Security Incident Response Orchestration Lead
Chicago, Illinois;Washington, District of Columbia; Denver, Colorado
**To proceed with your application, you must be at least 18 years of age.**
Acknowledge (https://ghr.wd1.myworkdayjobs.com/Lateral-US/job/Chicago/Security-Incide...\_26025454)
**Bank of America employees are required to meet all** **posting eligibility requirements** **prior to applying for any new position.**
Acknowledge (https://ghr.wd1.myworkdayjobs.com/Lateral-US/job/Chicago/Security-Incide...\_26025454)
Refer a friend
**To proceed with your application, you must be at least 18 years of age.**
Acknowledge (https://ghr.wd1.myworkdayjobs.com/Lateral-US/job/Chicago/Security-Incide...\_26025454)
**Bank of America employees are required to meet all** **posting eligibility requirements** **prior to applying for any new position.**
Acknowledge (https://ghr.wd1.myworkdayjobs.com/Lateral-US/job/Chicago/Security-Incide...\_26025454)
**Job Description:**
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.
We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.
Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
**Job Description:**
The Security Incident Response Orchestration Lead is the senior technical authority responsible for setting the vision, architecture, and execution strategy for enterprise‑scale security automation. This role leads the design and evolution of orchestration capabilities across Splunk SOAR, Tines, and AI‑enabled platforms, ensuring scalable, resilient, and governed solutions aligned to enterprise security objectives.
As a principal‑level contributor, this role drives cross‑organizational alignment across security operations, product management, engineering, and executive leadership to transform incident response through automation and intelligent decisioning. The role defines long‑term strategy, establishes engineering standards, and ensures measurable business outcomes through effective orchestration.
This position is accountable for advancing agentic AI adoption in security operations, embedding governance, observability, and control mechanisms that enable safe, reliable, and value‑driven automation at scale.
**Core Responsibilities**
+ Serve as the **enterprise technical authority** for security orchestration across Splunk SOAR and Tines
+ Define and evolve the **long‑term architecture, strategy, and roadmap** for SOAR and automation platforms
+ Establish **enterprise standards, reusable frameworks, and orchestration patterns** to drive consistency and scale
+ Lead **end‑to‑end design authority** for complex, cross‑platform automation initiatives
+ Partner with Product Management and senior leadership to **shape portfolio prioritization and strategic investments**
+ Drive **intake governance model** , ensuring automation demand is evaluated, prioritized, and aligned to measurable outcomes
+ Define and track **enterprise value metrics** (MTTR reduction, analyst efficiency, operational risk reduction, automation coverage)
+ Influence and guide **multiple security domain teams (15+ teams)** to adopt standardized automation patterns and best practices
+ Provide **technical leadership and mentorship** to senior and principal engineers across SOAR platforms
+ Act as escalation point for **high‑risk, high‑complexity orchestration challenges** and systemic platform issues
+ Lead design and oversight of **enterprise integrations** , including but not limited to:
+ Microsoft Graph / Entra ID / M365 Defender
+ CrowdStrike Falcon
+ Tanium
+ BloodHound
+ Anvilogic
+ ThreatQ
+ ServiceNow (Incidents, SecOps, CMDB, IR workflows)
+ Drive **platform reliability, resilience, and auditability standards** across all automation implementations
**AI‑Enabled & Agentic Automation**
+ Define enterprise vision for **AI‑driven security operations** , including copilots, agents, and MCP‑aligned orchestration
+ Lead design of **AI‑assisted investigation, triage, and response workflows** integrated with SOAR decisioning
+ Establish and enforce **enterprise AI governance framework** , including:
+ Human‑in‑the‑loop approval models and escalation paths
+ Deterministic fallback and fail‑safe execution patterns
+ Access controls, observability, logging, and auditability aligned with enterprise risk standards
+ Define architectural patterns for **AI‑integrated SOAR systems** , including:
+ Retrieval‑Augmented Generation (RAG) design and secure knowledge integration
+ Vector embedding strategies for semantic search and correlation
+ Scalable data pipelines for incident context, detections, and response history
+ Evaluate and approve **AI use cases** based on operational value, risk, and production readiness
+ Partner with governance, risk, and compliance teams to ensure **safe, auditable deployment of AI capabilities**
**Required Qualifications**
+ 10+ years of experience in Security Operations, Incident Response, Detection Engineering, or Security Automation
+ 5+ years of deep, hands on experience with Splunk SOAR (Phantom) in addition to hands on experience with **Tines (required)** in enterprise environments
+ Proven track record of **leading large‑scale SOAR or automation programs**
+ Deep expertise in **incident response lifecycle, SOC operating models, and automation strategy**
+ Strong experience designing and scaling **secure, reliable, and governed automation architectures**
+ Experience integrating SOAR platforms with enterprise systems (Microsoft Graph, CrowdStrike, Tanium, ServiceNow, etc.)
