Job Title: Security Detection & Response Specialist
Corporate Title: Up to Assistant Vice President
Location: Chester
Company Overview
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being a diverse and inclusive workplace, attracting and developing exceptional talent, supporting our teammates' physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Location Overview
Find us in the city of Chester, a destination renowned for its culture, history, and beauty. Working at Bank of America Chester offers a far-reaching global career for a world-renowned organisation, whilst being ideally situated against the backdrop of the rolling North Wales hills and the banks of the serene River Dee.
Role Description
We are seeking a motivated and analytically driven Security Detection & Response Analyst (SDR) to join the GIS Monitoring and Triage team. This role supports cybersecurity operations across threat detection, investigation, response, and continuous service improvement.
The ideal candidate will have security practitioner experience with strong analytical aptitude and foundational technical skills, who contributes to the detection and response lifecycle by supporting investigations and response activities under guidance.
This role focuses on developing the ability to analyse security events, build contextual understanding of threats, and progressively operate with increasing independence across multiple security domains. The analyst will work alongside experienced practitioners to validate detections, investigate events, and execute response actions while building foundational skills in automation, orchestration, and AI-driven technologies.
Responsibilities
- Support the detection and response lifecycle (detect β investigate β respond β improve) by triaging alerts and analysing logs and telemetry from multiple sources to assess potential security events
- Correlate and analyse data across endpoint, identity, network, and application sources to develop context and determine whether activity is benign or suspicious
- Assist in the investigation of security events by applying structured, hypothesis-driven analysis and escalating complex or high-risk findings to more senior analysts
- Perform guided response activities under supervision, including alert enrichment, containment support, documentation, and coordination with more senior team members during active investigations
- Validate alerts and contribute to improving detection fidelity by identifying false positives and providing feedback to enhance detection logic and coverage
- Contribute to the development and refinement of investigation guides, runbooks, and playbooks, while learning to leverage automation, SOAR workflows, and AI-assisted tools to improve efficiency
- Identify gaps in telemetry, monitoring, or processes and escalation improvement opportunities to support continuous enhancement of detection and response capabilities
What we're looking for
- Experience in cybersecurity, security operations, IT support, or related technical fields (internships, academic projects, or equivalent experience included)
- Foundational knowledge of security detection, investigation, or incident response principles, with a demonstrated ability to learn and apply concepts across multiple domains
- Basic experience with log analysis and telemetry interpretation, including familiarity with querying or analyzing data using tools such as SIEM platforms or query languages (KQL, SPL, SQL, or similar)
- Exposure to security platforms and technologies such as SIEM, EDR/XDR, identity systems, or cloud environments
- Foundational understanding of common attacker tactics, techniques, and procedures (TTPs), with familiarity of frameworks such as MITRE ATT&CK
- Analytical and problem-solving skills, with the ability to follow structured investigation processes and document findings clearly
- Effective communication skills, including the ability to provide clear updates and collaborate with team members during investigations
- Willingness to learn, take direction, and progressively develop independent decision-making capabilities in security operations environments
Skills that will help
- Deep analytical and problem-solving skills, with the ability to follow structured investigation processes and document findings clearly
- Effective communication skills, including the ability to provide clear updates and collaborate with team members during investigations
#J-18808-Ljbffr