Principal AI Threat Detection Engineer
$117.2k - $157.5kBlackbaud
Role Description
We are looking for a savvy, high-performing Principal AI Threat Detection Engineer – Insider Threat to lead the strategy, design, and day-to-day management of Blackbaud’s Insider Threat program as it matures into an AI-augmented capability, protecting Blackbaud’s and our clients’ information. As a technical leader within Security Engineering, this individual will direct AI-driven and agentic tooling to investigate anomalous events and alerts, detect malicious and anomalous insider activity, and reverse engineer malware, while personally applying the contextual judgment, escalation authority, and accountability that AI cannot provide on its own.
The Principal AI Threat Detection Engineer serves as the subject matter expert for Insider Threat tooling, User and Entity Behavior Analytics (UEBA), Security Orchestration Automation and Response (SOAR) platforms, and the AI/ML models underpinning them, validating model outputs, tuning detection logic, and partnering with leadership to report on the business impact of theft, destruction, alteration, or denial of access to information. As the program shifts more first-pass analysis to AI, this role increasingly focuses human effort where it matters most: resolving ambiguous or high-stakes cases, overseeing AI-assisted decisions, and troubleshooting complex threats that impact the information security infrastructure at the data, application, service, operating system, and network levels.
Qualifications
- 8+ years of Security Engineering and Analysis experience, preferably in Threat Detection and Response, including demonstrated experience supporting Insider Threat programs
- 5+ years of IT or networking experience
- Hands-on experience administering, tuning, and optimizing Insider Threat detection tools, User and Entity Behavior Analytics (UEBA) platforms, and the AI/ML models that power them
- Experience with SOAR tools and playbook development, including explicit expertise applying AI-driven and agentic automation to security operations and critically evaluating AI-generated findings for accuracy
- Experience with security metrics and reporting, preferably including automating recurring metrics and reporting processes
- Demonstrated ability to critically evaluate AI/ML model outputs
- Intermediate to Advanced Linux/Unix OS and Windows knowledge
- Firewall rule and policy, and network routing fundamentals
- Ability to manage parallel tasks and accurately document resolutions
- Proven ability to implement automation through scripting (e.g., PowerShell, PERL, Python, Bash scripting), including integrating AI/ML APIs or agentic frameworks into detection workflows
- Experience leveraging APIs to integrate third-party tooling into an existing tool stack
- Familiarity with cyber security frameworks such as NIST and MITRE ATT&CK, and awareness of emerging AI governance and security frameworks (e.g., NIST AI RMF, MITRE ATLAS)
- Industry-recognized professional certification such as Security+, CBROPS, CSA, CEH, GSEC, SSCP
Requirements
- Lead the maturation of Blackbaud’s Insider Threat detection program toward an AI-augmented capability, including administration, tuning, and optimization of Insider Threat tools, UEBA platforms, and the AI/ML models underneath them
- Perform intrusion and insider risk analysis using SIEM technology, UEBA behavioral analytics, AI-generated insights, reports, data visualization, log analysis, and pattern analysis, applying human judgment to validate AI findings and separate true signal from noise
- Direct AI-driven hunting tools and agents to identify threat actor groups (external and insider) and their respective tactics, techniques, and procedures, personally leading the investigation of cases that require nuanced human judgment
- Serve as the human escalation point and first responder for security events that AI and automated tooling flag but cannot fully resolve, via email, phone, and tickets across corporate user networks, data centers, and cloud environments
- Own remediation of information security incidents, including insider threat investigations, ensuring AI-assisted findings are verified and contextualized before action is taken
- Document and communicate findings, escalate critical incidents, and interact with lines of business, HR, Legal, and other stakeholders on sensitive insider matters, exercising the discretion and judgment that AI systems cannot provide
- Design and build AI-driven and SOAR-based automated workflows within Detection Engineering, defining the guardrails, escalation thresholds, and human checkpoints that keep automation safe, effective, and improve analyst performance
- Champion responsible use of AI-driven analysis and automation to enhance detection accuracy and accelerate triage, while evaluating model accuracy, bias, and drift to keep detection logic explainable and trustworthy
- Document automation and AI model deployment processes, to include defining pre-build requirements, validation criteria, and human review checkpoints for high-risk decisions
- Utilize AI and automation to build metrics and dashboards supporting the Insider Threat and broader detection program, applying human interpretation to translate outputs into decisions leadership can act on
- Serve as a thought leader on the evolving division of labor between AI and human analysts – determining which decisions should be automated, which require human review, and how that boundary should shift as the program matures – as well as on new alert content, data correlation, and anomaly thresholds
- Improve and challenge existing processes and procedures in a very agile and fast-paced cyber security environment
- Keep current on the threat landscape, insider risk trends, cyber security developments, and emerging AI/ML techniques relevant to detection engineering
