Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Incident Response Orchestration Lead

$150k - $190.7k

Bank of America ATM

Job Description:At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!Job Description:The Security Incident Response Orchestration Lead is the senior technical authority responsible for setting the vision, architecture, and execution strategy for enterprise‑scale security automation. This role leads the design and evolution of orchestration capabilities across Splunk SOAR, Tines, and AI‑enabled platforms, ensuring scalable, resilient, and governed solutions aligned to enterprise security objectives.As a principal‑level contributor, this role drives cross‑organizational alignment across security operations, product management, engineering, and executive leadership to transform incident response through automation and intelligent decisioning. The role defines long‑term strategy, establishes engineering standards, and ensures measurable business outcomes through effective orchestration.This position is accountable for advancing agentic AI adoption in security operations, embedding governance, observability, and control mechanisms that enable safe, reliable, and value‑driven automation at scale.Core ResponsibilitiesServe as the enterprise technical authority for security orchestration across Splunk SOAR and TinesDefine and evolve the long‑term architecture, strategy, and roadmap for SOAR and automation platformsEstablish enterprise standards, reusable frameworks, and orchestration patterns to drive consistency and scaleLead end‑to‑end design authority for complex, cross‑platform automation initiativesPartner with Product Management and senior leadership to shape portfolio prioritization and strategic investmentsDrive intake governance model, ensuring automation demand is evaluated, prioritized, and aligned to measurable outcomesDefine and track enterprise value metrics (MTTR reduction, analyst efficiency, operational risk reduction, automation coverage)Influence and guide multiple security domain teams (15+ teams) to adopt standardized automation patterns and best practicesProvide technical leadership and mentorship to senior and principal engineers across SOAR platformsAct as escalation point for high‑risk, high‑complexity orchestration challenges and systemic platform issuesLead design and oversight of enterprise integrations, including but not limited to:Microsoft Graph / Entra ID / M365 DefenderCrowdStrike FalconTaniumBloodHoundAnvilogicThreatQServiceNow (Incidents, SecOps, CMDB, IR workflows)Drive platform reliability, resilience, and auditability standards across all automation implementationsAI‑Enabled & Agentic AutomationDefine enterprise vision for AI‑driven security operations, including copilots, agents, and MCP‑aligned orchestrationLead design of AI‑assisted investigation, triage, and response workflows integrated with SOAR decisioningEstablish and enforce enterprise AI governance framework, including:Human‑in‑the‑loop approval models and escalation pathsDeterministic fallback and fail‑safe execution patternsAccess controls, observability, logging, and auditability aligned with enterprise risk standardsDefine architectural patterns for AI‑integrated SOAR systems, including:Retrieval‑Augmented Generation (RAG) design and secure knowledge integrationVector embedding strategies for semantic search and correlationScalable data pipelines for incident context, detections, and response historyEvaluate and approve AI use cases based on operational value, risk, and production readinessPartner with governance, risk, and compliance teams to ensure safe, auditable deployment of AI capabilitiesRequired Qualifications10+ years of experience in Security Operations, Incident Response, Detection Engineering, or Security Automation5+ years of deep, hands on experience with Splunk SOAR (Phantom) in addition to hands on experience with Tines (required) in enterprise environmentsProven track record of leading large‑scale SOAR or automation programsDeep expertise in incident response lifecycle, SOC operating models, and automation strategyStrong experience designing and scaling secure, reliable, and governed automation architecturesExperience integrating SOAR platforms with enterprise systems (Microsoft Graph, CrowdStrike, Tanium, ServiceNow, etc.)Demonstrated ability to influence senior leadership and drive cross‑organizational initiativesExpertise in translating complex, ambiguous problems into clear architectural solutions and execution plansDesired QualificationsPrior experience operating at principal, staff, or architect level in cybersecurity engineeringExperience defining or leading enterprise security architecture or SOC transformation initiativesStrong proficiency in Python, REST APIs, and modern authentication (OAuth, SAML, etc.)Experience with AI‑enabled security operations, including copilots, LLM integrations, or agent‑based systemsHands‑on or architectural experience with RAG frameworks, vector databases, and AI data platformsFamiliarity with cloud security architectures across AWS, Azure, and Google CloudExperience working with governance frameworks (MRM, audit, compliance, risk controls) in regulated environmentsSkills:InfluenceResult OrientationSolution DesignStakeholder ManagementTechnical Strategy DevelopmentAccess and Identity ManagementCyber SecurityInformation Systems ManagementRisk ManagementSolution Delivery ProcessCollaborationCritical ThinkingDevOps PracticesFinancial ManagementTest EngineeringThis job will be open and accepting applications for a minimum of seven days from the date it was posted.Shift:1st shift (United States of America)Hours Per Week: 40Pay Transparency detailsUS - CO - Denver - 1144 15th St - Denver Gis (CO9926), US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540)Pay and benefits informationPay range$150,000.00 - $190,700.00 annualized salary, offers to be determined based on experience, education and skill set.Discretionary incentive eligibleThis role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.BenefitsThis role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.SummaryLocation: Chicago; Washington; DenverType: Full time

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Security Incident Response Orchestration Lead in Washington DC vacancy
  •  ...A leading consulting firm is seeking a Security Operations Lead to oversee SOC functions and manage a team of Analysts and Engineers in Washington,...  ...cybersecurity experience with specific expertise in incident response, threat hunting, and SIEM technologies like Splunk... 
    Suggested

    Accenture

    Washington DC
    3 days ago
  • $135k - $216k

     ...a next-generation national security company that drives missions...  ...the galaxy. As the world's leading mission capability...  ...an experienced Tier 2 Cyber Incident Response Team (CIRT) Shift Lead to join...  ...respond to the CIRT Security Orchestration and Automation Response (SOAR... 
    Suggested
    Contract work
    Temporary work
    Work at office
    Local area
    All shifts
    Shift work
    Afternoon shift

    Peraton

    Beltsville, MD
    3 days ago
  •  ...GCA) is seeking a mission-driven Rapid Response Team Lead to support the high-priority, time-sensitive...  ...in GO/Flag quarters, and immediate incident response across critical infrastructure...  ...) and Flag Officer quarters, ensuring secure and functional communications across all... 
    Suggested
    Full time
    Contract work
    Immediate start
    Worldwide
    Night shift

    Geospatial And Cloud Analytics Inc

    Washington DC
    17 days ago
  • $140k - $150k

    Job DescriptionEverforth ECS is seeking an Incident Response Lead to work in our Washington, DC office / remote. The role is contingent upon...  ...a senior-level Incident Response Lead to join our advanced security operations team which is a specialized group focused on the... 
    Suggested
    Work at office
    Remote work

    ECS Federal

    Washington DC
    1 day ago
  •  ...EmergencyMD is seeking a Lead Incident Responder for a potential government client. This role will involve leading incident response operations, managing complex threats, and ensuring compliance with federal cybersecurity frameworks. The candidate must have a Bachelor’... 
    Suggested

    EmergencyMD

    Washington DC
    4 days ago
  • $100k - $120k

     ...Bering Straits Native Corporation is seeking a Sr. Cybersecurity Incident Response Specialist in Washington, DC. This role involves monitoring cyber threats and ensuring the security of networks and systems. The ideal candidate should have a deep understanding of cybersecurity... 

    Bering Straits Native Corporation

    Washington DC
    2 days ago
  •  ...Incident Response Lead ShorePoint is a fast-growing, industry recognized and award-winning cybersecurity services firm with a focus on high...  ...public-sector customers who demand experience and proven security models to protect their data. ShorePoint subscribes to a "work... 
    Contract work

    ShorePoint Inc

    Washington DC
    3 days ago
  •  ...seeking Cyber Eviction Analysts to support the DHS's Hunt and Incident Response Team. The role requires extensive experience in incident...  ...must have a strong understanding of network architecture and security, as well as excellent communication skills. This position offers... 

