Infrastructure Security Engineer Jobs in New York
Infrastructure Security Engineer jobs in New York are among the most active in the country, with strong demand from financial services, healthcare systems, government agencies, and cloud-driven technology firms at every level from entry-level analyst to senior architect. Most hiring concentrates in New York City, Albany, and Buffalo, where institutions like JPMorgan Chase, IBM, and New York-Presbyterian anchored demand across both private and public sectors. The most sought-after specialties include zero-trust architecture, network perimeter security, and cloud infrastructure hardening. Find a role that fits below and apply directly.
Find JobsOverview
Showing 5 of 5+ Infrastructure Security Engineer jobs










Looking for more infrastructure security engineer jobs?
Explore related role searches to find more openings that fit.
See related jobs
Requisition ID
94128
Department
Tech Data AI Ventures
Job Function
Tech Data AI Ventures
Location
Remote, New York, United States
Role Location Designation
Hybrid - 3 days per quarter
Role Summary
Own New York Life’s platform operating system (OS) standards and the hardened/certified image artifacts used to build workloads across hybrid environments. This role engineers and governs standardized build paths for Linux and Windows platforms, including on-prem VM templates, AWS EC2 base images/AMIs, node images, and container base images. The engineer also owns the Terraform “golden path” modules that provision these platforms, implementing guardrails and enforcement to ensure compliant, repeatable builds at scale. Success requires strong cross-platform OS expertise, infrastructure-as-code (Terraform), image lifecycle engineering, and close partnership with ETS to execute the standard golden path across teams.
What You’ll Do:
Vulnerability Management:
- Research and download all patches for the Compute environment
- Test each of the patches to ensure that each patch resolves its intended vulnerability or issue.
- Bundle the vendor patches and release them to the team for non-prod deployment; be available to resolve issues before and during and after production release.
- If a critical patch is released from a vendor during or in between patch cycles, immediately research the vulnerability, test the patch and prepare it for an out of band patch cycle if necessary.
Platform OS Standards & Certified Images:
- Define and maintain cross-platform OS standards for Linux and Windows (configuration baselines, hardening, packages, services, logging, time sync, and required agents).
- Engineer hardened/certified image artifacts: install/base images, on-prem VM templates, AWS AMIs for EC2, node images, and container base images.
- Coordinate certification and security sign-off for image releases (CIS-aligned hardening, approved crypto settings, certificates, and required controls).
- Maintain image versioning, release notes, and lifecycle (deprecation, end-of-support posture, and upgrade paths) with clear consumer guidance.
- Ensure that engineering, design, server build, configuration and other related documentation is present and up to date and easily retrievable.
Terraform Golden Path Modules:
- Own and evolve Terraform modules that implement the standard “golden path” for provisioning compliant OS platforms across environments.
- Design modules to be reusable, opinionated, and safe-by-default (networking hooks, identity integrations, logging/monitoring, secrets handling, tagging/metadata).
- Enable Git-based workflows and CI/CD for module promotion and consumption at scale (testing, validation, approvals, and rollback patterns).
Guardrails, Enforcement & Exception Workflow:
- Implement and operate guardrails/enforcement to prevent drift from OS standards (policy-as-code, validations, and automated compliance checks).
- Define and run the exception workflow: intake, risk assessment, approvals, time-bound waivers, tracking, and remediation plans.
- Partner with Security, IAM, and Risk teams to ensure governance, auditability, and evidence collection for standards adoption.
Rollout Sequencing & Operations:
- Plan and execute rollout sequencing for new standards and image releases (pilot early adopters broad rollout), minimizing operational risk.
- Operate production support for golden path platforms, including incident response, root cause analysis, and continuous improvements to reduce repeat issues.
- Establish runbooks, operational procedures, and communications for consumers and platform operators.
Monitoring & Observability:
- Define and implement monitoring and dashboards for image/standard adoption, compliance status, and drift detection across Linux, Windows, EC2/AMI, and container bases.
- Integrate telemetry with enterprise monitoring to provide proactive alerting and visibility for stakeholders and operations.
Partner & Influence Across Teams (with ETS):
- Partner with technology team to execute the standard golden path at scale, aligning on implementation patterns, operational handoffs, and support models.
- Collaborate with application teams, cloud platform teams, and infrastructure engineering to onboard workloads to the golden path.
- Provide technical leadership and mentorship, driving adoption through clear documentation, training, and stakeholder engagement.
What You'll Bring:
- Experience: 7+ years engineering and operating enterprise OS platforms across Linux and Windows in mission-critical, hybrid environments.
- Golden images & provisioning: Proven expertise building and maintaining hardened/certified images (VM templates, EC2 AMIs, node images, container base images) and operating image build pipelines (e.g., Packer or equivalent).
