Security Incident Response Lead

Jobtailor

Colorado

On-site

USD 150,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking an experienced Enterprise Security Orchestration Architect to lead SOAR automation across Splunk SOAR and Tines. You will define the long‑term architecture, standards, and patterns to scale across 15+ teams.

You will partner with product and leadership, govern automation intake, and drive AI governance and integration with MS Graph, CrowdStrike, Tanium, and ServiceNow. This role demands strong leadership and hands‑on architectural expertise.

Qualifications

  • 10+ years of experience in Security Operations, Incident Response, Detection Engineering, or Security Automation.
  • 5+ years of hands-on Splunk SOAR (Phantom) and Tines experience in enterprise environments.
  • Proven track record leading large-scale SOAR or automation programs.
  • Deep expertise in incident response lifecycle, SOC operating models, and automation strategy.
  • Experience integrating SOAR with enterprise systems (Microsoft Graph, CrowdStrike, Tanium, ServiceNow).

Responsibilities

  • Serve as the enterprise technical authority for security orchestration across Splunk SOAR and Tines.
  • Define and evolve the long‑term architecture, strategy, and roadmap for SOAR and automation platforms.
  • Establish enterprise standards, reusable frameworks, and orchestration patterns to drive consistency and scale.
  • Lead end‑to‑end design authority for complex, cross‑platform automation initiatives.
  • Partner with Product Management and senior leadership to shape portfolio prioritization and strategic investments.
  • Drive intake governance model, ensuring automation demand is evaluated, prioritized, and aligned to measurable outcomes.
  • Define and track enterprise value metrics (MTTR reduction, analyst efficiency, operational risk reduction, automation coverage).
  • Influence and guide multiple security domain teams to adopt standardized automation patterns and best practices.
  • Provide technical leadership and mentorship to senior and principal engineers across SOAR platforms.
  • Act as escalation point for high‑risk, high‑complexity orchestration challenges and systemic platform issues.

Skills

Security Operations
Incident Response
Detection Engineering
Automation Strategy
Automation Architecture
Cross-Organizational Leadership
Influencing Senior Leadership
Problem-Solving

Tools

Splunk SOAR
Tines
Microsoft Graph
CrowdStrike Falcon
Tanium
ServiceNow

Job description


  • Serve as the enterprise technical authority for security orchestration across Splunk SOAR and Tines

  • Define and evolve the long‑term architecture, strategy, and roadmap for SOAR and automation platforms

  • Establish enterprise standards, reusable frameworks, and orchestration patterns to drive consistency and scale

  • Lead end‑to‑end design authority for complex, cross‑platform automation initiatives

  • Partner with Product Management and senior leadership to shape portfolio prioritization and strategic investments

  • Drive intake governance model, ensuring automation demand is evaluated, prioritized, and aligned to measurable outcomes

  • Define and track enterprise value metrics (MTTR reduction, analyst efficiency, operational risk reduction, automation coverage)

  • Influence and guide multiple security domain teams (15+ teams) to adopt standardized automation patterns and best practices

  • Provide technical leadership and mentorship to senior and principal engineers across SOAR platforms

  • Act as escalation point for high‑risk, high‑complexity orchestration challenges and systemic platform issues

  • Lead design and oversight of enterprise integrations, including but not limited to: Microsoft Graph / Entra ID / M365 Defender, CrowdStrike Falcon, Tanium, BloodHound, Anvilogic, ThreatQ, ServiceNow (Incidents, SecOps, CMDB, IR workflows)

  • Drive platform reliability, resilience, and auditability standards across all automation implementations

  • Define enterprise vision for AI‑driven security operations, including copilots, agents, and MCP‑aligned orchestration

  • Lead design of AI‑assisted investigation, triage, and response workflows integrated with SOAR decisioning

  • Establish and enforce enterprise AI governance framework, including: Human‑in‑the‑loop approval models and escalation paths, Deterministic fallback and fail‑safe execution patterns, Access controls, observability, logging, and auditability aligned with enterprise risk standards

  • Define architectural patterns for AI‑integrated SOAR systems, including: Retrieval‑Augmented Generation (RAG) design and secure knowledge integration, Vector embedding strategies for semantic search and correlation, Scalable data pipelines for incident context, detections, and response history

  • Evaluate and approve AI use cases based on operational value, risk, and production readiness

  • Partner with governance, risk, and compliance teams to ensure safe, auditable deployment of AI capabilities.


