Principal Security Engineer, Orchestration and Automation
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+13 more
Job description
The Cyber Detection & Response Automation Engineer is responsible for building the automation, orchestration, and AI-driven capabilities that power the organization’s detection and response function. This role treats the SIEM as one component in a broader automation ecosystem - the primary focus is designing workflows, integrations, and intelligent tooling that reduce manual analyst effort, accelerate response, and scale detection coverage. The ideal candidate is an automation/orchestration engineer with a security background: comfortable building integrations and pipelines across multiple tools, applying AI/ML or LLM-assisted techniques to triage and enrichment, and engineering detection logic. This person will also maintain a working level of SIEM platform administration - data onboarding, health, and configuration - to support the automation and detection layers built on top of it, and will partner closely with Security Operations and the Detection Engineering Lead.
What you’ll be doing:
- Design, build, and maintain orchestration workflows and SOAR playbooks that automate triage, enrichment, containment, and response actions across the security tool stack.
- Apply AI/ML and LLM-assisted techniques (e.g., automated alert summarization, natural-language investigation assistance, anomaly scoring) to reduce analyst workload and speed decision-making.
- Develop and maintain Python-based integrations and APIs connecting the SIEM, SOAR, EDR, ticketing, threat intel, and cloud platforms into unified automated workflows.
- Design, build, and tune SIEM correlation rules, alerts, and detection use cases mapped to MITRE ATT&CK, with an eye toward which detections can be paired with automated response.
- Own core SIEM administration tasks needed to support automation and detection: data source onboarding, index/data model health, log ingestion monitoring, and configuration management.
- Build and maintain custom field extractions, parsers, and content packs to ensure new data sources are automation- and detection-ready.
- Continuously tune detections and automation logic to improve signal-to-noise ratio, reduce false positives, and reduce mean-time-to-respond (MTTR).
- Create dashboards and reporting that measure automation coverage, orchestration reliability, AI-assisted triage accuracy, and detection effectiveness.
- Apply CI/CD and infrastructure-as-code practices to manage detection content, playbooks, and integrations as versioned, testable code.
- Evaluate and pilot new automation, orchestration, and AI tooling to expand the detection and response automation footprint.
Requirements
- 5+ years building automation, orchestration, or SOAR playbooks in a cyber security or SOC environment.
- 3+ years of SIEM engineering or administration experience - data onboarding, correlation rule development, platform configuration.
- Strong Python (or comparable scripting) skills; experience building APIs/integrations across security and IT tooling.
- Hands-on experience with AI/ML or LLM-based tooling applied to security use cases - triage, summarization, enrichment, and/or anomaly detection; experience building such capability strongly preferred.
- Working knowledge of MITRE ATT&CK and experience mapping detections/automation to adversary tactics and techniques.
- Experience with a SOAR or security orchestration platform (e.g., NG-SIEM Fusion, Splunk SOAR, Palo Alto XSOAR, Tines, or similar).
- Cloud security experience (AWS, Azure, or GCP), including automation for ingesting and processing security data from cloud sources.
- Experience with CI/CD, infrastructure-as-code, and version-controlling detection/automation content.
- Familiarity with containerized and serverless environments and their automation/logging considerations.
- SIEM, SOAR, or security automation platform certification preferred.
- Regulatory compliance experience a plus.
Stay up to date on everything Blackbaud, follow us on Linkedin, Twitter, Instagram, Facebook and YouTube
Benefits & conditions
The starting base pay is $117,200.00 to $157,500.00. Blackbaud may pay more or less based on employee qualifications, market value, Company finances, and other operational considerations.
Benefits Include:
- Medical, dental, and vision insurance
- Remote-flexible workforce
- Wellness Programs
- 401(k) program with employer match
- Flexible paid time off
- Generous Parental Leave
- Donations for Doers
- Pet insurance, legal and identity protection
- Tuition reimbursement program
About the company
Blackbaud powers social impact through purpose-driven technology and responsible AI. Guided by our Intelligence for Good® vision, we’re building a culture where innovation, trust, and human expertise come together to help organizations make a greater difference in the world.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
9 Ways to Make Money Hacking
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Dev Digest 134 - Where pixels sing?