Blackbaud

Blackbaud

Manager, Defensive Cyber Operations

Remote, United States of America

Sponsorship not specified$117k-$158kDetected 65 days ago
PythonAWSAzureSIEMCRM

About the role

  • We're hiring a Manager, Defensive Cyber Operations to mature, scale, and continuously iterate our agentic SOC.

Responsibilities

  • Lead and develop a small defensive operations team Manage, mentor, and grow a small team of security engineers and analysts focused on detection, response, and automation. Act as the primary technical escalation point for high‑severity incidents
  • Lead and develop a small defensive operations team Manage, mentor, and grow a small team of security engineers and analysts focused on detection, response, and automation.
  • Act as the primary technical escalation point for high‑severity incidents; lead investigations and response decision‑making.
  • Detection engineering & threat detection operations Own detection engineering outcomes end‑to‑end: alert logic, correlation rules, anomaly thresholds, tuning, and continuous improvement.
  • SOAR & security automation Design, iterate on, and maintain SOAR playbooks for alert enrichment, containment, remediation, and case management.
  • Breach & attack simulation (continuous validation) Mature an existing breach & attack simulation capability to continuously validate detection and response effectiveness.
  • Proven experience maturing SOAR automation and/or custom tooling to drive repeatable response actions.
  • you will lead a small team of engineers and analysts while personally owning critical technical outcomes across detection engineering, SOAR automation, breach and attack simulation, and insider threat.
  • This role is ideal for a technical leader who improves existing systems, writes production‑quality detection and automation, leads investigations, and raises the operational bar through disciplined iteration.
  • lead investigations and response decision‑making.

Nice to have

  • Experience iterating on AI‑assisted or agentic SOC workflows with measurable operational impact.
  • Strong scripting experience (e.g., Python) for automation, integrations, and enrichment logic.
  • Experience with breach and attack simulation, purple team exercises, or continuous control validation programs.
  • Detection and response experience across AWS and Azure, including cloud-native logs, identity signals, and workload telemetry.
  • Working knowledge of adversary tradecraft and defensive frameworks (e.g., MITRE ATT&CK, NIST‑aligned approaches).
  • Blackbaud is proud to be an equal opportunity employer and is committed to maintaining a diverse and inclusive work environment.
  • The starting base pay is $117,200.00 to $157,500.00.
  • Blackbaud may pay more or less based on employee qualifications, market value, Company finances, and other operational considerations.

Skills

  • BLKB) is the world's leading cloud software company powering social good.

Compensation

  • The starting base pay is $117,200.00 to $157,500.00.

Benefits

  • Guided by our Intelligence for Good® vision, we're building a culture where innovation, trust, and human expertise come together to help organizations make a greater difference in the world.
  • Benefits Include:
  • Define and track operational metrics such as detection coverage, alert fidelity, automation success rates, and MTTD/MTTR improvements.

Equal opportunity

  • equal opportunity employer and is committed to maintaining a diverse and inclusive work environment.

This listing is sourced directly from Blackbaud's careers page and normalized into a canonical job model.