Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Principal AI Threat Detection Engineer

$117.2k - $157.5k
Full-time

Blackbaud

Role Description

We are looking for a savvy, high-performing Principal AI Threat Detection Engineer – Insider Threat to lead the strategy, design, and day-to-day management of Blackbaud’s Insider Threat program as it matures into an AI-augmented capability, protecting Blackbaud’s and our clients’ information. As a technical leader within Security Engineering, this individual will direct AI-driven and agentic tooling to investigate anomalous events and alerts, detect malicious and anomalous insider activity, and reverse engineer malware, while personally applying the contextual judgment, escalation authority, and accountability that AI cannot provide on its own.

The Principal AI Threat Detection Engineer serves as the subject matter expert for Insider Threat tooling, User and Entity Behavior Analytics (UEBA), Security Orchestration Automation and Response (SOAR) platforms, and the AI/ML models underpinning them, validating model outputs, tuning detection logic, and partnering with leadership to report on the business impact of theft, destruction, alteration, or denial of access to information. As the program shifts more first-pass analysis to AI, this role increasingly focuses human effort where it matters most: resolving ambiguous or high-stakes cases, overseeing AI-assisted decisions, and troubleshooting complex threats that impact the information security infrastructure at the data, application, service, operating system, and network levels.

Qualifications

  • 8+ years of Security Engineering and Analysis experience, preferably in Threat Detection and Response, including demonstrated experience supporting Insider Threat programs
  • 5+ years of IT or networking experience
  • Hands-on experience administering, tuning, and optimizing Insider Threat detection tools, User and Entity Behavior Analytics (UEBA) platforms, and the AI/ML models that power them
  • Experience with SOAR tools and playbook development, including explicit expertise applying AI-driven and agentic automation to security operations and critically evaluating AI-generated findings for accuracy
  • Experience with security metrics and reporting, preferably including automating recurring metrics and reporting processes
  • Demonstrated ability to critically evaluate AI/ML model outputs
  • Intermediate to Advanced Linux/Unix OS and Windows knowledge
  • Firewall rule and policy, and network routing fundamentals
  • Ability to manage parallel tasks and accurately document resolutions
  • Proven ability to implement automation through scripting (e.g., PowerShell, PERL, Python, Bash scripting), including integrating AI/ML APIs or agentic frameworks into detection workflows
  • Experience leveraging APIs to integrate third-party tooling into an existing tool stack
  • Familiarity with cyber security frameworks such as NIST and MITRE ATT&CK, and awareness of emerging AI governance and security frameworks (e.g., NIST AI RMF, MITRE ATLAS)
  • Industry-recognized professional certification such as Security+, CBROPS, CSA, CEH, GSEC, SSCP

Requirements

  • Lead the maturation of Blackbaud’s Insider Threat detection program toward an AI-augmented capability, including administration, tuning, and optimization of Insider Threat tools, UEBA platforms, and the AI/ML models underneath them
  • Perform intrusion and insider risk analysis using SIEM technology, UEBA behavioral analytics, AI-generated insights, reports, data visualization, log analysis, and pattern analysis, applying human judgment to validate AI findings and separate true signal from noise
  • Direct AI-driven hunting tools and agents to identify threat actor groups (external and insider) and their respective tactics, techniques, and procedures, personally leading the investigation of cases that require nuanced human judgment
  • Serve as the human escalation point and first responder for security events that AI and automated tooling flag but cannot fully resolve, via email, phone, and tickets across corporate user networks, data centers, and cloud environments
  • Own remediation of information security incidents, including insider threat investigations, ensuring AI-assisted findings are verified and contextualized before action is taken
  • Document and communicate findings, escalate critical incidents, and interact with lines of business, HR, Legal, and other stakeholders on sensitive insider matters, exercising the discretion and judgment that AI systems cannot provide
  • Design and build AI-driven and SOAR-based automated workflows within Detection Engineering, defining the guardrails, escalation thresholds, and human checkpoints that keep automation safe, effective, and improve analyst performance
  • Champion responsible use of AI-driven analysis and automation to enhance detection accuracy and accelerate triage, while evaluating model accuracy, bias, and drift to keep detection logic explainable and trustworthy
  • Document automation and AI model deployment processes, to include defining pre-build requirements, validation criteria, and human review checkpoints for high-risk decisions
  • Utilize AI and automation to build metrics and dashboards supporting the Insider Threat and broader detection program, applying human interpretation to translate outputs into decisions leadership can act on
  • Serve as a thought leader on the evolving division of labor between AI and human analysts – determining which decisions should be automated, which require human review, and how that boundary should shift as the program matures – as well as on new alert content, data correlation, and anomaly thresholds
  • Improve and challenge existing processes and procedures in a very agile and fast-paced cyber security environment
  • Keep current on the threat landscape, insider risk trends, cyber security developments, and emerging AI/ML techniques relevant to detection engineering
  • Adapt to fluid infrastructures, and evaluate, pilot, and integrate new AI-enabled technologies and platforms
  • Act as peer reviewer and technical escalation point within the core security engineering team, including reviewing AI-assisted detection logic and automation before deployment
  • Advise and inform leadership on how to optimize the current toolset and evaluate future tools, including UEBA, SOAR, and AI-enabled analysis platforms, recommending where automation should expand and where human oversight must remain

