Principal Incident Response Engineer

Blackbaud

United States

Remote

USD 117,000 - 158,000

Full time

11 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical, dental, and vision insurance
Remote-flexible workforce
401(k) with employer match
Flexible paid time off
Generous parental leave
Tuition reimbursement program
Pet insurance

Job summary

Blackbaud is seeking a Principal Incident Response Engineer to lead digital forensics, incident response, and threat hunting for our Threat Detection & Response team. You will drive containment, remediation, and root-cause analysis across on-prem, hybrid, and cloud workloads.

You will guide high-severity incidents, coordinate with cross-functional teams, and advance AI/LLM integrations for stronger detection. We offer a remote-flexible workforce and a comprehensive benefits package.

Qualifications

  • 8+ years of cyber incident response experience.
  • Certifications such as CISSP, GCIH, GFCA, GREM, or ECIH are highly desirable.
  • Proficient with security tools (SIEM/IDS/IPS/EDR) and cloud monitoring solutions.
  • Solid knowledge of incident response lifecycle (containment, eradication, recovery) and common frameworks (NIST, SANS, CSA).
  • Experience with digital forensics tools and procedures.

Responsibilities

  • Lead in-depth analysis of security events to determine incident severity.
  • Respond to incidents following established IR procedures.
  • Act as technical lead for high-severity security incidents.
  • Coordinate with cross-functional teams to contain and mitigate threats.
  • Perform forensic investigations to determine root causes and remediation strategies across on-prem, hybrid, and cloud workloads.
  • Lead intelligence-driven threat hunting to identify gaps in detection.
  • Collaborate with detection engineering to improve MITRE ATT&CK coverage.
  • Support AI/LLM workflows to enhance incident detection and response.
  • Coordinate with law enforcement and legal teams for evidence handling and preservation.

Skills

Incident response
Digital forensics
Threat hunting
MITRE ATT&CK
AI/LLM workflows

Education

CISSP
GCIH
GFCA
GREM
ECIH

Tools

SIEM
IDS/IPS
EDR
Cloud monitoring

Job description

About the role:

We are looking for an accomplished, high-performing Principal Incident Response Engineer for our Threat Detection & Response team with experience performing digital forensics, incident response, and threat hunting. The Principal Incident Response Engineer is responsible for ensuring the confidentiality, integrity, and availability of critical information and IT assets. This role requires a deep understanding of cybersecurity principles, incident response methodologies, digital forensics, and the ability to work efficiently under pressure.


What you’ll be doing:


  • Conduct in-depth analysis of security events and indicators to determine the nature and severity of incidents.

  • Respond promptly to security incidents, following established incident response procedures.

  • Serve as the technical lead for high‑severity security incidents.

  • Coordinate and collaborate with cross‑functional teams to contain and mitigate cyber threats effectively.

  • Perform forensic investigations to determine the root cause of incidents and develop appropriate remediation strategies across on-prem, hybrid, and cloud workloads.

  • Lead regular intelligence‑driven threat hunt activities to identify and investigate gaps in detection.

  • Partner with detection engineering to increase coverage across MITRE ATT&CK framework.

  • Identify, scope, and support the development of AI/LLM workflows to enhance incident detection and response capabilities.

  • Collaborate with other forensic analysts, law enforcement officers, and legal experts to identify methods and procedures for recovery, preservation, and presentation of computer evidence, ensuring proper precautions are taken in the preservation and prevention of spoliation of electronic evidence.

  • Support On‑call rotation as applicable.


What we’ll want you to have:


  • 8+ years of cyber incident response experience in a relevant environment.

  • Cyber industry certifications are highly desirable (CISSP, GCIH, GFCA, GREM, ECIH).

  • Subject matter expertise with security tools and technologies, such as SIEM, IDS/IPS, EDR, and cloud monitoring solutions.

  • Strong knowledge of incident response methodologies, including containment, eradication, recovery, and common security frameworks (NIST, SANS, CSA).

  • Ability to acquire and analyze endpoint and network artifacts, volatile memory, malicious files/binaries and scripts.

  • Experience with forensic tools, such as Encase, FTK, Axiom, and Cellebrite to carry out digital forensic investigations.


Stay up to date on everything Blackbaud, follow us on Linkedin, Twitter, Instagram, Facebook and YouTube


Blackbaud powers social impact through purpose‑driven technology and responsible AI.


Guided by our Intelligence for Good® vision, we’re building a culture where innovation, trust, and human expertise come together to help organizations make a greater difference in the world.


Blackbaud is proud to be an equal opportunity employer and is committed to maintaining a diverse and inclusive work environment.


All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, physical or mental disability, age, or veteran status or any other basis protected by federal, state, or local law.


The starting base pay is $117,200.00 to $157,500.00. Blackbaud may pay more or less based on employee qualifications, market value, Company finances, and other operational considerations.


Benefits Include:


  • Medical, dental, and vision insurance

  • Remote-flexible workforce

  • Wellness Programs

  • 401(k) program with employer match

  • Flexible paid time off

  • Generous Parental Leave

  • Donations for Doers

  • Pet insurance, legal and identity protection

  • Tuition reimbursement program


Blackbaud (NASDAQ: BLKB) is the world’s leading cloud software company powering social good. Serving the entire social good community—nonprofits, foundations, corporations, education institutions, healthcare institutions and individual change agents—Blackbaud connects and empowers organizations to increase their impact through software, services, expertise, and data intelligence. Serving the industry for more than three decades, Blackbaud is headquartered in Charleston, South Carolina and has operations in the United States, Australia, Canada, and the United Kingdom.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal Security Engineer, Orchestration and Automation
Principal Security Engineer, Orchestration and Automation

Blackbaud • Northern (KY)

On-site
USD 117,000 - 158,000
Medical insurance
Remote-friendly
Wellness programs
+7
Senior Manager, Professional Services
Senior Manager, Professional Services

Blackbaud • Northern (KY)

On-site
USD 102,000 - 133,000
Remote-flexible workforce
401(k) program with employer match
Generous Parental Leave
Senior Manager, Enterprise AI Platform
Senior Manager, Enterprise AI Platform

Blackbaud • United States

Remote
USD 117,000 - 158,000
Remote-friendly policy
Health & wellness programs
401(k) program with employer match
+2
Senior Manager, Professional Services
Senior Manager, Professional Services

Blackbaud • United States

On-site
USD 102,000 - 133,000
Remote‑flexible workforce
Wellness programs
401(k) with employer match
+2
Principal Security Engineer, Orchestration and Automation
Principal Security Engineer, Orchestration and Automation

Blackbaud • Charleston (SC)

On-site
USD 117,000 - 158,000
Remote-flexible workforce
Medical, dental, and vision insurance
401(k) with employer match
+4
Principal Tax Analyst
Principal Tax Analyst

Blackbaud • United States

On-site
USD 88,000 - 114,000
Remote-flexible workforce
Wellness Programs
401(k) program with employer match
+1
Sales Solutions Architect, Principal
Sales Solutions Architect, Principal

Blackbaud • Northern (KY)

On-site
USD 135,000 - 180,000
Medical, dental, and vision insurance
Remote-flexible workforce
Wellness Programs
+6
Principal Software Engineer, .NET / Data / AI
Principal Software Engineer, .NET / Data / AI

Blackbaud • Charleston (SC)

On-site
USD 133,700 - 173,800
Medical, dental, and vision insurance
401(k) program with employer match
Flexible paid time off
+2
Business Portfolio Lead
Business Portfolio Lead

Blackbaud • Charleston (SC)

On-site
USD 87,700 - 114,200
Medical, dental, and vision insurance
401(k) program with employer match
Flexible paid time off
+2
Senior Security Engineer, Cyber Threat Intelligence
Senior Security Engineer, Cyber Threat Intelligence

Blackbaud • Charleston (SC)

On-site
USD 101,900 - 132,800
Medical, dental, and vision insurance
401(k) program with employer match
Flexible paid time off
+4