Blackbaud, Inc.

Principal Security Engineer, Orchestration and Automation

Blackbaud, Inc.$117K — $157K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in automation, orchestration, or SOAR playbooks in cybersecurity/SOC environments.
  • 3+ years of SIEM engineering or administration experience.
  • Strong Python or comparable scripting skills.
  • Hands-on experience with AI/ML or LLM-based security tooling.
  • Knowledge of MITRE ATT&CK principles for detection mapping.
  • Experience with SOAR or security orchestration platforms.
  • Cloud security experience with AWS, Azure, or GCP.
  • Experience with CI/CD and infrastructure-as-code practices.

Responsibilities

  • Design and maintain orchestration workflows and SOAR playbooks for automation.
  • Apply AI/ML techniques to enhance security processes and analyst workloads.
  • Develop Python-based integrations and APIs for unified automated workflows.
  • Create and tune SIEM correlation rules and detection use cases.
  • Carry out essential SIEM tasks for automation and detection support.
  • Build custom extractions and content packs for new data sources.
  • Continuously improve detections and reduce false positives via tuning.
  • Create dashboards to measure automation and detection effectiveness.

Benefits

  • Medical, dental, and vision insurance.
  • Remote-flexible workforce.
  • Wellness programs.
  • 401(k) program with employer match.
  • Flexible paid time off.
  • Generous parental leave.
  • Donations for doers program.
  • Pet insurance, legal, and identity protection.
  • Tuition reimbursement program.
Full Job Description

Cyber Detection & Response Automation Engineer

The Cyber Detection & Response Automation Engineer is responsible for building the automation, orchestration, and AI-driven capabilities that power the organization's detection and response function. This role treats the SIEM as one component in a broader automation ecosystem — the primary focus is designing workflows, integrations, and intelligent tooling that reduce manual analyst effort, accelerate response, and scale detection coverage. The ideal candidate is an automation/orchestration engineer with a security background: comfortable building integrations and pipelines across multiple tools, applying AI/ML or LLM-assisted techniques to triage and enrichment, and engineering detection logic. This person will also maintain a working level of SIEM platform administration — data onboarding, health, and configuration — to support the automation and detection layers built on top of it, and will partner closely with Security Operations and the Detection Engineering Lead.

What you'll be doing:

  • Design, build, and maintain orchestration workflows and SOAR playbooks that automate triage, enrichment, containment, and response actions across the security tool stack.
  • Apply AI/ML and LLM-assisted techniques (e.g., automated alert summarization, natural-language investigation assistance, anomaly scoring) to reduce analyst workload and speed decision-making.
  • Develop and maintain Python-based integrations and APIs connecting the SIEM, SOAR, EDR, ticketing, threat intel, and cloud platforms into unified automated workflows.
  • Design, build, and tune SIEM correlation rules, alerts, and detection use cases mapped to MITRE ATT&CK, with an eye toward which detections can be paired with automated response.
  • Own core SIEM administration tasks needed to support automation and detection: data source onboarding, index/data model health, log ingestion monitoring, and configuration management.
  • Build and maintain custom field extractions, parsers, and content packs to ensure new data sources are automation- and detection-ready.
  • Continuously tune detections and automation logic to improve signal-to-noise ratio, reduce false positives, and reduce mean-time-to-respond (MTTR).
  • Create dashboards and reporting that measure automation coverage, orchestration reliability, AI-assisted triage accuracy, and detection effectiveness.
  • Apply CI/CD and infrastructure-as-code practices to manage detection content, playbooks, and integrations as versioned, testable code.
  • Evaluate and pilot new automation, orchestration, and AI tooling to expand the detection and response automation footprint.

What we'll want you to have:

  • 5+ years building automation, orchestration, or SOAR playbooks in a cyber security or SOC environment.
  • 3+ years of SIEM engineering or administration experience - data onboarding, correlation rule development, platform configuration.
  • Strong Python (or comparable scripting) skills; experience building APIs/integrations across security and IT tooling.
  • Hands-on experience with AI/ML or LLM-based tooling applied to security use cases - triage, summarization, enrichment, and/or anomaly detection; experience building such capability strongly preferred.
  • Working knowledge of MITRE ATT&CK and experience mapping detections/automation to adversary tactics and techniques.
  • Experience with a SOAR or security orchestration platform (e.g., NG-SIEM Fusion, Splunk SOAR, Palo Alto XSOAR, Tines, or similar).
  • Cloud security experience (AWS, Azure, or GCP), including automation for ingesting and processing security data from cloud sources.
  • Experience with CI/CD, infrastructure-as-code, and version-controlling detection/automation content.
  • Familiarity with containerized and serverless environments and their automation/logging considerations.
  • SIEM, SOAR, or security automation platform certification preferred.
  • Regulatory compliance experience a plus.

The starting base pay is $117,200.00 to $157,500.00. Blackbaud may pay more or less based on employee qualifications, market value, Company finances, and other operational considerations.

Benefits Include:

  • Medical, dental, and vision insurance

  • Remote-flexible workforce

  • Wellness Programs

  • 401(k) program with employer match

  • Flexible paid time off

  • Generous Parental Leave

  • Donations for Doers

  • Pet insurance, legal and identity protection

  • Tuition reimbursement program

About Blackbaud, Inc.

Blackbaud is a cloud computing provider that serves the social good community—nonprofits, foundations, corporations, education institutions, healthcare organizations, religious organizations, and individual change agents. Its products focus on fundraising, website management, CRM, analytics, financial management, ticketing, and education administration. Blackbaud's flagship product is a fundraising SQL database software, Raiser's Edge. Revenue from the sale of Raiser's Edge and related services accounted for thirty percent of Blackbaud's total revenue in 2012. Other products and services include Blackbaud Enterprise CRM, Altru, Financial Edge, Education Edge, Blackbaud NetCommunity, eTapestry, Luminate Online, Luminate CRM, Friends Asking Friends. In addition, Blackbaud offers consultancy services to nonprofit organizations. Blackbaud was founded in 1981 by Anthony Bakker. The company is headquartered in Charleston, South Carolina. It has regional offices in Austin, Texas; Plano, Texas; St. Paul, Minnesota; and Bedford, New Hampshire. Internationally, Blackbaud has offices in London, England; Sydney, Australia and Glasgow, Scotland. Michael Gianoni is Blackbaud's CEO.
Learn more about Blackbaud, Inc.
Size
3,600 employees
Market Cap
$3 billion
Industry
Net Income
$7.7 million
Founded
1981
5 Year Trend
+4.9%
Revenue
$913.2 million
NASDAQ

Similar Jobs

More Jobs at Blackbaud, Inc.

More Information Technology Jobs

Find similar Principal Security Engineer, Orchestration and Automation jobs: