Manager, Defensive Cyber Operations

Reposted 3 Days Ago
Be an Early Applicant
Hiring Remotely in USA
Remote
117K-158K Annually
Senior level
Cloud • Social Impact • Software
Blackbaud is the leading provider of software for powering social impact.
The Role
The manager will lead a defensive operations team, focusing on improving detection and response capabilities, automation, and handling high-severity incidents.
Summary Generated by Built In

About the role

We’re hiring a Manager, Defensive Cyber Operations to mature, scale, and continuously iterate our agentic SOC. This is a hands-on player/coach role: you will lead a small team of engineers and analysts while personally owning critical technical outcomes across detection engineering, SOAR automation, breach and attack simulation, and insider threat.

This role is ideal for a technical leader who improves existing systems, writes production‑quality detection and automation, leads investigations, and raises the operational bar through disciplined iteration.

What you’ll do

Lead and develop a small defensive operations team

  • Manage, mentor, and grow a small team of security engineers and analysts focused on detection, response, and automation.
  • Act as the primary technical escalation point for high‑severity incidents; lead investigations and response decision‑making.
  • Set and reinforce quality standards for investigations, detections, automation, documentation, and on‑call readiness.

Mature and iterate on an agentic SOC

  • Evolve and refine agentic SOC workflows that improve triage speed, consistency, and decision quality through automated enrichment, correlation, and recommended or automated response actions.
  • Iterate on existing SOC workflows, converting repeatable analyst effort into safe, reliable automation with clear guardrails, validation, and auditability.
  • Define and track operational metrics such as detection coverage, alert fidelity, automation success rates, and MTTD/MTTR improvements.

Detection engineering & threat detection operations

  • Own detection engineering outcomes end‑to‑end: alert logic, correlation rules, anomaly thresholds, tuning, and continuous improvement.
  • Mature a detection‑as‑engineering operating model, including requirements, testing, rollout, post‑deployment measurement, and documentation.

SOAR & security automation

  • Design, iterate on, and maintain SOAR playbooks for alert enrichment, containment, remediation, and case management.
  • Enhance custom automation, integrations, and enrichment logic to reduce manual analyst effort and improve response consistency.
  • Ensure automation remains resilient, production‑grade, well‑documented, and operationally safe at scale.

Breach & attack simulation (continuous validation)

  • Mature an existing breach & attack simulation capability to continuously validate detection and response effectiveness.
  • Translate BAS findings into prioritized detection, automation, and response improvements on a repeatable cadence.

Insider risk

  • Advance insider threat detection and response capabilities, including use‑case refinement, signal quality, investigation workflows, and playbooks.
  • Balance speed, precision, and appropriate controls while improving investigative consistency.

What we want you to have:

  • 5+ years experience leading security operations, detection engineering, incident response, and/or security engineering teams, with direct ownership of operational outcomes.
  • Strong hands‑on background in intrusion analysis using SIEM/log analytics, packet captures, and investigation tooling.
  • Proven experience maturing SOAR automation and/or custom tooling to drive repeatable response actions.
  • Strong detection engineering fundamentals, including alert fidelity, correlation, and continuous tuning.
  • Experience operating in cloud‑first environments, with hands‑on security detection or response exposure in AWS and Azure.
  • Comfort operating as both technical leader and people manager in on‑call, real‑time security environments.

Preferred qualifications

  • Experience iterating on AI‑assisted or agentic SOC workflows with measurable operational impact.
  • Strong scripting experience (e.g., Python) for automation, integrations, and enrichment logic.
  • Experience with breach and attack simulation, purple team exercises, or continuous control validation programs.
  • Detection and response experience across AWS and Azure, including cloud-native logs, identity signals, and workload telemetry.
  • Working knowledge of adversary tradecraft and defensive frameworks (e.g., MITRE ATT&CK, NIST‑aligned approaches).
  • Security+, CEH, GSEC, CISSP, GCIA, GCIH, GSOC (Equivalent or comparable security engineering, detection, or incident response certifications are welcome.)

Stay up to date on everything Blackbaud, follow us on Linkedin, Twitter, Instagram, Facebook and YouTube ​

Blackbaud powers social impact through purpose‑driven technology and responsible AI. Guided by our Intelligence for Good® vision, we’re building a culture where innovation, trust, and human expertise come together to help organizations make a greater difference in the world.


Blackbaud is proud to be an equal opportunity employer and is committed to maintaining a diverse and inclusive work environment. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, physical or mental disability, age, or veteran status or any other basis protected by federal, state, or local law.

The starting base pay is $117,200.00 to $157,500.00. Blackbaud may pay more or less based on employee qualifications, market value, Company finances, and other operational considerations.

Benefits Include:

  • Medical, dental, and vision insurance

  • Remote-flexible workforce

  • Wellness Programs

  • 401(k) program with employer match

  • Flexible paid time off

  • Generous Parental Leave

  • Donations for Doers

  • Pet insurance, legal and identity protection

  • Tuition reimbursement program

Skills Required

  • 5+ years experience leading security operations, detection engineering, incident response, and/or security engineering teams
  • Strong hands-on background in intrusion analysis
  • Proven experience maturing SOAR automation
  • Experience operating in cloud-first environments
  • Strong scripting experience (e.g., Python) for automation
  • Experience with breach and attack simulation
  • Security+, CEH, GSEC, CISSP, GCIA, GCIH certifications

Blackbaud Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Blackbaud and has not been reviewed or approved by Blackbaud.

  • Leave & Time Off Breadth Paid time off, paid holidays, and “wellbeing days” are emphasized, and feedback suggests PTO is a consistent strength. Remote/hybrid flexibility further supports time-away needs.
  • Wellbeing & Lifestyle Benefits Wellbeing programs, health coaching, and flexibility (including remote/hybrid schedules) are highlighted as part of a holistic support approach. Tuition reimbursement, wellness recognition, and home-office support add everyday value.
  • Inclusive Benefits Coverage Benefits extend to mental health support, fertility options, and travel support for abortion care, with parental leave also included. These offerings signal attention to diverse needs across life stages.

Blackbaud Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Charleston, SC
3,400 Employees

What We Do

Blackbaud unleashes the potential of the people and organizations who change the world. As the leading software provider exclusively dedicated to powering social impact, Blackbaud expands what is possible across the nonprofit and education sectors, at companies committed to social responsibility, and for individual change makers. Built specifically for fundraising, nonprofit financial management, digital giving, grantmaking, corporate social responsibility and education management, Blackbaud’s essential software accelerates impact through unmatched expertise and powerful data intelligence. Millions of people across more than 100 countries connect, give, learn, and engage through Blackbaud platforms.

Why Work With Us

We’re here to fuel impact that creates a better, more connected world. When nonprofits, social impact teams, schools and individual change-makers have powerful and effective foundational infrastructure, they transform our communities and our world.

Gallery

Gallery

Similar Jobs

Cox Enterprises Logo Cox Enterprises

Dealer.com Performance Manager

Artificial Intelligence • Automotive • Greentech • Information Technology • Machine Learning • Software • Cybersecurity
Remote or Hybrid
PA, USA
50000 Employees
75K-113K Annually

Cox Enterprises Logo Cox Enterprises

Human Resources Business Partner

Artificial Intelligence • Automotive • Greentech • Information Technology • Machine Learning • Software • Cybersecurity
Remote or Hybrid
United States
50000 Employees
67K-101K Annually

Cox Enterprises Logo Cox Enterprises

Dealer.com Performance Manager

Artificial Intelligence • Automotive • Greentech • Information Technology • Machine Learning • Software • Cybersecurity
Remote or Hybrid
OH, USA
50000 Employees
75K-113K Annually

Cox Enterprises Logo Cox Enterprises

Dealer.com Performance Manager

Artificial Intelligence • Automotive • Greentech • Information Technology • Machine Learning • Software • Cybersecurity
Remote or Hybrid
IN, USA
50000 Employees
75K-113K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
31 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account