KeyBank

Cyber Defense Incident Response Lead

KeyBank$96K — $181K *
US-AnywhereRemote in United States
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Business Continuity, Risk Management, or related field.
  • 8+ years of experience in cybersecurity, incident response, or related fields.
  • Demonstrated experience leading cybersecurity incidents in complex environments.
  • Strong understanding of the incident response lifecycle.
  • Experience developing incident response plans, playbooks, and reports.
  • Strong executive communication skills with the ability to translate technical incidents into business impact.
  • Familiarity with security operations and incident tracking platforms.

Responsibilities

  • Lead cybersecurity incident response coordination for significant events.
  • Serve as the primary incident response lead during active incidents.
  • Ensure accurate and complete documentation of incidents and actions taken.
  • Develop and maintain the Cyber Defense incident response program.
  • Create and update incident response playbooks and standard operating procedures.
  • Design and facilitate tabletop exercises to validate response plans.
  • Lead post-incident reviews, documenting root causes and improvement opportunities.

Benefits

  • Flexible work options for roles that can be performed remotely.
  • Access to employee benefits including health coverage and retirement plans.
Full Job Description

Location:

4910 Tiedeman Road, Brooklyn Ohio

Job Description

Cyber Incident Response Lead

As a member of the Cyber Defense team within Corporate Information Security, the Incident Response Lead plays a critical role in strengthening KeyBank’s ability to prepare for, coordinate, and respond to cybersecurity incidents across the enterprise. This position is responsible for leading high-impact cyber incident response activities, ensuring timely coordination across Cyber Defense, technology, business, risk, legal, communications, and executive stakeholders. The Incident Response Lead will own and continuously mature the Cyber Defense incident response program by maintaining response documentation, improving playbooks and runbooks, developing repeatable response processes, and ensuring lessons learned are translated into actionable program improvements.

This role requires a strong blend of cyber incident response experience, program development capability, executive communication skills, and operational leadership. The Incident Response Lead will facilitate tabletop exercises, support incident simulations, drive post-incident reviews, develop executive-level reporting, and help ensure KeyBank’s incident response capabilities remain aligned to the evolving threat landscape, regulatory expectations, and business resilience needs. This position directly supports KeyBank’s mission to Deter, Detect, Deny, and Disrupt adversaries through coordinated, well-documented, and continuously improving cyber defense capabilities.

Key Responsibilities

Incident Leadership: Lead cybersecurity incident response coordination for significant cyber events, ensuring appropriate triage, escalation, containment coordination, stakeholder engagement, and resolution tracking.

Incident Command & Coordination: Serve as a primary Cyber Defense incident response lead during active incidents, coordinating across Cyber Threat Response, Cyber Threat Management, Cyber Detection and Automation, Cyber Application and Cloud Defense, Cyber Adversary and Exposure Management, Technology Incident Management, Corporate Incident Response, and other enterprise partners as needed.

Documentation & Case Management: Ensure accurate, timely, and complete documentation of incident timelines, actions taken, decisions made, evidence collected, communications issued, and lessons learned.

Program Development: Develop, mature, and maintain the Cyber Defense incident response program, including response frameworks, operating models, escalation paths, governance routines, templates, metrics, and continuous improvement processes.

Playbook & Runbook Management: Create, update, and maintain incident response playbooks, runbooks, quick reference guides, and standard operating procedures to support consistent execution during cyber events.

Tabletop Exercises: Design, facilitate, and evaluate cyber tabletop exercises, simulations, and scenario-based discussions to test readiness, validate response plans, identify gaps, and drive remediation actions.

Post-Incident Reviews: Lead post-incident reviews and lessons-learned sessions, documenting root cause, response effectiveness, improvement opportunities, and ownership of follow-up actions.

Executive Reporting: Develop clear, concise, and business-relevant incident reporting for Cyber Defense leadership, CIS leadership, executive stakeholders, committees, and board-level audiences as appropriate.

Metrics & Continuous Improvement: Establish and track incident response performance metrics, including response timelines, documentation quality, action closure, recurring themes, exercise findings, and program maturity indicators.

Stakeholder Engagement: Partner with business, technology, risk, legal, compliance, communications, and third-party teams to ensure Cyber Defense response processes are understood, practiced, and integrated with enterprise incident management expectations.

Regulatory & Audit Support: Support internal audit, regulatory, and compliance requests related to cybersecurity incident response documentation, testing, governance, and program effectiveness.

Threat-Informed Readiness: Collaborate with Threat Intelligence, Detection Engineering, SOC operations, and other Cyber Defense teams to ensure response plans reflect current adversary tactics, emerging threats, and relevant attack scenarios.

Crisis Communication Support: Support the development of leadership updates, incident summaries, situation reports, after-action reports, and communication artifacts during and after cyber events.

Process Automation & AI Enablement: Identify opportunities to improve incident response efficiency through automation, AI-enabled workflows, structured data capture, and repeatable response templates.

Knowledge Sharing: Provide training, coaching, and knowledge transfer to Cyber Defense team members and cross-functional partners on incident response expectations, playbook usage, tabletop outcomes, and program changes.

Required Qualifications

Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Business Continuity, Risk Management, or related field — or equivalent practical experience.

8+ years of experience in cybersecurity, incident response, security operations, cyber risk management, technology incident management, or related disciplines.

Demonstrated experience leading or coordinating cybersecurity incidents in complex enterprise environments.

Strong understanding of incident response lifecycle activities, including preparation, detection, analysis, containment, eradication, recovery, and post-incident improvement.

Experience developing or maintaining incident response plans, playbooks, runbooks, procedures, executive summaries, or after-action reports.

Ability to lead cross-functional teams during high-pressure situations and drive clarity, accountability, and timely decision-making.

Strong executive communication skills, including the ability to translate technical cyber incidents into business impact, risk, actions taken, and next steps.

Experience planning, facilitating, or participating in tabletop exercises, cyber simulations, or crisis response exercises.

Familiarity with security operations, SIEM, EDR/XDR, SOAR, threat intelligence, vulnerability management, cloud security, identity security, and other enterprise security capabilities.

Working knowledge of common cybersecurity frameworks and guidance, such as NIST CSF, NIST incident response guidance, MITRE ATT&CK, FFIEC Cybersecurity Assessment Tool, or similar industry standards.

Strong documentation, organization, and program management skills.

Ability to manage multiple priorities, coordinate stakeholders, and maintain structure during ambiguous or fast-moving incidents.

Experience supporting audit, regulatory, risk, or governance activities related to cyber incident response.

Ability to provide after-hours support during significant cybersecurity incidents or exercises, as needed.

Preferred Qualifications

Experience in financial services, banking, critical infrastructure, or other highly regulated environments.

Experience working with Corporate Incident Response, Technology Incident Management, Business Resiliency, Legal, Privacy, Communications, Fraud, Third Party Risk, or similar enterprise response partners.

Experience developing executive-level incident reports, board-level summaries, or committee reporting materials.

Experience with ServiceNow Security Incident Response, major incident management workflows, or similar incident tracking platforms.

Experience with Palo Alto Cortex XSIAM/XSOAR/XDR, or similar security operations technologies.

Experience integrating incident response workflows with automation, AI-enabled response support, SOAR playbooks, or structured response workspaces.

Experience conducting post-incident maturity reviews and translating findings into program roadmaps.

Strong understanding of ransomware, business email compromise, cloud compromise, data exfiltration, third-party cyber incidents, DDoS, insider threat, and other major cyber incident scenarios.

Preferred Certifications

Certified Information Systems Security Professional — CISSP
GIAC Certified Incident Handler — GCIH
GIAC Certified Forensic Analyst — GCFA
GIAC Certified Enterprise Defender — GCED
Certified Information Security Manager — CISM
Certified in Risk and Information Systems Control — CRISC
Project Management Professional — PMP
ITIL Foundation or equivalent incident/problem management certification

COMPENSATION AND BENEFITS

This position is eligible to earn a base salary in the range of $96,000.00 - $181,000.00 annually. Placement within the pay range may differ based upon various factors, including but not limited to skills, experience and geographic location. Compensation for this role also includes eligibility for incentive compensation which may include production, commission, and/or discretionary incentives.