+ Demonstrated ability to influence **senior leadership and drive cross‑organizational initiatives**
+ Expertise in translating complex, ambiguous problems into **clear architectural solutions and execution plans**
+ BA or BS in Computer Science, Engineering, Information Systems, or a related technical field; advanced Masters degree preferred
**Desired Qualifications**
+ Prior experience operating at **principal, staff, or architect level** in cybersecurity engineering
+ Experience defining or leading **enterprise security architecture or SOC transformation initiatives**
+ Strong proficiency in Python, REST APIs, and modern authentication (OAuth, SAML, etc.)
+ Experience with **AI‑enabled security operations** , including copilots, LLM integrations, or agent‑based systems
+ Hands‑on or architectural experience with **RAG frameworks, vector databases, and AI data platforms**
+ Familiarity with **cloud security architectures** across AWS, Azure, and Google Cloud
+ Experience working with **governance frameworks (MRM, audit, compliance, risk controls)** in regulated environments
**Skills:**
+ Influence
+ Result Orientation
+ Solution Design
+ Stakeholder Management
+ Technical Strategy Development
+ Access and Identity Management
+ Cyber Security
+ Information Systems Management
+ Risk Management
+ Solution Delivery Process
+ Collaboration
+ Critical Thinking
+ DevOps Practices
+ Financial Management
+ Test Engineering
This job will be open and accepting applications for a minimum of seven days from the date it was posted.
**Shift:**
1st shift (United States of America)
**Hours Per Week:**
40
Bank of America and its affiliates consider for employment and hire qualified candidates without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote the concept of equal employment opportunity, in accordance with all applicable federal, state, provincial and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our teammates.
View your "Know your Rights (https://www.eeoc.gov/sites/default/files/2023-06/22-088\_EEOC\_KnowYourRights6.12.pdf) " poster.
View the LA County Fair Chance Ordinance (https://dcba.lacounty.gov/wp-content/uploads/2024/08/FCOE-Official-Notic...) .
Bank of America aims to create a workplace free from the dangers and resulting consequences of illegal and illicit drug use and alcohol abuse. Our Drug-Free Workplace and Alcohol Policy (“Policy”) establishes requirements to prevent the presence or use of illegal or illicit drugs or unauthorized alcohol on Bank of America premises and to provide a safe work environment.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. Should you be offered a role with Bank of America, your hiring manager will provide you with information on the in-office expectations associated with your role. These expectations are subject to change at any time and at the sole discretion of the Company. To the extent you have a disability or sincerely held religious belief for which you believe you need a reasonable accommodation from this requirement, you must seek an accommodation through the Bank’s required accommodation request process before your first day of work.
This communication provides information about certain Bank of America benefits. Receipt of this document does not automatically entitle you to benefits offered by Bank of America. Every effort has been made to ensure the accuracy of this communication. However, if there are discrepancies between this communication and the official plan documents, the plan documents will always govern. Bank of America retains the discretion to interpret the terms or language used in any of its communications according to the provisions contained in the plan documents. Bank of America also reserves the right to amend or terminate any benefit plan in its sole discretion at any time for any reason.
Investment products offered through MLPF&S and insurance and annuity products offered through MLLA:
**Are Not FDIC Insured** **Are Not Bank Guaranteed** **May Lose Value**
**Are Not Deposits** **Are Not Insured by Any Federal Government Agency** **Are not a condition to Any Banking Service or Activity**
Merrill Lynch, Pierce, Fenner & Smith Incorporated (also referred to as “MLPF&S” or “Merrill”) makes available certain investment products sponsored, managed, distributed or provided by companies that are affiliates of Bank of America Corporation (“BofA Corp.”). MLPF&S is a registered broker-dealer, registered investment adviser, **Member SIPC** and a wholly owned subsidiary of BofA Corp. Insurance and annuity products are offered through Merrill Lynch Life Agency Inc., a licensed insurance agency and wholly owned subsidiary of Bank of America Corporation.
Trust, fiduciary and investment management services are provided by Bank of America, N.A., Member FDIC and wholly owned subsidiary of Bank of America Corporation (“BofA Corp.”).
Bank of America Private Bank is a division of Bank of America, N.A.
Banking products are provided by Bank of America, N.A. and affiliated banks, Members FDIC and wholly owned subsidiaries of Bank of America Corporation.
© 2026 Bank of America Corporation. All rights reserved.