Senior Associate, Cybersecurity Regulatory Compliance

Posted 8 minutes ago
$111.5K - $130K / year

Are you applying to the internship?

Job Description

Senior Associate, Cybersecurity Regulatory Compliance | New York Life Insurance Company

The Tone:
This is a full-time role at New York Life Insurance Company, located in a hybrid capacity requiring 3 days per quarter onsite. New York Life is a Fortune 100 mutual company with an 180-year legacy, currently evolving into a technology-, data-, and AI-enabled organization. This role is crucial for ensuring the company’s cybersecurity practices align with evolving state and federal regulations, thereby protecting the company and its policy owners and maintaining its reputation for integrity.

The TL;DR
• Role: Full Time
• Type: Exempt
• Location: Hybrid – 3 days per quarter
• Pay: $111500–$130000 yearly
• Mission: Owns the coordination and documentation for cybersecurity regulatory compliance certifications and examinations.
• Tech Stack: Microsoft 365, Teams, SharePoint, DocuSign, ChatGPT, Copilot

What You’ll Actually Do
• Annual Compliance Certifications Management: Manage annual cybersecurity compliance certifications by maintaining a detailed tracker of state requirements, aligned documentation, evidence, due dates, and year-over-year changes.
• Stakeholder Coordination & Review: Communicate and coordinate with internal teams, evidence providers, reviewers, and approvers involved in the annual certification process, reviewing all responses and evidence for accuracy and completeness.
• DocuSign & Process Improvement: Organize responses and evidence for review, manage the internal DocuSign sign-off process for executive approvals, and collaborate on post-certification analysis to identify and incorporate improvement opportunities.
• Regulatory Examination Facilitation: Facilitate cybersecurity and technology examinations, reviews, regulatory reporting, and requests by serving as a liaison between state examiners, Legal, and the Cybersecurity and Technology teams.
• Regulatory Response Management: Assess exam requests, assign appropriate control owners, create and maintain a tracker of all requests and responses, review all responses for accuracy, and maintain a repository of regulatory responses and documents.

The Must-Haves
• Background: Bachelor’s degree in Information Security/Technology, Cybersecurity, Risk Management, or a related field; or equivalent work experience, fitting a Senior-level career.
• Experience: 3+ years of experience in cybersecurity risk, technology risk, IT audit, regulatory compliance, or related Governance, Risk, and Compliance (GRC) functions, preferably within financial services or insurance.
• Skills: Demonstrated knowledge of Information Security principles, controls, and technology risk management; proven ability to analyze complex information, manage competing priorities, and work independently; strong organizational, project management, written communication, and stakeholder management skills.
• Bonus: Proficiency using Microsoft 365, particularly Teams and SharePoint; familiarity with AI Generative tools such as ChatGPT and Copilot; experience with DocuSign administration and workflow management.

Related Jobs