Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Bank of America

Security Incident Response Lead

Bank of America

Security Incident Response Orchestration Lead responsible for enterprise-scale security automation at Bank of America. Leading orchestration capabilities and cross-organizational alignment for incident response.

Posted 7/22/2026full-timeChicago • Colorado, District of Columbia, Illinois • 🇺🇸 United StatesSenior💰 $150,000 - $190,700 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive expertise in Security Operations and Incident Response, with a strong focus on Splunk SOAR and Tines for automation. Proven ability to lead complex automation initiatives and establish enterprise standards for security orchestration.

Highest-signal resume keywords
Splunk SOAR (Phantom) ExpertiseTines ExperienceIncident Response Lifecycle KnowledgeAutomation Architecture DesignCross-Organizational Initiative Leadership

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Security OperationsIncident ResponseDetection EngineeringAutomation StrategyAutomation ArchitectureIntegration with Microsoft GraphIntegration with CrowdStrikeIntegration with TaniumIntegration with ServiceNowAI Governance Framework
Soft Skills
Influencing Senior LeadershipMentorshipProblem-Solving
Tools & Technologies
Splunk SOARTinesMicrosoft GraphCrowdStrike FalconTaniumServiceNow
Industry Keywords
Security OrchestrationAutomation PlatformsEnterprise StandardsOperational Risk ReductionAI-Driven Security Operations

Tech Stack

Tools & technologies
ServiceNowSplunk

About the role

Key responsibilities & impact
  • Serve as the enterprise technical authority for security orchestration across Splunk SOAR and Tines
  • Define and evolve the long‑term architecture, strategy, and roadmap for SOAR and automation platforms
  • Establish enterprise standards, reusable frameworks, and orchestration patterns to drive consistency and scale
  • Lead end‑to‑end design authority for complex, cross‑platform automation initiatives
  • Partner with Product Management and senior leadership to shape portfolio prioritization and strategic investments
  • Drive intake governance model, ensuring automation demand is evaluated, prioritized, and aligned to measurable outcomes
  • Define and track enterprise value metrics (MTTR reduction, analyst efficiency, operational risk reduction, automation coverage)
  • Influence and guide multiple security domain teams (15+ teams) to adopt standardized automation patterns and best practices
  • Provide technical leadership and mentorship to senior and principal engineers across SOAR platforms
  • Act as escalation point for high‑risk, high‑complexity orchestration challenges and systemic platform issues
  • Lead design and oversight of enterprise integrations, including but not limited to: Microsoft Graph / Entra ID / M365 Defender, CrowdStrike Falcon, Tanium, BloodHound, Anvilogic, ThreatQ, ServiceNow (Incidents, SecOps, CMDB, IR workflows)
  • Drive platform reliability, resilience, and auditability standards across all automation implementations
  • Define enterprise vision for AI‑driven security operations, including copilots, agents, and MCP‑aligned orchestration
  • Lead design of AI‑assisted investigation, triage, and response workflows integrated with SOAR decisioning
  • Establish and enforce enterprise AI governance framework, including: Human‑in‑the‑loop approval models and escalation paths, Deterministic fallback and fail‑safe execution patterns, Access controls, observability, logging, and auditability aligned with enterprise risk standards
  • Define architectural patterns for AI‑integrated SOAR systems, including: Retrieval‑Augmented Generation (RAG) design and secure knowledge integration, Vector embedding strategies for semantic search and correlation, Scalable data pipelines for incident context, detections, and response history
  • Evaluate and approve AI use cases based on operational value, risk, and production readiness
  • Partner with governance, risk, and compliance teams to ensure safe, auditable deployment of AI capabilities.

Requirements

What you’ll need
  • 10+ years of experience in Security Operations, Incident Response, Detection Engineering, or Security Automation
  • 5+ years of deep, hands on experience with Splunk SOAR (Phantom) in addition to hands on experience with Tines (required) in enterprise environments
  • Proven track record of leading large-scale SOAR or automation programs
  • Deep expertise in incident response lifecycle, SOC operating models, and automation strategy
  • Strong experience designing and scaling secure, reliable, and governed automation architectures
  • Experience integrating SOAR platforms with enterprise systems (Microsoft Graph, CrowdStrike, Tanium, ServiceNow, etc.)
  • Demonstrated ability to influence senior leadership and drive cross-organizational initiatives
  • Expertise in translating complex, ambiguous problems into clear architectural solutions and execution plans.

Benefits

Comp & perks
  • Discretionary incentive eligible
  • Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.
  • Industry-leading benefits
  • Access to paid time off
  • Resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.