    Nightwing

    Arlington, VA
    2 days ago
  •  ...seeking a hands-on technical leader for its Cyber Investigation and Forensic Response practice in Arlington, Virginia. This role involves conducting complex forensic analyses, leading incident response efforts, and mentoring junior investigators. The ideal candidate has... 

    Accenture

    Arlington, VA
    3 days ago
  •  ...third-party validation. is searching for a Rapid Response Team Lead to oversee the integrity, security, and efficiency of the network framework that supports...  ...they occur.Communicate plans and responses to incidents to customer leadership, providing them confidence that... 
    Full time
    Contract work
    Local area

    ValidaTek

    Arlington, VA
    9 hours ago
  • DescriptionSAIC is seeking a technical Security Tools Team Lead to join our dynamic team in...  ...to the Security Operations Manager.Responsibilities:Lead a team of security tool administrators...  ...instructions, change management requests, incident tickets, and email communications.... 
    Work experience placement
    Work at office
    2 days per week

    Science Applications International Corporation

    Washington DC
    2 days ago
  • $94k - $151.8k

     ...Credo, Johnson & Johnson is responsible to our employees who work with...  ...& SecurityJob Sub Function: Security & ControlsJob Category:Scientific...  ...top talent for Cybersecurity Lead, You will be the Business...  ...Operations Center (SOC) with security incident investigation activities;... 
    Full time
    Local area
    Immediate start
    Remote work

    Johnson & Johnson

    Washington DC
    2 days ago
  •  ...Position Title SOC Operations Lead / Managed Detection & Response (MDR) Lead Position Overview The...  ...Operations Lead will oversee 24x7x365 Security Operations Center (SOC) and Managed...  ...The Lead will direct SOC analysts, incident responders, and MDR personnel responsible... 
    Full time

    cFocus Software Incorporated

    Washington DC
    22 days ago
  • $132.5k - $221.3k

     ...and Training.ResponsibilitiesAs The Security Administration Team Lead, you will:Provide disciplined...  ...volume security operations.Essential Responsibilities:Process and track administrative security...  ..., and administrative support for incidents, waivers, and accreditations when... 
    For contractors
    Work experience placement

    AMERICAN SYSTEMS

    Arlington, VA
    1 day ago
  • $90.3k - $189.6k

    Job Title: Lead Senior Information System Security OfficerJob Category: Information TechnologyTime Type: Full...  ...documentation is kept up to date.Responsibilities:Primary Responsibilities:The Lead...  ...and testing Contingency Plans and Incident Response Plans to ensure business... 
    Contract work
    Work experience placement
    Work at office
    Flexible hours

    CACI International

    Washington DC
    3 days ago
  •  ...Purpose and Scope The Head of Physical Security is a senior security executive responsible for the strategic leadership,...  ...Prevention & Behavioral Threat Assessment Lead enterprise-wide Workplace Violence...  ...third parties. Investigations & Incident Management Lead or oversee complex... 
    Local area

    Fresenius Medical Care

    Washington DC
    3 days ago
  • $138k - $209k

     ...that matter, alongside industry‑leading experts, in an environment...  ...individual to join AIS as a Security Architect. Core Knowledge & Skills...  ...needs of our client as an Incident Management Lead. Project...  ...Incident Management Lead is responsible for directing enterprise‑wide... 
    Contract work
    Temporary work

    AIS (Applied Information Sciences)

    Alexandria, VA
    3 days ago
  •  ...Improbable U.S. Defense & National Security and you will help users...  ...The Security & Compliance Lead/Facility Security Officer (“FSO...  ...report security violations and incidents Maintain all security...  ...analyzing resumes, or assessing responses and identifying potential inconsistencies... 
    For contractors
    Flexible hours

    Improbable LLC

    Arlington, VA
    24 days ago
  •  ...Evolver Federal is seeking a Lead Incident Responder to fulfill a requirement for a potential...  ...accountability for day-to-day incident response operations, providing leadership and...  ...containment, eradication, and recovery from security incidents. The Lead Incident Responder... 
    Contract work
    Flexible hours