- Infrastructure as Code: Strong Terraform skills (module design, versioning, testing, promotion) with ability to deliver opinionated “golden path” modules for broad adoption; familiarity with Ansible and automation at scale.
- Cloud & platform engineering: Working knowledge of AWS compute patterns (EC2/AMI), IAM, logging/monitoring integrations, and tagging/metadata standards; exposure to Azure/Oracle Cloud and hybrid operations.
- Guardrails & governance: Experience implementing policy-as-code guardrails (validation, drift detection, compliance scanning) and running structured exception/waiver workflows.
- Core infrastructure fundamentals: Strong grounding in networking (TCP/IP, DNS, HTTP/S), storage (SAN/NAS/local/filesystems), HA/resiliency, and virtualization (VMware/UCS).
- Operational leadership: Excellent incident/change discipline, clear communication to technical and non-technical stakeholders, and ability to partner with ETS and cross-functional teams to execute standards at scale.
How Success Will Be Measured
- Golden path adoption & standardization — higher % of Linux/Windows platforms provisioned via approved Terraform modules and certified artifacts (base images, VM templates, EC2 AMIs, node/container images), with reduced build variance and drift.
- Secure, on-time releases — predictable cadence for certified images, monthly patch readiness, and major OS releases delivered on schedule with documented hardening/approvals to meet SLAs.
- Low-incident change execution — incident-free (or materially reduced) patch/image rollouts supported by guardrails, automated enforcement, rollout sequencing, and validated testing/rollback plans.
- Vulnerability reduction — fewer Vulnerability Incident Tickets (VIT) and improved security posture through hardened standards, continuous remediation, and reduced repeat findings across Linux services and Windows workloads.
- Operational excellence — fewer platform incidents attributable to standards/images, improved MTTR via runbooks and observability, and strong ServiceNow SLA performance (tickets closed within SLA).
- Governance, exceptions & audit readiness — efficient exception workflow (clear SLAs, time-bound waivers, tracked remediation) plus complete, consistent, easily retrievable documentation/evidence for audits and quarterly reviews.
Working Model
Hybrid role based in New York, NY with periodic on-site participation for key release and change windows. Availability after-hours for critical issue engagement is expected. You’ll operate under defined governance and established change procedures, partnering closely with ETS and cross-functional teams to execute the standard golden path at scale, maintain hardened/certified image artifacts, and keep platform standards audit-ready across Linux, Windows, and AWS.
Pay Transparency
Salary Range: $90,000-$128,500
Overtime eligible: Exempt
Discretionary bonus eligible: Yes
Sales bonus eligible: No
Actual base salary will be determined based on several factors but not limited to individual’s experience, skills, qualifications, and job location. Additionally, employees are eligible for an annual discretionary bonus. In addition to base salary, employees may also be eligible to participate in an incentive program.
Company Overview
At New York Life, our 180-year legacy of purpose and integrity fuels our future. As we evolve into a more technology-, data-, and AI-enabled organization, we remain grounded in the values that drive lasting impact.
Our diverse business portfolio creates opportunities to make a difference across industries and communities—inviting bold thinking, collaborative problem-solving, and purpose-driven innovation. Here, you’ll find the rare balance of long-standing stability and forward momentum, supported by an inclusive team that honors tradition while embracing progress.
As a Fortune 100 mutual company, we offer a place to grow your skills, contribute to meaningful work, and deliver solutions that matter. Your ideas drive what’s next, and your growth powers it.
Our Benefits
We provide a full package of benefits for employees – and have unique offerings for a modern workforce, including leave programs, adoption assistance, and student loan repayment programs. Based on feedback from our employees, we continue to refine and add benefits to our offering, so that you can flourish both inside and outside of work.
Our Commitment to Inclusion
At New York Life, fostering an inclusive workplace is fundamental to who we are and how we serve our communities. We have a longstanding commitment to creating an environment where individuals can contribute their best and succeed together. This foundation is rooted in our core values of humanity and integrity, ensuring that every employee feels valued and supported. By embracing a broad range of perspectives and experiences, we achieve greater success and fulfill our promise of providing financial security and peace of mind to families across all communities.
Recognized as one of Fortune’s World’s Most Admired Companies, New York Life is committed to improving local communities through a culture of employee giving and volunteerism, supported by the Foundation. We're proud that due to our mutuality, we operate in the best interests of our policy owners.
See All 5 Infrastructure Security Engineer Jobs in New York
Find roles in New York that match your experience and apply in just a few clicks.
Find JobsInfrastructure Security Engineer Jobs by City in New York
Where New York roles are concentrated, by current openings.
Infrastructure Security Engineer Job Market in New York
A snapshot from current New York openings, updated as new roles post.
Who's Hiring
- Barclays1

