- Salary
- $140k – $200k
- Location
- Denver, United States of America
- Workplace
- Onsite
- Type
- Full-time
- Seniority
- Lead
- Experience
- 8+ years
- Source
- Workday
Description
Job Description:
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work and providing a culture of caring is core to how we drive Responsible Growth. We are intentional about fostering an inclusive workplace where every teammate has the opportunity to succeed, build a career and contribute to our shared success. This includes attracting and developing exceptional talent, recognizing and rewarding performance, and supporting our teammates’ physical, emotional, and financial wellness through affordable, competitive and flexible benefits.
We value the unique perspectives individuals bring from all backgrounds and career paths - whether shaped by military service, community college education, or a wide range of work and life experiences. These journeys foster resilience, leadership and innovation, strengthening our workforce and positively impact the communities we serve.
Bank of America is committed to an in-office culture that supports collaboration, engagement, and career development. Our approach includes clear in-office expectations, while providing an appropriate level of flexibility based on role-specific responsibilities and business needs.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Job Description:
The Transformation Lead – Response and Recovery is a senior individual contributor responsible for driving innovation, modernization, and operational maturity across the organization's cyber incident response, cyber resiliency, recovery preparedness, and exercise capabilities.
Sitting within Cyber Security Operations (CSO), this role focuses on advancing the organization's ability to prepare for, respond to, recover from, and learn from cyber incidents. The role will lead strategic transformation initiatives across Cyber Incident Response Management (CIRM), cyber recovery, resiliency testing, and cyber exercises while evaluating emerging technologies, automation opportunities, and industry best practices.
The ideal candidate is a strategic self-starter who can independently lead complex, cross-functional initiatives while partnering with security, technology, business continuity, infrastructure, and executive stakeholders. Significant emphasis will be placed on leveraging automation and AI-enabled capabilities to improve operational effectiveness, enhance preparedness, accelerate recovery, and strengthen organizational resilience against evolving cyber threats.
Automation, AI & Operational Efficiency
- Lead initiatives to automate incident response, recovery validation, and coordination workflows.
- Leverage AI, automation, analytics, and orchestration capabilities to improve incident triage, decision support, impact assessment, and recovery readiness.
- Partner with engineering, SOAR, infrastructure, and platform teams to integrate automated response and recovery capabilities.
- Focus on improving operational scalability through workflow optimization, manual effort reduction, and accelerated decision making.
- Enhance executive awareness and response effectiveness through improved situational reporting and automated stakeholder communications.
Incident Response
- Drive enhancements to Cyber Incident Response Management (CIRM) capabilities, processes, and engagement models.
- Evaluate incident response effectiveness through post-incident reviews, lessons learned, trend analysis, and operational metrics.
- Develop strategies to reduce response complexity and improve coordination across business, technology, cybersecurity, and executive leadership teams.
- Support modernization of incident classification, escalation, response coordination, and executive communication processes.
- Partner with cyber recovery, technology recovery, and business continuity teams to strengthen recovery readiness and resilience.
Technology Transformation & Innovation
- Drive modernization of cyber incident response, recovery, and resiliency capabilities.
- Identify opportunities to enhance, streamline, or rationalize existing response and recovery platforms, processes, and operating models.
- Lead the exploration and evaluation of emerging technologies supporting incident management, cyber recovery, and resiliency validation.
- Assess and recommend new tools, vendors, and capabilities, developing business cases and transformation roadmaps.
- Shape future-state architectures supporting cyber response orchestration, recovery assurance, and operational resiliency.
Cyber Resiliency & Recovery Readiness
- Advance enterprise cyber resiliency capabilities focused on preparedness, recovering from, and adapting to disruptive cyber events.
- Develop and mature recovery validation programs, resilience assessments, and recovery assurance frameworks.
- Partner with infrastructure, application, and business stakeholders to identify recovery risks, dependencies, and opportunities for improvement.
- Evaluate emerging recovery technologies and approaches that improve organizational readiness for ransomware, destructive attacks, and major technology disruptions.
- Drive initiatives that strengthen recovery confidence, reduce recovery uncertainty, and improve restoration effectiveness.
Exercises, Testing & Preparedness
- Lead transformation of cyber exercises, simulations, tabletop events, and recovery testing programs.
- Develop innovative exercise methodologies that validate response, crisis management, decision-making, and recovery capabilities.
- Incorporate threat intelligence, real-world attack scenarios, and emerging risks into exercise development.
- Analyze exercise outcomes and drive measurable improvements through lessons learned and corrective actions.
- Partner with executive leadership, technology teams, and business stakeholders to increase preparedness and crisis response effectiveness.
Threat Awareness, Risk Strategy & Governance
- Stay current on emerging cyber threats, attacker methodologies, ransomware trends, and industry resiliency practices.
- Translate threat intelligence and operational insights into strategic investments and resiliency enhancements.
- Support alignment of response, recovery, and resiliency programs with regulatory expectations and frameworks such as NIST CSF, NIST 800-61, NIST 800-160, ISO 22301, and MITRE ATT&CK.
- Challenge existing processes and assumptions to continuously strengthen organizational preparedness and resilience.
Program & Initiative Leadership (IC Led)
- Drive large-scale, multi-phase transformation initiatives from strategy through execution.
- Establish measurable outcomes, milestones, KRIs, and success metrics for modernization efforts.
- Influence priorities and execution across organizations without formal authority.
- Lead working groups, steering committees, and strategic planning efforts supporting response and recovery transformation.
Metrics, Reporting & Executive Insight
- Define and mature KRIs, KPIs, and operational metrics measuring incident response effectiveness, recovery readiness, resiliency, and exercise outcomes.
- Deliver executive-ready reporting that clearly communicates risks, trends, preparedness levels, and transformation progress.
- Provide strategic recommendations to improve cyber resilience and operational maturity.
Required Qualifications & Skills
- 8+ years of experience in cybersecurity, incident response, cyber resiliency, crisis management, disaster recovery, or related domains.
- Proven experience leading large-scale transformational initiatives from concept through execution as an individual contributor.
- Strong understanding of cyber incident response, crisis management, cyber recovery, resilience engineering, and operational readiness practices.
- Experience managing or participating in significant cyber incidents, recovery efforts, or enterprise crisis events.
- Demonstrated ability to improve operational effectiveness through automation, orchestration, analytics, and process optimization.
- Experience evaluating and implementing technologies supporting incident response, recovery, resilience, or crisis management.
- Ability to operate independently, navigate ambiguity, and influence outcomes across complex organizational structures.
- Excellent communication skills with the ability to brief technical teams, executives, and risk stakeholders.
Desired Qualifications
- Experience within Cyber Incident Response Management (CIRM), cyber crisis management, cyber exercises, or resiliency programs.
- Experience designing and facilitating cyber exercises, tabletop exercises, simulations, and recovery testing events.
- Familiarity with SOAR platforms, response orchestration, automation tools, and AI-enabled security capabilities.
- Understanding of ransomware preparedness, cyber recovery, and resilience engineering concepts.
- Experience operating in large, highly regulated, matrixed enterprises.
- Knowledge of regulatory expectations related to incident response, cyber resilience, and operational recovery.
- Strong strategic planning skills with the ability to translate vision into executable roadmaps.
- Advanced degree in Information Security, Computer Science, Engineering, Business Continuity, or equivalent experience.
Skills:
- Cyber Security
- Data Privacy and Protection
- Problem Solving
- Process Management
- Threat Analysis
- Access and Identity Management
- Business Acumen
- Interpret Relevant Laws, Rules, and Regulations
- Risk Analytics
- Stakeholder Management
- Data Governance
- Data and Trend Analysis
- Incident Management
- Information Systems Management
- Technology System Assessment
This job will be open and accepting applications for a minimum of seven days from the date it was posted.
Shift:
1st shift (United States of America)Hours Per Week:
40Pay Transparency details
US - CO - Denver - 1144 15th St - Denver Gis (CO9926)Pay and benefits informationPay range$140,000.00 - $200,000.00 annualized salary, offers to be determined based on experience, education and skill set.Discretionary incentive eligibleThis role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.BenefitsThis role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.