Location Designation: Hybrid - 3 days per quarter
Business UnitTechnology, Data, AI and Ventures (TDAV)Role OverviewThe Cyber Security Operations team is seeking a Security Operations Center (SOC) Analyst to help protect New York Life's enterprise technology environment by monitoring, detecting, investigating, and responding to cyber threats across hybrid and cloud environments. This role combines hands-on incident response, cloud security operations, and threat detection to identify and mitigate evolving cyber risks while strengthening the organization's overall security posture.
As a member of the Security Operations Center, you will leverage SIEM, EDR/XDR, cloud-native security technologies, and threat intelligence to investigate security events, conduct threat hunting, and coordinate incident response activities. You will collaborate with security engineering, cloud platform, infrastructure, and application teams to improve detection capabilities, automate response processes, and support a resilient, secure technology environment.
What You'll Do- Monitor, investigate, and respond to security alerts and incidents across cloud and on-premises environments using SIEM, EDR/XDR, and cloud-native security platforms, ensuring timely detection, containment, and resolution of cyber threats.
- Perform threat hunting, malware analysis, and incident investigations involving phishing, ransomware, identity compromise, unauthorized access, and other advanced attack techniques while documenting findings and recommending remediation actions.
- Analyze security telemetry and logs from cloud platforms, including AWS, Google Cloud Platform (GCP), and cloud security services, to identify indicators of compromise, emerging threats, and opportunities to strengthen security controls.
- Develop and maintain incident response playbooks, standard operating procedures, and automation workflows while participating in tabletop exercises, security assessments, and continuous improvement initiatives to enhance operational readiness.
- Collaborate with cross-functional technology and cybersecurity teams to improve cloud security posture, reduce operational risk, leverage AI-enabled security capabilities, and provide actionable reporting to technical and business stakeholders.
What You'll BringRequired Skills- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent practical experience) with 3-4 years of experience in Security Operations, Incident Response, Cyber Defense, or a related cybersecurity discipline.
- Hands-on experience securing cloud environments using Amazon Web Services (AWS) and/or Google Cloud Platform (GCP), including familiarity with cloud-native security services such as AWS GuardDuty, AWS Security Hub, Microsoft Defender for Cloud, or Google Security Command Center.
- Experience working with SIEM platforms such as Elastic, Splunk, or Google Chronicle, along with EDR/XDR technologies including CrowdStrike Falcon, SentinelOne, or Palo Alto Cortex XDR.
- Strong understanding of incident response methodologies, threat detection, log analysis, cloud identity security, MITRE ATT&CK, Cyber Kill Chain, Zero Trust principles, and identity and access management (IAM).
- Knowledge of networking fundamentals, including TCP/IP, DNS, HTTP/S, VPNs, firewalls, IDS/IPS, proxy technologies, and the ability to investigate cloud-based attacks, privilege escalation, and lateral movement.
- Experience with scripting or automation using Python, PowerShell, or Bash, strong analytical and communication skills, and the ability to leverage AI-enabled tools to improve investigation quality and operational efficiency.
Preferred Skills- Industry certifications such as GIAC Certified Incident Handler (GCIH), AWS Certified Security - Specialty, CompTIA Security+, CompTIA CySA+, or comparable cybersecurity certifications.
- Experience supporting a 24x7 Security Operations Center (SOC), implementing SOAR automation, and developing security orchestration workflows.
- Familiarity with container security, Kubernetes, Docker, Infrastructure as Code (Terraform or CloudFormation), and DevSecOps practices.
- Understanding of AI agents, AI frameworks, AI security risks, and emerging cyber threats targeting AI-enabled applications and platforms.
Success Measures- Timely detection, investigation, and response to cybersecurity incidents.
- Continuous reduction in Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).
- Accurate and comprehensive incident documentation, reporting, and root cause analysis.
- Ongoing improvement of cloud security posture and detection capabilities.
- Effective collaboration across cybersecurity, cloud, infrastructure, and application teams to reduce enterprise cyber risk.
Pay TransparencySalary Range: $100,000-$143,000
Overtime eligible: Exempt
Discretionary bonus eligible: Yes
Sales bonus eligible: No
Actual base salary will be determined based on several factors but not limited to individual's experience, skills, qualifications, and job location. Additionally, employees are eligible for an annual discretionary bonus. In addition to base salary, employees may also be eligible to participate in an incentive program.
Our BenefitsWe provide a full package of benefits for employees - and have unique offerings for a modern workforce, including leave programs, adoption assistance, and student loan repayment programs. Based on feedback from our employees, we continue to refine and add benefits to our offering, so that you can flourish both inside and outside of work.Click hereto discover more about our comprehensive benefit options or visit our NYL Benefits Site.
Job Requisition ID: 94622