Security Incident Response Orchestration Lead
$150k - $190.7kBank of America Financial Center
Job Description:At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!Job Description:The Security Incident Response Orchestration Lead is the senior technical authority responsible for setting the vision, architecture, and execution strategy for enterprise‑scale security automation. This role leads the design and evolution of orchestration capabilities across Splunk SOAR, Tines, and AI‑enabled platforms, ensuring scalable, resilient, and governed solutions aligned to enterprise security objectives.As a principal‑level contributor, this role drives cross‑organizational alignment across security operations, product management, engineering, and executive leadership to transform incident response through automation and intelligent decisioning. The role defines long‑term strategy, establishes engineering standards, and ensures measurable business outcomes through effective orchestration.This position is accountable for advancing agentic AI adoption in security operations, embedding governance, observability, and control mechanisms that enable safe, reliable, and value‑driven automation at scale.Core ResponsibilitiesServe as the enterprise technical authority for security orchestration across Splunk SOAR and TinesDefine and evolve the long‑term architecture, strategy, and roadmap for SOAR and automation platformsEstablish enterprise standards, reusable frameworks, and orchestration patterns to drive consistency and scaleLead end‑to‑end design authority for complex, cross‑platform automation initiativesPartner with Product Management and senior leadership to shape portfolio prioritization and strategic investmentsDrive intake governance model, ensuring automation demand is evaluated, prioritized, and aligned to measurable outcomesDefine and track enterprise value metrics (MTTR reduction, analyst efficiency, operational risk reduction, automation coverage)Influence and guide multiple security domain teams (15+ teams) to adopt standardized automation patterns and best practicesProvide technical leadership and mentorship to senior and principal engineers across SOAR platformsAct as escalation point for high‑risk, high‑complexity orchestration challenges and systemic platform issuesLead design and oversight of enterprise integrations, including but not limited to:Microsoft Graph / Entra ID / M365 DefenderCrowdStrike FalconTaniumBloodHoundAnvilogicThreatQServiceNow (Incidents, SecOps, CMDB, IR workflows)Drive platform reliability, resilience, and auditability standards across all automation implementationsAI‑Enabled & Agentic AutomationDefine enterprise vision for AI‑driven security operations, including copilots, agents, and MCP‑aligned orchestrationLead design of AI‑assisted investigation, triage, and response workflows integrated with SOAR decisioningEstablish and enforce enterprise AI governance framework, including:Human‑in‑the‑loop approval models and escalation pathsDeterministic fallback and fail‑safe execution patternsAccess controls, observability, logging, and auditability aligned with enterprise risk standardsDefine architectural patterns for AI‑integrated SOAR systems, including:Retrieval‑Augmented Generation (RAG) design and secure knowledge integrationVector embedding strategies for semantic search and correlationScalable data pipelines for incident context, detections, and response historyEvaluate and approve AI use cases based on operational value, risk, and production readinessPartner with governance, risk, and compliance teams to ensure safe, auditable deployment of AI capabilitiesRequired Qualifications10+ years of experience in Security Operations, Incident Response, Detection Engineering, or Security Automation5+ years of deep, hands on experience with Splunk SOAR (Phantom) in addition to hands on experience with Tines (required) in enterprise environmentsProven track record of leading large‑scale SOAR or automation programsDeep expertise in incident response lifecycle, SOC operating models, and automation strategyStrong experience designing and scaling secure, reliable, and governed automation architecturesExperience integrating SOAR platforms with enterprise systems (Microsoft Graph, CrowdStrike, Tanium, ServiceNow, etc.)Demonstrated ability to influence senior leadership and drive cross‑organizational initiativesExpertise in translating complex, ambiguous problems into clear architectural solutions and execution plansDesired QualificationsPrior experience operating at principal, staff, or architect level in cybersecurity engineeringExperience defining or leading enterprise security architecture or SOC transformation initiativesStrong proficiency in Python, REST APIs, and modern authentication (OAuth, SAML, etc.)Experience with AI‑enabled security operations, including copilots, LLM integrations, or agent‑based systemsHands‑on or architectural experience with RAG frameworks, vector databases, and AI data platformsFamiliarity with cloud security architectures across AWS, Azure, and Google CloudExperience working with governance frameworks (MRM, audit, compliance, risk controls) in regulated environmentsSkills:InfluenceResult OrientationSolution DesignStakeholder ManagementTechnical Strategy DevelopmentAccess and Identity ManagementCyber SecurityInformation Systems ManagementRisk ManagementSolution Delivery ProcessCollaborationCritical ThinkingDevOps PracticesFinancial ManagementTest EngineeringThis job will be open and accepting applications for a minimum of seven days from the date it was posted.Shift:1st shift (United States of America)Hours Per Week: 40Pay Transparency detailsUS - CO - Denver - 1144 15th St - Denver Gis (CO9926), US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540)Pay and benefits informationPay range$150,000.00 - $190,700.00 annualized salary, offers to be determined based on experience, education and skill set.Discretionary incentive eligibleThis role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.BenefitsThis role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.SummaryLocation: Chicago; Washington; DenverType: Full time
