Remote Principal Incident Response & Forensics Lead

Blackbaud

Charleston (SC)

On-site

USD 102,000 - 133,000

Full time

13 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical, dental, and vision insurance
Remote-flexible workforce
Wellness Programs
401(k) with employer match
Flexible paid time off
Parental Leave
Donations for Doers
Pet insurance, identity protection
Tuition reimbursement program

Job summary

Blackbaud is seeking a Principal Incident Response Analyst for the Threat Detection & Response team to lead in-depth security event analysis, rapid incident containment, and forensic investigations. You will drive threat hunting, coordinate with cross-functional teams, and leverage threat intelligence to strengthen detection capabilities across the organization.

The role requires extensive experience in incident response, digital forensics, and familiarity with industry frameworks.

Qualifications

  • 8+ years of cyber incident response experience in a large and complex environment.
  • Certifications such as CISSP, GCIH, GFCA, GREM, ECIH are highly desirable.
  • Subject matter expertise with security tools and technologies, such as SIEM, IDS/IPS, EDR, and network monitoring solutions.
  • Strong knowledge of incident response methodologies, including containment, eradication, recovery, and common frameworks (NIST, SANS, CSA).
  • Ability to acquire and analyze endpoint and network artifacts, volatile memory, malicious files/binaries and scripts.
  • Experience with forensic tools such as Encase, FTK, Axiom, and Cellebrite for digital investigations.
  • Collaborate with forensic analysts, law enforcement, and legal experts to preserve evidence and prevent spoliation.

Responsibilities

  • Conduct in-depth analysis of security events and indicators to determine the nature and severity of incidents.
  • Respond promptly to security incidents, following established incident response procedures.
  • Coordinate and collaborate with cross-functional teams to contain and mitigate threats effectively.
  • Perform forensic investigations to determine the root cause and develop remediation strategies.
  • Lead regular threat hunt activities to identify and investigate gaps in detection.
  • Utilize threat intelligence and best practices to enhance incident detection capabilities.

Skills

Cyber incident response
Threat hunting
Cyber forensics
Security monitoring
Incident response frameworks

Tools

SIEM
IDS/IPS
EDR
Network monitoring

Job description

Blackbaud is seeking a Principal Incident Response Analyst for the Threat Detection & Response team to lead in-depth security event analysis, rapid incident containment, and forensic investigations. You will drive threat hunting, coordinate with cross-functional teams, and leverage threat intelligence to strengthen detection capabilities across the organization.

The role requires extensive experience in incident response, digital forensics, and familiarity with industry frameworks.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Incident Response Lead Consultant
Remote Incident Response Lead Consultant

CrowdStrike, Inc. • Sunnyvale (CA)

Remote
USD 115,000 - 160,000
Health benefits
Paid time off
Professional development
+1
Remote Principal Cyber Incident Response Lead
Remote Principal Cyber Incident Response Lead

Amtrak • United States

Remote
USD 125,000 - 161,000
Health Insurance
401K with Employer Match
Generous Paid Time Off
+3
Remote Principal DFIR Lead & Incident Response
Remote Principal DFIR Lead & Incident Response

Tokio Marine HCC • United States

On-site
USD 122,000 - 270,000
Remote Senior Incident Responder: Executive Cyber Defense
Remote Senior Incident Responder: Executive Cyber Defense

BlackCloak • United States

Remote
USD 105,000 - 115,000
Remote work USA
Medical benefits
401k with match
+4
Senior Incident Response Lead - Detection & Remediation
Senior Incident Response Lead - Detection & Remediation

Dun- • Jacksonville (FL)

On-site
USD 110,000 - 170,000
PTO
Parental leave
Sick time
+5
Senior DFIR Lead: Incident Response & Forensics
Senior DFIR Lead: Incident Response & Forensics

LevelBlue • United States

Hybrid
USD 120,000 - 170,000
Comprehensive medical, dental, and vis
401(k) with employer matching
Generous paid time off and holidays
+4
Senior Incident Response Leader (Remote)
Senior Incident Response Leader (Remote)

Centene Corp. • Illinois

On-site
USD 121,000 - 225,000
Health insurance
401K and stock purchase plans
Tuition reimbursement
+2
Senior DFIR Lead – Incident Response & Forensics Expert
Senior DFIR Lead – Incident Response & Forensics Expert

Trustwave • United States

Hybrid
USD 110,000 - 160,000
Comprehensive medical, dental, and vis
401(k) with employer matching
Generous paid time off and holidays
+4
Senior Forensic Lead — Incident Response & Investigations
Senior Forensic Lead — Incident Response & Investigations

Arete Advisors, LLC • Northern (KY)

Hybrid
USD 140,000 - 190,000
Principal Incident Response & Forensics Consultant — Remote
Principal Incident Response & Forensics Consultant — Remote

Kivu Consulting (a part of Quorum Cyber) • Orlando (FL)

Remote
USD 150,000 - 165,000