Security Incident Response Orchestration Lead
Bank of America ATM
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits. We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve. Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!The Security Incident Response Orchestration Lead is the senior technical authority responsible for setting the vision, architecture, and execution strategy for enterprise‑scale security automation. This role leads the design and evolution of orchestration capabilities across Splunk SOAR, Tines, and AI‑enabled platforms, ensuring scalable, resilient, and governed solutions aligned to enterprise security objectives.
As a principal‑level contributor, this role drives cross‑organizational alignment across security operations, product management, engineering, and executive leadership to transform incident response through automation and intelligent decisioning. The role defines long‑term strategy, establishes engineering standards, and ensures measurable business outcomes through effective orchestration.
This position is accountable for advancing agentic AI adoption in security operations, embedding governance, observability, and control mechanisms that enable safe, reliable, and value‑driven automation at scale.
Core Responsibilities
- Serve as the enterprise technical authority for security orchestration across Splunk SOAR and Tines
- Define and evolve the long‑term architecture, strategy, and roadmap for SOAR and automation platforms
- Establish enterprise standards, reusable frameworks, and orchestration patterns to drive consistency and scale
- Lead end‑to‑end design authority for complex, cross‑platform automation initiatives
- Partner with Product Management and senior leadership to shape portfolio prioritization and strategic investments
- Drive intake governance model , ensuring automation demand is evaluated, prioritized, and aligned to measurable outcomes
- Define and track enterprise value metrics (MTTR reduction, analyst efficiency, operational risk reduction, automation coverage)
- Influence and guide multiple security domain teams (15+ teams) to adopt standardized automation patterns and best practices
- Provide technical leadership and mentorship to senior and principal engineers across SOAR platforms
- Act as escalation point for high‑risk, high‑complexity orchestration challenges and systemic platform issues
- Lead design and oversight of enterprise integrations , including but not limited to:
- Microsoft Graph / Entra ID / M365 Defender
- CrowdStrike Falcon
- Tanium
- BloodHound
- Anvilogic
- ThreatQ
- ServiceNow (Incidents, SecOps, CMDB, IR workflows)
- Drive platform reliability, resilience, and auditability standards across all automation implementations
AI‑Enabled & Agentic Automation
- Define enterprise vision for AI‑driven security operations , including copilots, agents, and MCP‑aligned orchestration
- Lead design of AI‑assisted investigation, triage, and response workflows integrated with SOAR decisioning
- Establish and enforce enterprise AI governance framework , including:
- Human‑in‑the‑loop approval models and escalation paths
- Deterministic fallback and fail‑safe execution patterns
- Access controls, observability, logging, and auditability aligned with enterprise risk standards
- Define architectural patterns for AI‑integrated SOAR systems , including:
- Retrieval‑Augmented Generation (RAG) design and secure knowledge integration
- Vector embedding strategies for semantic search and correlation
- Scalable data pipelines for incident context, detections, and response history
- Evaluate and approve AI use cases based on operational value, risk, and production readiness
- Partner with governance, risk, and compliance teams to ensure safe, auditable deployment of AI capabilities
Required Qualifications
- 10+ years of experience in Security Operations, Incident Response, Detection Engineering, or Security Automation
- 5+ years of deep, hands on experience with Splunk SOAR (Phantom) in addition to hands on experience with Tines (required) in enterprise environments
- Proven track record of leading large‑scale SOAR or automation programs
- Deep expertise in incident response lifecycle, SOC operating models, and automation strategy
- Strong experience designing and scaling secure, reliable, and governed automation architectures
- Experience integrating SOAR platforms with enterprise systems (Microsoft Graph, CrowdStrike, Tanium, ServiceNow, etc.)
- Demonstrated ability to influence senior leadership and drive cross‑organizational initiatives
- Expertise in translating complex, ambiguous problems into clear architectural solutions and execution plans
Desired Qualifications
- Prior experience operating at principal, staff, or architect level in cybersecurity engineering
- Experience defining or leading enterprise security architecture or SOC transformation initiatives
- Strong proficiency in Python, REST APIs, and modern authentication (OAuth, SAML, etc.)
- Experience with AI‑enabled security operations , including copilots, LLM integrations, or agent‑based systems
- Hands‑on or architectural experience with RAG frameworks, vector databases, and AI data platforms
- Familiarity with cloud security architectures across AWS, Azure, and Google Cloud
- Experience working with governance frameworks (MRM, audit, compliance, risk controls) in regulated environments
Skills:
- Influence
- Result Orientation
- Solution Design
- Stakeholder Management
- Technical Strategy Development
- Access and Identity Management
- Cyber Security
- Information Systems Management
- Risk Management
- Solution Delivery Process
- Collaboration
- Critical Thinking
- DevOps Practices
- Financial Management
- Test Engineering
This job will be open and accepting applications for a minimum of seven days from the date it was posted.
