Security Incident Response Orchestration Lead
$98.4k - $160kBank of America
Overview At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day. Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates’ physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve. Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us! Job Description The Security Incident Response Orchestration Lead is responsible for defining, scoping, and guiding the technical execution of enterprise‑scale security automation. This role partners closely with security operations teams, product management, and engineering leadership to translate incident response workflows into scalable, governed orchestration using Splunk SOAR, Tines, and emerging AI‑enabled capabilities. The lead ensures a healthy, value‑driven backlog while enabling the responsible adoption of agentic AI through strong governance, guardrails, and observable control mechanisms. Core Responsibilities Serve as senior technical authority for security orchestration across Splunk SOAR and Tines Define architectural standards, reusable automation patterns, and orchestration best practices Scope and evaluate incoming automation requests in partnership with the Product Manager to support prioritization decisions Coordinate with the Product Owner to ensure clearly defined requirements and acceptance criteria are maintained in the backlog Collect and define value metrics at intake including MTTR reduction, analyst time savings, and incident quality improvements Partner with over 15 security operations teams to identify and design high‑impact automation opportunities Coordinate with SOAR feature leads to ensure shared understanding of scope, intent, and accurate execution Collaborate with senior and principal‑level engineers to design strategic, cross‑platform orchestration solutions Design, implement, and guide integrations across common SOAR ecosystems, including but not limited to: Microsoft Graph / Entra ID / M365 Defender CrowdStrike Falcon Tanium BloodHound Anvilogic ThreatQ ServiceNow (Incidents, SecOps, CMDB, IR workflows) Serve as escalation point for complex orchestration design, execution, and automation failures Required Qualifications 8+ years’ experience in Security Operations, Incident Response, Detection Engineering, or Security Automation 4+ years hands‑on experience with Splunk SOAR (Phantom) and Tines in enterprise environments Deep understanding of incident response workflows and SOC operating models Strong experience integrating SOAR platforms with common security and enterprise systems (e.g., MS Graph, CrowdStrike, Tanium, ServiceNow) Experience designing automation with emphasis on control, reliability, auditability, and operational safety Proven ability to translate ambiguous operational needs into clear, actionable technical designs Experience working across a broad set of cybersecurity vendor products and APIs Desired Qualifications Experience supporting enterprise‑scale SOAR programs Background in security architecture or SOC leadership Proficiency with Python, REST APIs, and modern authentication models Hands‑on or architectural experience with AI‑enabled security operations, including copilots or agent‑based workflows Understanding of RAG‑based architectures, vector databases, and elastic data platforms Skills Influence Result Orientation Solution Design Stakeholder Management Technical Strategy Development Access and Identity Management Critical Thinking Cyber Security Information Systems Management Risk Management Collaboration DevOps Practices Financial Management Solution Delivery Process Test Engineering This job will be open and accepting applications for a minimum of seven days from the date it was posted. Shift 1st shift (United States of America) Hours Per Week 40 Pay Transparency details US - CO - Denver - 1144 15th St - Denver Gis (CO9926), US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540) Pay range: $98,400.00 - $160,000.00 annualized salary, offers to be determined based on experience, education and skill set. Discretionary incentive eligible. This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company. Benefits: This role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve. #J-18808-Ljbffr
- ...A leading consulting firm is seeking a Security Operations Lead to oversee SOC functions and manage a team of Analysts and Engineers in Washington,... ...cybersecurity experience with specific expertise in incident response, threat hunting, and SIEM technologies like Splunk...Suggested
$116.9k - $243.1k
...clients across defense, national security, public safety, civilian, and... ...We are hiring a CIRT Lead to manage 24x7x365 front‑line defense against cyber incidents. You will oversee the full lifecycle... ...’s security posture. Key Responsibilities Lead CIRT operations in advanced...SuggestedLive inWork at officeLocal area$207k - $301k
Google is seeking a Security Engineer in Washington D.C. You will be responsible for managing incident response operations and forensics while collaborating with software engineers to fix vulnerabilities. You should have a Bachelor's degree and substantial experience in...Suggested- A cybersecurity firm located in Falls Church, Virginia, seeks a Security Operations Center (SOC) Lead to manage daily security operations, coordinate incident response activities, and oversee SOC analysts. Candidates should have over 12 years of experience in cybersecurity...Suggested
- Dc-Aapor is seeking a Senior Manager, Security Operations in Washington, DC, responsible for leading the security operations to ensure the protection of the organization... ...skills, with a focus on risk management and incident response. The ideal candidate will have over 8...Suggested
- ...Time/Part-Time Full-Time Description RiVidium is seeking an Incident Response Lead to support our planned MODES III team supporting Military... ...expectations. Ability to satisfy applicable Government personnel security requirements for the assigned role. For IT and...Full timeContract workPart timeShift workNight shift
- ...prominent government contractor is seeking a highly skilled Lead Incident Responder to manage critical security documentation and ensure compliance with government standards. This role involves leading incident response efforts, conducting annual Security Control Assessments...For contractors
- ...We have a new and exciting role available within our Cyber Security division for an Incident Response Engagement Lead in the United States. S-RM is a global intelligence and cybersecurity consultancy. Since 2005, we’ve helped some of the most demanding clients in the...Immediate startFlexible hours
- ...Incident Response Lead ShorePoint is a fast-growing, industry recognized and award-winning cybersecurity services firm with a focus on high... ...public-sector customers who demand experience and proven security models to protect their data. ShorePoint subscribes to a "work...Contract work
- A leading provider of real estate information is seeking a Lead Security Engineer in Arlington, VA. The ideal candidate will have over 10 years of experience in... ...Information Security and a strong background in incident response and technical assessments. The role requires...
- ...seeking a Cybersecurity Engineer / Team Lead in Arlington (REMOTE). In this role, you will provide technical leadership to secure federal information systems and oversee... ...NIST RMF compliance, team leadership, and incident response planning, ensuring a robust...Remote job
$116.9k - $243.1k
A leading technology firm is seeking a CIRT Lead in Arlington, Virginia. This role involves managing 24x7 cyber incident response and overseeing the entire investigation lifecycle, while enhancing the client’s security posture. Candidates should have over 5 years in cybersecurity...- Kapili Services, LLC is seeking an Incident Responder/Incident Response Coordinator to offer support for government clients in Arlington, VA. The ideal candidate will have a four year degree in information technology and a minimum of eight years of relevant experience...
$95.58k
Summary ValidaTek is searching for a Rapid Response Team Lead to oversee the integrity, security, and efficiency of the network framework that supports a large... ...they occur. Communicate plans and responses to incidents to customer leadership, providing them confidence that...Contract workLocal area- Po'kela is seeking an Incident Responder/Incident Response Coordinator to support government clients in Arlington, VA or Mechanicsburg, PA. The ideal candidate will have significant experience in information technology, alongside a proven track record in urgent incident...
- KellyMitchell Group is seeking a Vulnerability Management Team Lead in Bethesda, Maryland. In this role, you will lead a team to develop and execute a comprehensive vulnerability management program, overseeing daily operations and coordinating with various stakeholders...
- GOEBEL FIXTURE COMPANY is seeking a Senior Security Operations Analyst in Washington, DC to safeguard digital assets and respond to security incidents. This role involves monitoring systems for threats, developing incident handling procedures, and ensuring compliance with...
- Nightwing is seeking an Enterprise Architect and Project Lead to support critical cyber-incident response missions for U.S. Government clients. This role involves leading technology insertion teams, developing workflows, and delivering strategic planning documentation....
- ...missions. This role requires serving as a subject matter expert in incident response and analyzing cybersecurity incidents. The ideal candidate... ...an active TS/SCI clearance. Strong understanding of network security and the ability to travel domestically are also required....
- ...relevant field, with at least 5 years of system administration experience and an active DoD Secret Clearance. Knowledge of networking, Linux/Unix, and VPNs is essential, along with experience managing technical issues and systems security. #J-18808-Ljbffr NewGen Technologies
$98.4k - $160k
A leading financial services company located in Washington seeks a Security Incident Response Orchestration Lead. This position is responsible for enterprise-scale security automation and requires extensive experience with Splunk SOAR and Tines. The ideal candidate will...- ...Forensics Analyst to provide advanced technical support for cybersecurity incidents. This position requires US citizenship, TS/SCI clearance, and strong skills in cyber forensics and incident response. The candidate will oversee teams, assist in investigations, and write...For contractors
$135k - $216k
Responsibilities Peraton is seeking an experienced Tier 2 Cyber Incident Response Team (CIRT) Shift Lead to join Peratons' Federal Strategic Cyber Mission... ..., and report on cyber security events and incidents.... ...respond to the CIRT Security Orchestration and Automation Response...Contract workLocal areaAll shiftsShift workAfternoon shift$21.6 per hour
National Geographic is seeking an on-site security staff member for its Base Camp in Washington, D.C. Responsibilities include observing safety, responding to emergencies, and operating security systems. A high school diploma and a minimum of 2 years in physical security...Hourly payVisa sponsorshipFlexible hours- Powder River Industries is seeking a mission-driven NOC Lead in Washington, DC, to ensure the operational integrity of IT services. This role involves overseeing performance, managing incidents, and leading a team for continuous improvement. The ideal candidate has expertise...For contractorsNight shift
- A leading security services provider is seeking a PSO Supervisor in Washington, DC, to oversee guard operations and ensure compliance with... ...experience in law enforcement or military service. Responsibilities include supervising officers, conducting briefings, and training...Contract workShift work
- ...Overview Evolver Federal is seeking a Lead Incident Responder to fulfill a requirement for... ...accountability for day-to-day incident response operations, providing leadership and direction... ..., eradication, and recovery from security incidents. The Lead Incident Responder...Contract workFlexible hours
- Itlearn360 is seeking a SOC Security Analyst L3 to work from its College Park, Maryland office for four days a week. This role is vital in... ...threats faced by global customers. You'll analyze alerts, lead investigations, and mentor junior analysts while contributing to...Work at office
$86.6k - $181.8k
...Inc is actively seeking an experienced Incident Responder to support a DoD client in Suitland... ...to recovery, ensuring the integrity and security of data while collaborating with... ..., have extensive experience in incident response, and be proficient in cybersecurity practices...- Powder River Industries is seeking a skilled SOC Lead to oversee the Security Operations Center operations. You will guide a team of analysts... ...SOC teams and is proficient in threat detection and incident response. Benefits include medical, dental, vision, and 401k. #J...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Incident Response Orchestration Lead. Be the first to apply!

