Security Incident Response Orchestration Lead

Bank of America Bank of America · Banking · Chicago, IL +2

Lead the design and evolution of enterprise-scale security automation, focusing on orchestration capabilities across SOAR and AI-enabled platforms. This role drives agentic AI adoption in security operations, embedding governance, observability, and control mechanisms for safe and reliable automation at scale. Responsibilities include defining architecture, strategy, and standards for SOAR and AI integration, including RAG and vector embeddings, while ensuring compliance and measurable outcomes.

What you'd actually do

  1. Serve as the enterprise technical authority for security orchestration across Splunk SOAR and Tines
  2. Define and evolve the long-term architecture, strategy, and roadmap for SOAR and automation platforms
  3. Establish enterprise standards, reusable frameworks, and orchestration patterns to drive consistency and scale
  4. Lead end-to-end design authority for complex, cross-platform automation initiatives
  5. Partner with Product Management and senior leadership to shape portfolio prioritization and strategic investments

Skills

Required

  • 10+ years of experience in Security Operations, Incident Response, Detection Engineering, or Security Automation
  • 5+ years of deep, hands on experience with Splunk SOAR (Phantom)
  • Hands on experience with Tines in enterprise environments
  • Leading large-scale SOAR or automation programs
  • Incident response lifecycle, SOC operating models, and automation strategy
  • Designing and scaling secure, reliable, and governed automation architectures
  • Integrating SOAR platforms with enterprise systems (Microsoft Graph, CrowdStrike, Tanium, ServiceNow, etc.)
  • Influencing senior leadership and driving cross-organizational alignment

Nice to have

  • Experience with AI-enabled platforms
  • Experience with AI-driven security operations
  • Experience with agentic AI adoption
  • Experience with AI-assisted investigation, triage, and response workflows
  • Experience with AI governance frameworks
  • Experience with Retrieval-Augmented Generation (RAG)
  • Experience with vector embedding strategies

What the JD emphasized

  • setting the vision, architecture, and execution strategy for enterprise‑scale security automation
  • leading the design and evolution of orchestration capabilities across Splunk SOAR, Tines, and AI‑enabled platforms
  • advancing agentic AI adoption in security operations
  • embedding governance, observability, and control mechanisms that enable safe, reliable, and value‑driven automation at scale
  • Define enterprise vision for AI‑driven security operations, including copilots, agents, and MCP‑aligned orchestration
  • Lead design of AI‑assisted investigation, triage, and response workflows integrated with SOAR decisioning
  • Establish and enforce enterprise AI governance framework
  • Define architectural patterns for AI‑integrated SOAR systems
  • Evaluate and approve AI use cases based on operational value, risk, and production readiness
  • Partner with governance, risk, and compliance teams to ensure safe, auditable deployment of AI capabilities
  • 10+ years of experience in Security Operations, Incident Response, Detection Engineering, or Security Automation
  • 5+ years of deep, hands on experience with Splunk SOAR (Phantom) in addition to hands on experience with Tines (required) in enterprise environments
  • Proven track record of leading large‑scale SOAR or automation programs
  • Deep expertise in incident response lifecycle, SOC operating models, and automation strategy
  • Strong experience designing and scaling secure, reliable, and governed automation architectures
  • Experience integrating SOAR platforms with enterprise systems (Microsoft Graph, CrowdStrike, Tanium, ServiceNow, etc.)
  • Demonstrated ability to influence senior leadership and drive cross-organizational alignment

Other signals

  • AI-enabled platforms
  • AI-driven security operations
  • agentic AI adoption
  • AI-assisted investigation, triage, and response workflows
  • AI governance framework