Principal Security Engineer, Orchestration and Automation

Blackbaud

Charleston (SC)

Hybrid

USD 117,000 - 158,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Remote-flexible workforce
Medical, dental, and vision insurance
401(k) with employer match
Generous PTO
Tuition reimbursement
Donations for Doers
Pet insurance

Job summary

Blackbaud seeks a Cyber Detection & Response Automation Engineer to design and maintain automation and SOAR workflows that reduce analyst effort and accelerate response. You will integrate SIEM, SOAR, EDR, and cloud data, applying AI-assisted techniques to triage and enrich alerts while tuning detection logic.

You’ll own core SIEM tasks, build pipelines, and craft content packs, with a focus on MITRE ATT&CK mappings and scalable automation across the security stack.

Qualifications

  • 5+ years building automation, orchestration, or SOAR playbooks in a cyber security or SOC environment.
  • 3+ years of SIEM engineering or administration experience.
  • Strong Python skills and experience building APIs across security tools.
  • Hands-on AI/ML or LLM tooling for security use cases.
  • Working knowledge of MITRE ATT&CK and mapping detections to tactics.
  • Experience with SOAR platforms (NG-SIEM Fusion, Splunk SOAR, XSOAR, or similar).
  • Cloud security experience (AWS, Azure, GCP).
  • CI/CD, IaC, and version-controlling content.

Responsibilities

  • Design, build, and maintain orchestration workflows and SOAR playbooks across the security tool stack.
  • Apply AI/ML and LLM-assisted techniques to reduce analyst workload and speed decision-making.
  • Develop Python-based integrations connecting SIEM, SOAR, EDR, ticketing, threat intel, and cloud platforms.
  • Design and tune SIEM correlation rules and alerts mapped to MITRE ATT&CK.
  • Own SIEM administration tasks: data onboarding, health, and configuration.
  • Create content packs and parsers for new data sources.
  • Tune detections to reduce false positives and MTTR.
  • Create dashboards measuring automation coverage and detection effectiveness.
  • Apply CI/CD practices to manage content as code.
  • Pilot new automation tools to expand the automation footprint.

Skills

Automation & Orchestration
SIEM engineering
Python scripting
AI/ML for security
MITRE ATT&CK
SOAR platform
Cloud security
CI/CD & IaC
Container/serverless
Security certifications

Tools

NG-SIEM Fusion
Splunk SOAR
Palo Alto XSOAR
Tines

Job description

Cyber Detection & Response Automation Engineer

The Cyber Detection & Response Automation Engineer is responsible for building the automation, orchestration, and AI-driven capabilities that power the organization’s detection and response function. This role treats the SIEM as one component in a broader automation ecosystem — the primary focus is designing workflows, integrations, and intelligent tooling that reduce manual analyst effort, accelerate response, and scale detection coverage. The ideal candidate is an automation/orchestration engineer with a security background: comfortable building integrations and pipelines across multiple tools, applying AI/ML or LLM-assisted techniques to triage and enrichment, and engineering detection logic. This person will also maintain a working level of SIEM platform administration — data onboarding, health, and configuration — to support the automation and detection layers built on top of it, and will partner closely with Security Operations and the Detection Engineering Lead.

What You'll Be Doing
  • Design, build, and maintain orchestration workflows and SOAR playbooks that automate triage, enrichment, containment, and response actions across the security tool stack.
  • Apply AI/ML and LLM-assisted techniques (e.g., automated alert summarization, natural-language investigation assistance, anomaly scoring) to reduce analyst workload and speed decision-making.
  • Develop and maintain Python-based integrations and APIs connecting the SIEM, SOAR, EDR, ticketing, threat intel, and cloud platforms into unified automated workflows.
  • Design, build, and tune SIEM correlation rules, alerts, and detection use cases mapped to MITRE ATT&CK, with an eye toward which detections can be paired with automated response.
  • Own core SIEM administration tasks needed to support automation and detection: data source onboarding, index/data model health, log ingestion monitoring, and configuration management.
  • Build and maintain custom field extractions, parsers, and content packs to ensure new data sources are automation- and detection-ready.
  • Continuously tune detections and automation logic to improve signal-to-noise ratio, reduce false positives, and reduce mean-time-to-respond (MTTR).
  • Create dashboards and reporting that measure automation coverage, orchestration reliability, AI-assisted triage accuracy, and detection effectiveness.
  • Apply CI/CD and infrastructure-as-code practices to manage detection content, playbooks, and integrations as versioned, testable code.
  • Evaluate and pilot new automation, orchestration, and AI tooling to expand the detection and response automation footprint.
What We'll Want You To Have
  • 5+ years building automation, orchestration, or SOAR playbooks in a cyber security or SOC environment.
  • 3+ years of SIEM engineering or administration experience - data onboarding, correlation rule development, platform configuration.
  • Strong Python (or comparable scripting) skills; experience building APIs/integrations across security and IT tooling.
  • Hands-on experience with AI/ML or LLM-based tooling applied to security use cases - triage, summarization, enrichment, and/or anomaly detection; experience building such capability strongly preferred.
  • Working knowledge of MITRE ATT&CK and experience mapping detections/automation to adversary tactics and techniques.
  • Experience with a SOAR or security orchestration platform (e.g., NG-SIEM Fusion, Splunk SOAR, Palo Alto XSOAR, Tines, or similar).
  • Cloud security experience (AWS, Azure, or GCP), including automation for ingesting and processing security data from cloud sources.
  • Experience with CI/CD, infrastructure-as-code, and version-controlling detection/automation content.
  • Familiarity with containerized and serverless environments and their automation/logging considerations.
  • SIEM, SOAR, or security automation platform certification preferred.
  • Regulatory compliance experience a plus.

