Security Incident Response Orchestration Lead
Chicago, IL - USA
Job Summary
Job Description:
At Bank of America we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients teammates communities and shareholders every day.
Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed build a career and contribute to our shared success. This includes attracting and developing exceptional talent recognizing and rewarding performance and supporting our teammates physical emotional and financial wellness through affordable competitive and flexible benefits.
We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service community college education or a wide range of work and life experiences. These journeys foster resilience leadership and innovation strengthening our workforce and positively impact the communities we serve.
Bank of America is committed to an in-office culture that supports collaboration engagement and career development. Our approach includes clear in-office expectations while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.
At Bank of America you can build a successful career with opportunities to learn grow and make an impact. Join us!
Job Description:
The Security Incident Response Orchestration Lead is the senior technical authority responsible for setting the vision architecture and execution strategy for enterprisescale security automation. This role leads the design and evolution of orchestration capabilities across Splunk SOAR Tines and AIenabled platforms ensuring scalable resilient and governed solutions aligned to enterprise security objectives.
As a principallevel contributor this role drives crossorganizational alignment across security operations product management engineering and executive leadership to transform incident response through automation and intelligent decisioning. The role defines longterm strategy establishes engineering standards and ensures measurable business outcomes through effective orchestration.
This position is accountable for advancing agentic AI adoption in security operations embedding governance observability and control mechanisms that enable safe reliable and valuedriven automation at scale.
Core Responsibilities
- Serve as the enterprise technical authorityfor security orchestration across Splunk SOAR and Tines
- Define and evolve the longterm architecture strategy and roadmapfor SOAR and automation platforms
- Establish enterprise standards reusable frameworks and orchestration patternsto drive consistency and scale
- Lead endtoend design authorityfor complex crossplatform automation initiatives
- Partner with Product Management and senior leadership to shape portfolio prioritization and strategic investments
- Drive intake governance model ensuring automation demand is evaluated prioritized and aligned to measurable outcomes
- Define and track enterprise value metrics(MTTR reduction analyst efficiency operational risk reduction automation coverage)
- Influence and guide multiple security domain teams (15 teams)to adopt standardized automation patterns and best practices
- Provide technical leadership and mentorshipto senior and principal engineers across SOAR platforms
- Act as escalation point for highrisk highcomplexity orchestration challengesand systemic platform issues
- Lead design and oversight of enterprise integrations including but not limited to:
- Microsoft Graph / Entra ID / M365 Defender
- CrowdStrike Falcon
- Tanium
- BloodHound
- Anvilogic
- ThreatQ
- ServiceNow (Incidents SecOps CMDB IR workflows)
- Drive platform reliability resilience and auditability standardsacross all automation implementations
AIEnabled & Agentic Automation
- Define enterprise vision for AIdriven security operations including copilots agents and MCPaligned orchestration
- Lead design of AIassisted investigation triage and response workflowsintegrated with SOAR decisioning
- Establish and enforce enterprise AI governance framework including:
- Humanintheloop approval models and escalation paths
- Deterministic fallback and failsafe execution patterns
- Access controls observability logging and auditability aligned with enterprise risk standards
- Define architectural patterns for AIintegrated SOAR systems including:
- RetrievalAugmented Generation (RAG) design and secure knowledge integration
- Vector embedding strategies for semantic search and correlation
- Scalable data pipelines for incident context detections and response history
- Evaluate and approve AI use casesbased on operational value risk and production readiness
- Partner with governance risk and compliance teams to ensure safe auditable deployment of AI capabilities
Required Qualifications
- 10 years of experience in Security Operations Incident Response Detection Engineering or Security Automation
- 5 years of deep hands on experience with Splunk SOAR (Phantom) in addition to hands on experience with Tines (required) in enterprise environments
- Proven track record of leading largescale SOAR or automation programs
- Deep expertise in incident response lifecycle SOC operating models and automation strategy
- Strong experience designing and scaling secure reliable and governed automation architectures
- Experience integrating SOAR platforms with enterprise systems (Microsoft Graph CrowdStrike Tanium ServiceNow etc.)
- Demonstrated ability to influence senior leadership and drive crossorganizational initiatives
- Expertise in translating complex ambiguous problems into clear architectural solutions and execution plans
- BA or BS in Computer Science Engineering Information Systems or a related technical field; advanced Masters degree preferred
Desired Qualifications
- Prior experience operating at principal staff or architect levelin cybersecurity engineering
- Experience defining or leading enterprise security architecture or SOC transformation initiatives
- Strong proficiency in Python REST APIs and modern authentication (OAuth SAML etc.)
- Experience with AIenabled security operations including copilots LLM integrations or agentbased systems
- Handson or architectural experience with RAG frameworks vector databases and AI data platforms
- Familiarity with cloud security architecturesacross AWS Azure and Google Cloud
- Experience working with governance frameworks (MRM audit compliance risk controls)in regulated environments
Skills:
- Influence
- Result Orientation
- Solution Design
- Stakeholder Management
- Technical Strategy Development
- Access and Identity Management
- Cyber Security
- Information Systems Management
- Risk Management
- Solution Delivery Process
- Collaboration
- Critical Thinking
- DevOps Practices
- Financial Management
- Test Engineering
This job will be open and accepting applications for a minimum of seven days from the date it was posted.
Shift:
1st shift (United States of America)Hours Per Week:
40Pay Transparency details
US - CO - Denver - 1144 15th St - Denver Gis (CO9926) US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842) US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540)Pay and benefits informationPay range$150000.00 - $190700.00 annualized salary offers to be determined based on experience education and skill set.Discretionary incentive eligibleThis role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors the performance and contributions of their line of business and/or group; and the overall success of the Company.BenefitsThis role is currently benefits eligible. We provide industry-leading benefits access to paid time off resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.About Company
What would you like the power to do? At Bank of America, our purpose is to help make financial lives better through the power of every connection.