Enter a job title or keyword

Cyber Defense Incident Response Lead

KeyBank


Job Location:

Brooklyn, NY - USA

Yearly Salary: USD 96000 - 181000
Posted: 5 September 2026 (7 days ago)
Application Deadline: 3 December 2026
Vacancies: 1 Vacancy

Job Summary

Location:

4910 Tiedeman Road Brooklyn Ohio

Job Description

Cyber Incident Response Lead

As a member of the Cyber Defense team within Corporate Information Security the Incident Response Lead plays a critical role in strengthening KeyBanks ability to prepare for coordinate and respond to cybersecurity incidents across the enterprise. This position is responsible for leading high-impact cyber incident response activities ensuring timely coordination across Cyber Defense technology business risk legal communications and executive stakeholders. The Incident Response Lead will own and continuously mature the Cyber Defense incident response program by maintaining response documentation improving playbooks and runbooks developing repeatable response processes and ensuring lessons learned are translated into actionable program improvements.

This role requires a strong blend of cyber incident response experience program development capability executive communication skills and operational leadership. The Incident Response Lead will facilitate tabletop exercises support incident simulations drive post-incident reviews develop executive-level reporting and help ensure KeyBanks incident response capabilities remain aligned to the evolving threat landscape regulatory expectations and business resilience needs. This position directly supports KeyBanks mission to Deter Detect Deny and Disrupt adversaries through coordinated well-documented and continuously improving cyber defense capabilities.

Key Responsibilities

Incident Leadership: Lead cybersecurity incident response coordination for significant cyber events ensuring appropriate triage escalation containment coordination stakeholder engagement and resolution tracking.

Incident Command & Coordination: Serve as a primary Cyber Defense incident response lead during active incidents coordinating across Cyber Threat Response Cyber Threat Management Cyber Detection and Automation Cyber Application and Cloud Defense Cyber Adversary and Exposure Management Technology Incident Management Corporate Incident Response and other enterprise partners as needed.

Documentation & Case Management: Ensure accurate timely and complete documentation of incident timelines actions taken decisions made evidence collected communications issued and lessons learned.

Program Development: Develop mature and maintain the Cyber Defense incident response program including response frameworks operating models escalation paths governance routines templates metrics and continuous improvement processes.

Playbook & Runbook Management: Create update and maintain incident response playbooks runbooks quick reference guides and standard operating procedures to support consistent execution during cyber events.

Tabletop Exercises: Design facilitate and evaluate cyber tabletop exercises simulations and scenario-based discussions to test readiness validate response plans identify gaps and drive remediation actions.

Post-Incident Reviews: Lead post-incident reviews and lessons-learned sessions documenting root cause response effectiveness improvement opportunities and ownership of follow-up actions.

Executive Reporting: Develop clear concise and business-relevant incident reporting for Cyber Defense leadership CIS leadership executive stakeholders committees and board-level audiences as appropriate.

Metrics & Continuous Improvement: Establish and track incident response performance metrics including response timelines documentation quality action closure recurring themes exercise findings and program maturity indicators.

Stakeholder Engagement: Partner with business technology risk legal compliance communications and third-party teams to ensure Cyber Defense response processes are understood practiced and integrated with enterprise incident management expectations.

Regulatory & Audit Support: Support internal audit regulatory and compliance requests related to cybersecurity incident response documentation testing governance and program effectiveness.

Threat-Informed Readiness: Collaborate with Threat Intelligence Detection Engineering SOC operations and other Cyber Defense teams to ensure response plans reflect current adversary tactics emerging threats and relevant attack scenarios.

Crisis Communication Support: Support the development of leadership updates incident summaries situation reports after-action reports and communication artifacts during and after cyber events.

Process Automation & AI Enablement: Identify opportunities to improve incident response efficiency through automation AI-enabled workflows structured data capture and repeatable response templates.

Knowledge Sharing: Provide training coaching and knowledge transfer to Cyber Defense team members and cross-functional partners on incident response expectations playbook usage tabletop outcomes and program changes.

Required Qualifications

Bachelors degree in Cybersecurity Computer Science Information Technology Business Continuity Risk Management or related field or equivalent practical experience.

8 years of experience in cybersecurity incident response security operations cyber risk management technology incident management or related disciplines.

Demonstrated experience leading or coordinating cybersecurity incidents in complex enterprise environments.

Strong understanding of incident response lifecycle activities including preparation detection analysis containment eradication recovery and post-incident improvement.

Experience developing or maintaining incident response plans playbooks runbooks procedures executive summaries or after-action reports.

Ability to lead cross-functional teams during high-pressure situations and drive clarity accountability and timely decision-making.

Strong executive communication skills including the ability to translate technical cyber incidents into business impact risk actions taken and next steps.

Experience planning facilitating or participating in tabletop exercises cyber simulations or crisis response exercises.

Familiarity with security operations SIEM EDR/XDR SOAR threat intelligence vulnerability management cloud security identity security and other enterprise security capabilities.

Working knowledge of common cybersecurity frameworks and guidance such as NIST CSF NIST incident response guidance MITRE ATT&CK FFIEC Cybersecurity Assessment Tool or similar industry standards.

Strong documentation organization and program management skills.

Ability to manage multiple priorities coordinate stakeholders and maintain structure during ambiguous or fast-moving incidents.

Experience supporting audit regulatory risk or governance activities related to cyber incident response.

Ability to provide after-hours support during significant cybersecurity incidents or exercises as needed.

Preferred Qualifications

Experience in financial services banking critical infrastructure or other highly regulated environments.

Experience working with Corporate Incident Response Technology Incident Management Business Resiliency Legal Privacy Communications Fraud Third Party Risk or similar enterprise response partners.

Experience developing executive-level incident reports board-level summaries or committee reporting materials.

Experience with ServiceNow Security Incident Response major incident management workflows or similar incident tracking platforms.

Experience with Palo Alto Cortex XSIAM/XSOAR/XDR or similar security operations technologies.

Experience integrating incident response workflows with automation AI-enabled response support SOAR playbooks or structured response workspaces.

Experience conducting post-incident maturity reviews and translating findings into program roadmaps.

Strong understanding of ransomware business email compromise cloud compromise data exfiltration third-party cyber incidents DDoS insider threat and other major cyber incident scenarios.

Preferred Certifications

Certified Information Systems Security Professional CISSP
GIAC Certified Incident Handler GCIH
GIAC Certified Forensic Analyst GCFA
GIAC Certified Enterprise Defender GCED
Certified Information Security Manager CISM
Certified in Risk and Information Systems Control CRISC
Project Management Professional PMP
ITIL Foundation or equivalent incident/problem management certification

COMPENSATION AND BENEFITS

This position is eligible to earn a base salary in the range of $96000.00 - $181000.00 annually. Placement within the pay range may differ based upon various factors including but not limited to skills experience and geographic location. Compensation for this role also includes eligibility for incentive compensation which may include production commission and/or discretionary incentives.

Please click here for a list of benefits for which this position is eligible.

Key has implemented an approach to employee workspaces which prioritizes in-office presence while providing flexible options in circumstances where roles can be performed effectively in a mobile environment.

Job Posting Expiration Date: 10/08/2026 KeyCorp is an Equal Opportunity Employer committed to sustaining an inclusive culture. All qualified applicants will receive consideration for employment without regard to race color religion sex sexual orientation gender identity national origin age genetic information pregnancy disability veteran status or any other characteristic protected by law.

Qualified individuals with disabilities or disabled veterans who are unable or limited in their ability to apply on this site may request reasonable accommodations by emailing

#LI-Remote