KeyBank Logo

KeyBank

Insider Threat Senior Analyst

Posted 6 Hours Ago
Be an Early Applicant
In-Office or Remote
Hiring Remotely in United States
96K-181K Annually
Senior level
In-Office or Remote
Hiring Remotely in United States
96K-181K Annually
Senior level
Lead and conduct insider threat investigations and proactive threat hunts across endpoints, networks, and cloud. Develop detections, analyze logs using SIEM/XDR/UEBA/UAM, leverage threat intelligence and MITRE ATT&CK, produce reports for stakeholders, advise program improvements, automate processes with scripting and APIs, and mentor junior analysts.
The summary above was generated by AI

Location:

4910 Tiedeman Road, Brooklyn Ohio

Our Cyber Threat Management team rolls up into Key’s broader Cyber Defense function within Corporate Information Security.  Cyber Defense’s mission is simple: We aim to Deter, Detect, Deny, and Disrupt adversaries through proactive threat-centric defense.

The Senior Insider Threat and Threat Hunting Analyst is a key member of the Cyber Threat Management (CTM) team. This role has responsibilities across both Insider Threat and Threat Hunting functions, with a primary focus on Insider Threat and a secondary focus on Threat Hunting.

In this role, you will perform hands‑on technical analysis related to insider threat investigations and proactive threat hunting activities. You will also play a critical role in maturing both programs by assessing current capabilities, identifying potential enhancements, and recommending improvements to processes, tools, and detection strategies. This position blends deep technical execution with strategic program development to strengthen KeyBank’s overall threat posture.

You will develop and maintain a deep understanding of the insider threat and cyber threat landscapes, by utilizing threat intelligence related to insider threats, along with threat actor Tactics, Techniques and Procedures (TTPs), and their associated threats, to support mitigation efforts while leveraging frameworks such as MITRE ATT&CK. This position requires strong insider threat and threat hunting investigation skills, and advanced knowledge of cybersecurity fundamentals and concepts. Success in this role demands an independent, thorough, and adaptable individual who can deliver accurate and complete intelligence outputs.

Key Responsibilities
  • Hands-on experience in Insider Threat, including conducting sensitive investigations, use case development, detection development and Insider Threat platforms such as User and Entity Behavior Analytics (UEBA), User Activity Monitoring (UAM), Security Information and Event Management (SIEM) or similar technologies.

  • Conduct comprehensive monitoring and analysis of insider threat indicators. Preserve evidence, prepare detailed reports, and present findings to key stakeholders, including HR and Legal.

  • Hands-on experience in designing and executing proactive, hypothesis-driven threat hunts across endpoints, networks, and cloud environments, leveraging threat intelligence and behavioral indicators to uncover hidden threats.

  • Apply deep knowledge of attacker tactics, techniques, and procedures (TTPs) to build proactive detections and alerts for potential adversary activities, leveraging threat intelligence and analytical insights.

  • Skilled in using security platforms such as Extended Detection and Response (XDR) and Security Information and Event Management (SIEM), along with the ability to analyze logs from diverse sources including Windows, Linux, cloud environments, and network devices.

  • Drive the evolution of the Insider Threat and Threat Hunt programs by advising on best practices, maintaining thorough documentation, enhancing metrics, and implementing improvements to increase organizational resilience.

  • Good knowledge of the cyber threat landscape (financial sector experience is beneficial) and the ability to communicate those threats to senior leadership, technical and non-technical audiences.

  • Apply frameworks (Ex. MITRE ATT&CK) to enhance detection and response.

  • Leverage automation to enhance intelligence gathering and processing, utilizing scripting languages and standardized frameworks such as Python, APIs, and STIX/TAXII.

  • Produce written reports, threat assessments, and briefings for technical and non-technical stakeholders.

  • Collaborate closely within and outside of the CTM team.

  • Participate, as needed, in technical incident response activities.

  • Actively engage in tabletop exercises and red/blue/purple team activities.