- Bloomberg1

- Haymarket Media1

- New York Life1

- OpenAI1

Top Industries Hiring
- Technology & Software2
- Insurance1
- Investment & Asset Management1
- Science & Research1
What New York Employers Look For
The qualifications that appear most often in infrastructure security engineer jobs across New York.
- Bachelor's degree in cybersecurity, computer science, information systems, or a related field
- Active CISSP, CISM, or CompTIA Security+ certification recognized by New York employers
- Hands-on experience securing enterprise network infrastructure including firewalls, VPNs, and IDS/IPS systems
- Proficiency with cloud security platforms such as AWS, Azure, or Google Cloud in regulated environments
- Familiarity with New York Department of Financial Services cybersecurity regulation 23 NYCRR 500 compliance requirements
- Experience conducting vulnerability assessments, penetration testing, and infrastructure risk analysis
Infrastructure Security Engineer Jobs in New York: Frequently Asked Questions
How do you become a infrastructure security engineer in New York?
New York does not require a state-issued license for infrastructure security engineers, but employers consistently expect a bachelor's degree in cybersecurity or a related field alongside industry certifications such as CISSP or CompTIA Security+. Candidates targeting financial services firms operating under New York's 23 NYCRR 500 regulation benefit from documented compliance experience. Government and public-sector roles in Albany may require background clearance through the New York State Office of Information Technology Services.
How much do infrastructure security engineers make in New York?
Infrastructure security engineers in New York earn a median of about $116,990 a year, based on May 2025 Bureau of Labor Statistics wage data, ranging from around $59,740 for the lowest 10% to over $203,040 for the top 10%. Pay rises with experience, specialty, and employer.
Which companies hire infrastructure security engineers in New York?
Employers hiring infrastructure security engineers in New York right now include Barclays, Bloomberg, and Haymarket Media, based on current listings on Migrate Mate as of June 2026. New York City's concentration of financial institutions, media companies, and large hospital networks makes it one of the deepest hiring pools for this role in the country.
Which New York cities have the most infrastructure security engineer jobs?
New York account for the largest share of infrastructure security engineer openings in New York. New York City leads by a significant margin due to its density of financial services firms, healthcare systems, and enterprise technology companies, while Albany draws demand from state government agencies and contractors, and Buffalo has grown as a regional hub for healthcare and manufacturing cybersecurity.
Are there remote infrastructure security engineer jobs in New York?
Yes, and more than many technical roles, because a meaningful portion of infrastructure security work involves monitoring, policy management, and cloud configuration that can be done off-site. About 60% of infrastructure security engineer openings tied to New York are remote or hybrid as of June 2026, though roles requiring physical data center access or government clearance remain predominantly on-site. Cloud security and security operations center analyst functions are the most commonly offered remotely.
How can I get hired as a infrastructure security engineer in New York with little or no experience?
The most realistic entry path is a junior security analyst or IT support role at a large New York employer, using that position to build hands-on infrastructure exposure. Institutions like New York-Presbyterian, Northwell Health, and major financial services firms run associate and rotational technology programs that accept candidates with CompTIA Security+ or Network+ certifications. Adjacent roles in network administration or systems administration at New York City or state government agencies also provide a credible bridge into infrastructure security.
Where can I find and apply to infrastructure security engineer jobs in New York?
You can find and apply to infrastructure security engineer jobs in New York on Migrate Mate, which lists current New York openings updated regularly. Search the listings, find roles that match your experience and location, and apply directly to the employers posting them.
See All 5 Infrastructure Security Engineer Jobs in New York
Find roles in New York that match your experience and apply in just a few clicks.
Find Jobs