Security Incident Response Orchestration Lead

Bank of America

Denver (CO)

On-site

USD 180,000 - 260,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Annual discretionary plan
Paid time off
Resources and support
Industry-leading benefits
Paid holidays

Job summary

Bank of America is seeking a Security Incident Response Orchestration Lead to set vision, architecture, and execution strategy for enterprise-scale security automation. You will lead the design and evolution of orchestration across Splunk SOAR, Tines, and AI-enabled platforms to ensure scalable and governed solutions aligned with security objectives.

As the senior technical authority, you will drive long-term roadmaps, establish reusable frameworks, and guide cross-functional teams to deliver

Qualifications

  • 10+ years in Security Operations, Incident Response, Detection Engineering, or Security Automation.
  • 5+ years hands-on experience with Splunk SOAR (Phantom) and Tines in enterprise environments.
  • Proven track record leading large-scale SOAR or automation programs.
  • Deep expertise in incident response lifecycle, SOC operating models, and automation strategy.
  • Experience integrating SOAR platforms with enterprise systems (Microsoft Graph, CrowdStrike, Tanium, ServiceNow).

Responsibilities

  • Define and evolve the long-term architecture, strategy, and roadmap for SOAR and automation platforms.
  • Establish enterprise standards, reusable frameworks, and orchestration patterns to drive consistency and scale.
  • Lead end-to-end design authority for complex, cross-platform automation initiatives.
  • Serve as the enterprise technical authority for security orchestration across Splunk SOAR and Tines.

Skills

Security Operations
Incident Response
Automation Strategy
Orchestration Patterns

Tools

Splunk SOAR (Phantom)
Tines

Job description

Role Overview

The Security Incident Response Orchestration Lead is the senior technical authority responsible for setting the vision, architecture, and execution strategy for enterprise-scale security automation. This role leads the design and evolution of orchestration capabilities across Splunk SOAR, Tines, and AI-enabled platforms, ensuring scalable, resilient, and governed solutions aligned to enterprise security objectives.


What You Will Do

Serve as the enterprise technical authority for security orchestration across Splunk SOAR and Tines, define and evolve the long-term architecture, strategy, and roadmap for SOAR and automation platforms, establish enterprise standards, reusable frameworks, and orchestration patterns to drive consistency and scale, and lead end-to-end design authority for complex, cross-platform automation initiatives.


Why It Might Be a Fit

This role requires a proven track record of leading large-scale SOAR or automation programs, deep expertise in incident response lifecycle, SOC operating models, and automation strategy, and strong experience designing and scaling secure, reliable, and governed automation architectures.


Requirements


  • 10+ years of experience in Security Operations, Incident Response, Detection Engineering, or Security Automation5+ years of deep, hands-on experience with Splunk SOAR (Phantom) in addition to hands-on experience with Tines (required) in enterprise environments

  • Proven track record of leading large-scale SOAR or automation programs

  • Deep expertise in incident response lifecycle, SOC operating models, and automation strategy

  • Strong experience designing and scaling secure, reliable, and governed automation architectures

  • Experience integrating SOAR platforms with enterprise systems (Microsoft Graph, CrowdStrike, Tanium, ServiceNow, etc.)

  • Demonstrated ability to influence senior leadership and drive cross-organizational initiatives

  • Expertise in translating complex, ambiguous problems into clear architectural solutions and execution plans


Benefits


  • Annual discretionary plan

  • Paid time off

  • Resources and support

  • Industry-leading benefits

  • Access to paid time off

  • Paid holidays

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Incident Response Orchestration Lead
Security Incident Response Orchestration Lead

Bank of America • Washington

On-site
USD 170,000 - 250,000
Security Incident Response Lead
Security Incident Response Lead

Jobtailor • Colorado

On-site
USD 150,000 - 190,000
Senior Security Orchestration Lead - SOAR & AI Automation
Senior Security Orchestration Lead - SOAR & AI Automation

Jobtailor • Colorado

On-site
USD 150,000 - 190,000
Senior Security Automation Engineer
Senior Security Automation Engineer

Piper Companies • United States

Remote
USD 130,000 - 145,000
Medical plan
Dental plan
Vision plan
+3
Senior Security Automation, SOAR Engineer
Senior Security Automation, SOAR Engineer

Jobtailor • Colorado

On-site
USD 140,000 - 170,000
Security Incident Response Orchestration Lead
Security Incident Response Orchestration Lead

Bank of America • Chicago (IL)

On-site
USD 150,000 - 191,000
Senior Security Orchestration Architect (SOAR & Automation)
Senior Security Orchestration Architect (SOAR & Automation)

Bank of America • Denver (CO)

On-site
USD 180,000 - 260,000
Annual discretionary plan
Paid time off
Resources and support
+2
SOAR Automation Engineer
SOAR Automation Engineer

Dragonfli Group • Washington

Remote
USD 120,000 - 160,000
Health, dental, and vision insurance
Paid Time Off (PTO) and 11 Federal Holidays
401(k) employer match
Enterprise Security Orchestration Lead (SOAR)
Enterprise Security Orchestration Lead (SOAR)

Bank of America • Chicago (IL)

On-site
USD 150,000 - 191,000
Senior Security Automation & SOAR Engineer
Senior Security Automation & SOAR Engineer

S&P Global, Inc. • New York (NY)

On-site
USD 140,000 - 155,000
Health & Wellness
Flexible Downtime
Continuous Learning
+3