Security Incident Response Orchestration Lead
Bank of America · Denver, CO · 1 wk ago
Information TechnologyFull-time
Core Responsibilities
- Serve as the enterprise technical authority for security orchestration across Splunk SOAR and Tines
- Define and evolve the long-term architecture, strategy, and roadmap for SOAR and automation platforms
- Establish enterprise standards, reusable frameworks, and orchestration patterns to drive consistency and scale
- Lead end-to-end design authority for complex, cross-platform automation initiatives
- Partner with Product Management and senior leadership to shape portfolio prioritization and strategic investments
- Define and track enterprise value metrics (MTTR reduction, analyst efficiency, operational risk reduction, automation coverage)
- Influence and guide multiple security domain teams (15+ teams) to adopt standardized automation patterns and best practices
- Provide technical leadership and mentorship to senior and principal engineers across SOAR platforms
- Act as escalation point for high-risk, high-complexity orchestration challenges and systemic platform issues
- Lead design and oversight of enterprise integrations, including but not limited to: Microsoft Graph / Entra ID / M365 Defender, CrowdStrike Falcon, Tanium, BloodHound, Anvilogic, ThreatQ, ServiceNow (Incidents, SecOps, CMDB, IR workflows)
- Drive platform reliability, resilience, and auditability standards across all automation implementations
- AI-Enabled & Agentic Automation
- Define enterprise vision for AI-driven security operations, including copilots, agents, and MCP-aligned orchestration
- Lead design of AI-assisted investigation, triage, and response workflows integrated with SOAR decisioning
- Establish and enforce enterprise AI governance framework, including: Human-in-the-loop approval models and escalation paths, Deterministic fallback and fail-safe execution patterns, Access controls, observability, logging, and auditability aligned with enterprise risk standards
- Define architectural patterns for AI-integrated SOAR systems, including: Retrie-Augmented Generation (RAG) design and secure knowledge integration, Vector embedding strategies for semantic search and correlation, Scalable data pipelines for incident context, detections, and response history
- Evaluate and approve AI use cases based on operational value, risk, and production readiness
- Partner with governance, risk, and compliance teams to ensure safe, auditable deployment of AI capabilities
Required Qualifications
- 10+ years of experience in Security Operations, Incident Response, Detection Engineering, or Security Automation
- 5+ years of deep, hands-on experience with Splunk SOAR (Phantom) in addition to hands-on experience with Tines (required) in enterprise environments
- Proven track record of leading large-scale SOAR or automation programs
- Deep expertise in incident response lifecycle, SOC operating models, and automation strategy
- Strong experience designing and scaling secure, reliable, and governed automation architectures
- Experience integrating SOAR platforms with enterprise systems (Microsoft Graph, CrowdStrike, Tanium, ServiceNow, etc.)
- Demonstrated ability to influence senior leadership and drive cross-organizational initiatives
- Expertise in translating complex, ambiguous problems into clear architectural solutions and execution plans
Desired Qualifications
- Prior experience operating at principal, staff, or architect level in cybersecurity engineering
- Experience defining or leading enterprise security architecture or SOC transformation initiatives
- Strong proficiency in Python, REST APIs, and modern authentication (OAuth, SAML, etc.)
- Experience with AI-enabled security operations, including copilots, LLM integrations, or agent-based systems
- Familiarity with cloud security architectures across AWS, Azure, and Google Cloud
- Experience working with governance frameworks (MRM, audit, compliance, risk controls) in regulated environments