Principal Security Engineer, Orchestration and Automation

🏢 Blackbaud · all Blackbaud jobs (33)
📍 United States
💰 USD 117,200 - 157,500 / annual
📅 Posted 2026-09-07 · via Himalayas
🏷 Security-Engineering,SOAR-Engineering,Detection-Engineering,Cybersecurity,Security-Automation,Senior-Security-Automation-Engineer,Principal-Security-Engineer,Senior-Principal-Security-Engineer,Principal-Cybersecurity-Engineer,Cyber-Security-Automation-Engineer,Senior-Security-Operations-Engineer
Apply on original site ↗

Cyber Detection & Response Automation Engineer

The Cyber Detection & Response Automation Engineer is responsible for building the automation, orchestration, and AI-driven capabilities that power the organization's detection and response function. This role treats the SIEM as one component in a broader automation ecosystem — the primary focus is designing workflows, integrations, and intelligent tooling that reduce manual analyst effort, accelerate response, and scale detection coverage. The ideal candidate is an automation/orchestration engineer with a security background: comfortable building integrations and pipelines across multiple tools, applying AI/ML or LLM-assisted techniques to triage and enrichment, and engineering detection logic. This person will also maintain a working level of SIEM platform administration — data onboarding, health, and configuration — to support the automation and detection layers built on top of it, and will partner closely with Security Operations and the Detection Engineering Lead.
What you'll be doing:

- Design, build, and maintain orchestration workflows and SOAR playbooks that automate triage, enrichment, containment, and response actions across the security tool stack.

- Apply AI/ML and LLM-assisted techniques (e.g., automated alert summarization, natural-language investigation assistance, anomaly scoring) to reduce analyst workload and speed decision-making.

- Develop and maintain Python-based integrations and APIs connecting the SIEM, SOAR, EDR, ticketing, threat intel, and cloud platforms into unified automated workflows.

- Design, build, and tune SIEM correlation rules, alerts, and detection use cases mapped to MITRE ATT&CK, with an eye toward which detections can be paired with automated response.

- Own core SIEM administration tasks needed to support automation and detection: data source onboarding, index/data model health, log ingestion monitoring, and configuration management.

- Build and maintain custom field extractions, parsers, and content packs to ensure new data sources are automation- and detection-ready.

- Continuously tune detections and automation logic to improve signal-to-noise ratio, reduce false positives, and reduce mean-time-to-respond (MTTR).

- Create dashboards and reporting that measure automation coverage, orchestration reliability, AI-assisted triage accuracy, and detection effectiveness.

- Apply CI/CD and infrastructure-as-code practices to manage detection content, playbooks, and integrations as versioned, testable code.

- Evaluate and pilot new automation, orchestration, and AI tooling to expand the detection and response automation footprint.

What we'll want you to have:

- 5+ years building automation, orchestration, or SOAR playbooks in a cyber security or SOC environment.

- 3+ years of SIEM engineering or administration experience - data onboarding, correlation rule development, platform configuration.

- Strong Python (or comparable scripting) skills; experience building APIs/integrations across security and IT tooling.

- Hands-on experience with AI/ML or LLM-based tooling applied to security use cases - triage, summarization, enrichment, and/or anomaly detection; experience building such capability strongly preferred.

- Working knowledge of MITRE ATT&CK and experience mapping detections/automation to adversary tactics and techniques.

- Experience with a SOAR or security orchestration platform (e.g., NG-SIEM Fusion, Splunk SOAR, Palo Alto XSOAR, Tines, or similar).

- Cloud security experience (AWS, Azure, or GCP), including automation for ingesting and processing security data from cloud sources.

- Experience with CI/CD, infrastructure-as-code, and version-controlling detection/automation content.

- Familiarity with containerized and serverless environments and their automation/logging considerations.

- SIEM, SOAR, or security automation platform certification preferred.

- Regulatory compliance experience a plus.

Stay up to date

← All remote jobs

Get remote jobs like this by email

One weekly digest. No spam, unsubscribe anytime.

Similar for you