Security Incident Response Orchestration Lead
$98.4k - $160kBank of America ATM
Overview At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day. Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates’ physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve. Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us! Job Description The Security Incident Response Orchestration Lead is responsible for defining, scoping, and guiding the technical execution of enterprise‑scale security automation. This role partners closely with security operations teams, product management, and engineering leadership to translate incident response workflows into scalable, governed orchestration using Splunk SOAR, Tines, and emerging AI‑enabled capabilities. The lead ensures a healthy, value‑driven backlog while enabling the responsible adoption of agentic AI through strong governance, guardrails, and observable control mechanisms. Core Responsibilities Serve as senior technical authority for security orchestration across Splunk SOAR and Tines Define architectural standards, reusable automation patterns, and orchestration best practices Scope and evaluate incoming automation requests in partnership with the Product Manager to support prioritization decisions Coordinate with the Product Owner to ensure clearly defined requirements and acceptance criteria are maintained in the backlog Collect and define value metrics at intake including MTTR reduction, analyst time savings, and incident quality improvements Partner with over 15 security operations teams to identify and design high‑impact automation opportunities Coordinate with SOAR feature leads to ensure shared understanding of scope, intent, and accurate execution Collaborate with senior and principal‑level engineers to design strategic, cross‑platform orchestration solutions Design, implement, and guide integrations across common SOAR ecosystems, including but not limited to: Microsoft Graph / Entra ID / M365 Defender CrowdStrike Falcon Tanium BloodHound Anvilogic ThreatQ ServiceNow (Incidents, SecOps, CMDB, IR workflows) Serve as escalation point for complex orchestration design, execution, and automation failures Required Qualifications 8+ years’ experience in Security Operations, Incident Response, Detection Engineering, or Security Automation 4+ years hands‑on experience with Splunk SOAR (Phantom) and Tines in enterprise environments Deep understanding of incident response workflows and SOC operating models Strong experience integrating SOAR platforms with common security and enterprise systems (e.g., MS Graph, CrowdStrike, Tanium, ServiceNow) Experience designing automation with emphasis on control, reliability, auditability, and operational safety Proven ability to translate ambiguous operational needs into clear, actionable technical designs Experience working across a broad set of cybersecurity vendor products and APIs Desired Qualifications Experience supporting enterprise‑scale SOAR programs Background in security architecture or SOC leadership Proficiency with Python, REST APIs, and modern authentication models Hands‑on or architectural experience with AI‑enabled security operations, including copilots or agent‑based workflows Understanding of RAG‑based architectures, vector databases, and elastic data platforms Skills Influence Result Orientation Solution Design Stakeholder Management Technical Strategy Development Access and Identity Management Critical Thinking Cyber Security Information Systems Management Risk Management Collaboration DevOps Practices Financial Management Solution Delivery Process Test Engineering This job will be open and accepting applications for a minimum of seven days from the date it was posted. Shift 1st shift (United States of America) Hours Per Week 40 Pay Transparency details US - CO - Denver - 1144 15th St - Denver Gis (CO9926), US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540) Pay range: $98,400.00 - $160,000.00 annualized salary, offers to be determined based on experience, education and skill set. Discretionary incentive eligible. This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company. Benefits: This role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve. #J-18808-Ljbffr Bank of America
$116.9k - $243.1k
...clients across defense, national security, public safety, civilian, and... ...We are hiring a CIRT Lead to manage 24x7x365 front‑line defense against cyber incidents. You will oversee the full lifecycle... ...’s security posture. Key Responsibilities Lead CIRT operations in advanced...SuggestedLive inWork at officeLocal area- A leading consulting firm is seeking a Security Operations Lead to oversee SOC functions and manage a team of Analysts and Engineers in Washington,... ...cybersecurity experience with specific expertise in incident response, threat hunting, and SIEM technologies like Splunk...Suggested
$160k - $190k
Edgewater Federal Solutions, Inc. is seeking an Incident Response (IR) Tech Lead to oversee an Incident Response team on a Federal government contract. Responsibilities include leading incident responses, managing triage processes, and coordinating across cybersecurity...SuggestedContract work- A cybersecurity firm located in Falls Church, Virginia, seeks a Security Operations Center (SOC) Lead to manage daily security operations, coordinate incident response activities, and oversee SOC analysts. Candidates should have over 12 years of experience in cybersecurity...Suggested
- Dc-Aapor is seeking a Senior Manager, Security Operations in Washington, DC, responsible for leading the security operations to ensure the protection of the organization... ...skills, with a focus on risk management and incident response. The ideal candidate will have over 8...Suggested
- ...We have a new and exciting role available within our Cyber Security division for an Incident Response Engagement Lead in the United States. S-RM is a global intelligence and cybersecurity consultancy. Since 2005, we’ve helped some of the most demanding clients in the...Immediate startFlexible hours
$60k
...supporting mission-critical programs across national security, defense, and public service delivery. Our work focuses... ...218, T2, Band 5 Job-Specific Essential Duties and Responsibilities: Lead Command and Incident Center (CIC) shift operations, coordinating personnel...Contract workWork at officeShift workNight shift- A leading provider of real estate information is seeking a Lead Security Engineer in Arlington, VA. The ideal candidate will have over 10 years of experience in... ...Information Security and a strong background in incident response and technical assessments. The role requires...