Shift:
1st shift (United States of America)Hours Per Week:
40$150k - $190.7k
...the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities... ..., and make an impact. Join us!Job Description:The Security Incident Response Orchestration Lead is the senior technical authority responsible for...SuggestedFull timeWork at officeFlexible hoursShift workDay shift- ...Accenture is seeking a hands-on technical leader for their Cyber Investigation and Forensic Response (CIFR) practice in Chicago. The candidate will excel in incident response and digital forensics, conducting complex analyses, mentoring investigators, and communicating...Suggested
$98k - $117k
...owns the Silvertip silver-zinc-lead development project in... ...an IT Service Delivery Lead responsible for coordinating and delivering... ...Management best practices, support incident, request, and change... ...tools, collaboration platforms, security practices, and support channels...SuggestedWork at officeRemote workFlexible hours3 days per week- ...modernize infrastructure, strengthen security, and enable innovation across... ...and Security Engineer, Group Lead provides technical leadership... ...of Endpoint Detection & Response (EDR), Network Detection &... ...improvement for OT SOC operations Incident Response Act as a technical...SuggestedFull timeFlexible hours
- ...pride in providing customized security solutions for our clients.... ...Uniform and equipment provided Responsibilities Complete an approved 20‑hour... ...the extent of threats or incidents; summon appropriate assistance... ...Security Systems, Inc. is a leading US‑owned security company,...SuggestedPermanent employmentFor contractorsLocal areaImmediate startWorldwideFlexible hours
$114.1k - $268.18k
...world-class training facility, and leading market tools, we help our... ...seeking a Lead Specialist, Cloud Security to join our Managed Services practice.Responsibilities:Manage cloud security posture across... ...managed services, including incident, problem, and service request...H1bLocal area$24 per hour
...work for Justice Cannabis Co.? At Justice, security is a critical part of our operation. We are looking for a Lead Security Guard who understands the importance... ...facility security, surveillance operations, incident response, transportation oversight, and team support while...Hourly payFull timeTemporary workLocal areaShift workNight shiftWeekend work$20.3 per hour
...Lead Security Officer (Concierge) - Residential - Chicago, IL - Rogers Park Titan Security... ...pm must be able to hold over 4 hours. Responsibilities Help supervise operations of an assigned... ...responsibilities and patrols; review incident reports prior to submitting to Site...Full timeContract workMonday to FridayShift workAfternoon shift- ...solutions across technology, operations, security, cloud, and industry-specific needs to... ...scale. THE WORK:As an Oracle WMS Cloud Lead, you will design, configure, and... ...through end to end implementations.Key responsibilities include:Leading requirements gathering...Full timeWork experience placementLive inWork at officeLocal area
- ...delivering deep cloud, AI, and security expertise so clients can... ...the Senior Manager level, you orchestrate program-wide deployment... ...analysis, and rollback triggers Lead two or more mock cutovers -... ...person at Accenture has the responsibility to create and sustain an inclusive...Full timeWork experience placementLive inWork at officeLocal areaImmediate start
- ...Accenture is a global professional services company with leading capabilities in digital, cloud and security. Combining unmatched experience and specialized... ...imperative, every person at Accenture has the responsibility to create and sustain an inclusive environment.Inclusion...Full timeWork experience placementLive inWork at officeLocal area
$103k - $210k
...apply now.We are currently seeking a OCM Lead to join our team in Chicago, Illinois (... ...methodology-driven approach. • You have been responsible for managing $1M+ in revenue• You have 2... ...in enterprise-scale AI, cloud, security, connectivity, data centers and application...Temporary workWork at officeRemote workFlexible hours- ...Microsoft, delivering deep cloud, AI, and security expertise so clients can adopt AI at... ...senior Oracle Financials practitioner who leads the full functional workstream on... ...functional consultants; assign workstream responsibilities, review deliverables, and build team capability...Full timeWork experience placementLive inWork at officeLocal area
$196.5k - $291.5k
..., and shopping simple, personalized, and secure, PayPal empowers consumers and businesses... ...volumes in milliseconds. We're looking for a Lead PM to own the foundation model pillar — a... ...reduced time-to-market for new threat response.Job Description:Essential...Full timeContract workWork at officeLocal areaImmediate startFlexible hours$22 per hour
...GardaWorld Security Services is Now Hiring a Response Security Officer! Ready to suit up as a Special Response/Flex Security Guard What matters... ...access points and verify identities Respond quickly to incidents or potential threats Provide excellent customer...Hourly payFull timePart timeCasual workLocal areaImmediate startFlexible hoursShift work$25 - $50 per hour
