Skip to content

Open nowPosted 22 days ago

Senior Exposure Management Engineer

KeyBank21 open roles

Pay
$96,000 – $181,000 a year
Where
Brooklyn, OH
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Exposure Management EngineerKeyBank · Brooklyn, OH
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on KeyBank's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. KeyBank postings stay open a median of 4 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.5%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 33.9%30 days
This job: posted 22 days ago

KeyBank median: 4 days open

The posting

Location:

4910 Tiedeman Road, Brooklyn Ohio

Position Summary

As a member of the Cyber Defense team within Corporate Information Security, the Senior Exposure Management Engineer is responsible for governing, assessing, and maintaining enterprise security baseline standards across on-premises, cloud, and hybrid environments. This role ensures technology assets remain aligned with approved security configuration standards, industry frameworks, and regulatory requirements through continuous assessment, compliance monitoring, and risk-based remediation activities.

The Senior Exposure Management Engineer leverages automated assessment and compliance validation tools to identify configuration weaknesses, measure adherence to enterprise security baselines, and monitor configuration drift across the environment. The role partners closely with Security Architecture, Infrastructure, Engineering, Cloud, and Application teams to drive remediation, manage exceptions, support audit and regulatory examinations, and enhance the organization's overall security posture through consistent application of standards-based controls.

This position also leads the evolution of the enterprise baseline program by evaluating changes to industry guidance, improving compliance measurement capabilities, expanding automation, and providing actionable reporting that enables informed risk-based decisions and continuous exposure reduction

Key Responsibilities

  • Security Baseline GovernanceMaintain and govern enterprise-approved security baseline standards across operating systems, cloud platforms, applications, databases, and network infrastructure. Support the review and adoption of updates to CIS Benchmarks and other industry-recognized security standards through established governance processes. Partner with Security Architecture and technology teams to ensure baseline requirements are appropriately documented, communicated, and operationalized.
  • Configuration Compliance AssessmentConduct ongoing configuration compliance assessments utilizing automated scanning and validation tools to measure adherence to approved baseline standards. Validate remediation activities through continuous monitoring and reassessment. Identify, analyze, and report configuration weaknesses that increase organizational risk.
  • Configuration Drift MonitoringMonitor configuration drift across enterprise assets and provide reporting on deviations from approved security baselines. Partner with technology owners to investigate non-compliant configurations and drive timely remediation.
  • Exception and Risk ManagementManage baseline exceptions, compensating controls, and risk acceptance documentation. Ensure approved deviations from security standards are appropriately documented, reviewed, and tracked through remediation or renewal cycles.
  • Compliance Reporting & MetricsDevelop and maintain configuration compliance metrics, dashboards, and executive reporting. Provide visibility into compliance trends, remediation progress, assessment coverage, and risk reduction activities. Support reporting through ServiceNow and other enterprise governance platforms.
  • Audit & Regulatory SupportMaintain documentation, evidence, and reporting required to support internal audits, external examinations, and regulatory assessments. Demonstrate compliance with enterprise security requirements, industry standards, and applicable regulatory obligations.
  • Cross-Functional CollaborationPartner with Infrastructure, Cloud, Application, Engineering, and Security teams to support implementation and maintenance of approved security baselines. Provide guidance regarding baseline compliance requirements and remediation priorities.
  • Continuous Improvement & AutomationIdentify opportunities to improve assessment coverage, compliance measurement, reporting, and operational efficiencies through automation. Support implementation of automated compliance validation and reporting capabilities.
  • Threat-Informed Exposure ReductionCollaborate with Vulnerability Management, Threat Intelligence, Red Team, and Exposure Management teams to prioritize remediation of configuration weaknesses that contribute to exploitable attack paths and elevated risk. Utilize risk-based methodologies to focus remediation efforts on the highest-impact configuration deficiencies.
  • Knowledge SharingShare security baseline best practices, emerging standards, and compliance requirements through documentation, training, and stakeholder engagement.

Required Qualifications

  • Bachelor’s degree in computer science, Cybersecurity, or related field—or equivalent experience.
  • 8+ years of experience in security engineering, configuration management, or related roles.
  • Experience with Vulnerability Management platforms (Tenable, Qualys, Rapid7 etc) running vulnerability scans, monitoring agent health, and maintaining scanner operability.
  • Comprehensive expertise in Tenable or comparable vendor solutions for compliance scanning.
  • Broad understanding of enterprise computing platforms and their configuration management, compliance, and security considerations.
  • Hands-on experience with cloud platforms (Google Cloud, Microsoft Azure, AWS).
  • Familiarity with security frameworks and standards (e.g., CIS Benchmarks, SCAP, NIST CSF, MITRE ATT\&CK).
  • Experience with ServiceNow security related modules such as Vulnerability Response & Configuration Compliance
  • Effective research, documentation, and reporting skills.
  • Willingness to travel.

Preferred Certifications

  • Certified Information Systems Security Professional (CISSP)
  • GIAC Security Essentials (GSEC)
  • GIAC Certified Vulnerability Assessor (GCVA)
  • Microsoft Certified: Azure Security Engineer Associate
  • AWS Certified Security – Specialty
  • Google Cloud Security Engineer

COMPENSATION AND BENEFITS

This position is eligible to earn a base salary in the range of $96,000.00 - $181,000.00 annually. Placement within the pay range may differ based upon various factors, including but not limited to skills, experience and geographic location. Compensation for this role also includes eligibility for incentive compensation which may include production, commission, and/or discretionary incentives.

Please click here for a list of benefits for which this position is eligible.

Key has implemented an approach to employee workspaces which prioritizes in-office presence, while providing flexible options in circumstances where roles can be performed effectively in a mobile environment.

Job Posting Expiration Date: 10/30/2026

KeyCorp is an Equal Opportunity Employer committed to sustaining an inclusive culture. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, genetic information, pregnancy, disability, veteran status or any other characteristic protected by law.

Qualified individuals with disabilities or disabled veterans who are unable or limited in their ability to apply on this site may request reasonable accommodations by emailing [email protected].

#LI-Hybrid

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against KeyBank's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on KeyBank's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    KeyBank's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.