  • Interface with stakeholders withing Cyber Defense, the broader security organization, and those outside of security such as technology, fraud, HR and other lines of business partners.

  • Provide mentorship and technical guidance to junior analysts and cross-functional partners.

  • Lead by example in fostering a culture of curiosity, rigor, and continuous learning within these functions.

Required Qualifications
  • Bachelor’s in Computer Science, Cybersecurity, or related field—or equivalent experience

  • 5+ years in Insider Threat and/or Threat Hunting roles.

  • Strong analytical, research, and writing skills.

  • Proficiency with Insider Threat and Threat Hunting tools, along with experience with log analysis.

  • Deep understanding of the MITRE ATT&CK framework and adversary TTPs.

  • Strong ability to communicate concisely, effectively and directly with executive management.

  • Ability to work independently and escalate risks appropriately.

Preferred Certifications
  • GIAC Cyber Threat Intelligence (GCTI)

  • GIAC Certified Forensic Analyst (GCFA)

  • Certified Information Systems Security Professional (CISSP)

  • CompTIA Cybersecurity Analyst (CySA+)

  • CompTIA Security+

COMPENSATION AND BENEFITS

This position is eligible to earn a base salary in the range of $96,000.00 - $181,000.00 annually. Placement within the pay range may differ based upon various factors, including but not limited to skills, experience and geographic location. Compensation for this role also includes eligibility for incentive compensation which may include production, commission, and/or discretionary incentives.

Please click here for a list of benefits for which this position is eligible.

Key has implemented an approach to employee workspaces which prioritizes in-office presence, while providing flexible options in circumstances where roles can be performed effectively in a mobile environment.

Job Posting Expiration Date: 09/04/2026 KeyCorp is an Equal Opportunity Employer committed to sustaining an inclusive culture. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, genetic information, pregnancy, disability, veteran status or any other characteristic protected by law.

Qualified individuals with disabilities or disabled veterans who are unable or limited in their ability to apply on this site may request reasonable accommodations by emailing [email protected].



#LI-Remote

KeyBank Denver, Colorado, USA Office

Denver, United States, 0

KeyBank Lakewood, Colorado, USA Office

Lakewood, United States

Similar Jobs

5 Days Ago
Easy Apply
Remote
USA
Easy Apply
167K-197K Annually
Senior level
167K-197K Annually
Senior level
Artificial Intelligence • Blockchain • Fintech • Financial Services • Cryptocurrency • NFT • Web3
Lead end-to-end insider threat investigations, triage alerts from SIEM/UBA/DLP/endpoint signals, collect evidence and conduct interviews, produce decision-ready briefs and risk assessments, drive detection and automation improvements, and partner with Legal, HR, and business teams to reduce insider risk at scale.
Top Skills: DlpEndpoint DetectionGenerative AiLog AnalysisSIEMUba
5 Hours Ago
Remote
United States
142K-227K Annually
Senior level
142K-227K Annually
Senior level
Cloud • Fintech • Food • Information Technology • Software • Hospitality
Design and own end-to-end technical solutions and integration architecture for enterprise restaurant rollouts. Translate business requirements into scalable designs, validate integrations during pilots, oversee rollout integrity, produce handoff documentation, manage technical risk and escalations, and coordinate cross-functional teams from pre-sale through post-live stabilization.
Top Skills: Hardware ProvisioningJIRAMonday.ComNetwork TopologyPos SystemsRest ApiWebhooks
5 Hours Ago
Remote
United States
31-31 Annually
Junior
31-31 Annually
Junior
Cloud • Fintech • Food • Information Technology • Software • Hospitality
Provide multi-channel customer support for payroll tax accounts: research and resolve tax notices, coordinate with tax agencies and internal teams, reconcile liabilities, assist with TPA and POA setups, and contribute to recurring filings and process improvements.
Top Skills: Google SuiteMastertaxExcel

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account