Corporate Vice President - Cyber Security Incident Response Team Lead

Posted Yesterday
Be an Early Applicant
New York, NY, USA
Hybrid
185K-265K Annually
Senior level
Artificial Intelligence • Cloud • Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Powered by purpose. Driven by people. Built to evolve.
The Role
Leads the enterprise cybersecurity incident response function as senior incident commander and people leader. Directs containment, eradication, recovery, investigations, evidence handling, regulatory notifications, executive communications, crisis coordination, and post-incident improvement. Establishes incident response governance, playbooks, metrics, readiness objectives, and audit processes while coordinating security, technology, legal, compliance, business, vendors, and executive stakeholders. Builds and manages a multidisciplinary response team and maintains continuous coverage for high-impact incidents.
Summary Generated by Built In
Location Designation: Hybrid - 3 days per week
Technology, Data, AI and Ventures:
Within the Tech, Data, AI, Ventures (TDAV) organization, our work is guided by a shared vision: deploying the power of technology, data, AI and ventures to accelerate sustainable competitive advantage for New York Life's businesses. We build solutions that power how we serve policy owners, agents, advisors and employees while delivering measurable business outcomes.
Across technology, data, AI, cyber, product, digital experience, architecture and infrastructure, TDAV combines the scale and investment of an industry leader, access to leading-edge technologies and the opportunity to help shape how a world-class financial services company competes in the AI era - all backed by the stability and purpose of a mutual company built to last.
Corporate Vice President, Cyber Security Incident Response Team Lead
Job Title: Corporate Vice President, Cyber Security Incident Management (CSIR) Lead
Level: MG3
Function: Cybersecurity
Location Designation: Onsite - 3 Days
Role Overview
The Cyber Incident Response (IR) Lead reports directly to the Chief Information Security Officer within the Cybersecurity organization and is accountable for New York Life's enterprise cyber incident response capability. The role establishes unified ownership from cyber incident activation through containment, eradication, secure recovery, and post-incident improvement, integrating specialized technical response with business, executive, legal, regulatory, and external coordination.
This position is both the senior incident commander and the people leader for the IR function. The IR Lead directs response the enterprise response to cybersecurity incidents of all severities, makes or drives time-critical response decisions, and ensures clear accountability across technical responders and business coordinators. The role is accountable for regulatory notification readiness, executive incident reporting, and coordination with legal, privacy, compliance, fraud, human resources, corporate communications, and business unit leadership
The individual will lead through ambiguity and operational pressure, exercising authority and composure during active incidents while maintaining the documentation discipline, evidentiary rigor, regulatory readiness, and stakeholder trust required in a regulated financial services environment.
What You'll Do
Enterprise Incident Command & Leadership
• Act as the enterprise Incident Commander for cybersecurity incidents, with end-to-end accountability from activation through recovery.
• Own incident declaration, severity classification, escalation, command structure, decision logging, executive checkpoints, and transition to post-incident activity.
• Direct cross-functional response across Security Operations, Threat Intelligence, digital forensics, identity, cloud, network, endpoint, infrastructure, applications, business teams, and external specialists.
• Lead containment, eradication, and secure recovery strategy in partnership with technology owners, balancing business impact, operational risk, evidence preservation, and adversary presence.
• Oversee evidence handling, chain of custody, and investigative documentation to a standard that supports legal, regulatory, and law enforcement requirements.
• Serve as the senior escalation point for cyber incident response with clear decision rights between SOC and IR as events move from alert investigation to confirmed incident response.
Team Leadership & People Management
• Build, develop, and lead a dedicated Cyber Incident Response function accountable to the CISO, combining specialized technical response capabilities with business and operational coordination and establishing clear end-to-end ownership from incident activation through secure recovery.
• Establish the IR capability roadmap, operating priorities, talent strategy, readiness objectives, and measurable outcomes; provide the CISO with a clear view of response readiness, material gaps, investment needs, and improvement priorities.
• Lead a multidisciplinary team expected to include technical responders focused on detection and containment, systems recovery and IR readiness, specialist response across cloud/identity/network, and business coordinators focused on stakeholder communications and operational continuity.
• Set and enforce clear expectations for response quality, documentation standards, communication cadence, and stakeholder handling.
• Balance team capacity across active incidents, investigations, program work, audit support, and regulatory deliverables.
• Serve as the senior escalation point and incident commander for the most complex, sensitive, or high-impact events.
• Maintain on-call rotations, escalation trees, and coverage models that provide continuous incident response availability across business and after hours.
Incident Management Program & Governance
• Own the cybersecurity incident management standard, response plan, playbooks, runbooks, and supporting procedures, including annual review, revision, and approval.
• Maintain alignment between the incident response program and NIST SP 800-61, the NIST Cybersecurity Framework, and applicable regulatory requirements.
• Enhance and maintain the severity taxonomy, incident categorization model, service level expectations, and quality standards for incident records.
• Ensure incident tickets, timelines, and case files are complete, accurate, defensible, and audit-ready.
• Support internal audit, external audit, regulatory examination, and third-party assessment activities related to incident response.
Regulatory, Legal & Notification Readiness
• Partner with the Office of the General Counsel, privacy, and compliance functions to assess notification obligations and support timely, accurate regulatory filings.
• Maintain working knowledge of financial services and insurance cybersecurity regulations, including state cybersecurity regulations with defined notification windows, state breach notification statutes, and applicable federal requirements.
• Track notification triggers, deadlines, and evidentiary requirements throughout the incident lifecycle, and escalate where determinations are time-critical.
• Coordinate third-party and vendor incident response, including service provider notification obligations, contractual security requirements, and supply chain events.
• Support legal hold, electronic discovery, and litigation readiness activities arising from cyber incidents.
Stakeholder Coordination & Crisis Communications
• Serve as the primary point of coordination between security operations, threat intelligence, technology owners, business stakeholders, control functions, and executive audiences during incidents.
• Prepare and deliver incident briefings to cybersecurity leadership, technology leadership, risk partners, and senior executives.
• Partner with corporate communications on internal and external messaging for incidents carrying reputational, customer, or media exposure.