- Adapt to fluid infrastructures, and evaluate, pilot, and integrate new AI-enabled technologies and platforms
- Act as peer reviewer and technical escalation point within the core security engineering team, including reviewing AI-assisted detection logic and automation before deployment
- Advise and inform leadership on how to optimize the current toolset and evaluate future tools, including UEBA, SOAR, and AI-enabled analysis platforms, recommending where automation should expand and where human oversight must remain
Benefits
- Medical, dental, and vision insurance
- Remote-flexible workforce
- Wellness Programs
- 401(k) program with employer match
- Flexible paid time off
- Generous Parental Leave
- Donations for Doers
- Pet insurance, legal and identity protection
- Tuition reimbursement program
- We’re looking for a Senior Threat Detection & Intelligence Engineer to help us understand how adversaries operate, detect meaningful threats early, and lead investigations when it matters most. This role sits at the intersection of threat intelligence, detection engineering...SuggestedWork from home
$98k - $176k
...we care, grow, and win together. Join our team as a Senior Engineer and take a lead in building tools to aid fraud analysts... ...to work in a team-oriented environmentInterested in cyber threat or fraud detection Ability to demonstrate analytical expertise, close attention...SuggestedFull timeTemporary workWork experience placementWorldwideFlexible hours$119.32k - $202.85k
ICF is actively recruiting for an experienced Senior Threat Detection & Response Engineer to support the research and development of new cyber analytic... ...in the Transparency in (Benefits) Coverage Act. Candidate AI Usage PolicyAt ICF, we are committed to ensuring a fair...SuggestedFull timeContract workWork experience placementWork at officeRemote work$221.2k - $387.1k
...DescriptionIt all started when engineer Fred Luddy wrote code that... ...work. Today, ServiceNow is the AI control tower for business reinvention... ...exists. You'll architect the threat models, controls, and secure-... ...team practices, consolidate detection platforms, or take on the next...PrincipalWork at officeImmediate startRemote workFlexible hours- ICF is seeking an experienced Senior Threat Detection & Response Engineer to support R&D of cyber analytic capabilities for federal networks. The role is primarily telework-based with occasional client or ICF facility meetings in the DC metro area. Responsibilities include...SuggestedRemote job
$101.9k - $132.8k
Role Description We are looking for a savvy, high-performing Threat Detection Engineer who will be responsible for the day-to-day management of company-wide information security toolsets and the protection of Blackbaud’s and Client’s information. Security Engineers diligently...Full timeRemote workFlexible hours$2,000 per month
Join to apply for the Senior Threat Detection Engineer role at Miro Join to apply for the Senior Threat Detection Engineer role at Miro About The... ...knowledge in a new way. Experts add insights directly into each article, started with the help of AI. #J-18808-Ljbffr MiroFull timeInternshipWork at officeRemote workWork from homeWorldwideFlexible hours$160k - $250k
...with the world’s most advanced AI-native platform. We work on... ...is seeking an experienced Principal Product Manager who is technical... ...in-depth knowledge of the Threat Detection market (including Endpoint,... ...You will work closely with engineering, researchers, product marketing...PrincipalFull timeWork experience placementWork at officeLocal areaRemote workWorldwide2 days per week- ...Why Content Safety? As a Principal Machine Learning Engineer for Content Safety, you will define the future... ...systems proactively and effectively detect and mitigate violative content at massive... ...production stack, leveraging modern AI coding tools (e.g., Cursor) to...PrincipalFull time
- ...online communities. We systematically and proactively detect, remove, and prevent problematic content and... ...relationships between people around the world. Why Safety AI Systems? As a Senior/Principal Machine Learning Engineer for Safety AI Systems, you will define the...PrincipalFull time
- ...evaluate the defense team's ability in attack detection, alarm analysis, traceability analysis,... ...lines. Attack Surface Analysis and Threat Research Identify enterprise network exposure... ...surfaces to core assets. Tracking AI-related security risks, including...PrincipalFull time
- ...fearless and high-impact talent who see AI as a teammate – leveraging it to... ...Gen. About the Role: As a Principal Engineer, Security Logging & Detection , you will serve as the technical... ...These foundational services power threat detection, security investigations,...PrincipalFull timeFlexible hours
$120k - $165k
...in delivering advanced analytic, data engineering, and technology integration solutions... ...Overview:Praescient Analytics is seeking a Principal Cyber Systems Engineer, SME to provide... ...and fraud investigations, and insider threat detection.Our team of experts—skilled in cloud...PrincipalFull timeWork at office- ...seeking a highly motivated and experienced Machine Learning Engineer to join our AI & Threat Analytics team. This is a 100% remote position with an... ...a critical part in advancing Keeper’s AI-driven threat detection capabilities for our Privileged Access Management (PAM)...Remote jobFull timeTemporary work
- ...everyone. From advanced data analytics and AI to cybersecurity, we use innovative... .... Growing together.We are seeking a Principal Site Reliability Engineer (SRE) to define and scale... ...Azure environmentsApply AIOps (anomaly detection, intelligent alerting, automation)Influence...PrincipalMinimum wageFull timeWork experience placementWork at officeLocal areaRemote work
