Senior Security Engineer- Security Baselines

KeyBank

Brooklyn (OH)

Hybrid

USD 96,000 - 181,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work model
In-office with flexible options

Job summary

KeyBank is seeking a Senior Exposure Management Engineer to design, implement and maintain secure configurations across on‑prem, cloud and hybrid environments, aligning with CIS Benchmarks and internal baselines. The role emphasizes continuous assessment, vulnerability management and audit readiness with Tenable and other industry tools.

Based in Brooklyn, Ohio, it requires travel flexibility and collaboration with security, infrastructure and development teams.

Qualifications

  • Bachelor's degree in computer science, Cybersecurity, or related field or equivalent experience.
  • 8+ years of experience in security engineering, configuration management, or related roles.
  • Proficiency with configuration management tools (e.g., Ansible, Chef, Puppet) and scripting languages (PowerShell, Python, Bash).
  • Experience with Vulnerability Management platforms (Tenable, Qualys, Rapid7 etc) running vulnerability scans, monitoring agent health, and maintaining scanner operability.
  • Comprehensive expertise in Tenable or comparable vendor solutions for compliance scanning.
  • Strong understanding of Cisco, Windows, Linux, Kali Linux, and macOS operating systems.
  • Hands-on experience with cloud platforms (Google Cloud, Microsoft Azure, AWS).
  • Familiarity with security frameworks and standards (e.g., CIS Benchmarks, SCAP, NIST CSF, MITRE ATT&CK).
  • Experience with ServiceNow security related modules such as Vulnerability Response & Configuration Compliance
  • Effective research, documentation, and reporting skills.
  • Willingness to travel.

Responsibilities

  • Configuration Management: Develop, implement, and maintain secure configuration baselines for operating systems, cloud platforms, applications, and network devices, ensuring strict adherence to CIS Benchmarks and organizational standards.
  • Continuous Assessment: Conduct regular configuration assessments and audits using Tenable and other industry-standard tools to validate compliance with CIS Benchmarks, NIST, PCI-DSS, and other regulatory requirements.
  • Vulnerability Management: Perform authenticated and unauthenticated vulnerability scans with Tenable, analyze results, and coordinate remediation activities.
  • Threat Intelligence: Collaborate with the Cyber Threat Intelligence and Red Team to incorporate threat intelligence into configuration management and prioritization processes.
  • Project Collaboration: Work with project teams, architects, and third-party vendors to embed security controls in system designs and deployments and validate configuration requirements.
  • Cross-Team Collaboration: Partner with infrastructure, application, and security teams to ensure baseline requirements are understood, implemented, and maintained across all environments.
  • Compliance Reporting: Track and report on configuration compliance metrics, maintain automated dashboards, and provide visibility to stakeholders and leadership within the ServiceNow application.
  • Documentation & Audit Support: Document configuration changes, exceptions, and remediation activities. Support internal and external audits by providing evidence of compliance and remediation.
  • Process Automation: Assist in the development and automation of configuration management and compliance reporting tools and frameworks.
  • Knowledge Sharing: Share knowledge and best practices with the team through presentations, documentation, and training sessions.
  • Incident Response: Support incident response and remediation efforts by identifying and correcting misconfigurations and partnering with blue teams to improve detection and response capabilities related to configuration changes and vulnerabilities.

Skills

Security engineering
Configuration management
Vulnerability scanning
Documentation
Willingness to travel

Education

Bachelor's degree in computer science or related field

Tools

Ansible
Chef
Puppet
PowerShell
Python
Bash
Tenable
Qualys
Rapid7
CIS Benchmarks
SCAP
NIST CSF
MITRE ATT&CK
ServiceNow Vulnerability Response
ServiceNow Configuration Compliance

Job description

Location:

4910 Tiedeman Road, Brooklyn Ohio

As a member of the Cyber Defense team within Corporate Information Security, the Senior Exposure Management Engineer plays a critical role in safeguarding KeyBank's infrastructure by designing, implementing, and maintaining secure configurations across on-premises, cloud, and hybrid environments. This position is responsible for ensuring that systems, applications, and networks are configured in strict alignment with industry-recognized standards, particularly the CIS Benchmarks, as well as organizational security baselines. The engineer continuously monitors updates to CIS Benchmarks, integrates new controls, and supports audit readiness by maintaining comprehensive documentation and evidence of compliance. By leveraging industry standard automated scanning capabilities, the Senior Exposure Management Engineer validates configuration settings, identifies vulnerabilities, and ensures timely remediation and re-assessment, directly supporting KeyBank's mission to Deter, Detect, Deny, and Disrupt adversaries through robust, standards-based defense. The role involves collaborating with cross-functional teams to assess, remediate, and document configuration gaps, ensuring that all configurations meet or exceed CIS recommendations. This proactive approach directly supports the organization's mission to Deter, Detect, Deny, and Disrupt adversaries through robust, standards-based defense

