Senior Associate - SOC Analyst
Location Designation: Hybrid - 3 days per quarter
Technology, Data, AI and Ventures:
Within the Tech, Data, AI, Ventures (TDAV) organization, our work is guided by a shared vision: deploying the power of technology, data, AI and ventures to accelerate sustainable competitive advantage for New York Life's businesses. We build solutions that power how we serve policy owners, agents, advisors and employees while delivering measurable business outcomes.
Across technology, data, AI, cyber, product, digital experience, architecture and infrastructure, TDAV combines the scale and investment of an industry leader, access to leading-edge technologies and the opportunity to help shape how a world-class financial services company competes in the AI era - all backed by the stability and purpose of a mutual company built to last.
Role Overview
We are seeking a highly motivated and experienced SOC Analyst with strong expertise in cloud security and incident response to join our Cyber Security Operations team. The ideal candidate will be responsible for monitoring, detecting, analyzing, investigating, and responding to security incidents across hybrid and cloud environments. This role requires hands-on experience with cloud platforms, security monitoring tools, threat detection, and incident handling to protect organizational assets from evolving cyber threats.
What You'll Do:
· Monitor security alerts and events using SIEM, EDR, XDR, and cloud-native security tools.
· Investigate, triage, and respond to security incidents across cloud and on-premises environments.
· Perform incident analysis, containment, eradication, recovery, and post-incident reviews.
· Analyze logs from cloud platforms including AWS, Microsoft Azure, and Google Cloud Platform (GCP).
· Utilize cloud security services such as Microsoft Defender for Cloud, AWS GuardDuty, AWS Security Hub, and Google Security Command Center.
· Conduct threat hunting activities to identify indicators of compromise (IOCs) and emerging threats.
· Develop and maintain incident response playbooks, standard operating procedures (SOPs), and runbooks.
· Investigate phishing, malware, ransomware, insider threats, and unauthorized access incidents.
· Perform digital forensics evidence collection following established procedures.
· Participate in security assessments, tabletop exercises, and incident response drills.
· Prepare detailed incident reports, root cause analyses, and executive summaries.
· Stay current with the latest cyber threats, attack techniques, and cloud security best practices.
What You'll Bring:
· Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent work experience).
· 3-4 years of experience in Security Operations, Incident Response, or Cyber Defense.
· Hands-on experience with at least one major cloud platform:
o Amazon Web Services (AWS)
o Google Cloud Platform (GCP)
· Experience working with SIEM solutions such as Splunk, Google Chronicle, or Elastic.
· Experience with EDR/XDR platforms such as CrowdStrike Falcon, SentinelOne, or Palo Alto Cortex XDR.
· Strong understanding of security monitoring, log analysis, and threat detection.
· Experience investigating cloud-based attacks, identity compromise, privilege escalation, and lateral movement.
· Knowledge of MITRE ATT&CK framework and Cyber Kill Chain.
· Familiarity with identity and access management (IAM), Zero Trust principles, and multi-factor authentication.
· Experience with scripting or automation using PowerShell, Python, or Bash is preferred.
· Knowledge of networking concepts, TCP/IP, DNS, HTTP/S, VPNs, firewalls, IDS/IPS, and proxy technologies.
Preferred Certifications
· GIAC Certified Incident Handler (GCIH)
· AWS Certified Security – Specialty
· CompTIA Security+
· CompTIA CySA+
Technical Skills
· Cloud Security (AWS, Azure, GCP)
· Incident Response
· SIEM Engineering and Monitoring
· Threat Hunting
· Malware Analysis
· Cloud Identity Security
· Endpoint Detection and Response (EDR/XDR)
· Network Security
· Security Automation (SOAR)
· Log Analysis
· Threat Intelligence
· Scripting (Python, PowerShell, Bash)
Soft Skills
· Strong analytical and problem-solving abilities
· Excellent written and verbal communication skills
· Ability to perform effectively in high-pressure situations
· Strong attention to detail
· Team-oriented with excellent collaboration skills
· Ability to prioritize multiple incidents simultaneously
· Commitment to continuous learning and professional development
Preferred Experience
· Experience supporting 24x7 Security Operations Centers.
· Experience with SOAR platforms and automation workflows.
· Experience with container security (Kubernetes, Docker) and cloud-native application security.
· Familiarity with Infrastructure as Code (Terraform, CloudFormation) and DevSecOps practices.
Success Metrics
· Timely detection and response to security incidents.
· Reduction in Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).
· Accurate incident documentation and reporting.
· Continuous improvement of cloud security posture.
· Effective collaboration with cross-functional teams to minimize cyber risk.
Job Level: LEVELPF3
Pay Transparency
Salary Range: $100,000-$143,000
Overtime eligible: Exempt
Discretionary bonus eligible: Yes
Sales bonus eligible: No
Actual base salary will be determined based on several factors but not limited to individual’s experience, skills, qualifications, and job location. Additionally, employees are eligible for an annual discretionary bonus. In addition to base salary, employees may also be eligible to participate in an incentive program.
Company Overview
At New York Life, our 180-year legacy of purpose and integrity fuels our future. As we evolve into a more technology-, data-, and AI-enabled organization, we remain grounded in the values that drive lasting impact.
Our diverse business portfolio creates opportunities to make a difference across industries and communities—inviting bold thinking, collaborative problem-solving, and purpose-driven innovation. Here, you’ll find the rare balance of long-standing stability and forward momentum, supported by an inclusive team that honors tradition while embracing progress.
As a Fortune 100 mutual company, we offer a place to grow your skills, contribute to meaningful work, and deliver solutions that matter. Your ideas drive what’s next, and your growth powers it.
Our Benefits
We provide a full package of benefits for employees – and have unique offerings for a modern workforce, including leave programs, adoption assistance, and student loan repayment programs. Based on feedback from our employees, we continue to refine and add benefits to our offering, so that you can flourish both inside and outside of work. Click here to discover more about our comprehensive benefit options or visit our NYL Benefits Site.
Our Commitment to Inclusion
At New York Life, fostering an inclusive workplace is fundamental to who we are and how we serve our communities. We have a longstanding commitment to creating an environment where individuals can contribute their best and succeed together. This foundation is rooted in our core values of humanity and integrity, ensuring that every employee feels valued and supported. By embracing a broad range of perspectives and experiences, we achieve greater success and fulfill our promise of providing financial security and peace of mind to families across all communities. Click here to learn more about New York Life’s leadership in this space.
Recognized as one of Fortune’s World’s Most Admired Companies, New York Life is committed to improving local communities through a culture of employee giving and volunteerism, supported by the Foundation. We're proud that due to our mutuality, we operate in the best interests of our policy owners. To learn more about career opportunities at New York Life, please visit the Careers page of .
Job Requisition ID: 94887
Skills
- AI
- Authentication
- Automation
- AWS
- Azure
- Bash
- Cloud
- Cloud Native
- Cloud Security
- CloudFormation
- Container Security
- Crowdstrike
- Cybersecurity
- DevSecOps
- DNS
- Docker
- EDR
- Firewall
- GCP
- IAM
- Infrastructure as Code
- Kubernetes
- Network Security
- Networking
- PowerShell
- Python
- SIEM
- Splunk
- TCP/IP
- Terraform
- Threat Hunting
- XDR
- Zero Trust