Principal Security Engineer – Orchestration and Automation

🔥 16 hours ago

🇺🇸 United States – Remote

💵 $117.2k - $157.5k / year

⏰ Full Time

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Blackbaud

Blackbaud

1001 - 5000 employees

☁️ SaaS

🤝 Non-profit

🤝 B2B

💰 $6.5M Series A on 2000-02

SaaS • Non-profit • B2B

Blackbaud is a cloud software company that builds intelligent solutions for social impact, focusing on nonprofit organizations. It provides products and services for fundraising, donor management, engagement, and sector-specific cloud solutions to help charities, educational institutions, and other mission-driven organizations move faster and work smarter. Blackbaud also offers training, support, developer resources, a partner marketplace, and industry research through the Blackbaud Institute. The company emphasizes privacy, security, and corporate social responsibility.

📋 Description

• Design, build, and maintain orchestration workflows and SOAR playbooks automating triage, enrichment, containment, and response across the security tool stack • Apply AI/ML and LLM-assisted techniques to automate alert summarization, investigation assistance, and anomaly scoring • Develop and maintain Python-based integrations and APIs connecting SIEM, SOAR, EDR, ticketing, threat intelligence, and cloud platforms • Design, build, and tune SIEM correlation rules, alerts, and MITRE ATT&CK-mapped detection use cases • Perform SIEM administration, including data source onboarding, index/data model health, log ingestion monitoring, and configuration management • Build and maintain custom field extractions, parsers, and content packs • Tune detections and automation logic to improve signal-to-noise ratio, reduce false positives, and reduce MTTR • Create dashboards and reporting measuring automation coverage, orchestration reliability, AI-assisted triage accuracy, and detection effectiveness • Apply CI/CD and infrastructure-as-code practices to manage detection content, playbooks, and integrations as versioned, testable code • Evaluate and pilot new automation, orchestration, and AI tooling • Partner closely with Security Operations and the Detection Engineering Lead

🎯 Requirements

• 5+ years building automation, orchestration, or SOAR playbooks in a cyber security or SOC environment • 3+ years of SIEM engineering or administration experience, including data onboarding, correlation rule development, and platform configuration • Strong Python or comparable scripting skills • Experience building APIs and integrations across security and IT tooling • Hands-on experience with AI/ML or LLM-based tooling applied to security use cases such as triage, summarization, enrichment, and/or anomaly detection • Working knowledge of MITRE ATT&CK and experience mapping detections/automation to adversary tactics and techniques • Experience with a SOAR or security orchestration platform • Cloud security experience with AWS, Azure, or GCP, including automation for ingesting and processing security data from cloud sources • Experience with CI/CD, infrastructure-as-code, and version-controlling detection/automation content • Familiarity with containerized and serverless environments and their automation/logging considerations • SIEM, SOAR, or security automation platform certification preferred • Regulatory compliance experience a plus

🏖️ Benefits

• Medical, dental, and vision insurance • Remote-flexible workforce • Wellness Programs • 401(k) program with employer match • Flexible paid time off • Generous Parental Leave • Donations for Doers • Pet insurance, legal and identity protection • Tuition reimbursement program

Apply Now

Similar Jobs

🕒 Yesterday

Tidal Financial Group

51 - 200

💼 Consulting

📣 Marketing

💸 Finance

VP leading IT and cybersecurity strategy, reliability, and risk for Tidal Financial Group’s ETF investment technology platform. Advising executives and managing teams, vendors, incidents, and compliance.

🕒 Yesterday

CVS Health

10,000+ employees

🏥 Healthcare

⚕️ Healthcare Insurance

🛒 Retail

AVP securing CVS Health’s cloud, container, and AI platforms. Leading enterprise security strategy, engineering teams, governance, and AI protection.

🕒 Yesterday

GE Vernova

10,000+ employees

💼 Consulting

📦 Logistics

🏭 Manufacturing

Principal PSIRT leader protecting GE Vernova's critical energy infrastructure products. Managing vulnerability disclosure, CVE records, AI-powered incident response, and regulatory coordination.

🕒 Yesterday

GE Vernova

10,000+ employees

💼 Consulting

📦 Logistics

🏭 Manufacturing

GE Vernova PSIRT principal protecting critical energy infrastructure. Leading vulnerability disclosure, CVE governance, customer incident response, and AI-enabled cybersecurity operations.

🕒 Yesterday

Gainwell Technologies

10,000+ employees

💼 Consulting

📦 Logistics

⚕️ Healthcare Insurance

Information Security Officer overseeing application security, access controls, compliance, and investigations. Supporting Gainwell Technologies’ healthcare technology mission across the United States.