New York Life logo
New York Life
Posted 15 days agoVerified live 1d ago

Senior Associate - SOC Analyst Job Details | New York Life Insurance Co

Brief overview

Remote
UndergradOr in progress
$100k–$143k/yrStated range
3+ yrsMinimum
Cloud Security AWSCloud Security AzureCloud Security GCPIncident ResponseSIEM SplunkSIEM Google ChronicleSIEM ElasticEDR/XDR CrowdStrike FalconEDR/XDR SentinelOneEDR/XDR Palo Alto Cortex XDRSecurity Monitoring and Log AnalysisThreat HuntingCloud Identity Security IAMCloud Identity Security Zero TrustCloud Identity Security MFAMalware AnalysisNetwork Security TCP/IP

Job description

Summary

New York Life is a mutual financial services company advancing technology, data, AI, and cybersecurity capabilities to support its businesses. The Senior Associate SOC Analyst will monitor, investigate, and respond to security incidents across hybrid and cloud environments, while conducting threat hunting, digital forensics, incident reporting, and continuous improvement of cloud security operations.

Responsibilities

  • Monitor security alerts and events using SIEM, EDR, XDR, and cloud-native security tools
  • Investigate, triage, and respond to security incidents across cloud and on-premises environments
  • Perform incident analysis, containment, eradication, recovery, and post-incident reviews
  • Analyze logs from cloud platforms including AWS, Microsoft Azure, and Google Cloud Platform (GCP)
  • Utilize cloud security services such as Microsoft Defender for Cloud, AWS GuardDuty, AWS Security Hub, and Google Security Command Center
  • Conduct threat hunting activities to identify indicators of compromise (IOCs) and emerging threats
  • Develop and maintain incident response playbooks, standard operating procedures (SOPs), and runbooks
  • Investigate phishing, malware, ransomware, insider threats, and unauthorized access incidents
  • Perform digital forensics evidence collection following established procedures
  • Participate in security assessments, tabletop exercises, and incident response drills
  • Prepare detailed incident reports, root cause analyses, and executive summaries
  • Stay current with the latest cyber threats, attack techniques, and cloud security best practices

Skills

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent work experience)
  • 3-4 years of experience in Security Operations, Incident Response, or Cyber Defense
  • Hands-on experience with at least one major cloud platform:
  • O Amazon Web Services (AWS)
  • O Google Cloud Platform (GCP)
  • Experience working with SIEM solutions such as Splunk, Google Chronicle, or Elastic
  • Experience with EDR/XDR platforms such as CrowdStrike Falcon, SentinelOne, or Palo Alto Cortex XDR
  • Strong understanding of security monitoring, log analysis, and threat detection
  • Experience investigating cloud-based attacks, identity compromise, privilege escalation, and lateral movement
  • Knowledge of MITRE ATT&CK framework and Cyber Kill Chain
  • Familiarity with identity and access management (IAM), Zero Trust principles, and multi-factor authentication
  • Knowledge of networking concepts, TCP/IP, DNS, HTTP/S, VPNs, firewalls, IDS/IPS, and proxy technologies
  • · GIAC Certified Incident Handler (GCIH)
  • · AWS Certified Security – Specialty
  • · CompTIA Security+
  • · CompTIA CySA+
  • · Cloud Security (AWS, Azure, GCP)
  • · Incident Response
  • · SIEM Engineering and Monitoring
  • · Threat Hunting
  • · Malware Analysis
  • · Cloud Identity Security
  • · Endpoint Detection and Response (EDR/XDR)
  • · Network Security
  • · Security Automation (SOAR)
  • · Log Analysis
  • · Threat Intelligence
  • · Scripting (Python, PowerShell, Bash)
  • · Strong analytical and problem-solving abilities
  • · Excellent written and verbal communication skills
  • · Ability to perform effectively in high-pressure situations
  • · Strong attention to detail
  • · Team-oriented with excellent collaboration skills
  • · Ability to prioritize multiple incidents simultaneously
  • · Commitment to continuous learning and professional development
  • · Experience supporting 24x7 Security Operations Centers
  • · Experience with SOAR platforms and automation workflows
  • · Experience with container security (Kubernetes, Docker) and cloud-native application security
  • · Familiarity with Infrastructure as Code (Terraform, CloudFormation) and DevSecOps practices
  • · Experience with scripting or automation using PowerShell, Python, or Bash is preferred
  • Preferred Certifications
  • Preferred Experience

Qualifications

Must Haves

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent work experience)
  • 3-4 years of experience in Security Operations, Incident Response, or Cyber Defense
  • Hands-on experience with at least one major cloud platform:
  • o Amazon Web Services (AWS)
  • o Google Cloud Platform (GCP)
  • Experience working with SIEM solutions such as Splunk, Google Chronicle, or Elastic
  • Experience with EDR/XDR platforms such as CrowdStrike Falcon, SentinelOne, or Palo Alto Cortex XDR
  • Strong understanding of security monitoring, log analysis, and threat detection
  • Experience investigating cloud-based attacks, identity compromise, privilege escalation, and lateral movement
  • Knowledge of MITRE ATT&CK framework and Cyber Kill Chain
  • Familiarity with identity and access management (IAM), Zero Trust principles, and multi-factor authentication
  • Knowledge of networking concepts, TCP/IP, DNS, HTTP/S, VPNs, firewalls, IDS/IPS, and proxy technologies
  • · GIAC Certified Incident Handler (GCIH)
  • · AWS Certified Security – Specialty
  • · CompTIA Security+
  • · CompTIA CySA+
  • · Cloud Security (AWS, Azure, GCP)
  • · Incident Response
  • · SIEM Engineering and Monitoring
  • · Threat Hunting
  • · Malware Analysis
  • · Cloud Identity Security
  • · Endpoint Detection and Response (EDR/XDR)
  • · Network Security
  • · Security Automation (SOAR)
  • · Log Analysis
  • · Threat Intelligence
  • · Scripting (Python, PowerShell, Bash)
  • · Strong analytical and problem-solving abilities
  • · Excellent written and verbal communication skills
  • · Ability to perform effectively in high-pressure situations
  • · Strong attention to detail
  • · Team-oriented with excellent collaboration skills
  • · Ability to prioritize multiple incidents simultaneously
  • · Commitment to continuous learning and professional development
  • · Experience supporting 24x7 Security Operations Centers
  • · Experience with SOAR platforms and automation workflows
  • · Experience with container security (Kubernetes, Docker) and cloud-native application security
  • · Familiarity with Infrastructure as Code (Terraform, CloudFormation) and DevSecOps practices

Nice to Haves

  • · Experience with scripting or automation using PowerShell, Python, or Bash is preferred
  • Preferred Certifications
  • Preferred Experience

Benefits

  • Hybrid - 3 days per quarter
  • Annual discretionary bonus
  • May be eligible to participate in an incentive program
  • Leave programs
  • Adoption assistance
  • Student loan repayment programs

More jobs like this