Blackbaud Logo

Blackbaud

Principal Incident Response Engineer

Posted One Month Ago
Be an Early Applicant
Remote
Hiring Remotely in USA
117K-158K Annually
Senior level
Remote
Hiring Remotely in USA
117K-158K Annually
Senior level
Lead cybersecurity incident response, digital forensics, and threat hunting activities. Analyze security events, investigate root causes, contain and mitigate threats, coordinate cross-functional response efforts, and develop remediation strategies. Conduct forensic analysis of endpoint and network artifacts, volatile memory, malicious files, and scripts while preserving electronic evidence. Enhance detection capabilities using threat intelligence, security frameworks, and industry best practices.
The summary above was generated by AI

About the role:

We are looking for an accomplished, high-performing Principal Incident Response Engineer for our Threat Detection & Response team with experience performing digital forensics, incident response, and threat hunting.

The Principal Incident Response Engineer is responsible for ensuring the confidentiality, integrity, and availability of critical information and IT assets. This role requires a deep understanding of cybersecurity principles, incident response methodologies, digital forensics, and the ability to work efficiently under pressure.

What you'll be doing:

  • Conduct in-depth analysis of security events and indicators to determine the nature and severity of incidents.
  • Respond promptly to security incidents, following established incident response procedures.
  • Serve as the technical lead for high-severity security incidents. Coordinate and collaborate with cross-functional teams to contain and mitigate cyber threats effectively.
  • Perform forensic investigations to determine the root cause of incidents and develop appropriate remediation strategies across on-prem, hybrid, and cloud workloads
  • Lead regular intelligence-driven threat hunt activities to identify and investigate gaps in detection.
  • Partner with detection engineering to increase coverage across MITRE ATT&CK framework
  • Identify, scope, and support the development of AI/LLM workflows to enhance incident detection and response capabilities.
  • Collaborate with other forensic analysts, law enforcement officers, and legal experts to identify methods and procedures for recovery, preservation, and presentation of computer evidence, ensuring proper precautions are taken in the preservation and prevention of spoliation of electronic evidence.
  • Support On-call rotation as applicable

What we'll want you to have:

  • 8+ years of cyber incident response experience in a relevant environment. Cyber industry certifications are highly desirable (CISSP, GCIH, GFCA, GREM, ECIH).
  • Subject matter expertise with security tools and technologies, such as SIEM, IDS/IPS, EDR, and cloud monitoring solutions.
  • Strong knowledge of incident response methodologies, including containment, eradication, recovery, and common security frameworks (NIST, SANS, CSA).
  • Ability to acquire and analyze endpoint and network artifacts, volatile memory, malicious files/binaries and scripts.
  • Experience with forensic tools, such as Encase, FTK, Axiom, and Cellebrite to carry out digital forensic investigations.

Stay up to date on everything Blackbaud, follow us on Linkedin, Twitter, Instagram, Facebook and YouTube ​

Blackbaud powers social impact through purpose‑driven technology and responsible AI. Guided by our Intelligence for Good® vision, we’re building a culture where innovation, trust, and human expertise come together to help organizations make a greater difference in the world.


Blackbaud is proud to be an equal opportunity employer and is committed to maintaining a diverse and inclusive work environment. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, physical or mental disability, age, or veteran status or any other basis protected by federal, state, or local law.

The starting base pay is $117,200.00 to $157,500.00. Blackbaud may pay more or less based on employee qualifications, market value, Company finances, and other operational considerations.

Benefits Include:

  • Medical, dental, and vision insurance

  • Remote-flexible workforce

  • Wellness Programs

  • 401(k) program with employer match

  • Flexible paid time off

  • Generous Parental Leave

  • Donations for Doers

  • Pet insurance, legal and identity protection

  • Tuition reimbursement program

Similar Jobs

11 Minutes Ago
Easy Apply
Remote or Hybrid
USA
Easy Apply
Senior level
Senior level
Healthtech • Software
Build and lead the sales enablement function by designing onboarding, training, certification, and product education programs. Partner with Sales, Marketing, Customer Success, Professional Services, Product, and commercial leadership to address performance gaps, improve ramp time, increase quota attainment, and support retention. Own enablement technology, including LMS and HubSpot-related training, measure program outcomes, evolve the sales motion, and guide the growing enablement team.
Top Skills: AIHubspotLmsSaaSShowpad
Entry level
Insurance • Financial Services
Handles inbound cancellation calls and outbound lapse-recovery contacts for life insurance policyholders. The representative assesses customer needs, explains policy options, recommends coverage or payment solutions, documents interactions, maintains product knowledge, and meets contact-center KPIs for retention, call quality, resolution, attendance, and productivity. This is a remote, part-time Monday–Friday role requiring strong communication, customer service, and problem-solving skills.
Top Skills: ExcelMicrosoft OutlookMicrosoft Word
17 Minutes Ago
Remote
USA
Senior level
Senior level
Artificial Intelligence • Machine Learning • Software • Defense
Build and lead development of full-stack agentic AI products for systems modernization. Responsibilities include creating coding harnesses and runtime layers, integrating source control, CI/CD, security, and developer tools, scaling coding-agent workflows, and partnering with customers, designers, and mission teams. The role requires production-grade, cybersecurity-compliant systems, strong product judgment, and close collaboration with forward-deployed engineering teams supporting national security missions.
Top Skills: Agent2Agent (A2A)AWSCi/CdDevsecopsLanggraphModel Context Protocol (Mcp)Nist 800-53Node.jsOpenai SdkPostgresPythonReactTailwind CssTypescript

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account