Bank of America Logo

Bank of America

SIEM/SOAR Production Services Specialist ll

Reposted 14 Days Ago
Be an Early Applicant
In-Office
Chicago, IL, USA
74K-144K Annually
Expert/Leader
In-Office
Chicago, IL, USA
74K-144K Annually
Expert/Leader
Lead production triage and incident response for SIEM/SOAR and application portfolios. Manage Splunk detection, automation, and dashboards; drive root-cause analysis, remediation, and documentation while ensuring regulatory compliance and SLA-driven service restoration.
The summary above was generated by AI

Job Description:

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates’ physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!

Job Description:
This job is responsible for providing front-line support to end users, responding to issues related to incidents and problem management governance for multiple applications, and leading triage activities on all business impacting incidents. Key responsibilities include ensuring compliance with incident management and problem management policies and procedures, serving as a focal point for the customer, client, and associate experience, restoring complex production incidents under tight Service Level Agreements, and pursuing root cause and problem resolution follow ups.

Responsibilities:

  • Leads production support triage efforts, manages bridge line troubleshooting, engages in technical research, and escalates issues to leadership as needed

  • Ensures all impacts are accurately recorded and documented in the system of record, oversees that documents and wikis are updated and available for use during triage, and supports the documentation of application flows, upstream/downstream impacts during outages, the customer experience, and contacts for support needs

  • Identifies and/or validates business impacts through interpretation of monitors, dashboards, and logs to communicate with leadership and vendors

  • Manages activities to identify incident root cause, resolution, preventative actions, and change requests, and reports on incident data quality

  • Promotes and enforces production governance during triage/testing and identifies production failure scenarios, vulnerabilities, and opportunities for improvement

  • Serves as a subject matter expert for applications within a portfolio, leveraging extensive knowledge of application functionalities and application flows

  • Assesses and prioritizes research requests, ad hoc reports, and offline incidents at the direction of senior team members and delegates work as needed to team members and peers

Position Summary

  • We’re looking for an experienced IT Security professional with 5+ years of hands-on expertise in SIEM/SOAR to join our team. In this role, an ideal candidate will manage and optimize Splunk for advanced threat detection, automation, and incident response.

  • Will collaborate IT teams to build detection rules, automation playbooks, and dashboards that strengthen our security posture in a fast-paced FinTech environment.

  • Manage, configure, and optimize SIEM/SOAR platforms (primarily Splunk).

  • Develop detection rules, dashboards, and automation playbooks.

  • Monitor and analyze security events to identify threats and reduce response times.

  • This position is expected to deliver above and beyond services to our internal customers to facilitate business continuity with a meet or exceed SLAs.

  • This includes monitoring, incident response, problem engagement during triage, service restoral, identification of root cause, and facilitation and co-ordination for a permanent fix – in accordance with agreed best practices.

  • The Ideal candidate will have over 10 years of hands on experience within the realm of IAM (identity and Access Management) space. Well conversant with the tools and applications employed within the highly regulated FinTech industry.

  • SME with expert level hands-on knowledge of Access management and Entitlement technologies. Must have expert level experience in Windows OS, RedHat Linux, SQL queries, SQL/Oracle & other flavors of databases. Well versed with RedHat Linux OpenShift containers, Atlassian JIRA & Horizon platforms, GitHub, Ansible, Jenkins, ITSM Remedy, Splunk, Dynatrace, PowerShell/Unix Scripting, cloud experience including other CI/CD DevOps tools.

Required Qualifications

  • MUST BE ABLE TO WORK SATURDAY OR SUNDAY WHEN ON CALL OR FOR NEW RELEASES

  • 5+ years of experience in SIEM/SOAR administration and security operations.

  • Well conversant with 5 C's of cyber security - Change, Compliance, Cost, Continuity and Coverage

  • Passionate about cybersecurity and automation, a SIEM/SOAR expert to help us strengthen our cyber resilience, turning Splunk skills into impact

  • Use Splunk skills to fight threats and keep financial services secure

  • Strong hands-on knowledge of Splunk (searches, dashboards, alerts, playbooks).

  • Solid understanding of cybersecurity frameworks, threat detection, and incident response.

  • 5+ years of production support experience with expert level knowledge of MFA technologies, Splunk. Window OS, SQL/Oracle DB & Unix/Linux.

  • Excellent knowledge of Identity, Authentication and Access Management (IAM) domain including SRE and DevOps space.

  • Must have senior level production support experience and troubleshooting skills in SIEM/SOAR space, Splunk and IAM technologies.

  • Must be able to comply with bank regulatory and compliance policies

  • Must have expert level of Linux experience and must be well versed in Splunk queries.

  • Well versed with ITIL framework

  • Excellent Communication Skills lateral and vertical - be able to clearly explain issues, their impact and how to address them

  • Must be a great team player - be able to collaborate with other team members within or outside the group

  • Must be available for on-call coverage and willing to work off hours as and when needed.

  • Must be willing to work on-site 3 days a week as per current bank policies

  • Demonstrate a strong work ethics and takes pride in accomplishment.

  • Must be able to handle and work under pressure and stress

  • Attention to detail - able to evaluate smallest details

  • Problem-solving - be able to address complex challenges in creative ways

Desired Qualifications

  • CISSP or other equivalent Information Security domain certificates will be added value

  • A cybersecurity pro to safeguard systems in the fast-moving FinTech world

  • Go getter exhibiting strong motivation and drive for results and success.

  • Persists in the face of significant difficulties, does not give up easily.

  • Tower, BladeLogic

  • Strong understanding of network technologies

Skills:

  • Adaptability

  • Analytical Thinking

  • Influence

  • Production Support

  • Risk Management

  • Automation

  • Collaboration

  • Innovative Thinking

  • Result Orientation

  • Solution Design

  • Business Acumen

  • DevOps Practices

  • Project Management

  • Solution Delivery Process

  • Stakeholder Management

Shift:

1st shift (United States of America)

Hours Per Week: 

40

Pay Transparency details

US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540)

Pay and benefits information

Pay range$73,600.00 - $143,800.00 annualized salary, offers to be determined based on experience, education and skill set.

Discretionary incentive eligible

This role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.

Benefits

This role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.

Similar Jobs

58 Minutes Ago
Remote or Hybrid
United States
124K-217K Annually
Senior level
124K-217K Annually
Senior level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Design and deploy access controls, authorization policies, and automated lifecycle workflows on the Veza platform. Lead IAM architecture and integrations across cloud and SaaS, implement JML provisioning, govern non-human identities, build API-driven integrations, advise security leaders, and run customer-facing deployments from requirements to production.
Top Skills: AbacAWSAzureGCPGitIga (Identity Governance & Administration)Microsoft 365PythonRbacRest ApisSalesforceServicenowSQLVeza
59 Minutes Ago
Remote or Hybrid
United States
102K-179K Annually
Senior level
102K-179K Annually
Senior level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Act as an advocate for a portfolio of ServiceNow customers to drive adoption, outcomes, and license usage. Ensure technical health, guide cross-functional teams, apply Success Plays, create use cases, manage projects and escalations, and help customers realize maximum value from their ServiceNow investment.
Top Skills: AIServicenow
An Hour Ago
In-Office or Remote
United States
100K-140K Annually
Expert/Leader
100K-140K Annually
Expert/Leader
Big Data • Information Technology • Software • Analytics • Energy
Lead client-facing technical engagements for interconnection and transmission planning, deliver trainings and presentations, support sales pursuits, onboard and train users, analyze interconnection study results, troubleshoot client issues, provide product feedback, and deepen client relationships to expand product adoption. Attend industry events and travel ~10%.

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account