Senior Exposure Management Engineer

KeyCorp

Brooklyn (OH)

Hybrid

USD 96,000 - 181,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

KeyCorp’s Cyber Defense team seeks a Senior Exposure Management Engineer to govern enterprise security baselines across on-premises, cloud, and hybrid environments. You will drive remediation, assess compliance, and reduce exposure through automated validation and reporting.

You will collaborate with Security Architecture, Infrastructure, Cloud, and Engineering teams to expand automation, support audits, and provide actionable metrics aligned with CIS Benchmarks, NIST CSF, and MITRE ATT&CK.

Qualifications

  • Bachelor's degree or equivalent experience in computer science, cybersecurity, or related field.
  • 8+ years in security engineering, configuration management, or related roles.
  • Experience with vulnerability management platforms (Tenable, Qualys, Rapid7).
  • Expertise in Tenable or similar compliance-scanning solutions.
  • Broad understanding of enterprise platforms and security considerations.
  • Hands-on cloud experience (GCP, Azure, AWS).
  • Familiarity with CIS Benchmarks, SCAP, NIST CSF, MITRE ATT&CK.
  • Experience with ServiceNow Vulnerability Response & Configuration Compliance.
  • Strong research, documentation, and reporting skills.
  • Willingness to travel.

Responsibilities

  • Governing and maintaining enterprise security baseline standards across environments.
  • Conducting automated configuration assessments and remediation tracking.
  • Monitoring configuration drift and reporting deviations.
  • Managing baseline exceptions and risk acceptance documentation.
  • Developing configuration compliance metrics and executive reporting.
  • Supporting audits and regulatory assessments with documentation and evidence.
  • Collaborating with Infrastructure, Cloud, and App teams on baseline fidelity.
  • Identifying opportunities to improve automation and coverage.
  • Prioritizing remediation with vulnerability and threat teams.
  • Sharing best practices and compliance requirements.

Skills

Security engineering
Configuration management
Vulnerability management
Reporting skills

Education

Bachelor's degree or equivalent

Tools

Tenable
Qualys
Rapid7
ServiceNow

Job description

Location: 4910 Tiedeman Road, Brooklyn Ohio

Position Summary

As a member of the Cyber Defense team within Corporate Information Security, the Senior Exposure Management Engineer is responsible for governing, assessing, and maintaining enterprise security baseline standards across on-premises, cloud, and hybrid environments. This role ensures technology assets remain aligned with approved security configuration standards, industry frameworks, and regulatory requirements through continuous assessment, compliance monitoring, and risk-based remediation activities. The Senior Exposure Management Engineer leverages automated assessment and compliance validation tools to identify configuration weaknesses, measure adherence to enterprise security baselines, and monitor configuration drift across the environment. The role partners closely with Security Architecture, Infrastructure, Engineering, Cloud, and Application teams to drive remediation, manage exceptions, support audit and regulatory examinations, and enhance the organization’s overall security posture through consistent application of standards-based controls. This position also leads the evolution of the enterprise baseline program by evaluating changes to industry guidance, improving compliance measurement capabilities, expanding automation, and providing actionable reporting that enables informed risk-based decisions and continuous exposure reduction

