Network / System Engineer V

Bank of America Bank of America · Banking · Plano, TX

This role focuses on IT security operations within a FinTech environment, specifically managing and optimizing SIEM/SOAR platforms like Splunk for threat detection, automation, and incident response. It involves developing detection rules, automation playbooks, and dashboards, monitoring security events, and ensuring compliance with bank policies. The role requires extensive experience in SIEM/SOAR, IAM, and related technologies, with a strong emphasis on production support and troubleshooting in a regulated environment.

What you'd actually do

  1. Leads production support triage efforts, manages bridge line troubleshooting, engages in technical research, and escalates issues to leadership as needed
  2. Ensures all impacts are accurately recorded and documented in the system of record, oversees that documents and wikis are updated and available for use during triage, and supports the documentation of application flows, upstream/downstream impacts during outages, the customer experience, and contacts for support needs
  3. Identifies and/or validates business impacts through interpretation of monitors, dashboards, and logs to communicate with leadership and vendors
  4. Manages activities to identify incident root cause, resolution, preventative actions, and change requests, and reports on incident data quality
  5. Promotes and enforces production governance during triage/testing and identifies production failure scenarios, vulnerabilities, and opportunities for improvement

Skills

Required

  • SIEM/SOAR administration and security operations
  • Splunk (searches, dashboards, alerts, playbooks)
  • cybersecurity frameworks
  • threat detection
  • incident response
  • production support
  • MFA technologies
  • Splunk
  • Window OS
  • SQL/Oracle DB
  • Unix/Linux
  • Identity, Authentication and Access Management (IAM)
  • SRE
  • DevOps
  • Linux
  • SQL queries
  • Windows OS
  • RedHat Linux
  • SQL/Oracle
  • RedHat Linux OpenShift containers
  • Atlassian JIRA & Horizon platforms
  • GitHub
  • Ansible
  • Jenkins
  • ITSM Remedy
  • Dynatrace
  • PowerShell/Unix Scripting
  • cloud experience
  • CI/CD DevOps tools

Nice to have

  • automation
  • collaboration with IT teams
  • building detection rules
  • automation playbooks
  • dashboards
  • strengthening security posture
  • monitoring security events
  • reducing response times
  • facilitating business continuity
  • service restoral
  • identification of root cause
  • facilitation and co-ordination for a permanent fix
  • best practices
  • expert level hands-on knowledge of Access management and Entitlement technologies
  • 5 C's of cyber security - Change, Compliance, Cost, Continuity and Coverage
  • Passion for cybersecurity and automation
  • turning Splunk skills into impact
  • Use Splunk skills to fight threats and keep financial services secure

What the JD emphasized

  • SIEM/SOAR platforms
  • Splunk
  • security operations
  • incident response
  • threat detection
  • automation
  • IAM
  • highly regulated FinTech industry
  • Windows OS
  • RedHat Linux
  • SQL queries
  • SQL/Oracle
  • RedHat Linux OpenShift containers
  • Atlassian JIRA & Horizon platforms
  • GitHub
  • Ansible
  • Jenkins
  • ITSM Remedy
  • Splunk
  • Dynatrace
  • PowerShell/Unix Scripting
  • cloud experience
  • CI/CD DevOps tools
  • MUST BE ABLE TO WORK SATURDAY OR SUNDAY WHEN ON CALL OR FOR NEW RELEASES
  • 5+ years of experience in SIEM/SOAR administration and security operations
  • Strong hands-on knowledge of Splunk (searches, dashboards, alerts, playbooks)
  • 5+ years of production support experience with expert level knowledge of MFA technologies, Splunk. Window OS, SQL/Oracle DB & Unix/Linux
  • Must have senior level production support experience and troubleshooting skills in SIEM/SOAR space, Splunk and IAM technologies.
  • Must be able to comply with bank regulatory and compliance policies
  • Must have expert level of Linux experience