Security Incident Response Orchestration Lead

Koitecc Solutions

Denver, Northern (CO, KY)

Hybrid

USD 180,000 - 240,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Bank of America is seeking a Security Incident Response Orchestration Lead to set vision and architecture for enterprise‑scale security automation across SOAR platforms. You will drive cross‑functional alignment and govern AI‑enabled security operations at scale.

As a principal contributor, you will shape long‑term strategy, establish engineering standards, and ensure measurable outcomes through orchestration, governance, and cross‑team collaboration.

Qualifications

  • 10+ years in Security Operations, Incident Response, Detection Engineering, or Security Automation.
  • 5+ years with Splunk SOAR (Phantom) and hands-on with Tines in enterprise environments.
  • Led large-scale SOAR or automation programs with measurable outcomes.
  • Deep expertise in incident response lifecycle, SOC models, and automation strategy.
  • Experience designing scalable, governed automation architectures.

Responsibilities

  • Serve as enterprise technical authority for security orchestration across SOAR platforms.
  • Define long-term architecture, strategy, and roadmap for SOAR and automation.
  • Establish enterprise standards, reusable frameworks, and orchestration patterns.
  • Lead end-to-end design authority for cross-platform automation initiatives.
  • Shape portfolio prioritization and strategic investments with senior leadership.
  • Drive intake governance to ensure automation aligns with measurable outcomes.
  • Define and track enterprise value metrics (MTTR, analyst efficiency, risk reduction).
  • Influence 15+ security teams to adopt standardized automation patterns.
  • Provide technical leadership to senior/principal engineers across SOAR platforms.
  • Escalation point for high-risk orchestration challenges and platform issues.
  • Lead enterprise integrations (Microsoft Graph, Entra ID, M365 Defender, CrowdStrike, Tanium, ServiceNow).
  • Drive platform reliability, resilience, and auditability across automations.

Skills

Influence
Result Orientation
Solution Design
Stakeholder Management
Technical Strategy Development
Access and Identity Management
Cyber Security
Information Systems Management
Risk Management
Solution Delivery Process
Collaboration
Critical Thinking
DevOps Practices
Financial Management
Test Engineering

Education

BA/BS in CS/Engineering

Tools

Splunk SOAR (Phantom)
Tines
Microsoft Graph
Entra ID / M365 Defender
CrowdStrike Falcon
Tanium
ServiceNow
AI governance frameworks

Job description

Job Description:

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.

Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates' physical, emotional, and financial wellness through affordable, competitive and flexible benefits.

We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.

Bank of America is committed to an in‑office culture that supports collaboration, engagement, and career development. Our approach includes clear in‑office expectations, while providing an appropriate level of flexibility based on role‑specific responsibilities and business needs.

At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!

Job Description:

The Security Incident Response Orchestration Lead is the senior technical authority responsible for setting the vision, architecture, and execution strategy for enterprise‑scale security automation. This role leads the design and evolution of orchestration capabilities across Splunk SOAR, Tines, and AI‑enabled platforms, ensuring scalable, resilient, and governed solutions aligned to enterprise security objectives.

As a principal‑level contributor, this role drives cross‑organizational alignment across security operations, product management, engineering, and executive leadership to transform incident response through automation and intelligent decisioning. The role defines long‑term strategy, establishes engineering standards, and ensures measurable business outcomes through effective orchestration.

This position is accountable for advancing agentic AI adoption in security operations, embedding governance, observability, and control mechanisms that enable safe, reliable, and value‑driven automation at scale.

