Jobs Companies Blackbaud Principal Security Engineer, Orchestration and Automation

À propos de ce poste Principal Security Engineer, Orchestration and Automation chez Blackbaud

Blackbaud · Télétravail · Remote - Anywhere - USA

Cyber Detection & Response Automation Engineer

The Cyber Detection & Response Automation Engineer is responsible for building the automation, orchestration, and AI-driven capabilities that power the organization's detection and response function. This role treats the SIEM as one component in a broader automation ecosystem — the primary focus is designing workflows, integrations, and intelligent tooling that reduce manual analyst effort, accelerate response, and scale detection coverage. The ideal candidate is an automation/orchestration engineer with a security background: comfortable building integrations and pipelines across multiple tools, applying AI/ML or LLM-assisted techniques to triage and enrichment, and engineering detection logic. This person will also maintain a working level of SIEM platform administration — data onboarding, health, and configuration — to support the automation and detection layers built on top of it, and will partner closely with Security Operations and the Detection Engineering Lead.

What you'll be doing:

  • Design, build, and maintain orchestration workflows and SOAR playbooks that automate triage, enrichment, containment, and response actions across the security tool stack.
  • Apply AI/ML and LLM-assisted techniques (e.g., automated alert summarization, natural-language investigation assistance, anomaly scoring) to reduce analyst workload and speed decision-making.
  • Develop and maintain Python-based integrations and APIs connecting the SIEM, SOAR, EDR, ticketing, threat intel, and cloud platforms into unified automated workflows.
  • Design, build, and tune SIEM correlation rules, alerts, and detection use cases mapped to MITRE ATT&CK, with an eye toward which detections can be paired with automated response.
  • Own core SIEM administration tasks needed to support automation and detection: data source onboarding, index/data model health, log ingestion monitoring, and configuration management.
  • Build and maintain custom field extractions, parsers, and content packs to ensure new data sources are automation- and detection-ready.
  • Continuously tune detections and automation logic to improve signal-to-noise ratio, reduce false positives, and reduce mean-time-to-respond (MTTR).
  • Create dashboards and reporting that measure automation coverage, orchestration reliability, AI-assisted triage accuracy, and detection effectiveness.
  • Apply CI/CD and infrastructure-as-code practices to manage detection content, playbooks, and integrations as versioned, testable code.
  • Evaluate and pilot new automation, orchestration, and AI tooling to expand the detection and response automation footprint.

What we'll want you to have:

  • 5+ years building automation, orchestration, or SOAR playbooks in a cyber security or SOC environment.
  • 3+ years of SIEM engineering or administration experience - data onboarding, correlation rule development, platform configuration.
  • Strong Python (or comparable scripting) skills; experience building APIs/integrations across security and IT tooling.
  • Hands-on experience with AI/ML or LLM-based tooling applied to security use cases - triage, summarization, enrichment, and/or anomaly detection; experience building such capability strongly preferred.
  • Working knowledge of MITRE ATT&CK and experience mapping detections/automation to adversary tactics and techniques.
  • Experience with a SOAR or security orchestration platform (e.g., NG-SIEM Fusion, Splunk SOAR, Palo Alto XSOAR, Tines, or similar).
  • Cloud security experience (AWS, Azure, or GCP), including automation for ingesting and processing security data from cloud sources.
  • Experience with CI/CD, infrastructure-as-code, and version-controlling detection/automation content.
  • Familiarity with containerized and serverless environments and their automation/logging considerations.
  • SIEM, SOAR, or security automation platform certification preferred.
  • Regulatory compliance experience a plus.

Stay up to date on everything Blackbaud, follow us on Linkedin, Twitter, Instagram, Facebook and YouTube ​

Blackbaud powers social impact through purpose‑driven technology and responsible AI. Guided by our Intelligence for Good® vision, we’re building a culture where innovation, trust, and human expertise come together to help organizations make a greater difference in the world.

 

Blackbaud is proud to be an equal opportunity employer and is committed to maintaining a diverse and inclusive work environment. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, physical or mental disability, age, or veteran status or any other basis protected by federal, state, or local law.

The starting base pay is $117,200.00 to $157,500.00. Blackbaud may pay more or less based on employee qualifications, market value, Company finances, and other operational considerations.

Benefits Include:

  • Medical, dental, and vision insurance

  • Remote-flexible workforce

  • Wellness Programs

  • 401(k) program with employer match

  • Flexible paid time off

  • Generous Parental Leave

  • Donations for Doers

  • Pet insurance, legal and identity protection

  • Tuition reimbursement program

Prêt à postuler chez Blackbaud ?
Postuler chez Blackbaud

Comment se compare ce salaire pour Security Engineer

Ce poste paie $137,350/yren dessous de la fourchette habituelle pour les postes Security Engineer.

$110,281 la médiane $181,513 $260,000

Fourchette typique $141,000–$219,839/yr, à partir de 261 annonces Security Engineer comparables sur JobsRadar (rémunération annualisée en USD). Voir les aperçus de salaire pour Security Engineer →

À propos de Blackbaud

Blackbaud (NASDAQ: BLKB) is the world’s leading cloud software company powering social good. Serving the entire social good community—nonprofits, foundations, corporations, education institutions, healthcare institutions and individual change agents—Blackbaud connects and empowers organizations to increase their impact through software, services, expertise, and data intelligence. The Blackbaud portfolio is tailored to the unique needs of vertical markets, with solutions for fundraising and CRM, marketing, advocacy, peer-to-peer fundraising, corporate social responsibility, school management, ticketing, grantmaking, financial management, payment processing, and analytics. Serving the industry

Voir tous les emplois chez Blackbaud →

Emplois similaires

Okta
Staff Product Security Engineer, PSIRT
Okta
⚡ Postuler tôt Barcelona, Spain Sur site €74,000–€101,000
● Nouveau 👁 Vu ✓ Postulé il y a 7 h
Twilio
Security Engineer, Incident Response
Twilio
⚡ Postuler tôt Remote - United Kingdom · lieu restreint
● Nouveau 👁 Vu ✓ Postulé il y a 11 h
Twilio
Security Engineer, Incident Response
Twilio
⚡ Postuler tôt Remote - Ireland · lieu restreint
● Nouveau 👁 Vu ✓ Postulé il y a 11 h
DataDome
Senior Security Engineer
DataDome
⚡ Postuler tôt France - Remote · lieu restreint
● Nouveau 👁 Vu ✓ Postulé il y a 13 h
DataDome
GRC Security Engineer
DataDome
⚡ Postuler tôt France - Remote · lieu restreint
● Nouveau 👁 Vu ✓ Postulé il y a 13 h
Bugcrowd
Application Security Engineer II - Contract ( 6 months )
Bugcrowd
⚡ Postuler tôt Remote - India · lieu restreint
● Nouveau 👁 Vu ✓ Postulé il y a 16 h
SonicWall
Presales Engineer – Cybersecurity / Network Security* | Mumbai-Based
SonicWall
⚡ Postuler tôt Mumbai, Maharashtra, India Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 21 h
GDIT
Cybersecurity Systems Engineer
GDIT
⚡ Postuler tôt Any Location / Remote · lieu restreint $97,968–$126,500
● Nouveau 👁 Vu ✓ Postulé il y a 1 j
Abnormal
Software Engineer II - Behavioral Identity Security
Abnormal
⚡ Postuler tôt Remote - Singapore · lieu restreint
● Nouveau 👁 Vu ✓ Postulé il y a 1 j

Inscrivez-vous pour des suggestions adaptées aux emplois que vous ouvrez et aux recherches que vous enregistrez.

Plus d’emplois chez Blackbaud

Voir tous les emplois chez Blackbaud →

Postuler maintenant
🤖

Doucement — un instant

JobsRadar a été conçu pour de vraies personnes qui traversent une période difficile dans leur recherche d’emploi — pas pour des requêtes automatisées. Vous cliquez beaucoup trop vite et vous êtes maintenant temporairement bloqué.

Revenez plus tard. Si vous cherchez réellement un emploi, nous sommes de votre côté — agissez simplement comme un être humain.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Prenez une longueur d’avance dans votre recherche d’emploi.

Rejoignez notre canal Telegram pour ce qui vous aide à décrocher le poste — références salariales, le pouls hebdomadaire du marché et les annonces de nouveautés. Pas de spam, que du signal.

Rejoindre le canal — c’est gratuit