- Illinois Attorney General (IL) seeks a Senior Cybersecurity Operations Analyst to lead incident response efforts, coordinate containment actions, and guide improvements to security controls and processes. The role requires analyzing events from multiple tools to identify...Suggested
- Justice Cannabis Co. is seeking a Lead Security Guard to oversee facility security, surveillance operations, and incident response across all shifts. The role requires leadership, vigilance, and a commitment to safety for our team, customers, and premises. You will work...SuggestedLocal areaAll shifts
- ...Avanade's Security Practice seeks a Security Operations Manager to deliver security monitoring and incident response using Microsoft Sentinel, helping clients detect, investigate, and... ...Sentinel-based security solutions while leading delivery teams and collaborating with...Suggested
- RB Global Inc. is seeking a Lead, Cybersecurity Operations to drive the growth of our global CSOC capabilities... ...strategic vision, overseeing threat detection, incident response, and continuous improvement of security operations across the organization. The Lead will serve...Suggested
- Bank of America is seeking a Security Incident Response Orchestration Lead in Chicago to set the vision and execute enterprise-grade security automation across SOAR platforms such as Splunk SOAR and Tines. You will drive cross‑functional alignment with security operations...Suggested
- Salesforce is seeking a Senior Analyst for its Critical Customer Response team to manage communications during critical incidents. You will translate complex issues into clear, timely updates for customers, executives, and internal teams, driving action and accountability...
- ViziRecruiter,LLC. is seeking a Major Incident Management (MIM) Analyst responsible for leading incident responses across teams. This role ensures effective communication and management of major incidents. Candidates must have a bachelor's degree and 3+ years of relevant...Flexible hours
- EY in Chicago seeks a Junior Incident Coordinator for the Cyber & Investigative Services team to coordinate security incident response for cyber events. You’ll apply incident response plans, work with cross-functional teams, and maintain playbooks to ensure rapid, controlled...
- A leading staffing services company in the United States is seeking an Incident Response Manager with over 5 years of experience in IT and strong leadership skills. The ideal candidate should be familiar with security technologies, incident management, and legal operations...Night shift
$98k - $117k
...owns the Silvertip silver-zinc-lead development project in... ...an IT Service Delivery Lead responsible for coordinating and delivering... ...Management best practices, support incident, request, and change... ...tools, collaboration platforms, security practices, and support channels...Work at officeRemote workFlexible hours3 days per week- ...modernize infrastructure, strengthen security, and enable innovation across... ...and Security Engineer, Group Lead provides technical leadership... ...of Endpoint Detection & Response (EDR), Network Detection &... ...improvement for OT SOC operations Incident Response Act as a technical...Full timeFlexible hours
- ...pride in providing customized security solutions for our clients.... ...Uniform and equipment provided Responsibilities Complete an approved 20‑hour... ...the extent of threats or incidents; summon appropriate assistance... ...Security Systems, Inc. is a leading US‑owned security company,...Permanent employmentFor contractorsLocal areaImmediate startWorldwideFlexible hours
$91.1k - $193.6k
...everyone in EY Information Security has a critical role to play.... ...opportunity The CTF Shift Lead at EY plays a critical role... ...triage, combined with their responsibility for setting performance expectations... ...to information security incidents, develop, maintain, and...Full timeWork experience placementSummer holidayLocal areaFlexible hoursShift work$114.1k - $268.18k
...world-class training facility, and leading market tools, we help our... ...seeking a Lead Specialist, Cloud Security to join our Managed Services practice.Responsibilities:Manage cloud security posture across... ...managed services, including incident, problem, and service request...H1bLocal area$160k - $180k
...Security Operations Lead (SOC Modernization & AI Enablement) Overview: A rapidly growing technology... ...detection, investigation, and response. This is a highly cross-functional... ...queue health checks, reporting, and post-incident reviews AI Enablement &...Full time- Tempus AI in Illinois is seeking a Process Specialist - Major Incidents to join the IT team. You will lead end-to-end incident responses for critical events, drive rapid restoration, and coordinate cross-functional actions to minimize business disruption. You’ll collab...
