1,285,480open jobs
74,416companies
214,296added this week
Browse all
Salary
$96k – $181k per year
Location
Remote (United States)
Seniority
Senior · 12+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 6, 2026. First seen by Alion on Sep 17, 2026.

Overview
Company
Impact
Profile match
KeyBank is the banking subsidiary of KeyCorp, a US regional bank headquartered in Cleveland, Ohio, offering consumer and small business banking, mortgages, commercial lending, wealth management and investment banking through KeyBanc Capital Markets. KeyCorp is listed on the New York Stock Exchange and runs a branch network across states from Maine and New York to Ohio, Indiana, Colorado, Idaho, Washington and Alaska, with a large operations campus in Brooklyn, Ohio. Its job board lists branch managers, relationship managers, mortgage loan officers, credit and compliance risk staff, investment bankers, treasury analysts and GenAI product and technology roles.

Location:

4910 Tiedeman Road, Brooklyn Ohio

Position Summary

Our Cyber Adversary and Exposure Management team rolls up into Key’s broader Cyber Defense function within Corporate Information Security. Cyber Defense’s mission is simple: We aim to Deter, Detect, Deny, and Disrupt adversaries through proactive threat-centric defense.

The Senior Offensive Security Engineer serves as the technical and operational lead for the Cyber Defense Red Team and is responsible for guiding team execution, capability development, operational maturity, and offensive security strategy. The role is responsible for advancing the maturity, consistency, and effectiveness of adversarial simulation, red team, and penetration testing capabilities while providing day-to-day leadership for team execution. The role establishes testing strategy and standards, guides engagement planning and quality, coordinates priorities and resources, mentors team members, and drives measurable improvement across the offensive security program. The role also supports Continuous Threat Exposure Management (CTEM) objectives by validating prioritized exposures, assessing attack paths, and measuring the effectiveness of remediation activities against realistic adversary scenarios.

The role also simulates advanced cyber adversaries and emulates real-world adversaries to assess and improve KeyBank’s detection, response, and resilience capabilities. This work goes beyond traditional red teaming and penetration testing by incorporating threat intelligence, custom tooling, and stealthy tradecraft to test the effectiveness of security controls and incident response processes.

The ideal candidate will bring significant experience directing adversary emulation, red team engagements, and offensive security operations across enterprise on-premises and cloud environments, with experience leading or participating in physical security assessments. The role demands exceptional technical proficiency, strategic leadership, operational discipline, and the ability to clearly articulate complex security findings and risk implications to audiences ranging from engineers to senior executives.

Key Responsibilities

Team Leadership & Operational Management

  • Provide day-to-day technical and operational team leadership for the Red Team, reporting to the CAEM manager, including work prioritization, engagement assignments, execution oversight, issue escalation, and coordination of team deliverables.
  • Coach and mentor team members, facilitate knowledge sharing, identify capability gaps, and support development of technical depth and leadership readiness across the team.
  • Provide third-party vendor support, dependencies, and stakeholder communications to keep engagements on track and ensure risks, blockers, and decisions are elevated promptly.
  • Provide hands-on technical guidance during complex engagements and reinforce safe, responsible, and repeatable adversarial tradecraft.
  • Partner with Detection Engineering, Security Operations, Threat Intelligence, and Incident Response teams to conduct purple team exercises that validate control effectiveness, detection coverage, and response capabilities against real-world adversary behaviors.

Red Team Strategy, Governance & Program Maturity

  • Lead the development and execution of a maturity roadmap for adversarial simulation, red team, and penetration testing capabilities, including repeatable methodologies, standards, tooling, automation, and quality assurance practices.
  • Establish and maintain a risk-based testing strategy and engagement pipeline aligned with enterprise threats, critical assets, regulatory expectations, and stakeholder priorities.
  • Define and report program metrics that demonstrate coverage, execution quality, remediation outcomes, control validation, and progress against the offensive security maturity roadmap.
  • Use program metrics and engagement outcomes to identify trends, communicate risk, and prioritize improvements to testing coverage and team capabilities.
  • Drive continuous improvement of adversarial emulation methodologies, tooling, documentation, and operating practices.
  • Present offensive security program metrics, engagement outcomes, risk themes, and strategic recommendations to cybersecurity leadership, governance forums, and executive stakeholders.
  • Align adversarial testing activities with exposure management priorities by validating remediation efforts, identifying exploitable attack paths, and measuring reductions in organizational exposure.