Core Responsibilities
  • Serve as the enterprise technical authority for security orchestration across Splunk SOAR and Tines
  • Define and evolve the long‑term architecture, strategy, and roadmap for SOAR and automation platforms
  • Establish enterprise standards, reusable frameworks, and orchestration patterns to drive consistency and scale
  • Lead end‑to‑end design authority for complex, cross‑platform automation initiatives
  • Partner with Product Management and senior leadership to shape portfolio prioritization and strategic investments
  • Drive intake governance model, ensuring automation demand is evaluated, prioritized, and aligned to measurable outcomes
  • Define and track enterprise value metrics (MTTR reduction, analyst efficiency, operational risk reduction, automation coverage)
  • Influence and guide multiple security domain teams (15+ teams) to adopt standardized automation patterns and best practices
  • Provide technical leadership and mentorship to senior and principal engineers across SOAR platforms
  • Act as escalation point for high‑risk, high‑complexity orchestration challenges and systemic platform issues
  • Lead design and oversight of enterprise integrations, including but not limited to:
    • Microsoft Graph / Entra ID / M365 Defender
    • CrowdStrike Falcon
    • Tanium
    • BloodHound
    • Anvilogic
    • ThreatQ
    • ServiceNow (Incidents, SecOps, CMDB, IR workflows)
  • Drive platform reliability, resilience, and auditability standards across all automation implementations
AI‑Enabled & Agentic Automation
  • Define enterprise vision for AI‑driven security operations, including copilots, agents, and MCP‑aligned orchestration
  • Lead design of AI‑assisted investigation, triage, and response workflows integrated with SOAR decisioning
  • Establish and enforce enterprise AI governance framework, including:
    • Human‑in‑the‑loop approval models and escalation paths
    • Deterministic fallback and fail‑safe execution patterns
    • Access controls, observability, logging, and auditability aligned with enterprise risk standards
  • Define architectural patterns for AI‑integrated SOAR systems, including:
    • Retrieval‑Augmented Generation (RAG) design and secure knowledge integration
    • Vector embedding strategies for semantic search and correlation
    • Scalable data pipelines for incident context, detections, and response history
  • Evaluate and approve AI use cases based on operational value, risk, and production readiness
  • Partner with governance, risk, and compliance teams to ensure safe, auditable deployment of AI capabilities
Required Qualifications
  • 10+ years of experience in Security Operations, Incident Response, Detection Engineering, or Security Automation
  • 5+ years of deep, hands on experience with Splunk SOAR (Phantom) in addition to hands on experience with Tines (required) in enterprise environments
  • Proven track record of leading large‑scale SOAR or automation programs
  • Deep expertise in incident response lifecycle, SOC operating models, and automation strategy
  • Strong experience designing and scaling secure, reliable, and governed automation architectures
  • Experience integrating SOAR platforms with enterprise systems (Microsoft Graph, CrowdStrike, Tanium, ServiceNow, etc.)
  • Demonstrated ability to influence senior leadership and drive cross‑organizational initiatives
  • Expertise in translating complex, ambiguous problems into clear architectural solutions and execution plans
  • BA or BS in Computer Science, Engineering, Information Systems, or a related technical field; advanced Masters degree preferred
Desired Qualifications
  • Prior experience operating at principal, staff, or architect level in cybersecurity engineering
  • Experience defining or leading enterprise security architecture or SOC transformation initiatives
  • Strong proficiency in Python, REST APIs, and modern authentication (OAuth, SAML, etc.)
  • Experience with AI‑enabled security operations, including copilots, LLM integrations, or agent‑based systems
  • Hands‑on or architectural experience with RAG frameworks, vector databases, and AI data platforms
  • Familiarity with cloud security architectures across AWS, Azure, and Google Cloud
  • Experience working with governance frameworks (MRM, audit, compliance, risk controls) in regulated environments
Skills:
  • Influence
  • Result Orientation
  • Solution Design
  • Stakeholder Management
  • Technical Strategy Development
  • Access and Identity Management
  • Cyber Security
  • Information Systems Management
  • Risk Management
  • Solution Delivery Process
  • Collaboration
  • Critical Thinking
  • DevOps Practices
  • Financial Management
  • Test Engineering

This job will be open and accepting applications for a minimum of seven days from the date it was posted.

Shift:

1st shift (United States of America)

Hours
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Incident Response Orchestration Lead
Security Incident Response Orchestration Lead

Bank of America • Chicago (IL)

On-site
USD 150,000 - 191,000
Security Incident Response Orchestration Lead
Security Incident Response Orchestration Lead

Bank of America • Denver (CO)

On-site
USD 180,000 - 260,000
Annual discretionary plan
Paid time off
Resources and support
+2
Senior Security Automation Engineer
Senior Security Automation Engineer

Piper Companies • United States

Remote
USD 130,000 - 145,000
Medical plan
Dental plan
Vision plan
+3
SOAR Automation Engineer
SOAR Automation Engineer

Dragonfli Group • Washington

Remote
USD 120,000 - 160,000
Health, dental, and vision insurance
Paid Time Off (PTO) and 11 Federal Holidays
401(k) employer match
Senior Security Automation & SOAR Engineer
Senior Security Automation & SOAR Engineer

Relha LLC • New York (NY), Northern (KY)

Hybrid
USD 140,000 - 155,000
Engineer - Security Operations and Incident Response
Engineer - Security Operations and Incident Response

Jobgether • United States

Hybrid
USD 125,000 - 190,000
Remote or hybrid work
Sr. IT Security Engineer (Hybrid)
Sr. IT Security Engineer (Hybrid)

Belk • Town of Charlotte (NY)

Hybrid
CAD 207,000 - 276,000
Sr. Automation & Cybersecurity Engineer
Sr. Automation & Cybersecurity Engineer

Toyota Tsusho Systems • Plano (TX)

On-site
USD 130,000 - 170,000
Senior Incident Responder, Global CSIRT
Senior Incident Responder, Global CSIRT

Jobtailor • United States

On-site
USD 120,000 - 180,000
SOAR and AI Engineer - Managed Security
SOAR and AI Engineer - Managed Security

AHEAD • Chicago (IL)

On-site
USD 120,000 - 160,000
Medical Insurance
Dental Insurance
Vision Insurance
+3