• Coordinate with business continuity, disaster recovery, and crisis management functions when incidents require enterprise-level activation.
• Exercise extreme discretion and sound judgment when handling confidential investigations, sensitive findings, and need-to-know communications.
Reporting, Metrics & Executive Communications
• Develop and maintain incident reporting, dashboards, and executive-level materials summarizing incident volume, severity, themes, response performance, and remediation status.
• Define and track program metrics, including time to detect, time to contain, time to close, escalation accuracy, and recurrence rates.
• Translate complex technical incident detail into clear, practical, audience-appropriate communications.
• Identify recurring control gaps and organizational themes surfaced through incidents, and route them into remediation, issue management, and control improvement channels.
• Support recurring reporting to cybersecurity leadership, risk committees, senior management, and, as required, board-level audiences.
• Ensure reporting is accurate, balanced, actionable, and appropriately sensitive to audience and confidentiality considerations.
What You'll Bring
• Proven leadership of a cybersecurity incident response, digital forensics, security operations, or incident management capability, including direct people leadership.
• Demonstrated experience serving as Incident Commander or senior response lead for high-severity, cross-functional cybersecurity incidents in a large enterprise.
• Demonstrated technical depth in cybersecurity incident response sufficient to direct and challenge complex investigations, evaluate attacker activity and scope, assess containment and eradication options, and guide responders across endpoint, identity, cloud, network, applications, and enterprise technology environments.
• Working command of NIST SP 800-61 and the NIST Cybersecurity Framework, with experience operationalizing incident response standards, playbooks, severity models, exercises, and post-incident improvement.
• Experience coordinating across Security Operations, Threat Intelligence, digital forensics, identity and access management, cloud, network, endpoint, infrastructure, applications, business teams, vendors, legal, risk, privacy, compliance, and executive stakeholders.
• Experience with regulatory and breach-notification requirements applicable to financial services, insurance, or another highly regulated environment.
• Experience preparing executive-facing incident communications, metrics, dashboards, decision materials, and management reporting.
• Experience managing external IR/forensics retainers, vendors, statements of work, deliverables, and surge support.
• Experience managing cross-functional initiatives involving technology, cybersecurity, risk, legal, business, vendor, and executive stakeholders.
• Prior experience in a regulated financial services, insurance, or similarly complex enterprise environment preferred.
• Experience with incident management platforms, case management tooling, and security orchestration and automation preferred.
Knowledge and Education
• Bachelor's degree required or equivalent work experience.
• Eight or more years of cyber security or technology experience, including four or more years in incident response or incident management, and prior team leadership experience.
• Cyber security certification preferred, such as GCIH, GCFA, GCFE, CISSP, CISM, CRISC, or similar designation.
• Working knowledge of the NIST incident response lifecycle, the NIST Cybersecurity Framework, and common adversary frameworks such as MITRE ATT&CK.
• High-level understanding of cyber defense organizations, including security operations, incident response, threat intelligence, vulnerability management, identity, infrastructure, and application security functions.
• High-level understanding of enterprise technology functions, including application ownership, infrastructure, cloud, networking, end-user technology, and technology operations.
• Working knowledge of risk management, issue management, control remediation, and executive reporting practices.
Leadership, Communications and Collaboration
• Ability to communicate clearly and professionally with technical teams, business partners, risk stakeholders, vendors, and executive audiences.
• Demonstrated ability to assert authority, make decisions with incomplete information, maintain composure, and control the message during active incidents.
• Demonstrated ability to build trust and maintain positive working relationships, including in situations involving challenging findings, sensitive topics, or competing priorities.
• Strong organizational, analytical, written communication, and presentation skills.
• Ability to translate technical or complex cybersecurity concepts into practical business language.
• Proven ability to drive accountability and outcomes across teams without direct authority.
• Sound judgment, discretion, and professionalism when handling confidential or sensitive information.
• Self-motivated and detail-oriented, with the ability to manage shifting priorities in a dynamic execution environment.
• Ability to prioritize and deprioritize work based on risk, urgency, stakeholder impact, and
Job Level: LEVELMG3
Pay Transparency
Salary Range: $185,000-$264,500
Overtime eligible: Exempt
Discretionary bonus eligible: Yes
Sales bonus eligible: No
Actual base salary will be determined based on several factors but not limited to individual's experience, skills, qualifications, and job location. Additionally, employees are eligible for an annual discretionary bonus. In addition to base salary, employees may also be eligible to participate in an incentive program.
Company Overview
At New York Life, our 180-year legacy of purpose and integrity fuels our future. As we evolve into a more technology-, data-, and AI-enabled organization, we remain grounded in the values that drive lasting impact.
Our diverse business portfolio creates opportunities to make a difference across industries and communities-inviting bold thinking, collaborative problem-solving, and purpose-driven innovation. Here, you'll find the rare balance of long-standing stability and forward momentum, supported by an inclusive team that honors tradition while embracing progress.
As a Fortune 100 mutual company, we offer a place to grow your skills, contribute to meaningful work, and deliver solutions that matter. Your ideas drive what's next, and your growth powers it.
Our Benefits
We provide a full package of benefits for employees - and have unique offerings for a modern workforce, including leave programs, adoption assistance, and student loan repayment programs. Based on feedback from our employees, we continue to refine and add benefits to our offering, so that you can flourish both inside and outside of work.Click hereto discover more about our comprehensive benefit options or visit our NYL Benefits Site.
Our Commitment to Inclusion
At New York Life, fostering an inclusive workplace is fundamental to who we are and how we serve our communities. We have a longstanding commitment to creating an environment where individuals can contribute their best and succeed together. This foundation is rooted in our core values of humanity and integrity, ensuring that every employee feels valued and supported. By embracing a broad range of perspectives and experiences, we achieve greater success and fulfill our promise of providing financial security and peace of mind to families across all communities. Click here to learn more about New York Life's leadership in this space.
Recognized as one of Fortune's World's Most Admired Companies, New York Life is committed to improving local communities through a culture of employee giving and volunteerism, supported by the Foundation. We're proud that due to our mutuality, we operate in the best interests of our policy owners. To learn more about career opportunities at New York Life, please visit the Careers page of www.NewYorkLife.com.
Job Requisition ID: 94888
#BI-Hybrid

