Summary
New York Life is a mutual financial services company advancing technology, data, AI, and cybersecurity to support its businesses and customers. The Senior Associate - Security Operations Center (SOC) Analyst will monitor, investigate, detect, and respond to cyber threats across hybrid and cloud environments. The role also involves threat hunting, incident response, cloud security operations, automation, and collaboration with cybersecurity and technology teams to improve the organization’s security posture.
Responsibilities
- Monitor, investigate, and respond to security alerts and incidents across cloud and on-premises environments using SIEM, EDR/XDR, and cloud-native security platforms, ensuring timely detection, containment, and resolution of cyber threats
- Perform threat hunting, malware analysis, and incident investigations involving phishing, ransomware, identity compromise, unauthorized access, and other advanced attack techniques while documenting findings and recommending remediation actions
- Analyze security telemetry and logs from cloud platforms, including AWS, Google Cloud Platform (GCP), and cloud security services, to identify indicators of compromise, emerging threats, and opportunities to strengthen security controls
- Develop and maintain incident response playbooks, standard operating procedures, and automation workflows while participating in tabletop exercises, security assessments, and continuous improvement initiatives to enhance operational readiness
- Collaborate with cross-functional technology and cybersecurity teams to improve cloud security posture, reduce operational risk, leverage AI-enabled security capabilities, and provide actionable reporting to technical and business stakeholders
Skills
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent practical experience) with 3–4 years of experience in Security Operations, Incident Response, Cyber Defense, or a related cybersecurity discipline
- Hands-on experience securing cloud environments using Amazon Web Services (AWS) and/or Google Cloud Platform (GCP), including familiarity with cloud-native security services such as AWS GuardDuty, AWS Security Hub, Microsoft Defender for Cloud, or Google Security Command Center
- Experience working with SIEM platforms such as Elastic, Splunk, or Google Chronicle, along with EDR/XDR technologies including CrowdStrike Falcon, SentinelOne, or Palo Alto Cortex XDR
- Strong understanding of incident response methodologies, threat detection, log analysis, cloud identity security, MITRE ATT&CK, Cyber Kill Chain, Zero Trust principles, and identity and access management (IAM)
- Knowledge of networking fundamentals, including TCP/IP, DNS, HTTP/S, VPNs, firewalls, IDS/IPS, proxy technologies, and the ability to investigate cloud-based attacks, privilege escalation, and lateral movement
- Experience with scripting or automation using Python, PowerShell, or Bash, strong analytical and communication skills, and the ability to leverage AI-enabled tools to improve investigation quality and operational efficiency
- Industry certifications such as GIAC Certified Incident Handler (GCIH), AWS Certified Security – Specialty, CompTIA Security+, CompTIA CySA+, or comparable cybersecurity certifications
- Experience supporting a 24x7 Security Operations Center (SOC), implementing SOAR automation, and developing security orchestration workflows
- Familiarity with container security, Kubernetes, Docker, Infrastructure as Code (Terraform or CloudFormation), and DevSecOps practices
- Understanding of AI agents, AI frameworks, AI security risks, and emerging cyber threats targeting AI-enabled applications and platforms
Qualifications
Must Haves
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent practical experience) with 3–4 years of experience in Security Operations, Incident Response, Cyber Defense, or a related cybersecurity discipline
- Hands-on experience securing cloud environments using Amazon Web Services (AWS) and/or Google Cloud Platform (GCP), including familiarity with cloud-native security services such as AWS GuardDuty, AWS Security Hub, Microsoft Defender for Cloud, or Google Security Command Center
- Experience working with SIEM platforms such as Elastic, Splunk, or Google Chronicle, along with EDR/XDR technologies including CrowdStrike Falcon, SentinelOne, or Palo Alto Cortex XDR
- Strong understanding of incident response methodologies, threat detection, log analysis, cloud identity security, MITRE ATT&CK, Cyber Kill Chain, Zero Trust principles, and identity and access management (IAM)
- Knowledge of networking fundamentals, including TCP/IP, DNS, HTTP/S, VPNs, firewalls, IDS/IPS, proxy technologies, and the ability to investigate cloud-based attacks, privilege escalation, and lateral movement
- Experience with scripting or automation using Python, PowerShell, or Bash, strong analytical and communication skills, and the ability to leverage AI-enabled tools to improve investigation quality and operational efficiency
Nice to Haves
- Industry certifications such as GIAC Certified Incident Handler (GCIH), AWS Certified Security – Specialty, CompTIA Security+, CompTIA CySA+, or comparable cybersecurity certifications
- Experience supporting a 24x7 Security Operations Center (SOC), implementing SOAR automation, and developing security orchestration workflows
- Familiarity with container security, Kubernetes, Docker, Infrastructure as Code (Terraform or CloudFormation), and DevSecOps practices
- Understanding of AI agents, AI frameworks, AI security risks, and emerging cyber threats targeting AI-enabled applications and platforms
Benefits
- Hybrid - 3 days per quarter
- Annual discretionary bonus eligibility
- Eligibility to participate in an incentive program
- Leave programs
- Adoption assistance
- Student loan repayment programs