- A dynamic Woman Owned Small Business is seeking a Senior Incident Response Coordinator for their Program Management and Cyber Support Services project in Arlington, Virginia. The role entails coordinating cyber incident responses, managing stakeholder communications, and...
$310k - $375k
Menlo Ventures is looking for an Incident Response Manager to lead the Enforcement On-Call program, ensuring a quick response to escalations and managing cross-functional teams. This role requires a strong background in trust and safety operations and the ability to communicate...- ...and public-sector customers who demand experience and proven security models to protect their data. ShorePoint subscribes to a “... ...and more. Who we’re looking for: We are seeking an Incident Response Lead to serve as the Subject Matter Expert (SME) on all cybersecurity...Contract work
- Po'kela is seeking an Incident Responder/Incident Response Coordinator to support government clients in Arlington, VA or Mechanicsburg, PA. The ideal candidate will have significant experience in information technology, alongside a proven track record in urgent incident...
- Kapili Services, LLC is seeking an Incident Responder/Incident Response Coordinator to offer support for government clients in Arlington, VA. The ideal candidate will have a four year degree in information technology and a minimum of eight years of relevant experience...
$95.58k
Summary ValidaTek is searching for a Rapid Response Team Lead to oversee the integrity, security, and efficiency of the network framework that supports a large... ...they occur. Communicate plans and responses to incidents to customer leadership, providing them confidence that...Contract workLocal area- EmergencyMD is seeking a Lead Incident Responder for a potential government client. This role will involve leading incident response operations, managing complex threats, and ensuring compliance with federal cybersecurity frameworks. The candidate must have a Bachelor’s...
$116.9k - $243.1k
A leading technology firm is seeking a CIRT Lead in Arlington, Virginia. This role involves managing 24x7 cyber incident response and overseeing the entire investigation lifecycle, while enhancing the client’s security posture. Candidates should have over 5 years in cybersecurity...- KellyMitchell Group is seeking a Vulnerability Management Team Lead in Bethesda, Maryland. In this role, you will lead a team to develop and execute a comprehensive vulnerability management program, overseeing daily operations and coordinating with various stakeholders...
- ...prominent government contractor is seeking a highly skilled Lead Incident Responder to manage critical security documentation and ensure compliance with government standards. This role involves leading incident response efforts, conducting annual Security Control Assessments...For contractors
- ...A leading social media company is seeking a Lead Cyber Security Operations Center Analyst to oversee incident responses and investigations. This role involves leading a team of analysts, developing detection strategies, and ensuring the safety of user data on the platform...
- GOEBEL FIXTURE COMPANY is seeking a Senior Security Operations Analyst in Washington, DC to safeguard digital assets and respond to security incidents. This role involves monitoring systems for threats, developing incident handling procedures, and ensuring compliance with...
- A cybersecurity services firm in Washington, D.C. seeks an Incident Response Lead to be the subject matter expert in cybersecurity matters. The... ...strategies, coordinating recovery efforts, and advising on security architecture. Ideal candidates will have at least 5 years...
$98.4k - $160k
A leading financial services company located in Washington seeks a Security Incident Response Orchestration Lead. This position is responsible for enterprise-scale security automation and requires extensive experience with Splunk SOAR and Tines. The ideal candidate will...- ...relevant field, with at least 5 years of system administration experience and an active DoD Secret Clearance. Knowledge of networking, Linux/Unix, and VPNs is essential, along with experience managing technical issues and systems security. #J-18808-Ljbffr NewGen Technologies
- Farfield Systems in Arlington, Virginia is seeking a Cyber Incident Management professional to oversee the incident response lifecycle, coordinate with stakeholders, and support cyber operations. Ideal candidates should have over 5 years of relevant experience in cyber...
- A leading security solutions provider in Washington DC is looking for a skilled Security Architect to design and implement advanced security... ...skills and expertise in both PMP and CISSP certifications. Responsibilities include developing security standards, mentoring teams, and...
- ...Forensics Analyst to provide advanced technical support for cybersecurity incidents. This position requires US citizenship, TS/SCI clearance, and strong skills in cyber forensics and incident response. The candidate will oversee teams, assist in investigations, and write...For contractors
$21.6 per hour
National Geographic is seeking an on-site security staff member for its Base Camp in Washington, D.C. Responsibilities include observing safety, responding to emergencies, and operating security systems. A high school diploma and a minimum of 2 years in physical security...Hourly payVisa sponsorshipFlexible hours$79.4k - $135k
ASM Research, An Accenture Federal Services Company, is seeking an Incident Manager, Mid, to lead the lifecycle of IT incidents. You will ensure the execution of the incident management process and coordinate cross-functional teams to restore services swiftly. Applicants...$135k - $216k
Responsibilities Peraton is seeking an experienced Tier 2 Cyber Incident Response Team (CIRT) Shift Lead to join Peratons' Federal Strategic Cyber Mission... ..., and report on cyber security events and incidents.... ...respond to the CIRT Security Orchestration and Automation Response...Contract workLocal areaAll shiftsShift workAfternoon shift- ...seeking a Hazardous Materials Response Team Manager to oversee the... ...Nuclear, and Explosive (CBRNE) Incident Response Program. This role... ...candidate will be responsible for leading emergency response operations... ...compliance with safety and security standards. This is a full-...Permanent employmentFull time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Incident Response Orchestration Lead. Be the first to apply!

