All roles

[Remote] Manager, Defensive Cyber Operations

Remote · USA Full-time New today

Note: The job is a remote job and is open to candidates in USA. Blackbaud is a company that powers social impact through purpose-driven technology and responsible AI. They are seeking a Manager, Defensive Cyber Operations to lead a small team focused on enhancing detection, automation, and incident response capabilities within their security operations center.

Responsibilities

  • Manage, mentor, and grow a small team of security engineers and analysts focused on detection, response, and automation
  • Act as the primary technical escalation point for high‑severity incidents; lead investigations and response decision‑making
  • Set and reinforce quality standards for investigations, detections, automation, documentation, and on‑call readiness
  • Evolve and refine agentic SOC workflows that improve triage speed, consistency, and decision quality through automated enrichment, correlation, and recommended or automated response actions
  • Iterate on existing SOC workflows, converting repeatable analyst effort into safe, reliable automation with clear guardrails, validation, and auditability
  • Define and track operational metrics such as detection coverage, alert fidelity, automation success rates, and MTTD/MTTR improvements
  • Own detection engineering outcomes end‑to‑end: alert logic, correlation rules, anomaly thresholds, tuning, and continuous improvement
  • Mature a detection‑as‑engineering operating model, including requirements, testing, rollout, post‑deployment measurement, and documentation
  • Design, iterate on, and maintain SOAR playbooks for alert enrichment, containment, remediation, and case management
  • Enhance custom automation, integrations, and enrichment logic to reduce manual analyst effort and improve response consistency
  • Ensure automation remains resilient, production‑grade, well‑documented, and operationally safe at scale
  • Mature an existing breach & attack simulation capability to continuously validate detection and response effectiveness
  • Translate BAS findings into prioritized detection, automation, and response improvements on a repeatable cadence
  • Advance insider threat detection and response capabilities, including use‑case refinement, signal quality, investigation workflows, and playbooks
  • Balance speed, precision, and appropriate controls while improving investigative consistency

Skills

  • 5+ years experience leading security operations, detection engineering, incident response, and/or security engineering teams, with direct ownership of operational outcomes
  • Strong hands‑on background in intrusion analysis using SIEM/log analytics, packet captures, and investigation tooling
  • Proven experience maturing SOAR automation and/or custom tooling to drive repeatable response actions
  • Strong detection engineering fundamentals, including alert fidelity, correlation, and continuous tuning
  • Experience operating in cloud‑first environments, with hands‑on security detection or response exposure in AWS and Azure
  • Comfort operating as both technical leader and people manager in on‑call, real‑time security environments
  • Experience iterating on AI‑assisted or agentic SOC workflows with measurable operational impact
  • Strong scripting experience (e.g., Python) for automation, integrations, and enrichment logic
  • Experience with breach and attack simulation, purple team exercises, or continuous control validation programs
  • Detection and response experience across AWS and Azure, including cloud-native logs, identity signals, and workload telemetry
  • Working knowledge of adversary tradecraft and defensive frameworks (e.g., MITRE ATT&CK, NIST‑aligned approaches)
  • Security+, CEH, GSEC, CISSP, GCIA, GCIH, GSOC (Equivalent or comparable security engineering, detection, or incident response certifications are welcome.)

Benefits

  • Medical, dental, and vision insurance
  • Remote-flexible workforce
  • Wellness Programs
  • 401(k) program with employer match
  • Flexible paid time off
  • Generous Parental Leave
  • Donations for Doers
  • Pet insurance, legal and identity protection
  • Tuition reimbursement program

Company Overview

  • Blackbaud is the world’s leading provider of AI-powered solutions for social impact. It was founded in 1999, and is headquartered in Charleston, South Carolina, USA, with a workforce of 1001-5000 employees. Its website is http://www.etapestry.com.
  • Company H1B Sponsorship

  • Blackbaud has a track record of offering H1B sponsorships, with 1 in 2026, 5 in 2025, 4 in 2024, 3 in 2023, 15 in 2022, 4 in 2021, 15 in 2020. Please note that this does not guarantee sponsorship for this specific role.
  • Apply To This Job

    Related roles

    [Remote] Sr Director Analyst – Public Cloud Sourcing & Cloud Commercial Strategy (Remote: North America)

    Remote · USA Full-time

    [Remote] Director, US Field Market Access

    Remote · USA Full-time

    [Remote] Data Engineering Apprenticeship Coach

    Remote · USA Full-time

    [Remote] Lead Cloud Systems Engineer (Microsoft 365, AWS, Collaboration Tools)

    Remote · USA Full-time

    [Remote] Program/Data Analyst Advisor

    Remote · USA Full-time

    [Remote] Associate Territory Manager, Middle Market Business Development - Commercial Lines (Commercial Insurance Production Underwriter - Pacific Northwest)

    Remote · USA Full-time

    [Remote] Data Analyst Principal

    Remote · USA Full-time

    [Remote] Senior Director, Product Marketing

    Remote · USA Full-time

    [Remote] Enterprise Account Manager

    Remote · USA Full-time

    [Remote] Associate Account Manager

    Remote · USA Full-time

    Remote arenaflex Chat Process Executive – Customer Support Specialist for E‑Commerce Services

    Remote · USA Full-time

    Experienced First Notice of Loss (FNOL) Customer Service Representative - Work from Home Opportunity

    Remote · USA Full-time

    Experienced Data Entry Specialist – Part-Time Remote Opportunity with arenaflex

    Remote · USA Full-time

    Engineer/Architect 3 (Central Region Senior Construction Project Manager PCN 250415)

    Remote · USA Full-time

    Remote Data Entry Specialist – Precision‑Focused Database Management for arenaflex’s Global Operations

    Remote · USA Full-time

    Healthcare Policies, Department of Marketing, Management, and Health Care Administration - Adjunct Faculty

    Remote · USA Full-time

    Member Experience Associate

    Remote · USA Full-time

    # Technology Data Analyst I - Technology Planning & Business Analysis (Entry Level)

    Remote · USA Full-time

    Associate, Fund Accounting

    Remote · USA Full-time

    Business Development Representative (Inside Sales - SaaS / Telecom)

    Remote · USA Full-time