Security Incident Response Orchestration Lead

Bank of America Bank of America · Banking · Denver, CO +3

Lead for Security Incident Response Orchestration, focusing on enterprise-scale security automation using Splunk SOAR, Tines, and emerging AI-enabled capabilities. The role involves defining architectural standards, managing the backlog, and ensuring responsible adoption of agentic AI with strong governance and guardrails.

What you'd actually do

  1. Serve as senior technical authority for security orchestration across Splunk SOAR and Tines
  2. Define architectural standards, reusable automation patterns, and orchestration best practices
  3. Scope and evaluate incoming automation requests in partnership with the Product Manager to support prioritization decisions
  4. Coordinate with the Product Owner to ensure clearly defined requirements and acceptance criteria are maintained in the backlog
  5. Collect and define value metrics at intake including MTTR reduction, analyst time savings, and incident quality improvements

Skills

Required

  • 8+ years’ experience in Security Operations, Incident Response, Detection Engineering, or Security Automation
  • 4+ years hands‑on experience with Splunk SOAR (Phantom) and Tines in enterprise environments
  • Deep understanding of incident response workflows and SOC operating models
  • Strong experience integrating SOAR platforms with common security and enterprise systems (e.g., MS Graph, CrowdStrike, Tanium, ServiceNow)
  • Experience designing automation with emphasis on control, reliability, auditability, and operational safety
  • Proven ability to translate ambiguous operational needs into clear, actionable technical designs
  • Experience working across a broad set of cybersecurity vendor products and APIs

Nice to have

  • Experience supporting enterprise‑scale SOAR programs
  • Background in security architecture or SOC leadership
  • Proficiency with Python, REST APIs, and modern authentication models
  • Hands‑on or architectural experience with AI‑enabled security operations, including copilots or agent‑based workflows
  • Understanding of RAG‑based architectures, vector databases, and elastic data platforms

What the JD emphasized

  • emerging AI‑enabled capabilities
  • agentic AI
  • governance
  • guardrails
  • observable control mechanisms
  • Splunk SOAR
  • Tines

Other signals

  • AI-enabled capabilities
  • agentic AI
  • governance
  • guardrails
  • observable control mechanisms