Lead Cyber Detection & Response Automation Engineer

Blackbaud

Northern (KY)

Hybrid

USD 117,000 - 158,000

Full time

10 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical insurance
Remote-friendly
Wellness programs
401(k) match
Flexible PTO
Parental leave
Donations for Doers
Pet insurance
Identity protection
Tuition reimbursement

Job summary

Blackbaud is seeking a Cyber Detection & Response Automation Engineer to design and implement orchestration workflows that automate triage, enrichment, and response across the security tool stack. You will build Python-based integrations connecting SIEM, SOAR, EDR, ticketing, threat intel, and cloud platforms, while tuning detections against MITRE ATT&CK.

The role emphasizes AI/ML or LLM-assisted techniques to reduce analyst workload, improve MTTR, and expand automation coverage, with

Qualifications

  • 5+ years building automation, orchestration, or SOAR playbooks in a cyber security or SOC environment.
  • 3+ years of SIEM engineering or administration experience - data onboarding, correlation rule development, platform configuration.
  • Strong Python (or comparable scripting) skills; experience building APIs/integrations across security and IT tooling.
  • Hands-on experience with AI/ML or LLM-based tooling applied to security use cases - triage, summarization, enrichment, and/or anomaly detection; experience building such capability strongly preferred.
  • Working knowledge of MITRE ATT&CK and experience mapping detections/automation to adversary tactics and techniques.
  • Experience with a SOAR or security orchestration platform (e.g., NG-SIEM Fusion, Splunk SOAR, Palo Alto XSOAR, Tines, or similar).
  • Cloud security experience (AWS, Azure, or GCP), including automation for ingesting and processing security data from cloud sources.
  • Experience with CI/CD, infrastructure-as-code, and version-controlling detection/automation content.
  • Familiarity with containerized and serverless environments and their automation/logging considerations.
  • SIEM, SOAR, or security automation platform certification preferred.
  • Regulatory compliance experience a plus.

Responsibilities

  • Design, build, and maintain orchestration workflows and SOAR playbooks that automate triage, enrichment, containment, and response actions across the security tool stack.
  • Apply AI/ML and LLM-assisted techniques to reduce analyst workload and speed decision-making.
  • Develop and maintain Python-based integrations and APIs connecting the SIEM, SOAR, EDR, ticketing, threat intel, and cloud platforms into unified automated workflows.
  • Design, build, and tune SIEM correlation rules, alerts, and detection use cases mapped to MITRE ATT&CK.
  • Own core SIEM administration tasks needed to support automation and detection: data source onboarding, index/data model health, log ingestion monitoring, and configuration management.
  • Build and maintain custom field extractions, parsers, and content packs to ensure new data sources are automation- and detection-ready.
  • Continuously tune detections and automation logic to improve signal-to-noise ratio, reduce false positives, and reduce MTTR.
  • Create dashboards and reporting that measure automation coverage, orchestration reliability, AI-assisted triage accuracy, and detection effectiveness.
  • Apply CI/CD and infrastructure-as-code practices to manage detection content, playbooks, and integrations as versioned, testable code.
  • Evaluate and pilot new automation, orchestration, and AI tooling to expand the detection and response automation footprint.

Skills

Automation
SOAR playbooks
Python
AI/ML tooling
MITRE ATT&CK
SIEM engineering
Cloud security
CI/CD
Containerization
Security automation

Tools

NG-SIEM Fusion
Splunk SOAR
Palo Alto XSOAR
Tines
AWS
Azure
GCP

Job description

Blackbaud is seeking a Cyber Detection & Response Automation Engineer to design and implement orchestration workflows that automate triage, enrichment, and response across the security tool stack. You will build Python-based integrations connecting SIEM, SOAR, EDR, ticketing, threat intel, and cloud platforms, while tuning detections against MITRE ATT&CK.

The role emphasizes AI/ML or LLM-assisted techniques to reduce analyst workload, improve MTTR, and expand automation coverage, with

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Detection & Response Automation Engineer
Senior Cyber Detection & Response Automation Engineer

Blackbaud • United States

Remote
USD 117,000 - 158,000
Medical, dental, and vision insurance
Remote-flexible workforce
Wellness Programs
+6
Senior Cyber SOAR & Automation Engineer
Senior Cyber SOAR & Automation Engineer

Blackbaud • Charleston (SC)

Hybrid
USD 117,000 - 158,000
Remote-flexible workforce
Medical, dental, and vision insurance
401(k) with employer match
+4
Principal Security Engineer, Orchestration and Automation
Principal Security Engineer, Orchestration and Automation

Blackbaud • Charleston (SC)

Hybrid
USD 117,000 - 158,000
Remote-flexible workforce
Medical, dental, and vision insurance
401(k) with employer match
+4
Principal Security Engineer, Orchestration and Automation
Principal Security Engineer, Orchestration and Automation

Blackbaud • Northern (KY)

Hybrid
USD 117,000 - 158,000
Medical insurance
Remote-friendly
Wellness programs
+7
Detection and Response Engineer
Detection and Response Engineer

The available sources do not contain information about the company name for rounx.com. • United States

On-site
USD 120,000 - 180,000
Cybersecurity Automation Engineer — Automate Detection & Response
Cybersecurity Automation Engineer — Automate Detection & Response

First Merchants Brand • Daleville (AL)

On-site
USD 90,000 - 130,000
Medical, Dental and Vision Insurance
401k
Health Savings and Flexible Spending
+4
Remote Detection Engineer: Build & Automate Detections
Remote Detection Engineer: Build & Automate Detections

Binary-Defense • Houston (TX)

Remote
USD 110,000 - 170,000
Medical, dental, and vision coverage
401k match
Remote-friendly work environment
+1
Detection & Response Security Engineer
Detection & Response Security Engineer

Coinscapture • Northern (KY)

Hybrid
USD 140,000 - 210,000
AI-Driven Detection & Response Engineer
AI-Driven Detection & Response Engineer

The available sources do not contain information about the company name for rounx.com. • United States

On-site
USD 120,000 - 180,000
Senior AI-Driven SOC Automation Lead
Senior AI-Driven SOC Automation Lead

Toyota Tsusho Systems • Plano (TX)

On-site
USD 130,000 - 170,000