Senior Associate - Cyber Security Risk and Control jobs in United States
cer-icon
Apply on Employer Site
company-logo

New York Life Insurance Company · 2 weeks ago

Senior Associate - Cyber Security Risk and Control

New York Life Insurance Company is a Fortune 100 mutual company committed to improving local communities through a culture of employee giving and volunteerism. The Cybersecurity Risk and Controls Senior Associate will strengthen the company's cybersecurity posture by aligning security processes and controls with enterprise risk appetite and regulatory requirements, while also supporting governance, audits, and continuous improvement efforts.

FinanceFinancial ServicesInsurance
check
H1B Sponsor Likelynote

Responsibilities

Work closely with Technology Risk to support the design and execution of cybersecurity governance processes, including policy reviews, risk reporting, and control testing
Partner with Technology teams to ensure cybersecurity risks are identified, documented, and mitigated appropriately
Coordinate and support internal audits, regulatory exams, and external assessments related to cybersecurity
Prepare documentation and evidence for auditors, regulators, and senior management
Contribute to process enhancements, automation, and control rationalization efforts to improve cybersecurity controls
Identify opportunities to leverage AI and automation in risk monitoring and control testing
Stay abreast of evolving cybersecurity regulations, technologies, and industry standards
Support risk and control self-assessments across cybersecurity domains (e.g., identity management, data protection, incident response, and network security)
Evaluate control effectiveness against NIST CSF, ISO 27001, and other regulatory frameworks
Identify control gaps, track remediation progress, and validate closure activities
Track issues and ensure timely remediation of findings

Qualification

Cybersecurity risk managementInformation security governanceCybersecurity frameworksProfessional certificationsRegulatory compliance experienceRisk assessment methodologiesCollaboration with partnersProcess improvementCommunication skills

Required

Bachelor's degree in cybersecurity, information systems, risk management, or related field; or equivalent practical experience
Minimum of 3 years of experience in cybersecurity risk management, governance, or controls oversight within a financial services or regulated industry
Strong understanding of cybersecurity frameworks (NIST, CIS, ISO), IT general controls, and risk assessment methodologies
Excellent verbal and written communication skills, including experience presenting risk insights to management
Proven ability to work effectively with audit, technology, and business partners

Preferred

Professional certifications such as CISSP, CISA, CRISC, or CISM
Experience supporting regulatory exams (e.g., NYDFS, OCC, NAIC)
Familiarity with one or more of the following: AI/ML risk, cloud security, identity and access management, data protection, infrastructure security, endpoint protection, vulnerability management, application security, cybersecurity operations
Prior experience developing cyber risk metrics or dashboards for leadership

Benefits

Leave programs
Adoption assistance
Student loan repayment programs

Company

New York Life Insurance Company

twittertwittertwitter
company-logo
For over 180 years, we’ve helped turn your biggest dreams into milestones that last a lifetime.

H1B Sponsorship

New York Life Insurance Company has a track record of offering H1B sponsorships. Please note that this does not guarantee sponsorship for this specific role. Below presents additional info for your reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (149)
2024 (99)
2023 (85)
2022 (77)
2021 (48)
2020 (65)

Funding

Current Stage
Late Stage

Leadership Team

leader-logo
Craig DeSanto
CEO
leader-logo
Don Vu
Senior Vice President, Chief Data & Analytics Officer
linkedin
Company data provided by crunchbase