
Security Incident Response Lead
Bank of America
full-time
Posted on:
Location Type: Office
Location: Denver • Colorado • District of Columbia • United States
Visit company websiteExplore more
Salary
💰 $98,400 - $160,000 per year
Job Level
Tech Stack
About the role
- Serve as senior technical authority for security orchestration across Splunk SOAR and Tines
- Define architectural standards, reusable automation patterns, and orchestration best practices
- Scope and evaluate incoming automation requests in partnership with the Product Manager to support prioritization decisions
- Coordinate with the Product Owner to ensure clearly defined requirements and acceptance criteria are maintained in the backlog
- Collect and define value metrics at intake including MTTR reduction, analyst time savings, and incident quality improvements
- Partner with over 15 security operations teams to identify and design high-impact automation opportunities
- Coordinate with SOAR feature leads to ensure shared understanding of scope, intent, and accurate execution
- Collaborate with senior and principal-level engineers to design strategic, cross-platform orchestration solutions
- Design, implement, and guide integrations across common SOAR ecosystems, including but not limited to: Microsoft Graph / Entra ID / M365 Defender, CrowdStrike Falcon, Tanium, BloodHound, Anvilogic, ThreatQ, ServiceNow (Incidents, SecOps, CMDB, IR workflows)
- Serve as escalation point for complex orchestration design, execution, and automation failures
Requirements
- 8+ years’ experience in Security Operations, Incident Response, Detection Engineering, or Security Automation
- 4+ years hands-on experience with Splunk SOAR (Phantom) and Tines in enterprise environments
- Deep understanding of incident response workflows and SOC operating models
- Strong experience integrating SOAR platforms with common security and enterprise systems (e.g., MS Graph, CrowdStrike, Tanium, ServiceNow)
- Experience designing automation with emphasis on control, reliability, auditability, and operational safety
- Proven ability to translate ambiguous operational needs into clear, actionable technical designs
- Experience working across a broad set of cybersecurity vendor products and APIs
Benefits
- Discretionary incentive eligible
- Annual discretionary award based on individual performance
- Industry-leading benefits
- Paid time off
- Resources and support for employees
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
security orchestrationautomation designincident response workflowsdetection engineeringsecurity automationintegration of SOAR platformscontrol reliabilityauditabilityoperational safetytechnical design
Soft Skills
collaborationcommunicationprioritizationproblem-solvingstakeholder engagementrequirements definitionvalue metrics collectionstrategic thinkingleadershipescalation management