EdTech Jobs
Blackbaud

Senior Threat Detection Engineer

Blackbaud
🇺🇸Remote - Anywhere - USA$102K–$133K/yrJust now
Prep for this Role

Role Snapshot

Senior Threat Detection Engineer responsible for managing company-wide information security toolsets and protecting Blackbaud's and client information through investigation of anomalous events, malware reverse engineering, and signature development.

Key Responsibilities: Investigate security alerts and anomalous events, perform intrusion analysis using SIEM technology, serve as first responder to security incidents across corporate and cloud environments, hunt for threat actor groups, build automation to optimize team performance, and mentor core analyst team.
Skills & Tools: Advanced Linux/Unix and Windows OS knowledge, expertise in public cloud platforms (preferably Microsoft Azure), network packet analysis, automation scripting (PowerShell, Python, Perl, bash), API integration, firewall and network routing fundamentals, and familiarity with NIST and MITRE frameworks.
Qualifications: 5+ years of security engineering and analysis experience in threat detection and response, plus 5+ years of IT or networking experience required. Proven ability to implement automation and manage parallel tasks with strong documentation skills.
Location: Remote - Anywhere - USA
Compensation: $102K–$133K/yr

Job Description

About the role: We are looking for a savvy, high-performing Threat Detection Engineer who will be responsible for the day-to-day management of company-wide information security toolsets and the protection of Blackbaud’s and Client’s information. Security Engineers diligently investigate anomalous events and alerts, detect malicious activities, reverse engineer malware, and write signatures and scripts for various security tools to defend against malicious activity. The Security Engineer provides reports to management regarding the negative impact to the business caused by theft, destruction, alteration, or denial of access to information. The Security Engineer is primarily involved in the analysis, reverse engineering, troubleshooting and resolution of complex threats that impact the information security infrastructure at the data, application, service, operating system, and network levels. What you’ll be doing: Build out automations in order to optimize team performance and reduce response times Document automation building process, to include defining pre-build requirements and validation criteria Perform intrusion analysis using SIEM technology, reports, data visualization, log analysis and pattern analysis First responder to security events and escalations via email, phone, and tickets across corporate user networks, data centers, and cloud environments. Assist in remediation of information security incidents Hunting for and identifying threat actor groups and respective tactics, techniques and procedures Document and communicate findings, escalate critical incidents, and interact with lines of business Improve and challenge existing processes and procedures in a very agile and fast paced cyber security environment Keep current on the threat landscape and cyber security trends Ability to adapt to fluid infrastructures and to learn/support new technologies Thought leader around new security alert content creation, data correlation, anomaly thresholds, and logic updates Primary mentor to the core analyst team with regards to training & escalation Peer reviewer as a part of the core security engineering team Advising/informing leadership on how to optimize current toolset and performing evaluation of future tools What we'll want you to have: 5+ years Security Engineering and Analysis experience, preferably in Threat Detection and Response 5+ years of IT or networking experience Intermediate to Advanced Linux/Unix OS and Windows knowledge Expertise in at least one public cloud, preferably Microsoft Azure Firewall rule and policy fundamentals Network routing fundamentals Ability to manage parallel tasks and accurately document resolutions Working knowledge of network packet analysis tools Proven ability to implement automation through scripting (e.g., Powershell, PERL, Python, bash scripting) Experience with leveraging APIs to integrate third party tooling into an existing tool stack Familiarity with cyber security frameworks such as NIST and MITRE ATT&CK Industry recognized professional certification such as Security+, CBROPS, CSA, CEH, GSEC, SSCP What we'll prefer you have: CISSP, GBFA, GCDA, GCIA, GCIH, GMON, GNFA, GOSI, GPEN, GPPA, GREM, GSOC, OSDA, OSCP Direct experience with malware and analysis techniques and methodologies. Experience with playbook development using Security Orchestration and Automated Response (SOAR) platforms Stay up to date on everything Blackbaud, follow us on Linkedin, Twitter, Instagram, Facebook and YouTube Blackbaud powers social impact through purpose‑driven technology and responsible AI. Guided by our Intelligence for Good® vision, we’re building a culture where innovation, trust, and human expertise come together to help organizations make a greater difference in the world. Blackbaud is proud to be an equal opportunity employer and is committed to maintaining a diverse and inclusive work environment. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, physical or mental disability, age, or veteran status or any other basis protected by federal, state, or local law. The starting base pay is $101,900.00 to $132,800.00. Blackbaud may pay more or less based on employee qualifications, market value, Company finances, and other operational considerations.

Benefits Include: Medical, dental, and vision insurance Remote-flexible workforce Wellness Programs 401(k) program with employer match Flexible paid time off Generous Parental Leave Donations for Doers Pet insurance, legal and identity protection Tuition reimbursement program Blackbaud (NASDAQ: BLKB) is the world’s leading cloud software company powering social good. Serving the entire social good community—nonprofits, foundations, corporations, education institutions, healthcare institutions and individual change agents—Blackbaud connects and empowers organizations to increase their impact through software, services, expertise, and data intelligence. The Blackbaud portfolio is tailored to the unique needs of vertical markets, with solutions for fundraising and CRM, marketing, advocacy, peer-to-peer fundraising, corporate social responsibility, school management, ticketing, grantmaking, financial management, payment processing, and analytics. Serving the industry for more than three decades, Blackbaud is headquartered in Charleston, South Carolina and has operations in the United States, Australia, Canada, and the United Kingdom.