KeyBank Logo

KeyBank

Cyber Detection & Automation Engineer

Reposted 8 Days Ago
In-Office or Remote
2 Locations
85K-110K Annually
Mid level
In-Office or Remote
2 Locations
85K-110K Annually
Mid level
The Cyber Detection & Automation Engineer develops detection logic and automation capabilities, focusing on threat detection, security automation, and collaboration with threat intelligence teams.
The summary above was generated by AI

Location:

4910 Tiedeman Road, Brooklyn Ohio

Detection & Automation Engineer

Position Summary

Our Cyber Detection & Automation team rolls up into Key’s broader Cyber Defense function within Corporate Information Security. Cyber Defense’s mission is simple: We aim to Deter, Detect, Deny, and Disrupt adversaries through proactive threat centric defense.

As a member of the Cyber Detection & Automation (CDA) team within Key’s Cyber Defense function, you will work both independently and under the guidance of Senior Detection & Automation Engineers in the development of detection logic and automation capabilities that enable our mission to Deter, Detect, Deny, and Disrupt adversaries. This role is pivotal in advancing our threat-centric defense posture by engineering high-fidelity detections, orchestrating response workflows.

You will work across SIEM, SOAR, and DAM platforms to build scalable, resilient detection and response capabilities. You’ll also collaborate with Cyber Threat Intelligence, Threat Response, and Engineering teams to ensure our detection strategy aligns with evolving adversary tactics and business risk.

Key Responsibilities

Detection Engineering

· Design and implement detection-as-code rules, alerts, dashboards, and reports across SIEM and log aggregation platforms.

· Translate threat intelligence and adversary TTPs into actionable detection logic using frameworks like MITRE ATT&CK.

· Continuously tune detection content to reduce false positives and improve signal fidelity.

Security Automation

· Develop and maintain SOAR playbooks to automate triage, enrichment, and response actions.

· Identify manual processes suitable for automation and propose solutions to your Senior department leaders to transform the manual processes into orchestrated workflows.

Threat Analysis & Content Development

· Perform event correlation and log analysis to validate detection efficacy and identify gaps.

· Assist in conducting trend analysis to identify emerging threats and detection opportunities.

· Document detection use cases and maintain lifecycle documentation using team standards.

Collaboration & Mentorship

· Partner with Cyber Threat Response and Threat Intelligence teams to align detection priorities.

· Escalate confirmed or suspected malicious activity with contextual analysis.

· Aspire to become a subject matter expert (SME) in selected domain specialties within your team and contribute to team knowledge sharing and training.

Required Qualifications

Technical Expertise

· Understanding of cyber defense principles, adversary TTPs, and detection engineering.

· Proficiency in SIEM query languages, and industry formats (Sigma, YARA-L, etc)

· Working knowledge of scripting languages (PowerShell, Python, JavaScript, Bash)

· Experience with SOAR platforms and automation development.

· Familiarity with cloud security (Azure, AWS, GCP) and integrating cloud telemetry into detection pipelines.

Operational & Analytical Skills

· Strong problem-solving skills and ability to interpret complex log data.

· Experience in documenting and managing detection content lifecycle.

· Ability to communicate technical concepts to both technical and non-technical audiences.

· Ability to perform and apply Critical-Thinking through day-to-day assignments and taskings

Desired Qualifications

· Bachelor’s degree in Cybersecurity, Computer Science, or related field—or equivalent experience.

· Minimum 3+ years in security operations, detection engineering, or threat hunting roles.

· Familiarity with the MITRE ATT&CK and D3FEND framework and adversary TTPs.

Preferred Certifications

· Certified Information Systems Security Professional (CISSP)

· Certified Information Security Manager (CISM)

· Certified Information Systems Auditor (CISA)

· CompTIA Security+

· GIAC Certified Detection Analyst (GCDA)

· GIAC Cloud Threat Detection (GCTD)

· GIAC Certified Incident Handler (GCIH)

· GIAC Certified Intrusion Analyst (GCIA)

COMPENSATION AND BENEFITS

This position is eligible to earn a base salary in the range of $85,000.00 to $110,000.00 annually depending on job-related factors such as level of experience. Compensation for this role also includes eligibility for short-term incentive compensation and deferred incentive compensation subject to individual and company performance. Please click here for a list of benefits for which this position is eligible.

Please click here for a list of benefits for which this position is eligible.

Key has implemented a role-based Mobile by Design approach to our employee workspaces, dedicating space to those whose roles require specific workspaces, while providing flexible options for roles which are less dependent on assigned workspaces and can be performed effectively in a mobile environment. As a result, this role may be Mobile or Home-based, which means you may work primarily either at a home office or in a Key facility to perform your job duties.

Job Posting Expiration Date: 10/18/2025 KeyCorp is an Equal Opportunity Employer committed to sustaining an inclusive culture. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status.

Qualified individuals with disabilities or disabled veterans who are unable or limited in their ability to apply on this site may request reasonable accommodations by emailing [email protected].


#LI-Remote

Top Skills

AWS
Azure
Bash
Dam
GCP
JavaScript
Powershell
Python
SIEM
Soar

Similar Jobs

6 Hours Ago
Remote or Hybrid
Santa Clara, CA, USA
159K-278K Annually
Senior level
159K-278K Annually
Senior level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
As a Staff DevOps Engineer, you will support, deploy, and maintain Big Data infrastructure, manage containerized applications, automate CI/CD pipelines, and collaborate with various teams to resolve issues in a 24x7 production environment.
Top Skills: AnsibleBashBig DataCloudera Data PlatformDockerFlinkGitGrafanaHadoopHbaseHdfsHiveImpalaJenkinsKafkaKubernetesKuduMariadbPostgresPrometheusPythonRabbitMQRedisSparkSQLVictoriametricsYarn
6 Hours Ago
Remote or Hybrid
Santa Clara, CA, USA
125K-213K Annually
Senior level
125K-213K Annually
Senior level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
The Senior Network Operations Engineer operates and maintains cloud network infrastructure, resolves network issues, and drives automation for deployment across large-scale environments. Responsibilities include monitoring, troubleshooting, and collaborating with various teams to enhance network performance and reliability.
Top Skills: AnsibleAWSAzureBashDockerF5GCPGitlabGrafanaKubernetesLinuxNginxPrometheusPythonSplunkTerraform
12 Hours Ago
Easy Apply
Remote or Hybrid
7 Locations
Easy Apply
150K-253K Annually
Senior level
150K-253K Annually
Senior level
Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
The Senior Software Engineer II will design and deliver AI-powered products, collaborate with teams, and ensure system reliability within a fullstack environment.
Top Skills: GoGraphQLMySQLReactTypescript

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account