Key Responsibilities

  • Configuration Management: Develop, implement, and maintain secure configuration baselines for operating systems, cloud platforms (Google Cloud, Microsoft Azure, AWS), applications, and network devices, ensuring strict adherence to CIS Benchmarks and organizational standards.
  • Continuous Assessment: Conduct regular configuration assessments and audits using Tenable and other industry-standard tools to validate compliance with CIS Benchmarks, NIST, PCI-DSS, and other regulatory requirements.
  • Vulnerability Management: Perform authenticated and unauthenticated vulnerability scans with Tenable, analyze results, and coordinate remediation activities. Ensure that scan policies are tuned to cover CIS Benchmark controls, and that remediation is verified through re-scanning.
  • Threat Intelligence: Collaborate with the Cyber Threat Intelligence and Red Team to incorporate threat intelligence into configuration management and prioritization processes.
  • Project Collaboration: Work with project teams, architects, and third-party vendors to embed security controls in system designs and deployments and validate configuration requirements.
  • Cross-Team Collaboration: Partner with infrastructure, application, and security teams to ensure baseline requirements are understood, implemented, and maintained across all environments.
  • Compliance Reporting: Track and report on configuration compliance metrics, maintain automated dashboards, and provide visibility to stakeholders and leadership within the ServiceNow application.
  • Documentation & Audit Support: Document configuration changes, exceptions, and remediation activities. Support internal and external audits by providing evidence of compliance and remediation.
  • Process Automation: Assist in the development and automation of configuration management and compliance reporting tools and frameworks.
  • Knowledge Sharing: Share knowledge and best practices with the team through presentations, documentation, and training sessions.
  • Incident Response: Support incident response and remediation efforts by identifying and correcting misconfigurations and partnering with blue teams to improve detection and response capabilities related to configuration changes and vulnerabilities.

Required Qualifications

  • Bachelor\'s degree in computer science, Cybersecurity, or related field-or equivalent experience.
  • 8+ years of experience in security engineering, configuration management, or related roles.
  • Proficiency with configuration management tools (e.g., Ansible, Chef, Puppet) and scripting languages (PowerShell, Python, Bash).
  • Experience with Vulnerability Management platforms (Tenable, Qualys, Rapid7 etc) running vulnerability scans, monitoring agent health, and maintaining scanner operability.
  • Comprehensive expertise in Tenable or comparable vendor solutions for compliance scanning.
  • Strong understanding of Cisco, Windows, Linux, Kali Linux, and macOS operating systems.
  • Hands-on experience with cloud platforms (Google Cloud, Microsoft Azure, AWS).
  • Familiarity with security frameworks and standards (e.g., CIS Benchmarks, SCAP, NIST CSF, MITRE ATT\&CK).
  • Experience with ServiceNow security related modules such as Vulnerability Response & Configuration Compliance
  • Effective research, documentation, and reporting skills.
  • Willingness to travel.

Preferred Certifications

  • Certified Information Systems Security Professional (CISSP)
  • GIAC Security Essentials (GSEC)
  • GIAC Certified Vulnerability Assessor (GCVA)
  • Microsoft Certified: Azure Security Engineer Associate
  • AWS Certified Security - Specialty
  • Google Cloud Security Engineer
COMPENSATION AND BENEFITS

This position is eligible to earn a base salary in the range of $96,000.00 - $181,000.00 annually. Placement within the pay range may differ based upon various factors, including but not limited to skills, experience and geographic location. Compensation for this role also includes eligibility for incentive compensation which may include production, commission, and/or discretionary incentives.

Key has implemented an approach to employee workspaces which prioritizes in-office presence, while providing flexible options in circumstances where roles can be performed effectively in a mobile environment.

#LI-Hybrid

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer- Security Baselines
Senior Security Engineer- Security Baselines

KeyCorp • Brooklyn (OH)

Hybrid
USD 96,000 - 181,000
Hybrid work model
Sr Info Security Consultant
Sr Info Security Consultant

KeyBank • Brooklyn (OH)

Hybrid
USD 96,000 - 181,000
Technology Security Engineering Manager (Hybrid within a BankUnited Office Location)
Technology Security Engineering Manager (Hybrid within a BankUnited Office Location)

BankUnited • Orlando (FL), Northern (KY)

Hybrid
USD 160,000 - 180,000
Sr. Cybersecurity Operational Risk Officer
Sr. Cybersecurity Operational Risk Officer

KeyBank • Charlotte (NC)

On-site
USD 96,000 - 181,000
Sr. Cybersecurity Operational Risk Officer
Sr. Cybersecurity Operational Risk Officer

KeyBank • Chicago (IL)

On-site
USD 96,000 - 181,000
Sr Info Security Consultant
Sr Info Security Consultant

KeyBank • City of Albany (NY)

Hybrid
USD 96,000 - 181,000
Sr. Cybersecurity Operational Risk Officer
Sr. Cybersecurity Operational Risk Officer

KeyBank • Town of Amherst (NY)

On-site
USD 96,000 - 181,000
Senior CIS Security Engineer - Cloud, Config & Compliance
Senior CIS Security Engineer - Cloud, Config & Compliance

KeyCorp • Brooklyn (OH)

Hybrid
USD 96,000 - 181,000
Hybrid work model
Insider Threat Senior Analyst
Insider Threat Senior Analyst

KeyBank • Kentucky

On-site
USD 96,000 - 181,000
Insider Threat Senior Analyst
Insider Threat Senior Analyst

KeyBank • Brooklyn (OH)

On-site
USD 96,000 - 181,000