Connecting Odds
Back to jobs
Bank of America

Security Incident Response Orchestration Lead

Discovered
Bank of America
Chicago, IL; Denver, CO; Washington, DCexternalData and AnalyticsPosted 20 days ago (Jul 23, 2026)

Job Description

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day. Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates' physical, emotional, and financial wellness through affordable, competitive and flexible benefits. We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve. Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us! @@HD@@ Job Description:@@/HD@@ The Security Incident Response Orchestration Lead is the senior technical authority responsible for setting the vision, architecture, and execution strategy for enterprise-scale security automation. This role leads the design and evolution of orchestration capabilities across Splunk SOAR, Tines, and AI-enabled platforms, ensuring scalable, resilient, and governed solutions aligned to enterprise security objectives. As a principal-level contributor, this role drives cross-organizational alignment across security operations, product management, engineering, and executive leadership to transform incident response through automation and intelligent decisioning. The role defines long-term strategy, establishes engineering standards, and ensures measurable business outcomes through effective orchestration. This position is accountable for advancing agentic AI adoption in security operations, embedding governance, observability, and control mechanisms that enable safe, reliable, and value-driven automation at scale. @@HD@@ Core Responsibilities@@/HD@@ @@HD@@ • Serve as the enterprise technical authority@@/HD@@ for security orchestration across Splunk SOAR and Tines • Define and evolve the

long-term architecture, strategy, and roadmap

for SOAR and automation platforms • Establish

enterprise standards, reusable frameworks, and orchestration patterns

to drive consistency and scale • Lead

end-to-end design authority

for complex, cross-platform automation initiatives • Partner with Product Management and senior leadership to

shape portfolio prioritization and strategic investments

• Drive

intake governance model

, ensuring automation demand is evaluated, prioritized, and aligned to measurable outcomes • Define and track

enterprise value metrics

(MTTR reduction, analyst efficiency, operational risk reduction, automation coverage) • Influence and guide

multiple security domain teams (15+ teams)

to adopt standardized automation patterns and best practices • Provide

technical leadership and mentorship

to senior and principal engineers across SOAR platforms • Act as escalation point for

high-risk, high-complexity orchestration challenges

and systemic platform issues • Lead design and oversight of

enterprise integrations

, including but not limited to: • Microsoft Graph / Entra ID / M365 Defender • CrowdStrike Falcon • Tanium • BloodHound • Anvilogic • ThreatQ • ServiceNow (Incidents, SecOps, CMDB, IR workflows) • Drive

platform reliability, resilience, and auditability standards

across all automation implementations

AI-Enabled & Agentic Automation

@@HD@@ • Define enterprise vision for AI-driven security operations@@/HD@@ , including copilots, agents, and MCP-aligned orchestration • Lead design of

AI-assisted investigation, triage, and response workflows

integrated with SOAR decisioning • Establish and enforce

enterprise AI governance framework

, including: • Human-in-the-loop approval models and escalation paths • Deterministic fallback and fail-safe execution patterns • Access controls, observability, logging, and auditability aligned with enterprise risk standards • Define architectural patterns for

AI-integrated SOAR systems

, including: • Retrieval-Augmented Generation (RAG) design and secure knowledge integration • Vector embedding strategies for semantic search and correlation • Scalable data pipelines for incident context, detections, and response history • Evaluate and approve

AI use cases

based on operational value, risk, and production readiness • Partner with governance, risk, and compliance teams to ensure

Required Qualifications

• 10+ years of experience in Security Operations, Incident Response, Detection Engineering, or Security Automation • 5+ years of deep, hands on experience with Splunk SOAR (Phantom) in addition to hands on experience with

Tines (required)

in enterprise environments • Proven track record of

leading large-scale SOAR or automation programs

• Deep expertise in

incident response lifecycle, SOC operating models, and automation strategy

• Strong experience designing and scaling

secure, reliable, and governed automation architectures

• Experience integrating SOAR platforms with enterprise systems (Microsoft Graph, CrowdStrike, Tanium, ServiceNow, etc.) • Demonstrated ability to influence

senior leadership and drive cross-organizational initiatives

• Expertise in translating complex, ambiguous problems into

Desired Qualifications

@@HD@@ • Prior experience operating at principal, staff, or architect level@@/HD@@ in cybersecurity engineering • Experience defining or leading

enterprise security architecture or SOC transformation initiatives

• Strong proficiency in Python, REST APIs, and modern authentication (OAuth, SAML, etc.) • Experience with

AI-enabled security operations

, including copilots, LLM integrations, or agent-based systems • Hands-on or architectural experience with

RAG frameworks, vector databases, and AI data platforms

• Familiarity with

cloud security architectures

across AWS, Azure, and Google Cloud • Experience working with

governance frameworks (MRM, audit, compliance, risk controls)

in regulated environments

Skills

• Influence • Result Orientation • Solution Design • Stakeholder Management • Technical Strategy Development • Access and Identity Management • Cyber Security • Information Systems Management • Risk Management • Solution Delivery Process • Collaboration • Critical Thinking • DevOps Practices • Financial Management • Test Engineering This job will be open and accepting applications for a minimum of seven days from the date it was posted. @@HD@@ Shift:@@/HD@@ @@HD@@1st shift (United States of America) Hours Per Week: @@/HD@@ @@HD@@40 Pay Transparency details@@/HD@@ US - CO - Denver - 1144 15th St - Denver Gis (CO9926), US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540) Pay and benefits information Pay range $150,000.00 - $190,700.00 annualized salary, offers to be determined based on experience, education and skill set. Discretionary incentive eligible This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company. Benefits This role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.

Not published in this posting

The company didn't include what you'll do, benefits in the source posting. The hiring team may have more details on their own site.

Sign in to open the original posting

Apply on Bank of America

This role was discovered from a public careers page. Applications are handled by the hiring team at Bank of America.

Attribution: sourced from Bank of America's public The Muse board.

AI job toolkit

Sign in to see how well your profile matches this role, draft a cover letter, prepare for the interview, and find people who can introduce you.

Sign in to unlock