New York Life Insurance Co

Corporate Vice President - Cyber Security Incident Response Team Lead

New York Life Insurance Co$185K — $264K *
Finance & Insurance
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree or equivalent experience required.
  • 8+ years in cybersecurity/technology, with 4+ years in incident response/management.
  • Proven leadership in cybersecurity incident response and team management.
  • Experience as Incident Commander for high-severity cybersecurity incidents.
  • Strong knowledge of NIST SP 800-61 and Cybersecurity Framework.
  • Understanding of financial services cybersecurity regulations and breach notification requirements.
  • Preferred cybersecurity certifications (e.g., GCIH, CISSP, CISM).

Responsibilities

  • Lead enterprise incident response for cybersecurity incidents from activation to recovery.
  • Oversee cross-functional collaboration during incidents, ensuring efficient containment and eradication.
  • Manage evidence documentation to meet legal and regulatory standards during investigations.
  • Develop a strong Cyber Incident Response team and establish response capabilities and objectives.
  • Create and maintain incident management standards, including playbooks and response plans.
  • Coordinate regulatory notifications and compliance obligations during incident response.
  • Deliver executive-level briefings and communication strategies during incidents.

Benefits

  • Comprehensive benefits package including leave programs and adoption assistance.
  • Student loan repayment programs available.
  • Continuous enhancement of benefits based on employee feedback.
  • Emphasis on supporting employee well-being and work-life balance.
Full Job Description
Location Designation: Hybrid - 3 days per week

Technology, Data, AI and Ventures:

Within the Tech, Data, AI, Ventures (TDAV) organization, our work is guided by a shared vision: deploying the power of technology, data, AI and ventures to accelerate sustainable competitive advantage for New York Life's businesses. We build solutions that power how we serve policy owners, agents, advisors and employees while delivering measurable business outcomes.

Across technology, data, AI, cyber, product, digital experience, architecture and infrastructure, TDAV combines the scale and investment of an industry leader, access to leading-edge technologies and the opportunity to help shape how a world-class financial services company competes in the AI era - all backed by the stability and purpose of a mutual company built to last.

Corporate Vice President, Cyber Security Incident Response Team Lead

Job Title: Corporate Vice President, Cyber Security Incident Management (CSIR) Lead

Level: MG3

Function: Cybersecurity

Location Designation: Onsite - 3 Days

Role Overview

The Cyber Incident Response (IR) Lead reports directly to the Chief Information Security Officer within the Cybersecurity organization and is accountable for New York Life's enterprise cyber incident response capability. The role establishes unified ownership from cyber incident activation through containment, eradication, secure recovery, and post-incident improvement, integrating specialized technical response with business, executive, legal, regulatory, and external coordination.

This position is both the senior incident commander and the people leader for the IR function. The IR Lead directs response the enterprise response to cybersecurity incidents of all severities, makes or drives time-critical response decisions, and ensures clear accountability across technical responders and business coordinators. The role is accountable for regulatory notification readiness, executive incident reporting, and coordination with legal, privacy, compliance, fraud, human resources, corporate communications, and business unit leadership

The individual will lead through ambiguity and operational pressure, exercising authority and composure during active incidents while maintaining the documentation discipline, evidentiary rigor, regulatory readiness, and stakeholder trust required in a regulated financial services environment.

What You'll Do

Enterprise Incident Command & Leadership
• Act as the enterprise Incident Commander for cybersecurity incidents, with end-to-end accountability from activation through recovery.
• Own incident declaration, severity classification, escalation, command structure, decision logging, executive checkpoints, and transition to post-incident activity.
• Direct cross-functional response across Security Operations, Threat Intelligence, digital forensics, identity, cloud, network, endpoint, infrastructure, applications, business teams, and external specialists.
• Lead containment, eradication, and secure recovery strategy in partnership with technology owners, balancing business impact, operational risk, evidence preservation, and adversary presence.
• Oversee evidence handling, chain of custody, and investigative documentation to a standard that supports legal, regulatory, and law enforcement requirements.
• Serve as the senior escalation point for cyber incident response with clear decision rights between SOC and IR as events move from alert investigation to confirmed incident response.

Team Leadership & People Management
• Build, develop, and lead a dedicated Cyber Incident Response function accountable to the CISO, combining specialized technical response capabilities with business and operational coordination and establishing clear end-to-end ownership from incident activation through secure recovery.
• Establish the IR capability roadmap, operating priorities, talent strategy, readiness objectives, and measurable outcomes; provide the CISO with a clear view of response readiness, material gaps, investment needs, and improvement priorities.
• Lead a multidisciplinary team expected to include technical responders focused on detection and containment, systems recovery and IR readiness, specialist response across cloud/identity/network, and business coordinators focused on stakeholder communications and operational continuity.
• Set and enforce clear expectations for response quality, documentation standards, communication cadence, and stakeholder handling.
• Balance team capacity across active incidents, investigations, program work, audit support, and regulatory deliverables.
• Serve as the senior escalation point and incident commander for the most complex, sensitive, or high-impact events.
• Maintain on-call rotations, escalation trees, and coverage models that provide continuous incident response availability across business and after hours.