Skills Required

  • Proven leadership of a cybersecurity incident response, digital forensics, security operations, or incident management capability, including direct people leadership
  • Experience serving as Incident Commander or senior response lead for high-severity, cross-functional cybersecurity incidents in a large enterprise
  • Technical depth in cybersecurity incident response across endpoint, identity, cloud, network, applications, and enterprise technology environments
  • Working command of NIST SP 800-61 and the NIST Cybersecurity Framework
  • Experience operationalizing incident response standards, playbooks, severity models, exercises, and post-incident improvement
  • Experience coordinating with Security Operations, Threat Intelligence, digital forensics, identity and access management, cloud, network, endpoint, infrastructure, applications, business, vendor, legal, risk, privacy, compliance, and executive stakeholders
  • Experience with regulatory and breach-notification requirements in financial services, insurance, or another highly regulated environment
  • Experience preparing executive-facing incident communications, metrics, dashboards, decision materials, and management reporting
  • Experience managing external incident response or forensics retainers, vendors, statements of work, deliverables, and surge support
  • Experience managing cross-functional initiatives involving technology, cybersecurity, risk, legal, business, vendor, and executive stakeholders
  • Bachelor's degree or equivalent work experience
  • Eight or more years of cybersecurity or technology experience
  • Four or more years of incident response or incident management experience
  • Prior team leadership experience
  • Working knowledge of the NIST incident response lifecycle, NIST Cybersecurity Framework, and MITRE ATT&CK
  • High-level understanding of cyber defense organizations and enterprise technology functions
  • Working knowledge of risk management, issue management, control remediation, and executive reporting practices
  • Clear communication and presentation skills for technical, business, vendor, and executive audiences
  • Ability to make decisions with incomplete information and maintain composure during active incidents
  • Ability to drive accountability and outcomes across teams without direct authority
  • Sound judgment, discretion, and professionalism when handling confidential or sensitive information
  • Prior experience in a regulated financial services, insurance, or similarly complex enterprise environment
  • Experience with incident management platforms, case management tooling, and security orchestration and automation
  • Cybersecurity certification such as GCIH, GCFA, GCFE, CISSP, CISM, CRISC, or similar