$132.4k - $251.6k
.... For more than 70 years, scientists and engineers in a wide ranging disciplines at RTX BBN... ...Sophisticated Algorithms: Design and evolve advanced detection and classification algorithms start-of-... ...or marine environment processing.Modern AI Pipelines: Experience implementing...PrincipalTemporary workWork experience placementWork at officeRemote workWorldwideFlexible hours$148.75k - $192.5k
...productivity and growth. Role OverviewAs a Principal Enterprise Systems Engineer at Cboe, you will lead the... ...across the team. You will also champion AI-assisted engineering practices,... ...incident triage, configuration drift detection, Jira workflow automation, and runbook...PrincipalFull timeContract workWork at officeImmediate start$295.25k - $345.04k
...online communities. We systematically detect, remove, and prevent problematic accounts... ...automation, detection workflows, and AI-powered text filters. Aligned and... ...around the world.WHY GAME SAFETY?As a Principal Software Engineer on Game Safety, you’ll work on some of...PrincipalFull timeTemporary workWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to FridayFlexible hours$70 - $95 per hour
Join to apply for the Consultant - Threat Detection Engineer role at Kalles Group Base pay range $70.00/hr - $95.00/hr Everyone deserves to be secure. Our mission at Kalles Group is to help secure the future for companies of all shapes and sizes. While our expertise...Hourly payFull timeTemporary workRemote work- ...to QA innovation and mentoring junior engineers are key.Job Description*This position is... ...customers.About the Role:We’re seeking a Principal AI & Automation Engineer, to lead the... ...using AI/ML techniques (e.g., anomaly detection, flaky test prediction, intelligent test...PrincipalFull timeWork at officeRemote workWorldwideShift work
$175.88k - $251.25k
...efficient, resilient, and secure. As an AI-forward enterprise, we are constantly... ...systems to stay ahead of evolving threats. We believe in transparency and value... ...of cybersecurity.We are looking for a Principal Specialist Sales Engineer for Data Security serving our...PrincipalFull timeWork at officeLocal areaRemote workFlexible hours$90k - $130k
...experience in Site Reliability Engineering, Software Engineering, or... ...through automation, tooling, or AI-enabled methods. We need... ...production, such as anomaly detection, alert tuning, or automation.... ...challenges. This is a senior, remote Principal Site Reliability Engineer...PrincipalFull timeRemote work$107.5k - $204.5k
...of experience and renowned engineering expertise to meet the needs... ...and stay ahead of tomorrow’s threat. We deliver solutions that help... ...is seeking a talented Principal Systems Engineer to join our... ...raw sensor data, tracks, and detections to evaluate algorithm performance...PrincipalTemporary workWork experience placementInterim roleWork at officeRemote workRelocation packageFlexible hours$142.8k - $304.2k
...High Performance Computing (AI/HPC) organization powers some... ...joining us, you step into the engineering core responsible for ensuring... ...wave of AI innovation. As a Principal Supercomputing Operations... ...incidents end to end, including detection, triage, mitigation, recovery...PrincipalFull time- ...-to-face conversation.** Job Summary: The Principal Test Engineer comes with proven success applying AI to test automation and quality assurance. This individual... ..., execution efficiency, coverage, and defect detection. Define and maintain the overall testing...PrincipalFull timePart timeRemote work
$107.5k - $204.5k
...of experience and renowned engineering expertise to meet the needs... ...and stay ahead of tomorrow’s threat. We deliver solutions that help... ...organization is seeking a Principal System Engineer in Huntsville... ...test events to characterize detection, tracking, discrimination,...PrincipalTemporary workWork experience placementWork at officeRemote workRelocation packageFlexible hours- Anthropic is seeking a Threat Intelligence Engineer to build scalable threat discovery infrastructure and data pipelines. You will integrate external data sources, develop detection systems for automated lead generation, and create internal tooling that scales investigators...Remote job
$175k - $200k
...and deployment of Artificial Intelligence (AI) systems at Iovance Biotherapeutics. This... ...is a deeply technical, hands-on senior engineer with demonstrated production experience designing... ...and grounding metrics, hallucination detection, adversarial inputs, and regression...PrincipalFull timeWork experience placementWork at officeRemote work- ...tech pioneer delivering enterprise-grade AI and quantum sensing solutions to solve... ...seeking a visionary, deeply technical Principal Software Engineer (Senior Staff track) to serve as the... ...device authentication, and defensive threat modeling for connected hardware. ~ Location...PrincipalFull timeSeasonal workRemote workWork from homeFlexible hours
- ...forward. Job Description Focus: AI workload-driven product development, test... ...automated validation Partner with Test Engineering to deliver scalable and robust production... ...test data to identify yield limiters and detect anomalies Drive data-informed...PrincipalTemporary workRemote workFlexible hoursShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal AI Threat Detection Engineer. Be the first to apply!
- senior principal engineer Remote
- director data engineering Remote
- data center chief engineer Remote
- director quality engineering Remote
- director of product engineering Remote
- chief design engineer Remote
- chief engineer Remote
- senior chief engineer Remote
- principal engineer Remote
- senior director engineering Remote





