KeyBank Logo

KeyBank

Cyber Defense Incident Response Lead

Posted 26 Days Ago
Be an Early Applicant
In-Office or Remote
Hiring Remotely in United States
96K-181K Annually
Senior level
In-Office or Remote
Hiring Remotely in United States
96K-181K Annually
Senior level
Leads enterprise cybersecurity incident response, coordinating containment, escalation, stakeholder communications, documentation, and resolution tracking. Owns the incident response program, including playbooks, runbooks, governance, metrics, tabletop exercises, post-incident reviews, audit support, executive reporting, and continuous improvement. Partners with security, technology, business, legal, risk, compliance, communications, and third-party teams to strengthen threat-informed readiness and response capabilities. May provide after-hours support during significant incidents or exercises.
The summary above was generated by AI

Location:

4910 Tiedeman Road, Brooklyn Ohio

Job Description 

Cyber Incident Response Lead 

As a member of the Cyber Defense team within Corporate Information Security, the Incident Response Lead plays a critical role in strengthening KeyBank’s ability to prepare for, coordinate, and respond to cybersecurity incidents across the enterprise. This position is responsible for leading high-impact cyber incident response activities, ensuring timely coordination across Cyber Defense, technology, business, risk, legal, communications, and executive stakeholders. The Incident Response Lead will own and continuously mature the Cyber Defense incident response program by maintaining response documentation, improving playbooks and runbooks, developing repeatable response processes, and ensuring lessons learned are translated into actionable program improvements. 

This role requires a strong blend of cyber incident response experience, program development capability, executive communication skills, and operational leadership. The Incident Response Lead will facilitate tabletop exercises, support incident simulations, drive post-incident reviews, develop executive-level reporting, and help ensure KeyBank’s incident response capabilities remain aligned to the evolving threat landscape, regulatory expectations, and business resilience needs. This position directly supports KeyBank’s mission to Deter, Detect, Deny, and Disrupt adversaries through coordinated, well-documented, and continuously improving cyber defense capabilities. 

Key Responsibilities 

Incident Leadership: Lead cybersecurity incident response coordination for significant cyber events, ensuring appropriate triage, escalation, containment coordination, stakeholder engagement, and resolution tracking. 

Incident Command & Coordination: Serve as a primary Cyber Defense incident response lead during active incidents, coordinating across Cyber Threat Response, Cyber Threat Management, Cyber Detection and Automation, Cyber Application and Cloud Defense, Cyber Adversary and Exposure Management, Technology Incident Management, Corporate Incident Response, and other enterprise partners as needed. 

Documentation & Case Management: Ensure accurate, timely, and complete documentation of incident timelines, actions taken, decisions made, evidence collected, communications issued, and lessons learned. 

Program Development: Develop, mature, and maintain the Cyber Defense incident response program, including response frameworks, operating models, escalation paths, governance routines, templates, metrics, and continuous improvement processes. 

Playbook & Runbook Management: Create, update, and maintain incident response playbooks, runbooks, quick reference guides, and standard operating procedures to support consistent execution during cyber events. 

Tabletop Exercises: Design, facilitate, and evaluate cyber tabletop exercises, simulations, and scenario-based discussions to test readiness, validate response plans, identify gaps, and drive remediation actions. 

Post-Incident Reviews: Lead post-incident reviews and lessons-learned sessions, documenting root cause, response effectiveness, improvement opportunities, and ownership of follow-up actions. 

Executive Reporting: Develop clear, concise, and business-relevant incident reporting for Cyber Defense leadership, CIS leadership, executive stakeholders, committees, and board-level audiences as appropriate. 

Metrics & Continuous Improvement: Establish and track incident response performance metrics, including response timelines, documentation quality, action closure, recurring themes, exercise findings, and program maturity indicators. 

Stakeholder Engagement: Partner with business, technology, risk, legal, compliance, communications, and third-party teams to ensure Cyber Defense response processes are understood, practiced, and integrated with enterprise incident management expectations. 

Regulatory & Audit Support: Support internal audit, regulatory, and compliance requests related to cybersecurity incident response documentation, testing, governance, and program effectiveness. 

Threat-Informed Readiness: Collaborate with Threat Intelligence, Detection Engineering, SOC operations, and other Cyber Defense teams to ensure response plans reflect current adversary tactics, emerging threats, and relevant attack scenarios. 

Crisis Communication Support: Support the development of leadership updates, incident summaries, situation reports, after-action reports, and communication artifacts during and after cyber events. 

Process Automation & AI Enablement: Identify opportunities to improve incident response efficiency through automation, AI-enabled workflows, structured data capture, and repeatable response templates. 

Knowledge Sharing: Provide training, coaching, and knowledge transfer to Cyber Defense team members and cross-functional partners on incident response expectations, playbook usage, tabletop outcomes, and program changes. 

Required Qualifications 

Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Business Continuity, Risk Management, or related field — or equivalent practical experience. 

8+ years of experience in cybersecurity, incident response, security operations, cyber risk management, technology incident management, or related disciplines. 

Demonstrated experience leading or coordinating cybersecurity incidents in complex enterprise environments. 

Strong understanding of incident response lifecycle activities, including preparation, detection, analysis, containment, eradication, recovery, and post-incident improvement. 

