Assistant Vice President, Security Detection & Response, Global Information Security, Sydney
Job Description:
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.
We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.
Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Assistant Vice President, Security Detection & Response, Global Information Security, Sydney
Working Pattern:
This is a full-time role (38 hours per week), with standard working hours of 9:00AM to 7:30PM AEST 4 days per week (Wednesday to Saturday) to align with the nature of the support provided by the team.
Flexibility may occasionally be required to support business, operational, or project deliverables.
Role Description:
We are seeking a motivated and analytically driven Security Detection & Response Analyst (SDR I) to join the GIS Monitoring and Triage team. This role supports cybersecurity operations across threat detection, investigation, response, and continuous service improvement.
The ideal candidate is an early-career security practitioner with strong analytical aptitude and foundational technical skills, who contributes to the detection and response lifecycle by supporting investigations and response activities under guidance.
This role focuses on developing the ability to analyze security events, build contextual understanding of threats, and progressively operate with increasing independence across multiple security domains. The analyst will work alongside experienced practitioners to validate detections, investigate events, and execute response actions while building foundational skills in automation, orchestration, and AI-driven technologies.
Responsibilities:
- Support the detection and response lifecycle (detect → investigate → respond → improve) by triaging alerts and analyzing logs and telemetry from multiple sources to assess potential security events
- Correlate and analyze data across endpoint, identity, network, and application sources to develop context and determine whether activity is benign or suspicious
- Assist in the investigation of security events by applying structured, hypothesis-driven analysis and escalating complex or high-risk findings to more senior analysts
- Perform guided response activities under supervision, including alert enrichment, containment support, documentation, and coordination with more senior team members during active investigations
- Validate alerts and contribute to improving detection fidelity by identifying false positives and providing feedback to enhance detection logic and coverage
- Contribute to the development and refinement of investigation guides, runbooks, and playbooks, while learning to leverage automation, SOAR workflows, and AI-assisted tools to improve efficiency
- Identify gaps in telemetry, monitoring, or processes and escalate improvement opportunities to support continuous enhancement of detection and response capabilities
What we’re looking for:
- Experience in cybersecurity, security operations, IT support, or related technical fields (internships, academic projects, or equivalent experience included)
- Foundational knowledge of security detection, investigation, or incident response principles, with a demonstrated ability to learn and apply concepts across multiple domains
- Basic experience with log analysis and telemetry interpretation, including familiarity with querying or analyzing data using tools such as SIEM platforms or query languages (KQL, SPL, SQL, or similar)
- Exposure to security platforms and technologies such as SIEM, EDR/XDR, identity systems, or cloud environments
- Foundational understanding of common attacker tactics, techniques, and procedures (TTPs), with familiarity of frameworks such as MITRE ATT&CK
- Analytical and problem-solving skills, with the ability to follow structured investigation processes and document findings clearly
- Effective communication skills, including the ability to provide clear updates and collaborate with team members during investigations
- Willingness to learn, take direction, and progressively develop independent decision-making capabilities in security operations environments
Skills that will help:
- Deep analytical and problem-solving skills, with the ability to follow structured investigation processes and document findings clearly
- Effective communication skills, including the ability to provide clear updates and collaborate with team members during investigations