    Evolver

    Washington DC
    1 day ago
  •  ...Software seeks a Forensic and Malware Lead to join our program supporting the Administrative...  ...activities in support of AOUSC Security Operations Division (SOD) operations....  ...Coordinate with Cybersecurity Triage and Incident Response teams to support investigation,... 
    Work at office

    cFocus Software Incorporated

    Washington DC
    22 days ago
  •  ...Position Overview We are seeking a highly skilled Lead Incident Responder to manage and maintain critical security documentation and ensure compliance with...  ...extensive experience in risk management, incident response, and vulnerability assessment within a government... 
    Contract work
    For contractors
    Work at office
    Local area

    DirectViz Solutions

    Washington DC
    3 days ago
  • $150k - $170k

     ...Zachary Piper Solutions is seeking a SOC Lead to support a company focused on...  ...defense, and protection of critical national security infrastructure. This position is on-...  ...will oversee security operations, lead incident response efforts, and ensure continuous monitoring... 
    Night shift

    Piper Companies

    Washington DC
    2 days ago
  • $150k - $170k

    Zachary Piper Solutions is seeking a SOC Lead to support a company focused on...  ...Department of Energy (DOE) and National Nuclear Security Administration (NNSA). This position is...  ...Center (SOC) activities, lead incident response efforts, and mentor a team of cybersecurity... 

    Zachary Piper Solutions

    Washington DC
    1 day ago
  • $99k - $130k

     ...months, not years. About The Team The Security Operations Team consists of...  ...risks, responding immediately to incidents, and fostering a resilient security...  ...Northeast Regional Physical Security Lead. This critical role will be responsible for the strategic leadership and day... 
    Full time
    Work experience placement
    Local area
    Immediate start

    Anduril Industries

    Washington DC
    2 days ago
  • Lead Consultant for the IR/Forensics Practice Employment Type: 1099/Independent Consultant...  ...Lead Consultant will be part of the Incident Response and Forensics practice, whose services...  ...activities during suspected security events, manage customer recovery, and provide... 
    Remote work

    Lumifi Cyber

    Arlington, VA
    13 hours ago
  •  ...Job Description Description: A Team Lead will oversee all Escort Staff on site coordinating...  ...in their designated locations. Responsible for assuring that schedules are...  ...are performed and escort them outside the security perimeter after completion of business.... 

    SemperServe

    Washington DC
    28 days ago
  •  ...Position Title Threat Emulation & Readiness Lead / Red Team Lead Position Overview...  ...and improve organizational detection, response, resilience, and operational readiness....  ...Qualifications ~10+ years of offensive security or advanced cybersecurity operations experience... 

    cFocus Software Incorporated

    Washington DC
    22 days ago
  •  ...growing government contractor providing leading-edge support to federal customers, with...  ...focus on Defense and National Security mission sets. We leverage more than 17...  ...risk management with MC&FP priorities.Responsibilities:Lead engagement and coordination with external... 
    Contract work
    For contractors
    Local area

    Barbaricum

    Washington DC
    4 days ago
  • $83k - $167k

     ...Time On-Site /On-siteSecurity Management Lead (SML) - SME Work Location: Washington, DC...  ...Logistics Support CGS is seeking a skilled Security Management Lead (SML) - SME to support...  ...applications, analyzing resumes, or assessing responses and identifying potential inconsistencies... 
    Full time

    CONTACT GOVERNMENT SERVICES

    Washington DC
    1 day ago
  •  ...ResponsibilitiesLMI is seeking a driven, results-oriented FSO / Security Lead to own all aspects of personnel, physical, and industrial...  ...industrial or personnel security experience, including FSO responsibilities. Working knowledge of NISPOM and DoD/IC security... 
    Full time

    LMI

    Washington DC
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Incident Response Orchestration Lead. Be the first to apply!