Benefits

  • Medical, dental, and vision insurance
  • Remote-flexible workforce
  • Wellness Programs
  • 401(k) program with employer match
  • Flexible paid time off
  • Generous Parental Leave
  • Donations for Doers
  • Pet insurance, legal and identity protection
  • Tuition reimbursement program
Vacancy posted 7 days ago
Similar jobs that could be interesting for youBased on the Principal AI Threat Detection Engineer in Remote vacancy
  • We’re looking for a Senior Threat Detection & Intelligence Engineer to help us understand how adversaries operate, detect meaningful threats early, and lead investigations when it matters most. This role sits at the intersection of threat intelligence, detection engineering... 
    Suggested
    Work from home

    Miro

    Austin, TX
    2 days ago
  • $98k - $176k

     ...we care, grow, and win together. Join our team as a Senior Engineer and take a lead in building tools to aid fraud analysts...  ...to work in a team-oriented environmentInterested in cyber threat or fraud detection Ability to demonstrate analytical expertise, close attention... 
    Suggested
    Full time
    Temporary work
    Work experience placement
    Worldwide
    Flexible hours

    Target

    Brooklyn Park, MN
    20 hours ago
  • $119.32k - $202.85k

    ICF is actively recruiting for an experienced Senior Threat Detection & Response Engineer to support the research and development of new cyber analytic...  ...in the Transparency in (Benefits) Coverage Act. Candidate AI Usage PolicyAt ICF, we are committed to ensuring a fair... 
    Suggested
    Full time
    Contract work
    Work experience placement
    Work at office
    Remote work

    ICF

    Arlington, VA
    4 days ago
  • $221.2k - $387.1k

     ...DescriptionIt all started when engineer Fred Luddy wrote code that...  ...work. Today, ServiceNow is the AI control tower for business reinvention...  ...exists. You'll architect the threat models, controls, and secure-...  ...team practices, consolidate detection platforms, or take on the next... 
    Principal
    Work at office
    Immediate start
    Remote work
    Flexible hours

    ServiceNow

    Santa Clara, CA
    2 days ago
  • ICF is seeking an experienced Senior Threat Detection & Response Engineer to support R&D of cyber analytic capabilities for federal networks. The role is primarily telework-based with occasional client or ICF facility meetings in the DC metro area. Responsibilities include... 
    Suggested
    Remote job

    ICF

    Arlington, VA
    4 days ago
  • $101.9k - $132.8k

    Role Description We are looking for a savvy, high-performing Threat Detection Engineer who will be responsible for the day-to-day management of company-wide information security toolsets and the protection of Blackbaud’s and Client’s information. Security Engineers diligently... 
    Full time
    Remote work
    Flexible hours

    Blackbaud

    Remote
    3 days ago
  • $2,000 per month

    Join to apply for the Senior Threat Detection Engineer role at Miro Join to apply for the Senior Threat Detection Engineer role at Miro About The...  ...knowledge in a new way. Experts add insights directly into each article, started with the help of AI. #J-18808-Ljbffr Miro
    Full time
    Internship
    Work at office
    Remote work
    Work from home
    Worldwide
    Flexible hours

    Miro

    Austin, TX
    2 days ago
  • $160k - $250k

     ...with the world’s most advanced AI-native platform. We work on...  ...is seeking an experienced Principal Product Manager who is technical...  ...in-depth knowledge of the Threat Detection market (including Endpoint,...  ...You will work closely with engineering, researchers, product marketing... 
    Principal
    Full time
    Work experience placement
    Work at office
    Local area
    Remote work
    Worldwide
    2 days per week

