KeyBank Logo

KeyBank

Senior Detection & Automation Engineer

Reposted 5 Days Ago
Be an Early Applicant
In-Office or Remote
2 Locations
100K-150K Annually
Senior level
In-Office or Remote
2 Locations
100K-150K Annually
Senior level
Lead development of detection logic and automation capabilities within Cyber Defense. Build detection capabilities, automate workflows, mentor junior engineers, and align strategies with threat intelligence.
The summary above was generated by AI

Location:

4910 Tiedeman Road, Brooklyn Ohio

Senior Detection & Automation EngineerPosition Summary

Our Cyber Detection & Automation team rolls up into Key’s broader Cyber Defense function within Corporate Information Security.  Cyber Defense’s mission is simple: We aim to Deter, Detect, Deny, and Disrupt adversaries through proactive threat centric defense.

As a senior member of the Cyber Detection & Automation (CDA) team within Key’s Cyber Defense function, you will lead the development of detection logic and automation capabilities that enable our mission to Deter, Detect, Deny, and Disrupt adversaries. This role is pivotal in advancing our threat-centric defense posture by engineering high-fidelity detections, orchestrating response workflows, and mentoring junior engineers.

You will work across SIEM, SOAR, and DAM platforms to build scalable, resilient detection and response capabilities. You’ll also collaborate with Cyber Threat Intelligence, Threat Response, and Engineering teams to ensure our detection strategy aligns with evolving adversary tactics and business risk.

Key Responsibilities

Detection Engineering

  • Design and implement detection-as-code rules, alerts, dashboards, and reports across SIEM and log aggregation platforms.
  • Translate threat intelligence and adversary TTPs into actionable detection logic using frameworks like MITRE ATT&CK.
  • Continuously tune detection content to reduce false positives and improve signal fidelity.

Security Automation

  • Develop and maintain SOAR playbooks to automate triage, enrichment, and response actions.
  • Identify manual processes suitable for automation and lead their transformation into orchestrated workflows.

Threat Analysis & Content Development

  • Perform event correlation and log analysis to validate detection efficacy and identify gaps.
  • Conduct trend analysis to identify emerging threats and detection opportunities.
  • Document detection use cases and maintain lifecycle documentation using team standards.

Collaboration & Mentorship

  • Partner with Cyber Threat Response and Threat Intelligence teams to align detection priorities.
  • Escalate confirmed or suspected malicious activity with contextual analysis.
  • Mentor junior engineers and contribute to team knowledge sharing and training.
Required Qualifications

Technical Expertise

  • Deep understanding of cyber defense principles, adversary TTPs, and detection engineering.
  • Proficiency in scripting languages (PowerShell, Python, JavaScript, Bash), SIEM query languages, and industry formats (Sigma, YARA-L, etc)
  • Experience with SOAR platforms and automation development.
  • Familiarity with cloud security (Azure, AWS, GCP) and integrating cloud telemetry into detection pipelines.

Operational & Analytical Skills

  • Strong problem-solving skills and ability to interpret complex log data.
  • Experience in documenting and managing detection content lifecycle.
  • Ability to communicate technical concepts to both technical and non-technical audiences.

Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, or related field—or equivalent experience.
  • 5+ years in security operations, detection engineering, or threat hunting roles.
  • Familiarity with the MITRE ATT&CK and D3FEND framework and adversary TTPs.
Preferred Certifications
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Auditor (CISA)
  • CompTIA Security+
  • GIAC Certified Detection Analyst (GCDA)
  • GIAC Cloud Threat Detection (GCTD)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Intrusion Analyst (GCIA)

COMPENSATION AND BENEFITS

This position is eligible to earn a base salary in the range of $100,000.00 to $150,000.00 annually depending on job-related factors such as level of experience. Compensation for this role also includes eligibility for short-term incentive compensation and deferred incentive compensation subject to individual and company performance. Please click here for a list of benefits for which this position is eligible.

Please click here for a list of benefits for which this position is eligible.

Key has implemented an approach to employee workspaces which prioritizes in-office presence, while providing flexible options in circumstances where roles can be performed effectively in a mobile environment.

Job Posting Expiration Date: 10/05/2025 KeyCorp is an Equal Opportunity Employer committed to sustaining an inclusive culture. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status.

Qualified individuals with disabilities or disabled veterans who are unable or limited in their ability to apply on this site may request reasonable accommodations by emailing [email protected].


#LI-Remote

Top Skills

AWS
Azure
Bash
GCP
JavaScript
Powershell
Python
SIEM
Sigma
Soar
Yara-L

Similar Jobs

An Hour Ago
In-Office or Remote
Chicago, IL, USA
65K-75K Annually
Junior
65K-75K Annually
Junior
Fintech
The Compliance Analyst supports the Compliance and Risk Management Department by ensuring adherence to policies and regulations, conducting investigations, and managing compliance training.
Top Skills: ExcelMicrosoft OutlookMicrosoft SharepointMicrosoft TeamsMicrosoft VisioMicrosoft WordSalesforce
An Hour Ago
Easy Apply
Remote or Hybrid
USA
Easy Apply
64K-70K
Mid level
64K-70K
Mid level
Artificial Intelligence • Healthtech • Telehealth
The Mental Health Provider will deliver mental health counseling, respond to clinical crises, maintain caseloads, and ensure compliance with care standards.
Top Skills: ActCpt)Data-Driven Decision MakingDbtEmdrEvidence-Based Modalities (CbtTelehealth Technology
An Hour Ago
Remote or Hybrid
United States
117K-146K
Senior level
117K-146K
Senior level
Digital Media • Gaming • Information Technology • Software • Sports • Esports • Big Data Analytics
The Senior Data Engineer at DraftKings will design and implement data systems, maintain data pipelines, and ensure data quality while collaborating with various teams to drive improvements.
Top Skills: BigQueryGitRedshiftSnowflakeSQL

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account