Security Incident Response Orchestration Lead
Listed on 2026-07-26
-
Security
Cybersecurity
Job Description
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.
We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.
Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role‑specific responsibilities and business needs.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Job DescriptionThe Security Incident Response Orchestration Lead is the senior technical authority responsible for setting the vision, architecture, and execution strategy for enterprise‑scale security automation. This role leads the design and evolution of orchestration capabilities across Splunk SOAR, Tines, and AI‑enabled platforms, ensuring scalable, resilient, and governed solutions aligned to enterprise security objectives.
As a principal‑level contributor, this role drives cross‑organizational alignment across security operations, product management, engineering, and executive leadership to transform incident response through automation and intelligent decisioning. The role defines long‑term strategy, establishes engineering standards, and ensures measurable business outcomes through effective orchestration.
This position is accountable for advancing agentic AI adoption in security operations, embedding governance, observability, and control mechanisms that enable safe, reliable, and value‑driven automation at scale.
Core Responsibilities- Serve as the enterprise technical authority
for security orchestration across Splunk SOAR and Tines - Define and evolve the long‑term architecture, strategy, and roadmap
for SOAR and automation platforms - Establish enterprise standards, reusable frameworks, and orchestration patterns
to drive consistency and scale - Lead end‑to‑end design authority
for complex, cross‑platform automation initiatives - Partner with Product Management and senior leadership to shape portfolio prioritization and strategic investments
- Drive intake governance model
, ensuring automation demand is evaluated, prioritized, and aligned to measurable outcomes - Define and track enterprise value metrics
(MTTR reduction, analyst efficiency, operational risk reduction, automation coverage) - Influence and guide multiple security domain teams (15+ teams)to adopt standardized automation patterns and best practices
- Provide technical leadership and mentorship
to senior and principal engineers across SOAR platforms - Act as escalation point for high‑risk, high‑complexity orchestration challenges
and systemic platform issues - Lead design and oversight of enterprise integrations
, including but not limited to:- Microsoft Graph / Entra / M365 Defender
- Crowd Strike Falcon
- Tanium
- Blood Hound
- Anvilogic
- ThreatQ
- Service Now (Incidents, Sec Ops, CMDB, IR workflows)
- Drive platform reliability, resilience, and auditability standards
across all automation implementations
- Define enterprise vision for AI‑driven security operations
, including copilots, agents, and MCP‑aligned orchestration - Lead design of AI‑assisted investigation, triage, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).