Sr. Cybersecurity Operational Risk Officer
About this role
Location:
4910 Tiedeman Road, Brooklyn OhioAbout the Job
Reporting to the Director of Cybersecurity Risk Oversight, the Sr. Cybersecurity Risk Oversight Professional is a 2nd Line of Defense risk management position that provides independent oversight and Risk Management subject matter expertise to 1st Line of Defense Business Units and their corresponding Business Risk Teams.
This position is responsible for Cybersecurity and Information Security Risk Oversight of the Key Technology Services line of business, as well as technology and information security risk oversight for areas of the enterprise that manage technology, data and AI/ML systems. As part of this oversight role, experience with cybersecurity domains – including security operations, network and cloud security architecture, identity and access management, and cyber defenses – along with emerging AI security risk and AI governance frameworks. Candidates should have a background and proven, ability to identify material risks, provide credible challenge and assist in developing effective mitigation strategies.
Essential Functions
· Evaluate risk and control identification within key processes and perform gap assessments on control coverage as well as first line of defense identification processes
· Collaborate and independently foster relationships with leaders to gain insights on cybersecurity posture, emerging cyber and AI-related risks and strategic technology initiatives, identifying opportunities to mitigate risk.
· Evaluate and monitor security portfolio, strategic initiatives, including AI adoption and deployments, and new and emerging technologies to ensure alignment with cyber risk appetite and business goals.
· Review cybersecurity processes, risks and controls, and conduct targeted assessments to support effective oversight and compliance with enterprise risk management requirements.
· Provide expert advice on cybersecurity and AI risk management practices, offering practical solutions to mitigate identified risks.
· Analyze and assess cybersecurity and AI-related risks associated with new products or services including third parties.
· Assist with cybersecurity and technology audits and regulatory examinations, ensuring thorough and timely responses to inquiries and findings.
· Escalate and report any significant risk issues and facilitate appropriate corrective actions.
· Perform ongoing monitoring of emerging cyber and AI-related risks and industry and regulatory trends.
Required Qualifications
· Bachelor’s degree in cybersecurity, information systems, computer science, business or related field, or commensurate/relevant degree is required.
· Minimum 8 years industry experience in Cybersecurity Risk, Information Security Risk, Technology Risk or External/Internal Security Audit.
· Practical knowledge of cybersecurity domains such as security operations, cyber defenses, identity and access management, network/cloud security architecture.
· Functional knowledge with AI/ML security risk concepts (e.g., AI governance, data security, adversarial threats).
· Outstanding active listening skills with the ability to synthesize complex information or processes.
· Demonstrated ability to work with internal and external auditors and regulators.
· Ability to think strategically coupled with the ability to independently drive execution to closure.
· Ability to view risk holistically within a dynamic, fast-paced team environment
· In-depth practical knowledge of cybersecurity and technology controls, risk assessments and applicable techniques for implementation of compliance and regulatory requirements.·
· Manage workflows and task assignments simultaneously to ensure timely completion of work
· Have an execution-oriented, process efficiency and continuous improvement mindset
· Possessing intellectual curiosity and a passion for seeking to understand
· Proven ability to have, maintain, and establish strong contacts within the industry so as to be aware of current industry issues and practices
Licenses and Certifications
· Applicable certifications such as:
o ISACA: CISA, CRISC, CET, CGEIT, CISM
o ISC2: CISSP, CCSP, SSCP
o Cloud Security Alliance Certs: CCAK
o Cloud Provider-Specific Certifications
Preferred Qualifications
· BS or Masters in Technology or Security related field
· Current and practical knowledge of Technology and/or Information Security activities, challenges, and workflows
· Additional industry certifications such as those listed above
· MBA, Law Degree or other relevant advanced education
· Foundational knowledge of Archer GRC preferred
· Project management, Agile experience preferred
Tactical Skills
· Demonstrated experience working with regulatory agencies, guidelines and requirements
· Strong ability to work with all levels of management within the company
· Experience working/managing projects across multiple functional areas and dealing with multiple business partners
· Experience working on initiatives that require strategic planning/thinking
· Flexibility to switch priorities based on the needs of the company in a fast-paced environment
· Ability to grasp complex processes quickly and be able to identify risks and compensating controls
· Excellent problem-solving abilities and results oriented; able to make decisions independently
· Proven ability to work as a team
· Strong leadership skills and ability to influence others
· Sound understanding of compliance and operational risks and internal control frameworks
· Strong analytical/research skills coupled with ability to effectively summarize findings
· Excellent oral, written and interpersonal skills
· Ability to adapt to change and communicate changing requirements
· Excellent organizational skills and meticulous attention to detail
· Self-motivated
· Proficient PC skills with experience in Microsoft Office, Outlook and, SharePoint
Personal Skills
· Adaptability: Demonstrates a willingness to listen to other opinions and adjusts to new or changing assignments, processes, and people while avoiding snap reactions
· Agile Mindset: Explains specific agile processes and its associated checkpoints and deliverables and applies major agile tools and techniques to accomplish tasks; understands that failures/defects equate to new learnings
· Collaboration: Demonstrates experience in participating in productive collaborative processes that help solve business problems and meet business goals
· Problem Solving: Demonstrates the ability to examine a specific problem and understand the perspective of stakeholders; uses fact-finding techniques to identify and document specific problems
Practical Skills
· Business Acumen: Participates in business tasks to get things done in own business unit and communicates key considerations for business decision-making processes
· Data Analysis: Identifies correlations that reveal trends and determine conditions, often with disparate data sets; Evaluates the quality of data collected and the effectiveness of data analysis methods for evaluating performance
· Oral & Written Communication: Possesses the ability to adapt listening and facilitation style to others’ communication styles and uses various approaches appropriately and effectively
· Risk Management: Implements or manages risk management for own business unit and documents key steps of the risk management process and associated procedures
· Systems Thinking: Analyzes the dynamics of a system to determine key characteristics, properties, and functions; surfaces problems within systems and searches for root causes while leveraging a foundational knowledge of continuous improvement
Core Competencies
· All KeyBank employees are expected to demonstrate Key’s Values and sustain proficiency in identified Leadership Competencies.
Physical Demands
· General Office - Prolonged sitting, ability to communicate face to face in person or on the phone with teammates and clients, frequent use of PC/laptop, occasional lifting/pushing/pulling of backpacks, computer bags up to 10 lbs.
Travel
· Occasional travel to include overnight stay.
COMPENSATION AND BENEFITS
This position is eligible to earn a base salary in the range of $96,000.00 - $181,000.00 annually. Placement within the pay range may differ based upon various factors, including but not limited to skills, experience and geographic location. Compensation for this role also includes eligibility for incentive compensation which may include production, commission, and/or discretionary incentives.Please click here for a list of benefits for which this position is eligible.
Key has implemented an approach to employee workspaces which prioritizes in-office presence, while providing flexible options in circumstances where roles can be performed effectively in a mobile environment.
Job Posting Expiration Date: 09/04/2026

KeyCorp is an Equal Opportunity Employer committed to sustaining an inclusive culture. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, genetic information, pregnancy, disability, veteran status or any other characteristic protected by law.Qualified individuals with disabilities or disabled veterans who are unable or limited in their ability to apply on this site may request reasonable accommodations by emailing HR_Compliance@keybank.com.
#LI-Hybrid
