and work independently with limited oversight
- Strong organizational, project management, written communication, and stakeholder management skills
Nice to Haves
- Proficiency using Microsoft 365, particularly Teams and SharePoint
- Familiarity with AI Generative tools, such as ChatGPT and Copilot
- Experience with DocuSign administration and workflow management
Benefits
- Hybrid - 3 days per quarter
- Employees are eligible for an annual discretionary bonus.
- Employees may also be eligible to participate in an incentive program.
- Leave programs
- Adoption assistance
- Student loan repayment programs