Data Security (SecuPi) Administrator
KeybankLocation:
4910 Tiedeman Road, Brooklyn OhioWe are seeking a Data Security (SecuPi) Administrator to support, operate, and enhance enterprise data security technologies and controls. This role is responsible for protecting sensitive and regulated data across databases, applications, cloud platforms, analytics environments, and emerging AI-enabled services.
The Security Engineer will provide engineering and operational support for data security platforms such as SecuPi and other technologies used for data access governance, data masking, encryption, tokenization, database activity monitoring, data discovery and classification, and data loss prevention (DLP).
The role will partner with Cybersecurity, Infrastructure, Cloud, Database, Application Development, Data Governance, Privacy, and Risk teams to implement scalable controls that protect enterprise data while enabling appropriate business access.
Key Responsibilities
- Engineer, configure, administer, and maintain enterprise data security platforms, including SecuPi and comparable technologies.
- Implement and maintain policies for data access control, dynamic data masking, encryption, tokenization, filtering, and other data protection mechanisms.
- Support security controls across relational and NoSQL databases, data warehouses, cloud data platforms, APIs, applications, and analytics environments.
- Integrate data security technologies with enterprise identity and access management (IAM), privileged access management (PAM), SIEM, SOAR, DLP, and security monitoring platforms.
- Develop and maintain policies that enforce least-privilege and role- or attribute-based access to sensitive information.
- Support discovery and classification of sensitive data, including PII, financial information, credentials, intellectual property, and other regulated or confidential information.
- Monitor data access activity and investigate anomalous, unauthorized, or high-risk access patterns.
- Troubleshoot platform, policy, integration, connectivity, and performance issues affecting data security controls.
- Assess proposed database, application, cloud, and data-platform changes for potential security impacts.
- Partner with application and database teams to integrate security controls into new and existing solutions.
- Support security requirements for AI applications, copilots, and autonomous agents accessing enterprise data.
- Help ensure that AI-enabled services access only data authorized for the requesting user, application, or service identity.
- Develop automation and scripts to improve deployment, monitoring, policy management, reporting, and operational efficiency.
- Participate in vulnerability management, incident response, security investigations, and remediation activities involving enterprise data.
- Maintain security architecture diagrams, configuration standards, operating procedures, runbooks, and technical documentation.
- Support internal and external audits by providing evidence of data security controls and their effectiveness.
- Evaluate new data security technologies and recommend improvements to the organization’s data protection architecture.
Required Qualifications
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or Cyber Security.
- 3+ years of experience in cybersecurity, security engineering, infrastructure security, database security, or a related technical discipline.
- Experience administering or engineering enterprise security technologies.
- Working knowledge of database technologies such as Oracle, Microsoft SQL Server, PostgreSQL, MySQL, or similar platforms.
- Understanding of data security concepts including encryption, tokenization, masking, access control, data classification, and database activity monitoring.
- Knowledge of authentication and authorization concepts including IAM, RBAC, ABAC, SSO, service accounts, and privileged access.
- Experience troubleshooting complex enterprise technology integrations.
- Familiarity with Linux and/or Windows operating environments.
- Scripting or automation experience using technologies such as Python, PowerShell, Bash, REST APIs, or similar tools.
- Understanding of network security concepts including TCP/IP, TLS, proxies, firewalls, DNS, and secure communications.
- Experience securing cloud platforms such as AWS, Microsoft Azure, or Google Cloud.
- Familiarity with Kubernetes, containers, APIs, microservices, and modern application architectures.
- Strong analytical, troubleshooting, documentation, and communication skills.
Preferred Qualifications
- Experience with SecuPi or comparable data security, database security, or data access governance platforms.
- Experience with database activity monitoring (DAM), data security posture management (DSPM), DLP, encryption/key management, or data discovery and classification technologies.
- Experience securing cloud platforms such as AWS, Microsoft Azure, or Google Cloud.
- Experience securing cloud data platforms, data warehouses, or data lakes.
- Experience integrating security technologies with SIEM/SOAR platforms and enterprise monitoring systems.
- Experience implementing security controls for generative AI, AI agents, LLM applications, or retrieval-augmented generation (RAG) architectures.
- Understanding of Zero Trust and data-centric security principles.
- Familiarity with regulatory and security frameworks such as NIST, ISO 27001, PCI DSS, SOX, HIPAA, GDPR, or similar requirements.
- Relevant certifications such as CISSP, CCSP, Security+, GIAC, cloud security certifications, or vendor-specific security certifications.
Core Competencies
The successful candidate should demonstrate strong capabilities in security engineering, data protection, access control, troubleshooting, automation, and technical collaboration. The individual should be comfortable working across security, infrastructure, database, cloud, application, and data teams to translate security requirements into reliable technical controls.
Success in the Role
Success will be measured by the reliability and effectiveness of enterprise data security controls, reduction of unauthorized data exposure risk, timely resolution of security and platform issues, increased automation of security operations, and successful integration of data protection controls into new applications, cloud services, databases, and AI-enabled solutions.
COMPENSATION AND BENEFITS
This position is eligible to earn a base salary in the range of $80,000.00 - $150,000.00 annually. Placement within the pay range may differ based upon various factors, including but not limited to skills, experience and geographic location. Compensation for this role also includes eligibility for incentive compensation which may include production, commission, and/or discretionary incentives.Please click here for a list of benefits for which this position is eligible.
Key has implemented an approach to employee workspaces which prioritizes in-office presence, while providing flexible options in circumstances where roles can be performed effectively in a mobile environment.
Job Posting Expiration Date: 10/06/2026

KeyCorp is an Equal Opportunity Employer committed to sustaining an inclusive culture. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, genetic information, pregnancy, disability, veteran status or any other characteristic protected by law.Qualified individuals with disabilities or disabled veterans who are unable or limited in their ability to apply on this site may request reasonable accommodations by emailing HR_Compliance@keybank.com.
#LI-Remote