Experience developing or maintaining incident response plans, playbooks, runbooks, procedures, executive summaries, or after-action reports. 

Ability to lead cross-functional teams during high-pressure situations and drive clarity, accountability, and timely decision-making. 

Strong executive communication skills, including the ability to translate technical cyber incidents into business impact, risk, actions taken, and next steps. 

Experience planning, facilitating, or participating in tabletop exercises, cyber simulations, or crisis response exercises. 

Familiarity with security operations, SIEM, EDR/XDR, SOAR, threat intelligence, vulnerability management, cloud security, identity security, and other enterprise security capabilities. 

Working knowledge of common cybersecurity frameworks and guidance, such as NIST CSF, NIST incident response guidance, MITRE ATT&CK, FFIEC Cybersecurity Assessment Tool, or similar industry standards. 

Strong documentation, organization, and program management skills. 

Ability to manage multiple priorities, coordinate stakeholders, and maintain structure during ambiguous or fast-moving incidents. 

Experience supporting audit, regulatory, risk, or governance activities related to cyber incident response. 

Ability to provide after-hours support during significant cybersecurity incidents or exercises, as needed. 

Preferred Qualifications 

Experience in financial services, banking, critical infrastructure, or other highly regulated environments. 

Experience working with Corporate Incident Response, Technology Incident Management, Business Resiliency, Legal, Privacy, Communications, Fraud, Third Party Risk, or similar enterprise response partners. 

Experience developing executive-level incident reports, board-level summaries, or committee reporting materials. 

Experience with ServiceNow Security Incident Response, major incident management workflows, or similar incident tracking platforms. 

Experience with Palo Alto Cortex XSIAM/XSOAR/XDR, or similar security operations technologies. 

Experience integrating incident response workflows with automation, AI-enabled response support, SOAR playbooks, or structured response workspaces. 

Experience conducting post-incident maturity reviews and translating findings into program roadmaps. 

Strong understanding of ransomware, business email compromise, cloud compromise, data exfiltration, third-party cyber incidents, DDoS, insider threat, and other major cyber incident scenarios. 

Preferred Certifications 

Certified Information Systems Security Professional — CISSP 
GIAC Certified Incident Handler — GCIH 
GIAC Certified Forensic Analyst — GCFA 
GIAC Certified Enterprise Defender — GCED 
Certified Information Security Manager — CISM 
Certified in Risk and Information Systems Control — CRISC 
Project Management Professional — PMP 
ITIL Foundation or equivalent incident/problem management certification 

COMPENSATION AND BENEFITS

This position is eligible to earn a base salary in the range of $96,000.00 - $181,000.00 annually. Placement within the pay range may differ based upon various factors, including but not limited to skills, experience and geographic location. Compensation for this role also includes eligibility for incentive compensation which may include production, commission, and/or discretionary incentives.

Please click here for a list of benefits for which this position is eligible.

Key has implemented an approach to employee workspaces which prioritizes in-office presence, while providing flexible options in circumstances where roles can be performed effectively in a mobile environment.

Job Posting Expiration Date: 10/08/2026 KeyCorp is an Equal Opportunity Employer committed to sustaining an inclusive culture. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, genetic information, pregnancy, disability, veteran status or any other characteristic protected by law.

Qualified individuals with disabilities or disabled veterans who are unable or limited in their ability to apply on this site may request reasonable accommodations by emailing [email protected].



#LI-Remote

Similar Jobs

5 Minutes Ago
Remote
United States
130K-180K Annually
Senior level
130K-180K Annually
Senior level
Artificial Intelligence • Fintech • Information Technology • Marketing Tech • Payments • Social Impact • Software
Leads and builds Donorbox’s product marketing function, owning positioning, messaging, product-led growth, launches, enablement, competitive intelligence, and performance measurement. Partners with Product, Sales, Customer Success, and Marketing to drive acquisition, conversion, retention, and expansion. Manages one direct report, establishes scalable processes and KPIs, influences roadmap priorities, and presents data-driven insights to executive leadership.
Top Skills: Product-Led Growth (Plg)SaaS
6 Minutes Ago
Easy Apply
In-Office or Remote
IN, USA
Easy Apply
28-28 Hourly
Junior
28-28 Hourly
Junior
Healthtech • Pharmaceutical • Telehealth
Provides empathetic, non-clinical support to telehealth patients and providers. Responsibilities include answering patient questions, managing EHR messages, investigating care issues, coordinating with pharmacies and insurers, assisting with benefits verification and prior authorizations, and communicating actionable next steps. The role also identifies workflow improvements, supports operational initiatives, and works toward service and quality metrics in a remote, asynchronous environment.
Top Skills: Ai-Based ToolingElectronic Medical Records (Ehr)Google WorkspaceLlm-Based Message SystemsSlack
49 Minutes Ago
Easy Apply
Remote
United States
Easy Apply
69K-95K Annually
Mid level
69K-95K Annually
Mid level
Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
Provide high-level administrative support to sales executives including calendar, travel, expense reporting, and confidential communication. Prepare reports and sales materials using PowerPoint, Excel, and CRM. Plan and execute internal and external sales events and offsites. Liaise with clients and internal teams, multitask under pressure, and travel a few times a year.
Top Skills: CoupaCRMExcelGoogle SuiteNavanPowerPointSlack

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account