Job Summary:
Bank of America is committed to helping make financial lives better through the power of every connection. The Senior Engineer SIEM Platform Engineering & Operations is responsible for engineering, monitoring, and optimizing the firm’s SIEM ecosystem, enhancing the security data environment and serving as a SIEM subject-matter expert across Cyber Security Technology teams.
Responsibilities:
• Engineer, monitor, and maintain the operational health and resiliency of SIEM platforms including Splunk Enterprise/Cloud and Microsoft Sentinel.
• Implement SIEM platform resiliency controls including cluster monitoring, ingestion latency tracking, and workload distribution optimizations.
• Monitor, maintain, and troubleshoot the data ingestion pipeline including Kafka clusters, Cribl pipelines, Splunk Forwarders, and Sentinel connectors.
• Develop dashboards for pipeline throughput, message lag, schema drift, and end-to-end data quality validation.
• Manage and enforce data SLIs/SLOs across freshness, completeness, correctness, and availability.
• Ensure proper CIM/OCSF/CEF normalization and enrichment for all security-relevant data sources.
• Oversee the Anvilogic content management platform including rule execution health, version control, and analytics dependency monitoring.
• Develop unified observability dashboards covering SIEM platform state, ingestion health, detection pipeline execution, and analytic reliability.
• Serve as escalation point for SIEM data outages, ingestion failures, analytic misfires, and platform degradations.
• Collaborate with operational and engineering teams to design and enhance security detections, analytics, and proactive defenses.
• Write, optimize, and maintain SPL, KQL, and other query languages to support analytics, threat detection, and investigations.
• Support Model Risk Management (MRM) efforts to describe AI or ML Models in use by any of our SIEM Technologies.
Qualifications:
Required:
• 6+ years experience in Security Operations, SIEM Engineering, Detection Engineering, Incident Response, or related enterprise disciplines.
• Hands-on experience with Splunk Enterprise/Cloud and Microsoft Sentinel in large-scale environments.
• Experience with Kafka, Cribl, Databricks, Hadoop, Python, SQL, Pandas, Spark, or similar data platforms.
• Experience mapping log sources into structured models such as CIM, OCSF, CEF.
• Ability to troubleshoot complex SIEM ingestion, data quality, and infrastructure performance issues.
• Experience with EDR, SIEM, SOAR, and other enterprise-scale cybersecurity tools.
• Ability to manage competing priorities, drive consensus, and deliver results across distributed teams.
Preferred:
• Experience with offensive security tooling and integrating SIEM/SOAR/TIP platforms.
• Knowledge of data science processes and statistical methods for detection enhancement.
• Experience threat hunting or performing detection engineering in cloud environments such as Azure, AWS, or M365.
• Experience maintaining Splunk KV stores, apps, and performing regular upgrades.
• Experience building SRE-style observability and reliability patterns (SLIs, SLOs, error budgets) for cybersecurity platforms.
• Awareness of AI enabled Security Operations technologies.
Company:
Bank of America is a financial institution that offers credit cards, home loans, and auto loan services. Founded in 1998, the company is headquartered in Charlotte, USA, with a team of 10001+ employees. The company is currently Late Stage.