Please click for a list of benefits for which this position is eligible.

Key has implemented an approach to employee workspaces which prioritizes in-office presence, while providing flexible options in circumstances where roles can be performed effectively in a mobile environment.

Job Posting Expiration Date: 10/08/2026 #LI-Remote

About KeyBank

Shockingly, nearly 9-in-10 people who get their real estate license in America fail. We're solving that problem; And doing it while increasing profitability for the brokerage. Through technology, business automation, and a team approach we have created a system where agents focus solely on working with clients and closing deals.

KeyBank Careers

Joining KeyBank means stepping into a world of professional growth and innovation, where job opportunities abound in an environment that values leadership, diversity, and forward-thinking. As a member of our team, you will be part of a company that's committed to empowering your career journey while contributing to the financial wellness of our communities.

Work You'll Do

At KeyBank, we're not just in the business of banking; we're in the business of helping individuals and communities thrive. By joining our team, you will have the chance to be part of a culture that celebrates diversity and fosters leadership and professional development. Whether you're looking for a position in customer service, IT, finance, or management, KeyBank offers a variety of roles suited to your skills and career aspirations.

Innovate and Lead

KeyBank stands at the intersection of finance and innovation. Our employees are encouraged to lead with creativity and integrity, driving solutions that make a real difference. With a focus on digital transformation and sustainable growth, your work at KeyBank will challenge the status quo and encourage you to explore new ideas.

Grow Your Career

Career growth at KeyBank is not just a possibility—it's a priority. We are dedicated to your professional development through comprehensive training programs, leadership workshops, and continuous learning opportunities. Our commitment to your growth is matched by our dedication to inclusion, ensuring all voices are heard and valued.

Be Part of a Great Team

Our team at KeyBank is our strongest asset. We believe in using our collective skills to foster an environment of innovation and collaboration. Join us and connect with colleagues who are just as passionate and driven as you are. Through teamwork, we achieve exceptional results and push the boundaries of what's possible in the banking sector.

Internship and Employment Opportunities

For those starting their careers, KeyBank offers robust internship and employment opportunities that provide a solid foundation in the financial industry. Interns at KeyBank gain hands-on experience, beneficial networking connections, and insights into our day-to-day operations, setting the stage for a successful career.

Benefits and Culture

KeyBank is committed to offering benefits that enhance your life and well-being. From healthcare to retirement plans, and flexible working conditions, we ensure our employees are well taken care of. More than just benefits, our company culture is built on respect, integrity, and accountability—values that guide us in making a positive impact on our clients and communities.

Join Our Team

Explore the job opportunities at KeyBank and find the right fit for your skills and interests. We are continuously hiring and looking for individuals who are curious, innovative, and ready to make a difference. Prepare your resume, ace your interview, and join a team that's dedicated to your success and to transforming the landscape of banking.

Stay Connected

Keep up to date with the latest career tips, industry insights, and company news by following our careers blog. Personalize your experience by subscribing to job alert emails tailored to your preferences, and discover the exciting and rewarding career opportunities that await at KeyBank.

Search KeyBank Jobs

Ready to take the next step in your career? Search open positions at KeyBank that match your skills and interests. We look for passionate, creative, and solution-driven team players who are ready to grow and succeed in a dynamic and supportive environment.

SEARCH KEYBANK JOBS

Join KeyBank and be part of a company where your career is as important to us as it is to you. Together, let's unlock opportunities for growth, innovation, and meaningful impact in the financial world.
Learn more about KeyBank
Size
17,110 employees
Market Cap
$16 billion
Industry
Net Income
$1.3 billion
Founded
1825
5 Year Trend
+5.6%
NASDAQ

Similar Jobs

More Jobs at KeyBank

More Information Technology Jobs

Find similar Cyber Defense Incident Response Lead jobs: