Senior Associate - SOC Analyst

🏢 New York Life Insurance Co · all 67 jobs
📍 United States
💰 USD 100,000 - 143,000 / annual
📅 Posted Sep 20, 2026 · via Himalayas
🏷 Soc Analyst, Security Operations, Cybersecurity, Incident Response, Cloud Security, Senior Soc Analyst +5 more
Apply on original site ↗

Location Designation: Hybrid - 3 days per quarter
Technology, Data, AI and Ventures:

Within the Tech, Data, AI, Ventures (TDAV) organization, our work is guided by a shared vision: deploying the power of technology, data, AI and ventures to accelerate sustainable competitive advantage for New York Life's businesses. We build solutions that power how we serve policy owners, agents, advisors and employees while delivering measurable business outcomes.

Across technology, data, AI, cyber, product, digital experience, architecture and infrastructure, TDAV combines the scale and investment of an industry leader, access to leading-edge technologies and the opportunity to help shape how a world-class financial services company competes in the AI era - all backed by the stability and purpose of a mutual company built to last.
Role Overview

We are seeking a highly motivated and experienced SOC Analyst with strong expertise in cloud security and incident response to join our Cyber Security Operations team. The ideal candidate will be responsible for monitoring, detecting, analyzing, investigating, and responding to security incidents across hybrid and cloud environments. This role requires hands-on experience with cloud platforms, security monitoring tools, threat detection, and incident handling to protect organizational assets from evolving cyber threats.
What You'll Do:

- Monitor security alerts and events using SIEM, EDR, XDR, and cloud-native security tools.

- Investigate, triage, and respond to security incidents across cloud and on-premises environments.

- Perform incident analysis, containment, eradication, recovery, and post-incident reviews.

- Analyze logs from cloud platforms including AWS, Microsoft Azure, and Google Cloud Platform (GCP).

- Utilize cloud security services such as Microsoft Defender for Cloud, AWS GuardDuty, AWS Security Hub, and Google Security Command Center.

- Conduct threat hunting activities to identify indicators of compromise (IOCs) and emerging threats.

- Develop and maintain incident response playbooks, standard operating procedures (SOPs), and runbooks.

- Investigate phishing, malware, ransomware, insider threats, and unauthorized access incidents.

- Perform digital forensics evidence collection following established procedures.

- Participate in security assessments, tabletop exercises, and incident response drills.

- Prepare detailed incident reports, root cause analyses, and executive summaries.

- Stay current with the latest cyber threats, attack techniques, and cloud security best practices.

What You'll Bring:

- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent work experience).

- 3-4 years of experience in Security Operations, Incident Response, or Cyber Defense.

- Hands-on experience with at least one major cloud platform:

o Amazon Web Services (AWS)
o Google Cloud Platform (GCP)

- Experience working with SIEM solutions such as Splunk, Google Chronicle, or Elastic.

- Experience with EDR/XDR platforms such as CrowdStrike Falcon, SentinelOne, or Palo Alto Cortex XDR.

- Strong understanding of security monitoring, log analysis, and threat detection.

- Experience investigating cloud-based attacks, identity compromise, privilege escalation, and lateral movement.

- Knowledge of MITRE ATT&CK framework and Cyber Kill Chain.

- Familiarity with identity and access management (IAM), Zero Trust principles, and multi-factor authentication.

- Experience with scripting or automation using PowerShell, Python, or Bash is preferred.

- Knowledge of networking concepts, TCP/IP, DNS, HTTP/S, VPNs, firewalls, IDS/IPS, and proxy technologies.

Preferred Certifications
· GIAC Certified Incident Handler (GCIH)
· AWS Certified Security – Specialty
· CompTIA Security+
· CompTIA CySA+
Technical Skills
· Cloud Security (AWS, Azure, GCP)
· Incident Response
· SIEM Engineering and Monitoring
· Threat Hunting
· Malware A

Flights + hotels

This role requires you to be in the United States. If that means relocating or flying in, it is worth checking fares before you commit to a start date.

Compare flights and hotels →

← All remote jobs

Want more like this? Browse every live remote developer role.All remote developer jobs →
Get new developer jobs by email
Daily email, only when there's something new. One click to stop.

Get remote developer jobs like this by email

10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.

Similar for you