$100k - $120k
...Management experience with a minimum of 3 years in a dedicated Major Incident Management or Incident Commander role in a large enterprise... ...present actionable insights to senior leadership. Roles & Responsibilities Major Incident Command & Coordination Serve as the single...- Justice Cannabis is seeking a Lead Security Guard in Forest Park, IL. The role emphasizes leadership, accountability, and maintaining... ...and operations. You will oversee security operations, incident response, transportation oversight, and team support while working closely...All shiftsNight shift
- ViziRecruiter, LLC. is hiring a Major Incident Management Analyst in Chicago, IL. This position focuses on leading responses to major incidents and ensuring effective communication among IT teams. A flexible/hybrid work schedule includes 3 in-person and 2 remote days....Remote workFlexible hours
- Canopius Group is seeking an Incident Manager for its 24/7 CIMT to triage and lead cyber incident responses across the globe. You will coordinate experts, manage containment to restoration, and communicate clearly to policyholders under pressure. You’ll work with Claims...
- DLA Piper is seeking a Senior Information Security Analyst to identify, investigate, and address threats across the enterprise. The role emphasizes threat detection, incident response, vulnerability management, and leadership of a security operations team. You will mentor...
- We Are:Accenture Security is one of the fastest growing areas of our... ...Investigation and Forensic Response (CIFR) practice is at the heart... ...the most consequential cyber incidents. Within CIFR, our Cyber... ...growing the practice.The Work:Lead enterprise recovery engagements...Full timeLive inWork at officeLocal areaShift work
- ...work for Justice Cannabis Co.? At Justice, security is a critical part of our operation. We are looking for a Lead Security Guard who understands the importance... ...facility security, surveillance operations, incident response, transportation oversight, and team support while...Full timeTemporary workLocal areaShift workNight shiftWeekend work
$170k - $200k
...in navigating technology and security challenges, Foxhole delivers... .../Network Administrator Lead for a large-scale enterprise... ...critical application systems. Responsibilities Responsible for systems/network... ....). Maintain and create the Incident Response Plan and review the...For contractorsWork at officeFlexible hours- Justice Cannabis Co. is seeking a Lead Security Guard to oversee facility security, surveillance, incident response, and transportation oversight while coordinating with leadership and operations teams. The role requires leadership, decisive thinking, and the ability to...Night shiftWeekend work
- ...solutions across technology, operations, security, cloud, and industry-specific needs to... ...scale. THE WORK:As an Oracle WMS Cloud Lead, you will design, configure, and... ...through end to end implementations.Key responsibilities include:Leading requirements gathering...Full timeWork experience placementLive inWork at officeLocal area
- ...Accenture is a global professional services company with leading capabilities in digital, cloud and security. Combining unmatched experience and specialized... ...engagement, the Epic Payer Platform Lead will be responsible for overseeing the collaboration of multiple team with...Full timeWork experience placementLive inWork at officeLocal area
- ...Microsoft, delivering deep cloud, AI, and security expertise so clients can adopt AI at... ...senior Oracle Financials practitioner who leads the full functional workstream on... ...functional consultants; assign workstream responsibilities, review deliverables, and build team capability...Full timeWork experience placementLive inWork at officeLocal area
- ...Accenture is a global professional services company with leading capabilities in digital, cloud and security. Combining unmatched experience and specialized... ...imperative, every person at Accenture has the responsibility to create and sustain an inclusive environment.Inclusion...Full timeWork experience placementLive inWork at officeLocal area
- ...automation, and intelligent insights. The RolePresidio has an exciting opportunity for a Security Practice Lead to join our Cybersecurity National Practice. This individual’s primary responsibility is to act as subject matter expert for Presidio’s Cybersecurity Solutions,...Full timeFor contractorsLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Incident Response Orchestration Lead. Be the first to apply!


