This role leads the design and evolution of orchestration capabilities across Splunk SOAR, Tines, and AI-enabled platforms, ensuring scalable, resilient, and governed solutions aligned to enterprise ...
This role leads the design and evolution of orchestration capabilities across Splunk SOAR, Tines, and AI-enabled platforms, ensuring scalable, resilient, and governed solutions aligned to enterprise ...
This role leads the design and evolution of orchestration capabilities across Splunk SOAR, Tines, and AIenabled platforms, ensuring scalable, resilient, and governed solutions aligned to enterprise ...
This role leads the design and evolution of orchestration capabilities across Splunk SOAR, Tines, and AIenabled platforms, ensuring scalable, resilient, and governed solutions aligned to enterprise ...
Manager, Cyber Defense
Chicago, IL · On-site
$132.50 - $218.30/hr
Experience with SOAR, Splunk, Symantec/Netskope DLP, CrowdStrike and ability to create/tune alerts and rules independently. * Strong oral and written communication, analytical judgment and ...
Manager, Cyber Defense
Chicago, IL · On-site
$132.50 - $218.30/hr
Experience with SOAR, Splunk, Symantec/Netskope DLP, CrowdStrike and ability to create/tune alerts and rules independently. * Strong oral and written communication, analytical judgment and ...
Threat Analyst
$86K - $111K/yr
Experience with SOAR platforms (e.g., Splunk SOAR, Microsoft Sentinel automation, Swimlane) and building playbooks for enrichment and response. * Strong analytical and investigative skills; knowledge ...
Threat Analyst
$86K - $111K/yr
Experience with SOAR platforms (e.g., Splunk SOAR, Microsoft Sentinel automation, Swimlane) and building playbooks for enrichment and response. * Strong analytical and investigative skills; knowledge ...
Threat Analyst
Chicago, IL · On-site
$86K - $111K/yr
Experience with SOAR platforms (e.g., Splunk SOAR, Microsoft Sentinel automation, Swimlane) and building playbooks for enrichment and response. * Strong analytical and investigative skills; knowledge ...
Threat Analyst
Chicago, IL · On-site
$86K - $111K/yr
Experience with SOAR platforms (e.g., Splunk SOAR, Microsoft Sentinel automation, Swimlane) and building playbooks for enrichment and response. * Strong analytical and investigative skills; knowledge ...
SOAR products such as Splunk SOAR, Cortex XSOAR, FortiSOAR, etc. SOAR playbook development experience is a plus. * Endpoint detection and response tools, e.g. CrowdStrike, SentinelOne, Microsoft ...
SOAR products such as Splunk SOAR, Cortex XSOAR, FortiSOAR, etc. SOAR playbook development experience is a plus. * Endpoint detection and response tools, e.g. CrowdStrike, SentinelOne, Microsoft ...
SOAR products such as Splunk SOAR, Cortex XSOAR, FortiSOAR, etc. SOAR playbook development experience is a plus. * Endpoint detection and response tools, e.g. CrowdStrike, SentinelOne, Microsoft ...
SOAR products such as Splunk SOAR, Cortex XSOAR, FortiSOAR, etc. SOAR playbook development experience is a plus. * Endpoint detection and response tools, e.g. CrowdStrike, SentinelOne, Microsoft ...
SOAR products such as Splunk SOAR, Cortex XSOAR, FortiSOAR, etc. SOAR playbook development experience is a plus. * Endpoint detection and response tools, e.g. CrowdStrike, SentinelOne, Microsoft ...
SOAR products such as Splunk SOAR, Cortex XSOAR, FortiSOAR, etc. SOAR playbook development experience is a plus. * Endpoint detection and response tools, e.g. CrowdStrike, SentinelOne, Microsoft ...
SOAR products such as Splunk SOAR, Cortex XSOAR, FortiSOAR, etc. SOAR playbook development experience is a plus. * Endpoint detection and response tools, e.g. CrowdStrike, SentinelOne, Microsoft ...
SOAR products such as Splunk SOAR, Cortex XSOAR, FortiSOAR, etc. SOAR playbook development experience is a plus. * Endpoint detection and response tools, e.g. CrowdStrike, SentinelOne, Microsoft ...
SOAR products such as Splunk SOAR, Cortex XSOAR, FortiSOAR, etc. SOAR playbook development experience is a plus. * Endpoint detection and response tools, e.g. CrowdStrike, SentinelOne, Microsoft ...
SOAR products such as Splunk SOAR, Cortex XSOAR, FortiSOAR, etc. SOAR playbook development experience is a plus. * Endpoint detection and response tools, e.g. CrowdStrike, SentinelOne, Microsoft ...
Manager, Cyber Defense
Chicago, IL · On-site
$114K - $154K/yr
Experience in SOAR, Splunk, Symantec/Netskope DLP, CrowdStrike. Ability to create/tune alerts/rules independently. * Effective and excellent oral and written communication, analytical, judgment and ...
Manager, Cyber Defense
Chicago, IL · On-site
$114K - $154K/yr
Experience in SOAR, Splunk, Symantec/Netskope DLP, CrowdStrike. Ability to create/tune alerts/rules independently. * Effective and excellent oral and written communication, analytical, judgment and ...
Hands-on experience with Cortex XSOAR or similar SOAR platforms (e.g., Splunk SOAR, Tines). * Prior exposure to or foundational knowledge of AI frameworks, RAG implementations, or Agent-to-Agent ...
Hands-on experience with Cortex XSOAR or similar SOAR platforms (e.g., Splunk SOAR, Tines). * Prior exposure to or foundational knowledge of AI frameworks, RAG implementations, or Agent-to-Agent ...
AI & Automation Engineer
North Chicago, IL · On-site
$84K/yr
Hands-on experience with Cortex XSOAR or similar SOAR platforms (e.g., Splunk SOAR, Tines). * Prior exposure to or foundational knowledge of AI frameworks, RAG implementations, or Agent-to-Agent ...
AI & Automation Engineer
North Chicago, IL · On-site
$84K/yr
Hands-on experience with Cortex XSOAR or similar SOAR platforms (e.g., Splunk SOAR, Tines). * Prior exposure to or foundational knowledge of AI frameworks, RAG implementations, or Agent-to-Agent ...
Hands-on experience with Cortex XSOAR or similar SOAR platforms (e.g., Splunk SOAR, Tines). * Prior exposure to or foundational knowledge of AI frameworks, RAG implementations, or Agent-to-Agent ...
Quick apply
Hands-on experience with Cortex XSOAR or similar SOAR platforms (e.g., Splunk SOAR, Tines). * Prior exposure to or foundational knowledge of AI frameworks, RAG implementations, or Agent-to-Agent ...
Senior Cyber Security Engineer I
Deerfield, IL · On-site
$98K - $157K/yr
Develop, maintain, and optimize Splunk SOAR playbooks to automate alert triage, enrichment, containment, and case management workflows. * Hands-on incident response experience, including forensic ...
Senior Cyber Security Engineer I
Deerfield, IL · On-site
$98K - $157K/yr
Develop, maintain, and optimize Splunk SOAR playbooks to automate alert triage, enrichment, containment, and case management workflows. * Hands-on incident response experience, including forensic ...
Translating SOC processes into SOAR automation playbooks to reduce alert fatigue and scale alert ... Splunk, Cortex XSOAR, and AI agentic frameworks, including Model Context Protocol (MCP) or Agent ...
Translating SOC processes into SOAR automation playbooks to reduce alert fatigue and scale alert ... Splunk, Cortex XSOAR, and AI agentic frameworks, including Model Context Protocol (MCP) or Agent ...
Sr Lead, Cyber Sec Eng
Chicago, IL · On-site
Experience integrating security platforms with Microsoft Sentinel, ServiceNow, Splunk, or comparable SIEM/SOAR technologies. * Familiarity with Java or similar development languages for SDK ...
Sr Lead, Cyber Sec Eng
Chicago, IL · On-site
Experience integrating security platforms with Microsoft Sentinel, ServiceNow, Splunk, or comparable SIEM/SOAR technologies. * Familiarity with Java or similar development languages for SDK ...
Experience with SIEM or SOAR tools such as Splunk, Cortex XSOAR, VirusTotal, Mandiant, or Google Threat Intelligence The wage range for this role takes into account the wide range of factors that are ...
Experience with SIEM or SOAR tools such as Splunk, Cortex XSOAR, VirusTotal, Mandiant, or Google Threat Intelligence The wage range for this role takes into account the wide range of factors that are ...
Experience integrating security platforms with Microsoft Sentinel, ServiceNow, Splunk, or comparable SIEM/SOAR technologies. * Familiarity with Java or similar development languages for SDK ...
Experience integrating security platforms with Microsoft Sentinel, ServiceNow, Splunk, or comparable SIEM/SOAR technologies. * Familiarity with Java or similar development languages for SDK ...
Sr Lead, Cyber Sec Eng
Chicago, IL · On-site
Experience integrating security platforms with Microsoft Sentinel, ServiceNow, Splunk, or comparable SIEM/SOAR technologies. * Familiarity with Java or similar development languages for SDK ...
Sr Lead, Cyber Sec Eng
Chicago, IL · On-site
Experience integrating security platforms with Microsoft Sentinel, ServiceNow, Splunk, or comparable SIEM/SOAR technologies. * Familiarity with Java or similar development languages for SDK ...
Splunk Soar information
See Chicago, IL salary details
$42.10 - $45.45
5% of jobs
$45.45 - $48.81
2% of jobs
$48.81 - $52.16
7% of jobs
$54.74 is the 25th percentile. Wages below this are outliers.
$52.16 - $55.51
14% of jobs
$55.51 - $58.87
8% of jobs
The median wage is $62.22 / hr.
$58.87 - $62.22
14% of jobs
$62.22 - $65.58
14% of jobs
$67.88 is the 75th percentile. Wages above this are outliers.
$65.58 - $68.93
17% of jobs
$68.93 - $72.29
17% of jobs
$72.29 - $75.64
2% of jobs
$75.64 - $78.99
1% of jobs
$42
$61
$78
How much do splunk soar jobs pay per hour?
What is the difference between Splunk Soar vs Splunk Security Analyst?
| Aspect | Splunk Soar | Splunk Security Analyst |
|---|---|---|
| Certifications | Splunk Certified SOAR User, Security certifications | CompTIA Security+, CISSP, Splunk certifications |
| Work Environment | Security operations centers, incident response teams | Security teams, SOCs, incident analysis |
| Primary Focus | Automating security workflows, incident response automation | Monitoring security alerts, analyzing threats |
Splunk Soar specializes in automating security incident response and streamlining workflows within security operations centers. In contrast, Splunk Security Analysts focus on monitoring security alerts, analyzing threats, and supporting incident investigations. While both roles require security knowledge and Splunk certifications, Splunk Soar emphasizes automation skills, whereas Security Analysts focus on threat analysis and monitoring.
What are popular job titles related to Splunk Soar jobs in Chicago, IL?
For Splunk Soar jobs in Chicago, IL, the most frequently searched job titles are:
What job categories do people searching Splunk Soar jobs in Chicago, IL look for?
The top searched job categories for Splunk Soar jobs in Chicago, IL are:
What cities near Chicago, IL are hiring for Splunk Soar jobs?
Cities near Chicago, IL with the most Splunk Soar job openings:

Security Incident Response Orchestration Lead
Chicago, IL • On-site
8.2
Based on 531 frontline employees who took The Breakroom Quiz
52nd of 172 rated banks
People enjoy working here
Good employer
Recommended by students
Recommended by parents
Respectful managers
Full-time
PTO
Re-posted 4 days ago
Job description
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates' physical, emotional, and financial wellness through affordable, competitive and flexible benefits.
We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.
Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Job Description:
The Security Incident Response Orchestration Lead is the senior technical authority responsible for setting the vision, architecture, and execution strategy for enterprise-scale security automation. This role leads the design and evolution of orchestration capabilities across Splunk SOAR, Tines, and AI-enabled platforms, ensuring scalable, resilient, and governed solutions aligned to enterprise security objectives.
As a principal-level contributor, this role drives cross-organizational alignment across security operations, product management, engineering, and executive leadership to transform incident response through automation and intelligent decisioning. The role defines long-term strategy, establishes engineering standards, and ensures measurable business outcomes through effective orchestration.
This position is accountable for advancing agentic AI adoption in security operations, embedding governance, observability, and control mechanisms that enable safe, reliable, and value-driven automation at scale.
Core Responsibilities
- Serve as the enterprise technical authority for security orchestration across Splunk SOAR and Tines
- Define and evolve the long-term architecture, strategy, and roadmap for SOAR and automation platforms
- Establish enterprise standards, reusable frameworks, and orchestration patterns to drive consistency and scale
- Lead end-to-end design authority for complex, cross-platform automation initiatives
- Partner with Product Management and senior leadership to shape portfolio prioritization and strategic investments
- Drive intake governance model, ensuring automation demand is evaluated, prioritized, and aligned to measurable outcomes
- Define and track enterprise value metrics (MTTR reduction, analyst efficiency, operational risk reduction, automation coverage)
- Influence and guide multiple security domain teams (15+ teams) to adopt standardized automation patterns and best practices
- Provide technical leadership and mentorship to senior and principal engineers across SOAR platforms
- Act as escalation point for high-risk, high-complexity orchestration challenges and systemic platform issues
- Lead design and oversight of enterprise integrations, including but not limited to:
- Microsoft Graph / Entra ID / M365 Defender
- CrowdStrike Falcon
- Tanium
- BloodHound
- Anvilogic
- ThreatQ
- ServiceNow (Incidents, SecOps, CMDB, IR workflows)
- Drive platform reliability, resilience, and auditability standards across all automation implementations
AI-Enabled & Agentic Automation
- Define enterprise vision for AI-driven security operations, including copilots, agents, and MCP-aligned orchestration
- Lead design of AI-assisted investigation, triage, and response workflows integrated with SOAR decisioning
- Establish and enforce enterprise AI governance framework, including:
- Human-in-the-loop approval models and escalation paths
- Deterministic fallback and fail-safe execution patterns
- Access controls, observability, logging, and auditability aligned with enterprise risk standards
- Define architectural patterns for AI-integrated SOAR systems, including:
- Retrieval-Augmented Generation (RAG) design and secure knowledge integration
- Vector embedding strategies for semantic search and correlation
- Scalable data pipelines for incident context, detections, and response history
- Evaluate and approve AI use cases based on operational value, risk, and production readiness
- Partner with governance, risk, and compliance teams to ensure safe, auditable deployment of AI capabilities
Required Qualifications
- 10+ years of experience in Security Operations, Incident Response, Detection Engineering, or Security Automation
- 5+ years of deep, hands on experience with Splunk SOAR (Phantom) in addition to hands on experience with Tines (required) in enterprise environments
- Proven track record of leading large-scale SOAR or automation programs
- Deep expertise in incident response lifecycle, SOC operating models, and automation strategy
- Strong experience designing and scaling secure, reliable, and governed automation architectures
- Experience integrating SOAR platforms with enterprise systems (Microsoft Graph, CrowdStrike, Tanium, ServiceNow, etc.)
- Demonstrated ability to influence senior leadership and drive cross-organizational initiatives
- Expertise in translating complex, ambiguous problems into clear architectural solutions and execution plans
- BA or BS in Computer Science, Engineering, Information Systems, or a related technical field; advanced Masters degree preferred
Desired Qualifications
- Prior experience operating at principal, staff, or architect level in cybersecurity engineering
- Experience defining or leading enterprise security architecture or SOC transformation initiatives
- Strong proficiency in Python, REST APIs, and modern authentication (OAuth, SAML, etc.)
- Experience with AI-enabled security operations, including copilots, LLM integrations, or agent-based systems
- Hands-on or architectural experience with RAG frameworks, vector databases, and AI data platforms
- Familiarity with cloud security architectures across AWS, Azure, and Google Cloud
- Experience working with governance frameworks (MRM, audit, compliance, risk controls) in regulated environments
Skills:
- Influence
- Result Orientation
- Solution Design
- Stakeholder Management
- Technical Strategy Development
- Access and Identity Management
- Cyber Security
- Information Systems Management
- Risk Management
- Solution Delivery Process
- Collaboration
- Critical Thinking
- DevOps Practices
- Financial Management
- Test Engineering
This job will be open and accepting applications for a minimum of seven days from the date it was posted.
Shift:
1st shift (United States of America)
Hours Per Week:
40
Pay Transparency details
US - CO - Denver - 1144 15th St - Denver Gis (CO9926), US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540)
Pay and benefits information
Pay range
$150,000.00 - $190,700.00 annualized salary, offers to be determined based on experience, education and skill set.
Discretionary incentive eligible
This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.
Benefits
This role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.
About Bank Of America
Sourced by ZipRecruiter
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day. One of the keys to driving Responsible Growth is being a great place to work for our teammates around the world. We're devoted to being a diverse and inclusive workplace for everyone. We hire individuals with a broad range of backgrounds and experiences and invest heavily in our teammates and their families by offering competitive benefits to support their physical, emotional, and financial well-being.
Industry
Finance and insurance
Company size
10,000+ Employees
Headquarters location
Charlotte, NC, US
Website
What Bank Of America employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom