×
Register Here to Apply for Jobs or Post Jobs. X

Cyber Defense Incident Response Lead

Job in Brooklyn, Cuyahoga County, Ohio, USA
Listing for: KeyCorp
Full Time position
Listed on 2026-09-06
Job specializations:
  • IT/Tech
    Cybersecurity, IT Project Manager
Salary/Wage Range or Industry Benchmark: 96000 - 181000 USD Yearly USD 96000.00 181000.00 YEAR
Job Description & How to Apply Below

Location:

4910 Tiedeman Road, Brooklyn Ohio

Cyber Incident Response Lead

As a member of the Cyber Defense team within Corporate Information Security, the Incident Response Lead plays a critical role in strengthening Key Bank’s ability to prepare for, coordinate, and respond to cybersecurity incidents across the enterprise. This position is responsible for leading high-impact cyber incident response activities, ensuring timely coordination across Cyber Defense, technology, business, risk, legal, communications, and executive stakeholders.

The Incident Response Lead will own and continuously mature the Cyber Defense incident response program by maintaining response documentation, improving playbooks and runbooks, developing repeatable response processes, and ensuring lessons learned are translated into actionable program improvements. This role requires a strong blend of cyber incident response experience, program development capability, executive communication skills, and operational leadership. The Incident Response Lead will facilitate tabletop exercises, support incident simulations, drive post-incident reviews, develop executive-level reporting, and help ensure Key Bank’s incident response capabilities remain aligned to the evolving threat landscape, regulatory expectations, and business resilience needs.

This position directly supports Key Bank’s mission to Deter, Detect, Deny, and Disrupt adversaries through coordinated, well-documented, and continuously improving cyber defense capabilities.

Key Responsibilities
  • Incident Leadership:
    Lead cybersecurity incident response coordination for significant cyber events, ensuring appropriate triage, escalation, containment coordination, stakeholder engagement, and resolution tracking.
  • Incident Command & Coordination:
    Serve as a primary Cyber Defense incident response lead during active incidents, coordinating across Cyber Threat Response, Cyber Threat Management, Cyber Detection and Automation, Cyber Application and Cloud Defense, Cyber Adversary and Exposure Management, Technology Incident Management, Corporate Incident Response, and other enterprise partners as needed.
  • Documentation & Case Management:
    Ensure accurate, timely, and complete documentation of incident timelines, actions taken, decisions made, evidence collected, communications issued, and lessons learned.
  • Program Development:
    Develop, mature, and maintain the Cyber Defense incident response program, including response frameworks, operating models, escalation paths, governance routines, templates, metrics, and continuous improvement processes.
  • Playbook & Runbook Management:
    Create, update, and maintain incident response playbooks, runbooks, quick reference guides, and standard operating procedures to support consistent execution during cyber events.
  • Tabletop Exercises:
    Design, facilitate, and evaluate cyber tabletop exercises, simulations, and scenario-based discussions to test readiness, validate response plans, identify gaps, and drive remediation actions.
  • Post-Incident Reviews:
    Lead post-incident reviews and lessons-learned sessions, documenting root cause, response effectiveness, improvement opportunities, and ownership of follow-up actions.
  • Executive Reporting:
    Develop clear, concise, and business-relevant incident reporting for Cyber Defense leadership, CIS leadership, executive stakeholders, committees, and board-level audiences as appropriate.
  • Metrics & Continuous Improvement:
    Establish and track incident response performance metrics, including response timelines, documentation quality, action closure, recurring themes, exercise findings, and program maturity indicators.
  • Stakeholder Engagement:
    Partner with business, technology, risk, legal, compliance, communications, and third-party teams to ensure Cyber Defense response processes are understood, practiced, and integrated with enterprise incident management expectations.
  • Regulatory & Audit Support:
    Support internal audit, regulatory, and compliance requests related to cybersecurity incident response documentation, testing, governance, and program effectiveness.
  • Threat-Informed Readiness:
    Collaborate with Threat Intelligence, Detection…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary