About this Security Detection & Response I role at Bank of America
Job Description:
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits. We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.
Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Job Description:
We are seeking a motivated and analytically driven Security Detection & Response Analyst (SDR I) to join the GIS Monitoring and Triage team. This role supports cybersecurity operations across threat detection, investigation, response, and continuous service improvement. The ideal candidate is an early-career security practitioner with strong analytical aptitude and foundational technical skills, who contributes to the detection and response lifecycle by supporting investigations and response activities under guidance. This role focuses on developing the ability to analyze security events, build contextual understanding of threats, and progressively operate with increasing independence across multiple security domains. The analyst will work alongside experienced practitioners to validate detections, investigate events, and execute response actions while building foundational skills in automation, orchestration, and AI-driven technologies.
***Schedule Requirement: Ability to work a 4x10 schedule (preferred Wednesday-Saturday, subject to operational needs)***
Responsibilities:
- Support the detection and response lifecycle by triaging alerts and analyzing logs and telemetry from multiple sources to assess potential security events.
- Correlate and analyze data across endpoint, identity, network, and application sources to develop context and determine whether activity is benign or suspicious.
- Assist in the investigation of security events using structured, hypothesis-driven analysis and escalate complex or high-risk findings to senior analysts.
- Perform guided response activities including alert enrichment, containment support, documentation, and coordination during active investigations.
- Validate alerts and contribute to improving detection fidelity by identifying false positives and providing feedback to enhance detection logic and coverage.
- Contribute to development and refinement of investigation guides, runbooks, and playbooks while learning to leverage automation, SOAR workflows, and AI-assisted tools.
- Identify gaps in telemetry, monitoring, or processes and escalate improvement opportunities to support continuous enhancement of detection and response capabilities.
Required Qualifications:
- Ability to work a 4x10 schedule (preferred Wednesday-Saturday, subject to operational needs).
- 2+ years of experience in cybersecurity, security operations, IT support, or related technical fields, including internships, academic projects, or equivalent experience.
- Foundational knowledge of security detection, investigation, or incident response principles, with demonstrated ability to learn and apply concepts across multiple domains.
- Basic experience with log analysis and telemetry interpretation, including familiarity with SIEM platforms and query languages such as KQL, SPL, SQL, or similar.
- Exposure to security technologies such as SIEM, EDR/XDR, identity systems, or cloud environments.
- Foundational understanding of attacker tactics, techniques, and procedures (TTPs), with familiarity with frameworks such as MITRE ATT&CK.
- Strong analytical and problem-solving skills with the ability to follow structured investigation processes and clearly document findings.
- Effective communication skills and ability to collaborate with team members during investigations.
- Willingness to learn, take direction, and progressively develop independent decision-making capabilities in security operations environments.
Desired Qualifications:
- Experience leveraging automation, orchestration, SOAR workflows, or AI-assisted security tools.
- Demonstrated interest in detection engineering, threat analysis, incident response, or cybersecurity operations.
- Ability to identify process improvement opportunities and contribute to continuous service improvement initiatives.
Skills:
- Architecture
- Customer and Client Focus
- Data and Trend Analysis
- Information Systems Management
- Problem Solving
- Access and Identity Management
- Incident Management
- Interpret Relevant Laws, Rules, and Regulations
- Technology System Assessment
- Threat Analysis
- Application Development
- Cyber Security
- Quality Assurance
- Risk Modeling
- Vendor Management
Shift:
1st shift (United States of America)Hours Per Week:
40