Adversarial Simulation & Red Team Operations

  • Lead and execute adversary emulation engagements using intelligence-driven threat scenarios aligned with frameworks such as MITRE ATT&CK.
  • Design and conduct full-scope red team operations, including initial access, lateral movement, privilege escalation, and data exfiltration simulation.
  • Conduct physical, external/internal, wireless network, web application, and mobile application security assessments.
  • Lead security assessments across cloud platforms (Google Cloud, Microsoft Azure, AWS), identity infrastructure, privileged access management solutions, hybrid enterprise environments, and embedded systems.
  • Develop and operationalize Red Team tooling, automation, and adversary emulation capabilities that replicate real-world threat actor behaviors and enable repeatable assessment of application, cloud, infrastructure, and network security controls.
  • Employ these tools and techniques within the environment with minimal supervision while mentoring team members in their safe and responsible use.
  • Lead adversarial testing of AI-enabled applications, machine learning systems, generative AI technologies, large language models, and autonomous agents to identify exploitable weaknesses, misuse scenarios, and gaps in preventive, detective, and responsive security controls.

Engagement Oversight & Stakeholder Management

  • Review engagement plans, rules of engagement, testing evidence, findings, and reports to promote consistent quality, accuracy, safety, and actionable outcomes.
  • Lead cross-functional teams during project testing phases and architectural design reviews to ensure appropriate security controls are in place to mitigate threats.
  • Coordinate and monitor third-party penetration testing engagements, ensuring alignment with requirements, effective communication, and timely, accurate reporting.
  • Provide detailed post-mortem reports and executive briefings with prioritized recommendations.
  • Present engagement outcomes, risk themes, maturity assessments, and strategic recommendations to senior leadership, governance committees, and cybersecurity stakeholders.

Threat Intelligence, Detection Validation & Purple Teaming

  • Partner with the Cyber Threat Intelligence team to ensure Red Team capabilities and tactics accurately reflect the current threat landscape and that real-world tactics, techniques, and procedures (TTPs) are translated into emulation plans.
  • Evaluate the effectiveness of detection and response capabilities across SOC, EDR/XDR, SIEM, and other security layers.
  • Build collaborative relationships with blue teams to conduct purple team exercises and improve detection engineering.

Findings Management & Risk Reduction

  • Lead efforts to track remediation of findings to completion through coordination with application and technology system owners.
  • Validate the effectiveness of remediation actions through retesting, attack path analysis, and other exposure validation activities.
  • Support Continuous Threat Exposure Management (CTEM) initiatives by validating prioritized exposure reductions and measuring security improvements resulting from remediation activities.

Research, Innovation & Capability Development

  • Expand team capabilities through:
    • Development of custom offensive security tools and automation capabilities to support adversary emulation and security testing.
    • Incorporation of artificial intelligence, automation, and emerging technologies to improve offensive security testing efficiency, scalability, and effectiveness.
    • Research and development of novel offensive techniques and tradecraft.
    • Incorporation of threat actor intelligence into emulation scenarios.
    • Delivery of internal presentations and knowledge-sharing sessions.

Required Qualifications

Education & Experience

  • Bachelor’s degree in Computer Science, Cybersecurity, or a related field, or equivalent professional experience.
  • 12+ years of experience in Red Team or Penetration Testing roles.
  • Demonstrated experience leading complex offensive security engagements and coordinating the work of technical teams.
  • Experience building or maturing a Red Team, adversarial simulation, or penetration testing program, including methodologies, quality standards, metrics, and multi-year capability planning.

Offensive Security & Adversary Emulation Expertise

  • Proficiency with Red Team tools and Command-and-Control (C2) frameworks.
  • Advanced networking knowledge and experience with attack simulation.
  • Deep understanding of the MITRE ATT&CK framework and adversary TTPs.
  • Deep understanding of one or more penetration testing methodologies, such as PTES, ISECOM, ISSAF, or OSSTMM.
  • Demonstrated knowledge of AI security risks and adversarial testing techniques, including experience evaluating generative AI applications, model and agent integrations, data exposure, prompt-based attacks, excessive agency, and other emerging AI threat scenarios.