Incident Management Program & Governance
• Own the cybersecurity incident management standard, response plan, playbooks, runbooks, and supporting procedures, including annual review, revision, and approval.
• Maintain alignment between the incident response program and NIST SP 800-61, the NIST Cybersecurity Framework, and applicable regulatory requirements.
• Enhance and maintain the severity taxonomy, incident categorization model, service level expectations, and quality standards for incident records.
• Ensure incident tickets, timelines, and case files are complete, accurate, defensible, and audit-ready.
• Support internal audit, external audit, regulatory examination, and third-party assessment activities related to incident response.

Regulatory, Legal & Notification Readiness
• Partner with the Office of the General Counsel, privacy, and compliance functions to assess notification obligations and support timely, accurate regulatory filings.
• Maintain working knowledge of financial services and insurance cybersecurity regulations, including state cybersecurity regulations with defined notification windows, state breach notification statutes, and applicable federal requirements.
• Track notification triggers, deadlines, and evidentiary requirements throughout the incident lifecycle, and escalate where determinations are time-critical.
• Coordinate third-party and vendor incident response, including service provider notification obligations, contractual security requirements, and supply chain events.
• Support legal hold, electronic discovery, and litigation readiness activities arising from cyber incidents.

Stakeholder Coordination & Crisis Communications
• Serve as the primary point of coordination between security operations, threat intelligence, technology owners, business stakeholders, control functions, and executive audiences during incidents.
• Prepare and deliver incident briefings to cybersecurity leadership, technology leadership, risk partners, and senior executives.
• Partner with corporate communications on internal and external messaging for incidents carrying reputational, customer, or media exposure.
• Coordinate with business continuity, disaster recovery, and crisis management functions when incidents require enterprise-level activation.
• Exercise extreme discretion and sound judgment when handling confidential investigations, sensitive findings, and need-to-know communications.

Reporting, Metrics & Executive Communications
• Develop and maintain incident reporting, dashboards, and executive-level materials summarizing incident volume, severity, themes, response performance, and remediation status.
• Define and track program metrics, including time to detect, time to contain, time to close, escalation accuracy, and recurrence rates.
• Translate complex technical incident detail into clear, practical, audience-appropriate communications.
• Identify recurring control gaps and organizational themes surfaced through incidents, and route them into remediation, issue management, and control improvement channels.
• Support recurring reporting to cybersecurity leadership, risk committees, senior management, and, as required, board-level audiences.
• Ensure reporting is accurate, balanced, actionable, and appropriately sensitive to audience and confidentiality considerations.

What You'll Bring
• Proven leadership of a cybersecurity incident response, digital forensics, security operations, or incident management capability, including direct people leadership.
• Demonstrated experience serving as Incident Commander or senior response lead for high-severity, cross-functional cybersecurity incidents in a large enterprise.
• Demonstrated technical depth in cybersecurity incident response sufficient to direct and challenge complex investigations, evaluate attacker activity and scope, assess containment and eradication options, and guide responders across endpoint, identity, cloud, network, applications, and enterprise technology environments.
• Working command of NIST SP 800-61 and the NIST Cybersecurity Framework, with experience operationalizing incident response standards, playbooks, severity models, exercises, and post-incident improvement.
• Experience coordinating across Security Operations, Threat Intelligence, digital forensics, identity and access management, cloud, network, endpoint, infrastructure, applications, business teams, vendors, legal, risk, privacy, compliance, and executive stakeholders.
• Experience with regulatory and breach-notification requirements applicable to financial services, insurance, or another highly regulated environment.
• Experience preparing executive-facing incident communications, metrics, dashboards, decision materials, and management reporting.
• Experience managing external IR/forensics retainers, vendors, statements of work, deliverables, and surge support.
• Experience managing cross-functional initiatives involving technology, cybersecurity, risk, legal, business, vendor, and executive stakeholders.
• Prior experience in a regulated financial services, insurance, or similarly complex enterprise environment preferred.
• Experience with incident management platforms, case management tooling, and security orchestration and automation preferred.

Knowledge and Education
• Bachelor's degree required or equivalent work experience.
• Eight or more years of cyber security or technology experience, including four or more years in incident response or incident management, and prior team leadership experience.
• Cyber security certification preferred, such as GCIH, GCFA, GCFE, CISSP, CISM, CRISC, or similar designation.
• Working knowledge of the NIST incident response lifecycle, the NIST Cybersecurity Framework, and common adversary frameworks such as MITRE ATT&CK.
• High-level understanding of cyber defense organizations, including security operations, incident response, threat intelligence, vulnerability management, identity, infrastructure, and application security functions.
• High-level understanding of enterprise technology functions, including application ownership, infrastructure, cloud, networking, end-user technology, and technology operations.
• Working knowledge of risk management, issue management, control remediation, and executive reporting practices.

