Bank of America

Security Incident Response Lead

Bank of America

full-time

Posted on:

Location Type: Office

Location: DenverColoradoDistrict of ColumbiaUnited States

Visit company website

Explore more

AI Apply
Apply

Salary

💰 $98,400 - $160,000 per year

Job Level

About the role

  • Serve as senior technical authority for security orchestration across Splunk SOAR and Tines
  • Define architectural standards, reusable automation patterns, and orchestration best practices
  • Scope and evaluate incoming automation requests in partnership with the Product Manager to support prioritization decisions
  • Coordinate with the Product Owner to ensure clearly defined requirements and acceptance criteria are maintained in the backlog
  • Collect and define value metrics at intake including MTTR reduction, analyst time savings, and incident quality improvements
  • Partner with over 15 security operations teams to identify and design high-impact automation opportunities
  • Coordinate with SOAR feature leads to ensure shared understanding of scope, intent, and accurate execution
  • Collaborate with senior and principal-level engineers to design strategic, cross-platform orchestration solutions
  • Design, implement, and guide integrations across common SOAR ecosystems, including but not limited to: Microsoft Graph / Entra ID / M365 Defender, CrowdStrike Falcon, Tanium, BloodHound, Anvilogic, ThreatQ, ServiceNow (Incidents, SecOps, CMDB, IR workflows)
  • Serve as escalation point for complex orchestration design, execution, and automation failures

Requirements

  • 8+ years’ experience in Security Operations, Incident Response, Detection Engineering, or Security Automation
  • 4+ years hands-on experience with Splunk SOAR (Phantom) and Tines in enterprise environments
  • Deep understanding of incident response workflows and SOC operating models
  • Strong experience integrating SOAR platforms with common security and enterprise systems (e.g., MS Graph, CrowdStrike, Tanium, ServiceNow)
  • Experience designing automation with emphasis on control, reliability, auditability, and operational safety
  • Proven ability to translate ambiguous operational needs into clear, actionable technical designs
  • Experience working across a broad set of cybersecurity vendor products and APIs
Benefits
  • Discretionary incentive eligible
  • Annual discretionary award based on individual performance
  • Industry-leading benefits
  • Paid time off
  • Resources and support for employees
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills & Tools
security orchestrationautomation designincident response workflowsdetection engineeringsecurity automationintegration of SOAR platformscontrol reliabilityauditabilityoperational safetytechnical design
Soft Skills
collaborationcommunicationprioritizationproblem-solvingstakeholder engagementrequirements definitionvalue metrics collectionstrategic thinkingleadershipescalation management