Technical & Platform Knowledge

  • Strong scripting and programming skills in PowerShell, Python, JavaScript, Bash, Golang, or similar languages.
  • Deep understanding of Windows, Linux, Kali Linux, and macOS operating systems.
  • Direct experience with one or more cloud platforms:
    • Microsoft Azure
    • AWS
    • Google Cloud Platform (GCP)

Research, Analysis & Communication

  • Strong research and reporting skills.
  • Ability to translate technical findings into actionable recommendations for technical and executive audiences.

Leadership & Program Management

  • Strong team leadership, coaching, prioritization, stakeholder management, and executive communication skills.
  • Experience presenting offensive security findings, program metrics, and strategic recommendations to executive leadership, governance committees, audit stakeholders, and technical teams.
  • Experience defining strategy, establishing standards, measuring performance, and driving continuous improvement of offensive security capabilities.
  • Ability and willingness to travel for on-site assessments.

Preferred Qualifications

  • Experience leading purple team engagements.
  • Experience validating security controls through adversarial simulation.
  • Experience supporting Continuous Threat Exposure Management (CTEM) or attack path analysis programs.
  • Experience assessing generative AI and agentic AI platforms.

Preferred Certifications

  • Offensive Security Certified Professional (OSCP)
  • Offensive Security Certified Expert (OSCE)
  • Offensive Security Experienced Penetration Tester (OSEP)
  • Certified Red Team Professional (CRTP)
  • Certified Red Team Operator (CRTO)
  • Certified Red Team Operator II (CRTO II)
  • GIAC Penetration Tester (GPEN)
  • GIAC Web Application Penetration Tester (GWAPT)
  • GIAC Exploit Researcher and Advanced Penetration Tester (GXPN)
  • CREST Registered Penetration Tester / CBEST Qualifications
  • Certified Azure Red Team Professional (CARTP)
  • Certified Azure Red Team Expert (CARTE)

COMPENSATION AND BENEFITS

This position is eligible to earn a base salary in the range of $96,000.00 - $181,000.00 annually. Placement within the pay range may differ based upon various factors, including but not limited to skills, experience and geographic location. Compensation for this role also includes eligibility for incentive compensation which may include production, commission, and/or discretionary incentives.

Please click here for a list of benefits for which this position is eligible.

Key has implemented an approach to employee workspaces which prioritizes in-office presence, while providing flexible options in circumstances where roles can be performed effectively in a mobile environment.

Job Posting Expiration Date: 10/30/2026 KeyCorp is an Equal Opportunity Employer committed to sustaining an inclusive culture. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, genetic information, pregnancy, disability, veteran status or any other characteristic protected by law.

Qualified individuals with disabilities or disabled veterans who are unable or limited in their ability to apply on this site may request reasonable accommodations by emailing [email protected].