Key Responsibilities
  • Security Baseline Governance: Maintain and govern enterprise-approved security baseline standards across operating systems, cloud platforms, applications, databases, and network infrastructure. Support the review and adoption of updates to CIS Benchmarks and other industry-recognized security standards through established governance processes. Partner with Security Architecture and technology teams to ensure baseline requirements are appropriately documented, communicated, and operationalized.
  • Configuration Compliance Assessment: Conduct ongoing configuration compliance assessments utilizing automated scanning and validation tools to measure adherence to approved baseline standards. Validate remediation activities through continuous monitoring and reassessment. Identify, analyze, and report configuration weaknesses that increase organizational risk.
  • Configuration Drift Monitoring: Monitor configuration drift across enterprise assets and provide reporting on deviations from approved security baselines. Partner with technology owners to investigate non-compliant configurations and drive timely remediation.
  • Exception and Risk Management: Manage baseline exceptions, compensating controls, and risk acceptance documentation. Ensure approved deviations from security standards are appropriately documented, reviewed, and tracked through remediation or renewal cycles.
  • Compliance Reporting & Metrics: Develop and maintain configuration compliance metrics, dashboards, and executive reporting. Provide visibility into compliance trends, remediation progress, assessment coverage, and risk reduction activities. Support reporting through ServiceNow and other enterprise governance platforms.
  • Audit & Regulatory Support: Maintain documentation, evidence, and reporting required to support internal audits, external examinations, and regulatory assessments. Demonstrate compliance with enterprise security requirements, industry standards, and applicable regulatory obligations.
  • Cross-Functional Collaboration: Partner with Infrastructure, Cloud, Application, Engineering, and Security teams to support implementation and maintenance of approved security baselines. Provide guidance regarding baseline compliance requirements and remediation priorities.
  • Continuous Improvement & Automation: Identify opportunities to improve assessment coverage, compliance measurement, reporting, and operational efficiencies through automation. Support implementation of automated compliance validation and reporting capabilities.
  • Threat-Informed Exposure Reduction: Collaborate with Vulnerability Management, Threat Intelligence, Red Team, and Exposure Management teams to prioritize remediation of configuration weaknesses that contribute to exploitable attack paths and elevated risk. Utilize risk-based methodologies to focus remediation efforts on the highest-impact configuration deficiencies.
  • Knowledge Sharing: Share security baseline best practices, emerging standards, and compliance requirements through documentation, training, and stakeholder engagement.
Required Qualifications
  • Bachelor's degree in computer science, Cybersecurity, or related field—or equivalent experience.
  • 8+ years of experience in security engineering, configuration management, or related roles.
  • Experience with Vulnerability Management platforms (Tenable, Qualys, Rapid7 etc) running vulnerability scans, monitoring agent health, and maintaining scanner operability.
  • Comprehensive expertise in Tenable or comparable vendor solutions for compliance scanning.
  • Broad understanding of enterprise computing platforms and their configuration management, compliance, and security considerations.
  • Hands-on experience with cloud platforms (Google Cloud, Microsoft Azure, AWS).
  • Familiarity with security frameworks and standards (e.g., CIS Benchmarks, SCAP, NIST CSF, MITRE ATT&CK).
  • Experience with ServiceNow security related modules such as Vulnerability Response & Configuration Compliance.
  • Effective research, documentation, and reporting skills.
  • Willingness to travel.
Preferred Certifications
  • Certified Information Systems Security Professional (CISSP)
  • GIAC Security Essentials (GSEC)
  • GIAC Certified Vulnerability Assessor (GCVA)
  • Microsoft Certified: Azure Security Engineer Associate
  • AWS Certified Security - Specialty
  • Google Cloud Security Engineer
COMPENSATION AND BENEFITS

This position is eligible to earn a base salary in the range of $96,000.00 - $181,000.00 annually. Placement within the pay range may differ based upon various factors, including but not limited to skills, experience and geographic location. Compensation for this role also includes eligibility for incentive compensation which may include production, commission, and/or discretionary incentives.

Key has implemented an approach to employee workspaces which prioritizes in-office presence, while providing flexible options in circumstances where roles can be performed effectively in a mobile environment.

Job Posting Expiration Date

10/30/2026

KeyCorp is an Equal Opportunity Employer committed to sustaining an inclusive culture. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, genetic information, pregnancy, disability, veteran status or any other characteristic protected by law. Qualified individuals with disabilities or disabled veterans who are unable or limited in their ability to apply on this site may request reasonable accommodations by emailing HR_Compliance@keybank.com.

KeyBank is an organization collectively committed to helping you unlock your potential and discover what truly drives you. Working here means sharing our purpose to help our clients, colleagues, and communities thrive. You'll find genuinely supportive teammates, a flexible, inclusive work environment, challenging projects, accessible leaders, and opportunities to grow in your position and your career. For 200 years, Key has opened doors in our communities. Let us open one for you.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Defense Incident Response Lead
Cyber Defense Incident Response Lead

KeyBank • Brooklyn (OH)

On-site
USD 96,000 - 181,000
Senior Offensive Security Engineer (Red Team)
Senior Offensive Security Engineer (Red Team)

KeyCorp • Brooklyn (OH)

On-site
USD 96,000 - 181,000
Cyber Defense Incident Response Lead
Cyber Defense Incident Response Lead

KeyBank • New York (NY)

Hybrid
USD 96,000 - 181,000
Benefits overview
Sr. Cybersecurity Operational Risk Officer
Sr. Cybersecurity Operational Risk Officer

KeyBank • Chicago (IL)

On-site
USD 96,000 - 181,000
Sr Info Security Consultant
Sr Info Security Consultant

KeyBank • Brooklyn (OH)

Hybrid
USD 96,000 - 181,000
Lead BRC Risk Advisor
Lead BRC Risk Advisor

KeyCorp • Brooklyn (OH)

Hybrid
USD 80,000 - 150,000
In-office presence with flexible work
Competitive base salary
Incentive compensation
Cyber Defense Incident Response Lead
Cyber Defense Incident Response Lead

KeyBank • United States

On-site
USD 96,000 - 181,000
Info Security Consultant
Info Security Consultant

KeyBank • United States

Hybrid
USD 69,000 - 105,000
Info Security Consultant
Info Security Consultant

KeyBank • Brooklyn (OH)

On-site
USD 69,000 - 105,000
Senior Offensive Security Engineer (Red Team)
Senior Offensive Security Engineer (Red Team)

KeyBank • United States

On-site
USD 96,000 - 181,000