Requirements


  • 10+ years of experience in Security Operations, Incident Response, Detection Engineering, or Security Automation

  • 5+ years of deep, hands on experience with Splunk SOAR (Phantom) in addition to hands on experience with Tines (required) in enterprise environments

  • Proven track record of leading large-scale SOAR or automation programs

  • Deep expertise in incident response lifecycle, SOC operating models, and automation strategy

  • Strong experience designing and scaling secure, reliable, and governed automation architectures

  • Experience integrating SOAR platforms with enterprise systems (Microsoft Graph, CrowdStrike, Tanium, ServiceNow, etc.)

  • Demonstrated ability to influence senior leadership and drive cross-organizational initiatives

  • Expertise in translating complex, ambiguous problems into clear architectural solutions and execution plans.


Core Competencies

Demonstrates extensive expertise in Security Operations and Incident Response, with a strong focus on Splunk SOAR and Tines for automation. Proven ability to lead complex automation initiatives and establish enterprise standards for security orchestration.


Highest-signal resume keywords


  • Splunk SOAR (Phantom) Expertise

  • Tines Experience

  • Incident Response Lifecycle Knowledge

  • Automation Architecture Design

  • Cross-Organizational Initiative Leadership


ATS Optimization Keywords

Hard Skills


  • Security Operations

  • Incident Response

  • Detection Engineering

  • Automation Strategy

  • Automation Architecture

  • Integration with Microsoft Graph

  • Integration with CrowdStrike

  • Integration with Tanium

  • Integration with ServiceNow

  • AI Governance Framework


Soft Skills


  • Influencing Senior Leadership

  • Mentorship

  • Problem-Solving


Industry Keywords


  • Security Orchestration

  • Automation Platforms

  • Enterprise Standards

  • Operational Risk Reduction

  • AI-Driven Security Operations


Tools & Technologies


  • Splunk SOAR

  • Tines

  • Microsoft Graph

  • CrowdStrike Falcon

  • Tanium

  • ServiceNow

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Incident Response Orchestration Lead
Security Incident Response Orchestration Lead

Bank of America • Washington

On-site
USD 170,000 - 250,000
Security Incident Response Orchestration Lead
Security Incident Response Orchestration Lead

Bank of America • Denver (CO)

On-site
USD 180,000 - 260,000
Annual discretionary plan
Paid time off
Resources and support
+2
Senior Automation, Cybersecurity Engineer
Senior Automation, Cybersecurity Engineer

Jobtailor • Plano (TX)

On-site
USD 140,000 - 190,000
Chief Information Security Officer – CISO
Chief Information Security Officer – CISO

Jobtailor • Salt Lake City (UT)

On-site
USD 180,000 - 240,000
Director – Security Remediation Operations
Director – Security Remediation Operations

Jobtailor • Arizona

On-site
USD 180,000 - 280,000
Associate Director, Threat Management Center
Associate Director, Threat Management Center

Jobtailor • Town of Florida (NY)

On-site
USD 150,000 - 190,000
Senior Security Engineer, AI Incident Response
Senior Security Engineer, AI Incident Response

Jobtailor • California (MO)

On-site
USD 180,000 - 230,000
Threat Detection Engineer, Data Engineering
Threat Detection Engineer, Data Engineering

Jobtailor • New York (NY)

On-site
USD 110,000 - 170,000
AI-Driven Security Automation Engineer
AI-Driven Security Automation Engineer

Jobtailor • Greensboro (NC)

On-site
USD 110,000 - 160,000
Principal Security Engineer
Principal Security Engineer

Jobtailor • Town of Texas (WI)

On-site
USD 140,000 - 190,000