Leadership, Communications and Collaboration
• Ability to communicate clearly and professionally with technical teams, business partners, risk stakeholders, vendors, and executive audiences.
• Demonstrated ability to assert authority, make decisions with incomplete information, maintain composure, and control the message during active incidents.
• Demonstrated ability to build trust and maintain positive working relationships, including in situations involving challenging findings, sensitive topics, or competing priorities.
• Strong organizational, analytical, written communication, and presentation skills.
• Ability to translate technical or complex cybersecurity concepts into practical business language.
• Proven ability to drive accountability and outcomes across teams without direct authority.
• Sound judgment, discretion, and professionalism when handling confidential or sensitive information.
• Self-motivated and detail-oriented, with the ability to manage shifting priorities in a dynamic execution environment.
• Ability to prioritize and deprioritize work based on risk, urgency, stakeholder impact, and

Job Level: LEVELMG3

Pay Transparency

Salary Range: $185,000-$264,500

Overtime eligible: Exempt

Discretionary bonus eligible: Yes

Sales bonus eligible: No

Actual base salary will be determined based on several factors but not limited to individual's experience, skills, qualifications, and job location. Additionally, employees are eligible for an annual discretionary bonus. In addition to base salary, employees may also be eligible to participate in an incentive program.

Our Benefits

We provide a full package of benefits for employees - and have unique offerings for a modern workforce, including leave programs, adoption assistance, and student loan repayment programs. Based on feedback from our employees, we continue to refine and add benefits to our offering, so that you can flourish both inside and outside of work.Click hereto discover more about our comprehensive benefit options or visit our NYL Benefits Site.

About New York Life Insurance Co

New York Life Insurance Company is a mutual life insurance company in the United States and one of the life insurers in the world, ranking #88 on the 2014 Fortune 500 list with over $540 billion in total assets under management, and more than $19 billion in surplus and AVR. New York Life and its subsidiaries provide insurance, investment, and retirement solutions. For 175 years, the company has been helping people put their love into action. It was founded in 1845 and is headquartered in New York.

New York Life Insurance Co Careers

Join the esteemed team at New York Life Insurance Co, a leader in the insurance industry, and propel your career to new heights with unparalleled job opportunities. As one of the most respected names in life insurance, we offer a platform where professionalism meets innovation, creating an environment ripe for personal and professional growth.

Work You’ll Do

At New York Life Insurance Co, you will be part of a culture that cherishes diversity and fosters leadership. Our team is composed of skilled professionals dedicated to providing financial security and peace of mind to our clients. By joining us, you will collaborate with top-tier experts in finance and insurance, leveraging your skills to make a meaningful impact.

Explore Career Paths

Whether you are seeking an internship, a full-time position, or a leadership role, New York Life Insurance Co provides a variety of career paths to help you achieve your professional goals. Our commitment to career development is evident through extensive training programs and continuous learning opportunities that ensure our team remains at the forefront of the industry.

Innovate and Lead

Embrace the opportunity to lead projects that drive innovation within the company and the insurance industry. New York Life Insurance Co is at the intersection of tradition and innovation, where we constantly strive to develop solutions that anticipate the needs of our clients.

Be Part of a Great Team

Our team at New York Life Insurance Co is our greatest asset. We thrive on collaboration and respect each other’s contributions, creating a supportive and inclusive workplace. Here, networking and mentorship go hand in hand with day-to-day operations, providing a robust support system for career advancement.

Future-Proof Your Career

With New York Life Insurance Co, your career is future-proofed with endless opportunities for advancement. Our comprehensive benefits package supports your life both inside and outside of work, while our leadership and diversity training prepare you to take on new challenges.

Join Our Team

Search for open positions that match your skills and interests. We are hiring creative, curious, and motivated individuals who are ready to drive their careers forward. Explore our job opportunities and find out how your talents can make a difference at New York Life Insurance Co.

Stay Connected

Keep up to date with the latest industry trends, career tips, and company news through our Careers Blog. Personalize your experience by subscribing to job alert emails, tailored to your preferences, and discover the exciting and rewarding opportunities that await at New York Life Insurance Co.

Prepare for Your Interview

Ready to join us? Prepare your resume and sharpen your interview skills to become part of a company that values vision, leadership, and a commitment to excellence. At New York Life Insurance Co, we are not just offering a job; we are offering a pathway to success.

New York Life Insurance Co – A Place Where Careers Are Made

From fostering innovation to encouraging diversity, New York Life Insurance Co is where you can pursue your passions and grow your career. Join us and make a difference in the lives of our clients and communities every day.
Learn more about New York Life Insurance Co
Size
11,960 employees
Industry
Founded
1845

Similar Jobs

More Jobs at New York Life Insurance Co

More Finance & Insurance Jobs

Find similar Corporate Vice President - Cyber Security Incident Response Team Lead jobs: