Blackbaud
Manager, Defensive Cyber Operations
Remote, United States of America
Sponsorship not specified$117k-$158kDetected 65 days ago
PythonAWSAzureSIEMCRM
About the role
- We're hiring a Manager, Defensive Cyber Operations to mature, scale, and continuously iterate our agentic SOC.
Responsibilities
- Lead and develop a small defensive operations team Manage, mentor, and grow a small team of security engineers and analysts focused on detection, response, and automation. Act as the primary technical escalation point for high‑severity incidents
- Lead and develop a small defensive operations team Manage, mentor, and grow a small team of security engineers and analysts focused on detection, response, and automation.
- Act as the primary technical escalation point for high‑severity incidents; lead investigations and response decision‑making.
- Detection engineering & threat detection operations Own detection engineering outcomes end‑to‑end: alert logic, correlation rules, anomaly thresholds, tuning, and continuous improvement.
- SOAR & security automation Design, iterate on, and maintain SOAR playbooks for alert enrichment, containment, remediation, and case management.
- Breach & attack simulation (continuous validation) Mature an existing breach & attack simulation capability to continuously validate detection and response effectiveness.
- Proven experience maturing SOAR automation and/or custom tooling to drive repeatable response actions.
- you will lead a small team of engineers and analysts while personally owning critical technical outcomes across detection engineering, SOAR automation, breach and attack simulation, and insider threat.
- This role is ideal for a technical leader who improves existing systems, writes production‑quality detection and automation, leads investigations, and raises the operational bar through disciplined iteration.
- lead investigations and response decision‑making.
Nice to have
- Experience iterating on AI‑assisted or agentic SOC workflows with measurable operational impact.
- Strong scripting experience (e.g., Python) for automation, integrations, and enrichment logic.
- Experience with breach and attack simulation, purple team exercises, or continuous control validation programs.
- Detection and response experience across AWS and Azure, including cloud-native logs, identity signals, and workload telemetry.
- Working knowledge of adversary tradecraft and defensive frameworks (e.g., MITRE ATT&CK, NIST‑aligned approaches).
- Blackbaud is proud to be an equal opportunity employer and is committed to maintaining a diverse and inclusive work environment.
- The starting base pay is $117,200.00 to $157,500.00.
- Blackbaud may pay more or less based on employee qualifications, market value, Company finances, and other operational considerations.
Skills
- BLKB) is the world's leading cloud software company powering social good.
Compensation
- The starting base pay is $117,200.00 to $157,500.00.
Benefits
- Guided by our Intelligence for Good® vision, we're building a culture where innovation, trust, and human expertise come together to help organizations make a greater difference in the world.
- Benefits Include:
- Define and track operational metrics such as detection coverage, alert fidelity, automation success rates, and MTTD/MTTR improvements.
Equal opportunity
- equal opportunity employer and is committed to maintaining a diverse and inclusive work environment.
Apply directly at Blackbaud →Create a free account for alerts like thisView Blackbaud immigration profile
This listing is sourced directly from Blackbaud's careers page and normalized into a canonical job model.