    CrowdStrike

    Austin, TX
    3 days ago
  •  ...Why Content Safety? As a Principal Machine Learning Engineer for Content Safety, you will define the future...  ...systems proactively and effectively detect and mitigate violative content at massive...  ...production stack, leveraging modern AI coding tools (e.g., Cursor) to... 
    Principal
    Full time

    Roblox

    Remote
    20 hours ago
  •  ...online communities. We systematically and proactively detect, remove, and prevent problematic content and...  ...relationships between people around the world. Why Safety AI Systems? As a Senior/Principal Machine Learning Engineer for Safety AI Systems, you will define the... 
    Principal
    Full time

    Roblox

    Remote
    20 hours ago
  •  ...evaluate the defense team's ability in attack detection, alarm analysis, traceability analysis,...  ...lines. Attack Surface Analysis and Threat Research Identify enterprise network exposure...  ...surfaces to core assets. Tracking AI-related security risks, including... 
    Principal
    Full time

    Bybit

    Remote
    14 days ago
  •  ...fearless and high-impact talent who see AI as a teammate – leveraging it to...  ...Gen. About the Role: As a Principal Engineer, Security Logging & Detection , you will serve as the technical...  ...These foundational services power threat detection, security investigations,... 
    Principal
    Full time
    Flexible hours

    MoneyLion

    Tempe, AZ
    13 days ago
  • $120k - $165k

     ...in delivering advanced analytic, data engineering, and technology integration solutions...  ...Overview:Praescient Analytics is seeking a Principal Cyber Systems Engineer, SME to provide...  ...and fraud investigations, and insider threat detection.Our team of experts—skilled in cloud... 
    Principal
    Full time
    Work at office

    Praescient Analytics

    Arlington, VA
    3 days ago
  •  ...seeking a highly motivated and experienced Machine Learning Engineer to join our AI & Threat Analytics team. This is a 100% remote position with an...  ...a critical part in advancing Keeper’s AI-driven threat detection capabilities for our Privileged Access Management (PAM)... 
    Remote job
    Full time
    Temporary work

    Keeper Security

    United States
    20 hours ago
  •  ...everyone. From advanced data analytics and AI to cybersecurity, we use innovative...  .... Growing together.We are seeking a Principal Site Reliability Engineer (SRE) to define and scale...  ...Azure environmentsApply AIOps (anomaly detection, intelligent alerting, automation)Influence... 
    Principal
    Minimum wage
    Full time
    Work experience placement
    Work at office
    Local area
    Remote work

    UnitedHealth Group

    Minnetonka, MN
    4 days ago
  • $132.4k - $251.6k

     .... For more than 70 years, scientists and engineers in a wide ranging disciplines at RTX BBN...  ...Sophisticated Algorithms: Design and evolve advanced detection and classification algorithms start-of-...  ...or marine environment processing.Modern AI Pipelines: Experience implementing... 
    Principal
    Temporary work
    Work experience placement
    Work at office
    Remote work
    Worldwide
    Flexible hours

    Raytheon

    Middletown, RI
    2 days ago
  • $148.75k - $192.5k

     ...productivity and growth. Role OverviewAs a Principal Enterprise Systems Engineer at Cboe, you will lead the...  ...across the team. You will also champion AI-assisted engineering practices,...  ...incident triage, configuration drift detection, Jira workflow automation, and runbook... 
    Principal
    Full time
    Contract work
    Work at office
    Immediate start

    Cboe Exchange

    Kansas City, MO
    4 days ago
  • $295.25k - $345.04k

     ...online communities. We systematically detect, remove, and prevent problematic accounts...  ...automation, detection workflows, and AI-powered text filters. Aligned and...  ...around the world.WHY GAME SAFETY?As a Principal Software Engineer on Game Safety, you’ll work on some of... 
    Principal
    Full time
    Temporary work
    Work experience placement
    H1b
    Work at office
    Local area
    Visa sponsorship
    Monday to Friday
    Flexible hours

    Roblox

    San Mateo, CA
    20 hours ago
  • $70 - $95 per hour

    Join to apply for the Consultant - Threat Detection Engineer role at Kalles Group Base pay range $70.00/hr - $95.00/hr Everyone deserves to be secure. Our mission at Kalles Group is to help secure the future for companies of all shapes and sizes. While our expertise... 
    Hourly pay
    Full time
    Temporary work
    Remote work