What the Team is Saying

Tyrone
Emma
Deepa
Patricia
Joel
Nishit

New York Life Insurance Company Compensation & Benefits Highlights

  • Retirement Support Corporate employees are offered a 401(k) with company match and, for many roles, a defined‑benefit pension, with both the employee contributions and company match vesting 100% from day one. Qualified financial professionals may also have access to a defined‑benefit plan, per plan documents.
  • Parental & Family Support Paid New Parent leave doubled to 8 weeks for all parents as of January 1, 2024, and birthing parents typically receive an additional 6 weeks of paid short‑term disability. The company also highlights fertility and adoption support, backup childcare, tutoring, and elder‑care resources.
  • Healthcare Strength Medical, dental, and vision coverage are paired with HRAs/FSAs, an Employee Assistance Program, wellness programs, and telemedicine. Work/life perks such as gym discounts or on‑site gyms further reinforce the health and wellbeing offering.

New York Life Insurance Company Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
12,000 Employees
Year Founded: 1845

What We Do

At New York Life, our 180-year legacy of integrity, mutuality, and financial strength fuels a future defined by bold transformation. As the largest mutual life insurance company in the U.S., we operate on behalf of our policy owners—not shareholders. That structure allows us to take a long-term view, investing in people, purpose, and innovation that endures. Guided by a clear enterprise vision to become a technology-, data-, and AI-powered company, we’re modernizing our platforms, rearchitecting experiences, and embedding intelligence across our products and services. Our mission has always been about helping people through life’s most meaningful moments. Today, technology is amplifying that mission—enabling us to serve clients, advisors, and communities in more personalized, proactive ways. With a diversified business portfolio spanning insurance, investments, retirement, group benefits, and direct-to-consumer offerings, New York Life delivers the stability of a Fortune 100 company with the agility of one that’s continuously evolving. We’re powered by a values-led culture, inclusive teams, and a shared belief that when our people thrive, so does our company. Here, tradition fuels momentum—and your ideas, energy, and growth power what’s next.

Why Work With Us

New York Life is transforming from the inside out—blending 180 years of trust with the velocity of innovation. What makes us different is our culture: grounded in integrity, humanity, and shared success—values that show up in how we work, lead, and grow. If you want a place where innovation has purpose—build what's next with us.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

New York Life Insurance Company Teams

Team
Finance
Team
Artificial Intelligence & Data
Team
Client Services
Team
Technology
About our Teams

New York Life Insurance Company Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Typical time on-site: Not Specified
Company Office Image
HQNew York, NY
Company Office Image
Jersey City, NJ
Philadelphia, PA
Company Office Image
Tampa, FL
Company Office Image
White Plains, NY
Learn more

Similar Jobs

New York Life Insurance Company Logo New York Life Insurance Company

LTD (Long Term Disability) Claim Manager

Artificial Intelligence • Cloud • Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
In-Office or Remote
New York, NY, USA
12000 Employees
50K-72K Annually

New York Life Insurance Company Logo New York Life Insurance Company

Insurance Portfolio Manager

Artificial Intelligence • Cloud • Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Hybrid
New York, NY, USA
12000 Employees
140K-340K Annually

New York Life Insurance Company Logo New York Life Insurance Company

Administrative Assistant

Artificial Intelligence • Cloud • Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Hybrid
New York, NY, USA
12000 Employees
61K-86K Annually

New York Life Insurance Company Logo New York Life Insurance Company

Senior Associate, GBS - Client Consulting and Analytics

Artificial Intelligence • Cloud • Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
In-Office or Remote
New York, NY, USA
12000 Employees
90K-120K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account