Senior Technology Manager – Security Operations Platform
Bank of AmericaAbout the role
Job Description:
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being a diverse and inclusive workplace, attracting and developing exceptional talent, supporting our teammates’ physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Job Description:
Global Information Security (GIS) is responsible for protecting bank information systems, confidential and proprietary data, and customer information. GIS develops the bank’s Information Security strategy and policy, manages the Information Security program, identifies and addresses vulnerabilities and operates a global security operations center that monitors, detects, and responds to cybersecurity incidents
Role Description:
We are seeking a cybersecurity domain expert to lead as a Senior Technology Manager to design, develop, and deploy technology supporting Detection and Response activities for various Cyber Defense and Security Operations Teams. This role requires an innovative leader who can blend enterprise cybersecurity expertise with user to create seamless, scalable, and highly effective security operations platforms.
As the development lead, you will drive the strategic vision for a multi environment platform that integrates security tools, telemetry, automation, and analytics into a unified experience. You will collaborate closely with SOC analysts, threat hunters, incident responders, and security engineers to ensure that the interface meets operational needs while reducing friction and improving response times.
Skills
- Deep expertise in cybersecurity operations, threat detection, and incident response workflows.
- Proven experience designing and deploying platforms that integrate SIEM, SOAR, TIP, EDR, and cloud-native telemetry
- Strong understanding of federated data access, log normalization, and real-time streaming (e.g., Cribl, Kafka)
- Familiarity with LLM orchestration frameworks (e.g., LangChain, LlamaIndex) and AI/ML-driven analytics
- Experience with advanced SOAR Playbooks and/or AI Agents.
- Experience with data modeling, schema mapping, and field correlation across hybrid/multi-cloud environments
- Strong interpersonal and executive communication skills; ability to translate technical vision into business value
- Demonstrated ability to lead cross-functional teams of engineers, data scientists, and security analysts
- Experience with agile development, DevSecOps, and secure software lifecycle practices
- Experience developing technology for MDR, or other large scale cybersecurity platform software providers.
Roles & Responsibilities
- Partner to lead the development of an AI-augmented threat hunting and security operations platform that unifies telemetry, automation, and analytics
- Architect and oversee the integration of federated data sources across cloud, on-prem, and legacy environments
- Collaborate with cybersecurity teams and engineering teams to define use cases for LLMs in threat detection, log correlation, and contextual enrichment
- Drive the implementation of a modular, scalable platform that supports real-time streaming, historical search, and AI-assisted investigation
- Champion the use of structured data models and field taxonomies (e.g., OCSF, ECS) to enable semantic search and automation
- Integrate LLMs to support use cases such as data cataloging, field mapping, log summarization, and hypothesis-driven hunting
- Establish performance metrics and feedback loops to continuously improve platform usability, detection efficacy, and analyst productivity
- Partner with SOAR teams to develop agent-based playbooks for automated context gathering and response
- Ensure platform security, compliance, and auditability across all integrated components
Required Qualifications:
- 10+ years of experience in cybersecurity engineering, threat detection, or security platform development
- 7+ years of leadership experience managing cross-functional technical teams
- Strong background in building or integrating security data platforms (e.g., Splunk, Elastic, Chronicle, Snowflake, Anvilogic)
- Experience with cloud-native security architectures (AWS, Azure, G
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s