...Role Overview TSA is accepting applications for Lead and Supervisory Transportation Security Officers at airports in Summit Argo. These roles are... ...provides training to prepare candidates for leadership responsibilities. Position Details Openings : Summit Argo and...Shift workNight shiftWeekend work$25 - $50 per hour
...Role Overview TSA is accepting applications for Lead and Supervisory Transportation Security Officers at airports in Evanston. These roles are ideal... ...training to prepare candidates for leadership responsibilities. Position Details Openings : Evanston and Nationwide...Shift workNight shiftWeekend work$142.3k - $195.7k
...of our caring communityThe Lead Solutions & AI Enablement Architect... ...engineering, EA Activation, security, data, and operations. You... ...Demonstrated depth in:Agent orchestration (tools/function calling,... ...guardrails (security, compliance, responsible AI)Robust MLOps/LLMOps...Full timeTemporary workFor contractorsWork at officeRemote workWork from homeHome office- ...PM to 6:00 AM. This supervisor role is responsible for leading the team in maintaining a safe,... ...throughout the night while fostering a secure and orderly atmosphere. Strong leadership... ...ensuring issues are resolved professionally. Incident report review - Ensure accurate and...Hourly payDaily paidPermanent employmentShift workNight shift
$185k - $200k
...and technology‑centric strategies. Ascot offers clients leading financial security while delivering bespoke products and world‑class... ...standards. The position is in‑office with a hybrid schedule. Responsibilities Own and evolve the enterprise AI governance framework,...Temporary workWork at officeFlexible hours$160k - $180k
...Security Operations Lead (SOC Modernization & AI Enablement) Overview: A rapidly growing technology... ...detection, investigation, and response. This is a highly cross-functional... ...queue health checks, reporting, and post-incident reviews AI Enablement & Automation...Permanent employment$102.5k - $210.6k
...26. Work you’ll do As a Lead Cloud Security Analyst, you are an advanced... ...business needs. Key Responsibilities Technical Leadership & Advanced... ...subject matter expert in incident response, vulnerability... ...as Code, Automation, and Orchestration.Demonstrated ability to mentor...Full timeFlexible hoursShift work$114.1k - $268.18k
...-class training facility, and leading market tools, we help our people... ...a Lead Specialist, Cloud Security to join our Managed Services practice. Responsibilities: Manage cloud security posture... ...governance managed services, including incident, problem, and service request...H1bLocal area$101.4k - $185.9k
..., apply now.We are currently seeking a Lead Acquisition Analyst to join our team in... ...strategic objectives of the initiative. Job Responsibilities Include: Develop procurement project... ...in enterprise-scale AI, cloud, security, connectivity, data centers and application...Temporary workWork experience placementWork at officeRemote workFlexible hours- ...-start, dispatchable power, our company supports both energy security and renewable growth with complete turbine services, project... ...Location: 6 401 North Eldridge Pkwy, Houston, TX 77041 Position Responsibilities Read and interpret work instructions provided. Use or learn...Permanent employmentWork at officeWork visa
$196.5k - $291.5k
...and shopping simple, personalized, and secure, PayPal empowers consumers and businesses... ...volumes in milliseconds. We're looking for a Lead Product Manager to own the strategy,... ...compliance.Job Description:Essential Responsibilities: Inputs to product strategy with cross-functional...Full timeWork at officeLocal areaImmediate startFlexible hours- ...The Security Supervisor is responsible for supervising the security operations at Justice Grown/Bloc Dispensary facilities, ensuring the safety and... ...access control, and alarm systems, responding promptly to incidents. Work closely with law enforcement, regulatory agencies,...Full timeTemporary workWork at officeFlexible hoursNight shift
$34 - $36 per hour
...Who are we hiring? The MSG Security Supervisor will be accountable... ...and event security officers. Lead and develop front line colleagues... ...company provided programs. Responsible for various administration... ...such as scheduling, invoices, incident reports, daily reports, and documentation...Hourly payWork at officeLocal areaLong distanceFlexible hoursNight shiftWeekend work$83.1k - $141.3k
...sophisticated clients using leading technology and exceptional service... ...& Platform Services is responsible for the strategic direction,... ...leadership and oversight for incident management, root cause analysis... ...ComplianceOversee platform governance, security, data quality, controls, and...Full timeContract workH1bWorldwideFlexible hours- ...world’s most sophisticated clients using leading technology and exceptional service. Role SummaryLead Cyber Security Engineer responsible for designing, implementing, and... ...Act as escalation point for high priority incidents• Influence engineering standards and control...Full timeH1bWorldwideFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Incident Response Orchestration Lead. Be the first to apply!