#LI-Remote
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,285,480 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
United States
$215k – $260k per year • Equity • In office • Full-Time • 5+ years exp • Bachelor's Degree • San Francisco
DevOps
SLI/SLO/SLA
Linux
Cybersecurity
CVE
Apply
$250k – $300k per year • Equity • In office • Full-Time • 5+ years exp • Bachelor's Degree • Sunnyvale
DevOps
SLI/SLO/SLA
Linux
Cybersecurity
CVE
Apply
$68k – $75k per year • Remote (United States) • Full-Time
Python
JavaScript
PowerShell
DevOps
Splunk
Ansible
GCP
Prometheus
Azure
AWS
SaltStack
Cortex
Windows
Cybersecurity
Crowdstrike
Microsoft Sentinel
SentinelOne
Microsoft Defender
MITRE ATT&CK
Cortex XSOAR
Microsoft Entra ID
SIEM
Apply
≈ $52k – $121k per year (Estimated) • Remote (Mexico) • Full-Time • Mexico City
DevOps
Incident Management
Apply
≈ $106k – $225k per year (Estimated) • Remote (Canada) • Full-Time • Montreal
DevOps
Incident Management
Apply
$150k – $185k per year • In office • 5+ years exp • Washington
Python
Ruby
PowerShell
Groovy
DevOps
Terraform
Ansible
GCP
Chef
CloudFormation
GitLab CI
Azure
CI/CD
Jenkins
Git
AWS
Kubernetes
Concourse
Bitbucket
GitHub
GitLab
Management
Agile
QA
Selenium
Apply
≈ $21k – $42k per year (Estimated) • In office • Chennai
Python
SQL
Databases
Snowflake
Amazon Redshift
AI/ML
Spark
Airflow
DevOps
Rest API
CI/CD
AWS
GitHub
GitLab
Analytics
ETL/ELT
Apply
QA Analyst 9 hours ago
In office • Full-Time • 1+ year exp • Pune
JavaScript
TypeScript
DevOps
Jenkins
Git
Game Dev
Vuforia
Management
Jira
Agile
QA
Selenium
Playwright
Apply
Java Engineer 9 hours ago
≈ $37k – $95k per year (Estimated) • Remote (Bulgaria) • Full-Time • Sofia
JavaScript
Java
Kotlin
TypeScript
SQL
Java
Spring Boot
Hibernate
Kotlin
Mockito
Databases
MySQL
PostgreSQL
Redis
Frontend
Angular
Mobile
JUnit
DevOps
Git
Cybersecurity
GDPR
Management
Agile
Apply
Intern 9 hours ago
≈ $7.5k – $15k per year (Estimated) • In office • Internship • Bengaluru
Python
C
C++
C
Embedded C
AI/ML
Copilot
DevOps
CI/CD
Jenkins
Git
Management
Agile
Apply
$96k – $181k per year • Remote (United States) • Full-Time • Bachelor's Degree • United States
Web3
DAO
Apply
$80k – $150k per year • Hybrid • Full-Time • 2+ years exp • Bachelor's Degree • New York
Analytics
Microsoft Excel
Apply
API Security Engineer 23 days ago
$116k – $216k per year • Remote (United States) • Full-Time • Associate's Degree • United States
Python
Go
JavaScript
SQL
PowerShell
Bash
Frontend
GraphQL
DevOps
Rest API
CI/CD
Kubernetes
Platform Engineering
eBPF
IAM
API Gateway
Linux
DNS
Cybersecurity
OWASP Top 10
STRIDE
Least Privilege
Threat Modeling
SIEM
OWASP
QA
Swagger
Apply
$96k – $181k per year • Remote (United States) • Full-Time • Bachelor's Degree • United States
Cybersecurity
MITRE ATT&CK
MITRE D3FEND
Cyber Kill Chain
Diamond Model
SIEM
Apply
$96k – $181k per year • Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Chicago • Albany • Cincinnati • Charlotte • Denver
Management
Outlook
SharePoint
Agile
Microsoft Office
Apply
$114k – $142k per year • Hybrid • Full-Time • 4+ years exp • Bachelor's Degree • United States
DevOps
GCP
Azure
AWS
SLI/SLO/SLA
Cybersecurity
SIEM
Management
Confluence
Jira
Apply
$191k – $248k per year • In office • Full-Time • 10+ years exp • Bachelor's Degree • New York • Pittsburgh • Boston
Marketing
Salesforce
Apply
≈ $116k – $231k per year (Estimated) • Equity • In office • Full-Time • 3+ years exp • Bachelor's Degree • Houston
Python
SQL
Python
pySpark
Databases
Databricks
Delta Lake
Apache Kafka
Azure SQL Database
AI/ML
Spark
MLFlow
Scikit-learn
MLlib
TensorFlow
Keras
PyTorch
Ray
Machine Learning
DevOps
Rest API
Azure DevOps
Azure
CI/CD
Git
Kubernetes
Azure AKS
Analytics
ETL/ELT
Azure Data Factory
Apply
≈ $52k – $91k per year (Estimated) • Equity • In office • Full-Time • 3+ years exp • High School Diploma • United States
Apply
≈ $39k – $89k per year (Estimated) • Hybrid • Full-Time • United States
Apply
See all jobs
This is one of many
1,285,480 more open roles from verified company boards, updated every day.