Back to search results

Vice President, Security Detection & Response, Global Information Security

Sydney, Australia
Refer a friend

Job Description:

At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.

Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.

We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.

Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.

At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!

Vice President, Security Detection & Response, Global Information Security, Sydney

Working Pattern:

This is a full-time role (38 hours per week), with standard working hours of 9:00AM to 7:30PM AEST 4 days per week (Sunday to Wednesday) to align with the nature of the support provided by the team. 

Flexibility may occasionally be required to support business, operational, or project deliverables.

Role Description:

We are seeking an experienced and motivated Security Detection & Response Analyst (SDR II) to join the GIS Monitoring and Triage team. This role supports cybersecurity operations across threat detection, investigation, response, and continuous service improvement.

You should be an experienced security practitioner capable of operating within the end-to-end detection and response lifecycle (detect → investigate → respond → improve), combining broad analytical capability with an engineering mindset to rapidly identify, investigate, and contain threats. The analyst will operate across multiple security domains, validating detections, investigating threats, and executing response actions with sound judgment.

This role requires cross-domain security expertise, broad analytical and engineering capabilities, and the ability to leverage automation, orchestration, and AI-driven technologies to improve detection outcomes, reduce manual effort, and continuously enhance overall security effectiveness.

Responsibilities:

  • You will operate within the end-to-end detection and response lifecycle (detect → investigate → respond → improve), including analyzing logs and telemetry from multiple sources to establish attack scope, impact, and root cause
  • You will build, validate, tune, and optimize detection logic and coverage, leveraging attacker tactics, techniques, and procedures (TTPs) and frameworks such as MITRE ATT&CK to improve accuracy and reduce false positives
  • Execute and coordinate security event response activities, including containment, isolation, escalation, and remediation, applying sound judgment during active engagements
  • You will maintain and improve automation and orchestration capabilities, including SOAR workflows, automated playbooks, scripted response actions, and AI-driven enhancements to reduce manual effort and improve detection and response outcomes. Accountable for measurable improvements in MTTR, detection quality, and signal-to-noise ratio
  • You will document and communicate security event findings, including timelines and lessons learned, while providing clear updates to stakeholders and driving continuous improvement in detection and response processes
  • Identify gaps in monitoring and detection coverage, contributing to operational maturity through continuous improvement initiatives, metrics, and enhancements to detection, response, and automation capabilities
  • Support integration of partner use cases into detection and monitoring workflows
  • Guide and instruct junior members of the team to support the achievement of professional goals

What we are looking for:

  • Experience in security operations, incident response, detection engineering, or related cybersecurity functions within a production environment
  • Experience in security detection, investigation, and response across multiple domains, with the ability to pivot across data sources and independently manage end-to-end investigations from initial triage through post-incident improvement
  • Ability to build, validate, and tune detections and response workflows, including reducing false positives. Considerable proficiency in log analysis, telemetry interpretation, and cross-system data correlation, including the ability to query, manipulate, and optimize data using KQL, SPL, SQL, or similar languages for investigative and detection use cases
  • Practical experience with containment, response actions, and automation, including developing or maintaining SOAR workflows, API integrations, and scripted response actions using sound judgment Experience with security platforms and technologies, including SIEM, EDR/XDR, identity security, and cloud security
  • Working knowledge of identity and access systems and common attack paths, including credential theft, privilege escalation, and session/token abuse
  • Considerable understanding of attacker tactics, techniques, and procedures (TTPs), including MITRE ATT&CK
  • Record of improving operational effectiveness, including reducing alert noise, improving detection coverage, and decreasing mean time to detect and respond
  • Great analytical, decision-making, and communication skills, including the ability to clearly articulate findings, provide timely incident updates to both technical and non-technical stakeholders, and operate effectively in high-pressure scenarios
  • Ability to operate with minimal supervision and make risk-informed decisions quickly

Skills that will help:

  • Exceptional communication and executive presence, with the ability to influence at all organizational levels
  • Process discipline
  • Leadership competency in geographically diverse matrixed environment.
  • Relevant Cyber Security Certificate
  • Worked in SOC environment before
  • Familiarity with Cyber Security and Information Technology.
  • Strong problem-solving and critical thinking skills.
  • Effective communication and interpersonal skills.

Learn more about this role

Refer a friend

Full time

JR-26031281

Manages People:

Age requirement: Must at least be 18 years of age.

Street Address

Primary Location:

1 FARRER PLACE, Sydney, 2000