Stay up to date on everything Blackbaud, follow us on Linkedin, Twitter, Instagram, Facebook and YouTube

Blackbaud powers social impact through purpose-driven technology and responsible AI. Guided by our Intelligence for Good vision, we’re building a culture where innovation, trust, and human expertise come together to help organizations make a greater difference in the world.

Blackbaud is proud to be an equal opportunity employer and is committed to maintaining a diverse and inclusive work environment. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, physical or mental disability, age, or veteran status or any other basis protected by federal, state, or local law.

The starting base pay is $117,200.00 to $157,500.00. Blackbaud may pay more or less based on employee qualifications, market value, Company finances, and other operational considerations.

Benefits Include
  • Medical, dental, and vision insurance
  • Remote-flexible workforce
  • Wellness Programs
  • 401(k) program with employer match
  • Flexible paid time off
  • Generous Parental Leave
  • Donations for Doers
  • Pet insurance, legal and identity protection
  • Tuition reimbursement program
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Security Engineer, Orchestration and Automation
Principal Security Engineer, Orchestration and Automation

Blackbaud • Northern (KY)

Hybrid
USD 117,000 - 158,000
Medical insurance
Remote-friendly
Wellness programs
+7
Lead Cyber Detection & Response Automation Engineer
Lead Cyber Detection & Response Automation Engineer

Blackbaud • Northern (KY)

Hybrid
USD 117,000 - 158,000
Medical insurance
Remote-friendly
Wellness programs
+7
Senior Cyber SOAR & Automation Engineer
Senior Cyber SOAR & Automation Engineer

Blackbaud • Charleston (SC)

Hybrid
USD 117,000 - 158,000
Remote-flexible workforce
Medical, dental, and vision insurance
401(k) with employer match
+4
Senior Security Automation Engineer
Senior Security Automation Engineer

Piper Companies • United States

Remote
USD 130,000 - 145,000
Medical plan
Dental plan
Vision plan
+3
Senior Security Automation & SOAR Engineer
Senior Security Automation & SOAR Engineer

Relha LLC • New York (NY), Northern (KY)

Hybrid
USD 140,000 - 155,000
Manager, Data Protection Services
Manager, Data Protection Services

Blackbaud • Charleston (SC)

Hybrid
USD 117,000 - 158,000
Medical, dental, and vision insurance
Remote-flexible workforce
401(k) program with employer match
+2
Senior Cyber Security Software Engineer
Senior Cyber Security Software Engineer

Optimum • Bethpage (NY)

On-site
USD 100,000 - 165,000
Security Incident Response Orchestration Lead
Security Incident Response Orchestration Lead

Koitecc Solutions • Denver (CO), Northern (KY)

Hybrid
USD 180,000 - 240,000
Senior Security Engineer, Cyber Threat Intelligence
Senior Security Engineer, Cyber Threat Intelligence

Blackbaud • Charleston (SC)

Remote
USD 101,000 - 133,000
Medical, dental, and vision insurance
401(k) program with employer match
Flexible paid time off
+4
Manager, Software Engineering - AI and Data Platform
Manager, Software Engineering - AI and Data Platform

Blackbaud • Charleston (SC)

Hybrid
USD 133,000 - 174,000
Medical, dental, and vision insurance
Remote‑flexible workforce
Wellness Programs
+4