We are looking for an accomplished, high-performing Principal Incident Response Analyst for our Threat Detection & Response team with experience performing digital forensics, incident response, and threat hunting. The Principal Incident Response Analyst is responsible for ensuring the confidentiality, integrity, and availability of critical information and IT assets. This role requires a deep understanding of cybersecurity principles, incident response methodologies, digital forensics, and the ability to work efficiently under pressure.
What you'll be doing:
Conduct in-depth analysis of security events and indicators to determine the nature and severity of incidents.
Respond promptly to security incidents, following established incident response procedures.
Coordinate and collaborate with cross-functional teams to contain and mitigate cyber threats effectively.
Perform forensic investigations to determine the root cause of incidents and develop appropriate remediation strategies.
Lead regular threat hunt activities to identify and investigate gaps in detection.
Utilize threat intelligence and industry best practices to enhance incident detection capabilities.
What we'll want you to have:
8+ years of cyber incident response experience in a large and complex environment. Relevant industry certifications are highly desirable (CISSP, GCIH, GFCA, GREM, ECIH).
Subject matter expertise with security tools and technologies, such as SIEM, IDS/IPS, EDR, and network monitoring solutions.
Strong knowledge of incident response methodologies, including containment, eradication, recovery, and common security frameworks (NIST, SANS, CSA).
Ability to acquire and analyze endpoint and network artifacts, volatile memory, malicious files/binaries and scripts.
Experience with forensic tools, such as Encase, FTK, Axiom, and Cellebrite to carry out digital forensic investigations.
Collaborate with other forensic analysts, law enforcement officers, and legal experts to identify methods and procedures for recovery, preservation, and presentation of computer evidence, ensuring proper precautions are taken in the preservation and prevention of spoliation of electronic evidence.
Stay up to date on everything Blackbaud, follow us on Linkedin, Twitter, Instagram, Facebook and YouTube
Blackbaud powers social impact through purpose‑driven technology and responsible AI. Guided by our Intelligence for Good® vision, we’re building a culture where innovation, trust, and human expertise come together to help organizations make a greater difference in the world.
Blackbaud is proud to be an equal opportunity employer and is committed to maintaining a diverse and inclusive work environment. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, physical or mental disability, age, or veteran status or any other basis protected by federal, state, or local law.
The starting base pay is $101,900.00 to $132,800.00. Blackbaud may pay more or less based on employee qualifications, market value, Company finances, and other operational considerations.Benefits Include:
Medical, dental, and vision insurance
Remote-flexible workforce
Wellness Programs
401(k) program with employer match
Flexible paid time off
Generous Parental Leave
Donations for Doers
Pet insurance, legal and identity protection
Tuition reimbursement program
Skills Required
- 8+ years of cyber incident response experience in a large and complex environment
- Subject matter expertise with SIEM, IDS/IPS, EDR, and network monitoring solutions
- Strong knowledge of incident response methodologies, including containment, eradication, and recovery
- Knowledge of common security frameworks including NIST, SANS, and CSA
- Ability to acquire and analyze endpoint and network artifacts, volatile memory, malicious files or binaries, and scripts
- Experience with EnCase, FTK, Axiom, and Cellebrite forensic tools
- Ability to collaborate with forensic analysts, law enforcement officers, and legal experts on computer evidence recovery, preservation, and presentation
- Relevant industry certifications such as CISSP, GCIH, GFCA, GREM, or ECIH
Blackbaud Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Blackbaud and has not been reviewed or approved by Blackbaud.
-
Leave & Time Off Breadth — Paid time off, paid holidays, and “wellbeing days” are emphasized, and feedback suggests PTO is a consistent strength. Remote/hybrid flexibility further supports time-away needs.
-
Wellbeing & Lifestyle Benefits — Wellbeing programs, health coaching, and flexibility (including remote/hybrid schedules) are highlighted as part of a holistic support approach. Tuition reimbursement, wellness recognition, and home-office support add everyday value.
-
Inclusive Benefits Coverage — Benefits extend to mental health support, fertility options, and travel support for abortion care, with parental leave also included. These offerings signal attention to diverse needs across life stages.
Blackbaud Insights
What We Do
Blackbaud unleashes the potential of the people and organizations who change the world. As the leading software provider exclusively dedicated to powering social impact, Blackbaud expands what is possible across the nonprofit and education sectors, at companies committed to social responsibility, and for individual change makers. Built specifically for fundraising, nonprofit financial management, digital giving, grantmaking, corporate social responsibility and education management, Blackbaud’s essential software accelerates impact through unmatched expertise and powerful data intelligence. Millions of people across more than 100 countries connect, give, learn, and engage through Blackbaud platforms.
Why Work With Us
We’re here to fuel impact that creates a better, more connected world. When nonprofits, social impact teams, schools and individual change-makers have powerful and effective foundational infrastructure, they transform our communities and our world.
Gallery







