Senior Exposure Management Engineer

KeyBankBrooklyn, OH
Hybrid

About The Position

As a member of the Cyber Defense team within Corporate Information Security, the Senior Exposure Management Engineer is responsible for governing, assessing, and maintaining enterprise security baseline standards across on-premises, cloud, and hybrid environments. This role ensures technology assets remain aligned with approved security configuration standards, industry frameworks, and regulatory requirements through continuous assessment, compliance monitoring, and risk-based remediation activities. The Senior Exposure Management Engineer leverages automated assessment and compliance validation tools to identify configuration weaknesses, measure adherence to enterprise security baselines, and monitor configuration drift across the environment. The role partners closely with Security Architecture, Infrastructure, Engineering, Cloud, and Application teams to drive remediation, manage exceptions, support audit and regulatory examinations, and enhance the organization's overall security posture through consistent application of standards-based controls. This position also leads the evolution of the enterprise baseline program by evaluating changes to industry guidance, improving compliance measurement capabilities, expanding automation, and providing actionable reporting that enables informed risk-based decisions and continuous exposure reduction.

Requirements

  • Bachelor’s degree in computer science, Cybersecurity, or related field—or equivalent experience.
  • 8+ years of experience in security engineering, configuration management, or related roles.
  • Experience with Vulnerability Management platforms (Tenable, Qualys, Rapid7 etc) running vulnerability scans, monitoring agent health, and maintaining scanner operability.
  • Comprehensive expertise in Tenable or comparable vendor solutions for compliance scanning.
  • Broad understanding of enterprise computing platforms and their configuration management, compliance, and security considerations.
  • Hands-on experience with cloud platforms (Google Cloud, Microsoft Azure, AWS).
  • Familiarity with security frameworks and standards (e.g., CIS Benchmarks, SCAP, NIST CSF, MITRE ATT&CK).
  • Experience with ServiceNow security related modules such as Vulnerability Response & Configuration Compliance
  • Effective research, documentation, and reporting skills.
  • Willingness to travel.

Nice To Haves

  • Certified Information Systems Security Professional (CISSP)
  • GIAC Security Essentials (GSEC)
  • GIAC Certified Vulnerability Assessor (GCVA)
  • Microsoft Certified: Azure Security Engineer Associate
  • AWS Certified Security – Specialty
  • Google Cloud Security Engineer

Responsibilities

  • Maintain and govern enterprise-approved security baseline standards across operating systems, cloud platforms, applications, databases, and network infrastructure.
  • Support the review and adoption of updates to CIS Benchmarks and other industry-recognized security standards through established governance processes.
  • Partner with Security Architecture and technology teams to ensure baseline requirements are appropriately documented, communicated, and operationalized.
  • Conduct ongoing configuration compliance assessments utilizing automated scanning and validation tools to measure adherence to approved baseline standards.
  • Validate remediation activities through continuous monitoring and reassessment.
  • Identify, analyze, and report configuration weaknesses that increase organizational risk.
  • Monitor configuration drift across enterprise assets and provide reporting on deviations from approved security baselines.
  • Partner with technology owners to investigate non-compliant configurations and drive timely remediation.
  • Manage baseline exceptions, compensating controls, and risk acceptance documentation.
  • Ensure approved deviations from security standards are appropriately documented, reviewed, and tracked through remediation or renewal cycles.
  • Develop and maintain configuration compliance metrics, dashboards, and executive reporting.
  • Provide visibility into compliance trends, remediation progress, assessment coverage, and risk reduction activities.
  • Support reporting through ServiceNow and other enterprise governance platforms.
  • Maintain documentation, evidence, and reporting required to support internal audits, external examinations, and regulatory assessments.
  • Demonstrate compliance with enterprise security requirements, industry standards, and applicable regulatory obligations.
  • Partner with Infrastructure, Cloud, Application, Engineering, and Security teams to support implementation and maintenance of approved security baselines.
  • Provide guidance regarding baseline compliance requirements and remediation priorities.
  • Identify opportunities to improve assessment coverage, compliance measurement, reporting, and operational efficiencies through automation.
  • Support implementation of automated compliance validation and reporting capabilities.
  • Collaborate with Vulnerability Management, Threat Intelligence, Red Team, and Exposure Management teams to prioritize remediation of configuration weaknesses that contribute to exploitable attack paths and elevated risk.
  • Utilize risk-based methodologies to focus remediation efforts on the highest-impact configuration deficiencies.
  • Share security baseline best practices, emerging standards, and compliance requirements through documentation, training, and stakeholder engagement.

Benefits

  • eligibility for incentive compensation which may include production, commission, and/or discretionary incentives.
  • list of benefits for which this position is eligible.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service