    Kalles Group

    Seattle, WA
    2 days ago
  •  ...to QA innovation and mentoring junior engineers are key.Job Description*This position is...  ...customers.About the Role:We’re seeking a Principal AI & Automation Engineer, to lead the...  ...using AI/ML techniques (e.g., anomaly detection, flaky test prediction, intelligent test... 
    Principal
    Full time
    Work at office
    Remote work
    Worldwide
    Shift work

    Comcast

    Philadelphia, PA
    1 day ago
  • $175.88k - $251.25k

     ...efficient, resilient, and secure. As an AI-forward enterprise, we are constantly...  ...systems to stay ahead of evolving threats. We believe in transparency and value...  ...of cybersecurity.We are looking for a Principal Specialist Sales Engineer for Data Security serving our... 
    Principal
    Full time
    Work at office
    Local area
    Remote work
    Flexible hours

    Zscaler

    Massachusetts
    2 days ago
  • $90k - $130k

     ...experience in Site Reliability Engineering, Software Engineering, or...  ...through automation, tooling, or AI-enabled methods. We need...  ...production, such as anomaly detection, alert tuning, or automation....  ...challenges. This is a senior, remote Principal Site Reliability Engineer... 
    Principal
    Full time
    Remote work

    UnitedHealth Group

    Minnetonka, MN
    7 days ago
  • $107.5k - $204.5k

     ...of experience and renowned engineering expertise to meet the needs...  ...and stay ahead of tomorrow’s threat. We deliver solutions that help...  ...is seeking a talented Principal Systems Engineer to join our...  ...raw sensor data, tracks, and detections to evaluate algorithm performance... 
    Principal
    Temporary work
    Work experience placement
    Interim role
    Work at office
    Remote work
    Relocation package
    Flexible hours

    Raytheon

    Woburn, MA
    2 days ago
  • $142.8k - $304.2k

     ...High Performance Computing (AI/HPC) organization powers some...  ...joining us, you step into the engineering core responsible for ensuring...  ...wave of AI innovation. As a Principal Supercomputing Operations...  ...incidents end to end, including detection, triage, mitigation, recovery... 
    Principal
    Full time

    Microsoft

    Remote
    1 day ago
  •  ...-to-face conversation.** Job Summary: The Principal Test Engineer comes with proven success applying AI to test automation and quality assurance. This individual...  ..., execution efficiency, coverage, and defect detection. Define and maintain the overall testing... 
    Principal
    Full time
    Part time
    Remote work

    Businessolver

    Remote
    8 days ago
  • $107.5k - $204.5k

     ...of experience and renowned engineering expertise to meet the needs...  ...and stay ahead of tomorrow’s threat. We deliver solutions that help...  ...organization is seeking a Principal System Engineer in Huntsville...  ...test events to characterize detection, tracking, discrimination,... 
    Principal
    Temporary work
    Work experience placement
    Work at office
    Remote work
    Relocation package
    Flexible hours

    Raytheon

    Huntsville, AL
    2 days ago
  • Anthropic is seeking a Threat Intelligence Engineer to build scalable threat discovery infrastructure and data pipelines. You will integrate external data sources, develop detection systems for automated lead generation, and create internal tooling that scales investigators... 
    Remote job

    Anthropic

    San Francisco, CA
    2 days ago
  • $175k - $200k

     ...and deployment of Artificial Intelligence (AI) systems at Iovance Biotherapeutics. This...  ...is a deeply technical, hands-on senior engineer with demonstrated production experience designing...  ...and grounding metrics, hallucination detection, adversarial inputs, and regression... 
    Principal
    Full time
    Work experience placement
    Work at office
    Remote work

    Iovance Biotherapeutics

    Remote
    20 hours ago
  •  ...tech pioneer delivering enterprise-grade AI and quantum sensing solutions to solve...  ...seeking a visionary, deeply technical Principal Software Engineer (Senior Staff track) to serve as the...  ...device authentication, and defensive threat modeling for connected hardware. ~ Location... 
    Principal
    Full time
    Seasonal work
    Remote work
    Work from home
    Flexible hours

    SandboxAQ

    Remote
    a month ago
  •  ...forward. Job Description Focus:  AI workload-driven product development, test...  ...automated validation Partner with Test Engineering to deliver scalable and robust production...  ...test data to identify yield limiters and detect anomalies Drive data-informed... 
    Principal
    Temporary work
    Remote work
    Flexible hours
    Shift work

    Sandisk

    Milpitas, CA
    more than 2 months ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Principal AI Threat Detection Engineer. Be the first to apply!