Full-Time

Senior Security Engineer

Attack Surface Management

Posted on 5/9/2026

Deadline 5/13/26
KeyBank

KeyBank

1,001-5,000 employees

Provides banking, loans, and financial services

Compensation Overview

$96k - $181k/yr

Brooklyn, OH, USA

Hybrid

Category
IT & Security (1)
Required Skills
PowerShell
Chef
Bash
Microsoft Azure
Python
Puppet
ServiceNow
Kali Linux
AWS
Ansible
Linux/Unix
Google Cloud Platform
Requirements
  • Bachelor’s degree in computer science, cybersecurity, or related field—or equivalent experience.
  • 8+ years of experience in security engineering, attack surface management, configuration management, or related roles.
  • Demonstrated experience in contextualizing vulnerabilities, using threat intelligence, asset classification and business impact.
  • Proficiency with scripting languages such as PowerShell, Python, or Bash for automation, integration, and process improvement in security operations.
  • Experience with ASM/OSINT tools (e.g., BurpSuite, AMASS, PassiveTotal, SecurityTrails, Nuclei, Recon-NG, GoWitness, MassDNS, Masscan, Censys.io, Shodan, Bitsight, etc.).
  • Proficiency with configuration management tools (e.g., Ansible, Chef, Puppet)
  • Experience with vulnerability management platforms (Tenable, Qualys, Rapid7, etc.), running vulnerability scans, monitoring agent health, and maintaining scanner operability.
  • Strong understanding of Cisco, Windows, Linux, Kali Linux, Oracle Linux, and macOS operating systems.
  • Hands-on experience with cloud platforms (Google Cloud, Microsoft Azure, AWS).
  • Familiarity with security frameworks and standards (e.g., CIS Benchmarks, SCAP, NIST CSF, MITRE ATT&CK, PCI-DSS).
  • Experience with ServiceNow security-related modules such as Vulnerability Response & Configuration Compliance.
  • Strong data management, reporting, and communication skills.
  • Willingness to travel.
Responsibilities
  • Attack Surface Reduction: Continuously discover all digital assets, including domains, IPs, cloud buckets, APIs, endpoints, and applications. Develop and implement strategies to reduce exposure across digital assets. Monitor KeyBank’s environment to ensure the attack surface is minimal.
  • Exposure & Vulnerability Monitoring: Lead vulnerability scanning operations and coordinate with patching teams for remediation. Monitor new threats, changes to the attack surface, and emerging risks using automated tools and threat intelligence feeds. Prioritize vulnerabilities based on asset criticality, threat intelligence, and exposure risk.
  • Risk-Based Prioritization & Remediation: Translate technical risk information into actionable insights for business leaders. Enable swift remediation through workflow automation, ServiceNow integration, and proactive notifications.
  • Threat Intelligence Integration: Collaborate with threat intelligence and Red Teams to incorporate external threat data and validate ASM controls through adversary simulation.
  • Governance, Reporting, and Collaboration: Support asset ownership identification and maintain robust accountability frameworks. Offer guidance on governance frameworks and support the creation of remediation playbooks. Collaborate with IT, CIS, and third-party risk teams to align ASM initiatives with organizational risk priorities.
  • Compliance Reporting: Define and track key performance indicators for ASM effectiveness (e.g., reduction in exposed assets, time to remediate vulnerabilities). Track and report on configuration compliance metrics, maintain automated dashboards, and provide visibility to stakeholders and leadership.
  • Documentation & Audit Support: Document configuration changes, exceptions, and remediation activities. Support internal and external audits by providing evidence of compliance and remediation.
  • Process Automation: Assist in the development and automation of configuration management and compliance reporting tools and frameworks.
  • Knowledge Sharing: Share knowledge and best practices with the team through presentations, documentation, and training sessions. Mentor junior team members to foster a culture of security awareness.
  • Incident Response: Support incident response and remediation efforts by identifying and correcting misconfigurations and partnering with blue teams to improve detection and response capabilities related to configuration changes and vulnerabilities.
Desired Qualifications
  • Certified Information Systems Security Professional (CISSP)
  • GIAC Security Essentials (GSEC)
  • GIAC Certified Vulnerability Assessor (GCVA)
  • Microsoft Certified: Azure Security Engineer Associate
  • AWS Certified Security – Specialty
  • Google Cloud Security Engineer
  • Offensive Security Certified Professional (OSCP)

KeyBank provides a full range of banking services for individuals, small businesses, and commercial clients across the United States. It offers checking and savings accounts, credit cards, mortgages, loans, and other financial products. Customers use these products by making deposits, borrowing money, or using credit in everyday life; the bank earns interest on loans, fees for services, and commissions on products. KeyBank differs from many rivals by offering a wide geographic footprint and a focus on tailored financial solutions plus tools to improve financial wellness, such as budgeting resources and planning guidance. Its goal is to help clients reach financial milestones—like buying a home, paying down debt, or saving for the future—through a comprehensive set of services.

Company Size

1,001-5,000

Company Stage

IPO

Headquarters

Massachusetts

Founded

1824

Simplify Jobs

Simplify's Take

What believers are saying

  • Q1 2026 net income surged 33% to $486M with 10% revenue growth.
  • Commercial loans hit $107.7B, up $3.4B YoY, fueling interest income.
  • Acquired Clearwater UK, expanding investment banking into Western Europe.

What critics are saying

  • Net charge-offs reach $101M in Q1 2026 from rapid commercial expansion.
  • CRE concentration in $107.7B loans triggers collapse like NYCB in 2024.
  • PNC poaches Midwest clients, undermining Tony Catalina's Michigan push.

What makes KeyBank unique

  • KeyBank specializes in middle-market firms with $10M-$1B revenues across 15 states.
  • KeyBanc Capital Markets delivers syndicated finance and M&A advisory nationally.
  • Targets family offices and private equity with dedicated national teams.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Medical, dental, & vision

Wellness Programs

Fitness Reimbursement

Alternative Work Schedules

PTO

Parental Leave

401(k) Savings Plan

Discounted Stock Purchase Plan

Tuition Reimbursement

Company News

National Today
Apr 8th, 2026
Cane Capital Partners buys $1.3M stake in KeyCorp with 62,105 shares

Cane Capital Partners LLC has purchased a new stake of 62,105 shares in KeyCorp, valued at approximately $1.28 million, according to a regulatory filing. The institutional investor acquired the shares during the fourth quarter of 2025. KeyCorp is a Cleveland-based financial services company providing retail and commercial banking products. The investment reflects institutional confidence in the regional bank's growth potential and business prospects. The purchase signals that institutional investors see value in KeyCorp's stock performance and future outlook in the financial services sector.

PR Newswire
Apr 2nd, 2026
Brookdale Announces Successful Refinancing Transaction; Extends 2027 Non-Recourse Mortgage Debt Maturity

/PRNewswire/ -- Brookdale Senior Living Inc. (NYSE: BKD) ("Brookdale" or "the Company") announced today the Company completed a successful refinancing...

Cintas
Mar 11th, 2026
CINTAS TO ACQUIRE UNIFIRST IN $5.5 BILLION TRANSACTION THAT EXPANDS SERVICE CAPABILITIES, ENHANCES WORKDAY SOLUTIONS AND ADVANCES INDUSTRY INNOVATION

Transaction expected to deliver substantial benefits for customers, workers and employees across North America and enhance value for shareholders of both companies.

Yahoo Finance
Feb 27th, 2026
KeyBank targets 10% commercial banker workforce growth for second consecutive year

KeyBank is targeting a 10% increase in its commercial banking workforce this year, following an 11% expansion in 2024. The Cleveland-based regional bank recently hired a five-person family office and private capital team in Kansas City to support the growth initiative. The bank currently employs 181 commercial bankers serving middle-market businesses generating between $10 million and $1 billion in revenue. Two teams hired last year in Chicago and Southern California have driven new customer growth and loan production at roughly twice the rate of the rest of the portfolio, according to Ken Gavrity, head of Key's commercial bank. KeyBank's commercial division generated approximately $2.1 billion in revenue last year, representing nearly one-third of total revenue. The bank is particularly focused on expanding in the Southeast, with Atlanta under consideration.

PR Newswire
Feb 9th, 2026
KeyBank adds five-person family office banking team to expand middle market capabilities

KeyBank has hired a five-person family office and private capital team led by Ward Nixon to expand its middle market capabilities. Nixon joins as Commercial Leader based in KeyBank's Overland Park, Kansas office. The team will provide national coverage serving family offices and private equity sponsors across direct investments, portfolio company banking, and wealth management. Nixon brings extensive experience in commercial banking and leveraged finance across multiple US regions. The hire follows KeyBank's successful team additions in Chicago and Southern California in late 2024. The move reflects KeyBank's strategic focus on family offices and private equity firms, which increasingly drive middle market ownership and capital deployment. KeyBank has approximately $184 billion in assets as of December 2025.

INACTIVE