Remotery

Principal AI Threat Detection Engineer – Insider Threat

atBlackbaudRemoteUS flagUnited StatesFull-timeArtificial IntelligenceLead$117.2k – $157.5k/year

Posted Jul 30

This is a fully remote position, open to applicants in United States.

📋 Description

• Lead the advancement of Blackbaud’s Insider Threat detection program towards an AI-enhanced capability, which includes the administration, tuning, and optimization of Insider Threat tools, UEBA platforms, and the underlying AI/ML models.

• Conduct intrusion and insider risk assessments utilizing SIEM technology, UEBA behavioral analytics, AI-generated insights, reports, data visualization, log analysis, and pattern analysis, applying human judgment to validate AI findings and distinguish true signals from noise.

• Guide AI-driven hunting tools and agents to identify threat actor groups (both external and internal) along with their respective tactics, techniques, and procedures, personally overseeing investigations that necessitate nuanced human judgment.

• Act as the human escalation point and initial responder for security events flagged by AI and automated tools that cannot be fully resolved, through email, phone, and ticketing across corporate user networks, data centers, and cloud environments.

• Take ownership of the remediation of information security incidents, including insider threat investigations, ensuring that AI-assisted findings are verified and contextualized prior to taking action.

• Document and communicate findings, escalate critical incidents, and engage with lines of business, HR, Legal, and other stakeholders on sensitive insider matters, exercising discretion and judgment that AI systems cannot provide.

• Design and develop AI-driven and SOAR-based automated workflows within Detection Engineering, defining the guardrails, escalation thresholds, and human checkpoints that maintain safety and effectiveness in automation while enhancing analyst performance.

• Advocate for the responsible use of AI-driven analysis and automation to improve detection accuracy and expedite triage, while assessing model accuracy, bias, and drift to ensure detection logic remains explainable and trustworthy.

• Document the processes for automation and AI model deployment, including defining pre-build requirements, validation criteria, and human review checkpoints for high-risk decisions.

• Utilize AI and automation to create metrics and dashboards that support the Insider Threat and broader detection program, applying human interpretation to translate outputs into actionable decisions for leadership.

• Serve as a thought leader on the evolving roles of AI and human analysts – determining which decisions should be automated, which require human review, and how this boundary should evolve as the program develops, as well as on new alert content, data correlation, and anomaly thresholds.

• Enhance and challenge existing processes and procedures in a dynamic and fast-paced cybersecurity environment.

• Stay informed on the threat landscape, insider risk trends, cybersecurity developments, and emerging AI/ML techniques relevant to detection engineering.

• Adapt to changing infrastructures and evaluate, pilot, and integrate new AI-enabled technologies and platforms.

• Serve as a peer reviewer and technical escalation point within the core security engineering team, including reviewing AI-assisted detection logic and automation before deployment.

• Advise and inform leadership on optimizing the current toolset and assessing future tools, including UEBA, SOAR, and AI-enabled analysis platforms, recommending areas for expanding automation and where human oversight is essential.


⛳️ Requirements

• At least 8 years of experience in Security Engineering and Analysis, preferably in Threat Detection and Response, with demonstrated experience supporting Insider Threat programs.

• A minimum of 5 years of IT or networking experience.

• Practical experience in administering, tuning, and optimizing Insider Threat detection tools, User and Entity Behavior Analytics (UEBA) platforms, and the AI/ML models that support them.

• Experience with SOAR tools and playbook development, including specific expertise in applying AI-driven and agentic automation to security operations and critically evaluating the accuracy of AI-generated findings.

• Familiarity with security metrics and reporting, ideally including the automation of recurring metrics and reporting processes.

• Proven ability to critically assess AI/ML model outputs.

• Intermediate to Advanced knowledge of Linux/Unix OS and Windows.

• Understanding of firewall rules and policies, as well as network routing fundamentals.

• Capability to manage multiple tasks concurrently and accurately document resolutions.

• Demonstrated ability to implement automation through scripting (e.g., PowerShell, PERL, Python, Bash scripting), including integrating AI/ML APIs or agentic frameworks into detection workflows.

• Experience utilizing APIs to incorporate third-party tools into an existing tool stack.

• Familiarity with cybersecurity frameworks such as NIST and MITRE ATT&CK, along with awareness of emerging AI governance and security frameworks (e.g., NIST AI RMF, MITRE ATLAS).

• An industry-recognized professional certification such as Security+, CBROPS, CSA, CEH, GSEC, or SSCP.


🏝️ Benefits

• Medical, dental, and vision insurance.

• Flexible remote work options.

• Wellness Programs.

• 401(k) plan with employer matching.

• Flexible paid time off.

• Generous Parental Leave.

• Donations for Doers program.

• Pet insurance, legal assistance, and identity protection.

• Tuition reimbursement program.

People also viewed

Ensemble Health Partners2 days ago

Engineer II, AI – Copilot Agent

IN flagIndia OnlyFull-timeArtificial Intelligence
ApplyView job
Mercor2 days ago

AI Safety Practitioner

US flagUnited States OnlyFreelanceArtificial Intelligence$60 – $70/hour
ApplyView job
Mercor2 days ago

AI Safety Practitioner

US flagUnited States OnlyFreelanceArtificial Intelligence$60 – $70/hour
ApplyView job
Mercor2 days ago

AI Safety Practitioner

US flagUnited States OnlyFreelanceArtificial Intelligence$60 – $70/hour
ApplyView job
Mercor2 days ago

AI Safety Practitioner

US flagUnited States OnlyFreelanceArtificial Intelligence$60 – $70/hour
ApplyView job
Gartner2 days ago

Senior Director Analyst – AI and Emerging Technologies Enterprise Strategy

GB flagUnited Kingdom, +4 more statesFull-timeArtificial Intelligence
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers