Blackbaud logo
Blackbaud

Blackbaud is a large, private company founded in 1981 to provide technology solutions to nonprofit organizations. The company helps its clients with fundraising, relationship manag

Manager, Defensive Cyber SecOps

Location

United States

Posted

18 days ago

Salary

$117.2K - $157.5K / year

Seniority

Lead

No structured requirement data.

Job Description

Manager, Defensive Cyber SecOps

Blackbaud

Role Description We’re hiring a Manager, Defensive Cyber Operations to mature, scale, and continuously iterate our agentic SOC. This is a hands-on player/coach role: you will lead a small team of engineers and analysts while personally owning critical technical outcomes across detection engineering, SOAR automation, breach and attack simulation, and insider threat. This role is ideal for a technical leader who improves existing systems, writes production‑quality detection and automation, leads investigations, and raises the operational bar through disciplined iteration. What you’ll do - Lead and develop a small defensive operations team. - Manage, mentor, and grow a small team of security engineers and analysts focused on detection, response, and automation. - Act as the primary technical escalation point for high‑severity incidents; lead investigations and response decision‑making. - Set and reinforce quality standards for investigations, detections, automation, documentation, and on‑call readiness. - Mature and iterate on an agentic SOC. - Evolve and refine agentic SOC workflows that improve triage speed, consistency, and decision quality through automated enrichment, correlation, and recommended or automated response actions. - Iterate on existing SOC workflows, converting repeatable analyst effort into safe, reliable automation with clear guardrails, validation, and auditability. - Define and track operational metrics such as detection coverage, alert fidelity, automation success rates, and MTTD/MTTR improvements. - Own detection engineering outcomes end‑to‑end: alert logic, correlation rules, anomaly thresholds, tuning, and continuous improvement. - Mature a detection‑as‑engineering operating model, including requirements, testing, rollout, post‑deployment measurement, and documentation. - Design, iterate on, and maintain SOAR playbooks for alert enrichment, containment, remediation, and case management. - Enhance custom automation, integrations, and enrichment logic to reduce manual analyst effort and improve response consistency. - Ensure automation remains resilient, production‑grade, well‑documented, and operationally safe at scale. - Mature an existing breach & attack simulation capability to continuously validate detection and response effectiveness. - Translate BAS findings into prioritized detection, automation, and response improvements on a repeatable cadence. - Advance insider threat detection and response capabilities, including use‑case refinement, signal quality, investigation workflows, and playbooks. - Balance speed, precision, and appropriate controls while improving investigative consistency. Qualifications - 5+ years experience leading security operations, detection engineering, incident response, and/or security engineering teams, with direct ownership of operational outcomes. - Strong hands‑on background in intrusion analysis using SIEM/log analytics, packet captures, and investigation tooling. - Proven experience maturing SOAR automation and/or custom tooling to drive repeatable response actions. - Strong detection engineering fundamentals, including alert fidelity, correlation, and continuous tuning. - Experience operating in cloud‑first environments, with hands‑on security detection or response exposure in AWS and Azure. - Comfort operating as both technical leader and people manager in on‑call, real‑time security environments. Preferred qualifications - Experience iterating on AI‑assisted or agentic SOC workflows with measurable operational impact. - Strong scripting experience (e.g., Python) for automation, integrations, and enrichment logic. - Experience with breach and attack simulation, purple team exercises, or continuous control validation programs. - Detection and response experience across AWS and Azure, including cloud-native logs, identity signals, and workload telemetry. - Working knowledge of adversary tradecraft and defensive frameworks (e.g., MITRE ATT&CK, NIST‑aligned approaches). - Security+, CEH, GSEC, CISSP, GCIA, GCIH, GSOC (Equivalent or comparable security engineering, detection, or incident response certifications are welcome.) Benefits - Medical, dental, and vision insurance. - Remote-flexible workforce. - Wellness Programs. - 401(k) program with employer match. - Flexible paid time off. - Generous Parental Leave. - Donations for Doers. - Pet insurance, legal and identity protection. - Tuition reimbursement program.

Related Categories

Related Job Pages

More Security Operations Jobs

Vice President, Information Security

LifeMD

LifeMD is a rapidly growing telehealth company that delivers virtual primary care and treatment services nationwide. Founded in 1987 and headquartered in New York, New York, LifeMD

Role Description The Vice President, Information Security will lead the enterprise cybersecurity, data protection, and IT compliance functions for a leading publicly-traded telehealth organization. This is a critical executive leadership role operating at the intersection of technology, patient safety, regulatory compliance, and enterprise risk management. Reporting directly to the Chief Technology Officer (CTO), the VP of Information Security will be responsible for defining and executing a comprehensive, enterprise-wide security strategy to safeguard protected health information (PHI), ensure regulatory compliance, and protect the organization’s digital and clinical ecosystems. This leader will play a pivotal role in advancing secure digital transformation, strengthening internal controls, and ensuring adherence to healthcare regulatory frameworks and other applicable standards including HIPAA, HITECH, and Sarbanes Oxley IT General Controls. This role requires a strategic yet hands-on leader capable of operating in a highly regulated, mission-critical healthcare environment where security directly impacts patient trust and clinical outcomes. Responsibilities - Cybersecurity & Risk Management - Lead all aspects of enterprise information security, including threat detection, incident response, vulnerability management, and continuous monitoring. - Establish and mature a comprehensive Governance, Risk, and Compliance (GRC) framework aligned to healthcare industry standards (e.g., NIST, HITRUST, ISO 27001). - Continuously assess enterprise risk posture, prioritizing cybersecurity risks in alignment with clinical, operational, and financial risk frameworks. - Data Protection & Patient Privacy - Design and implement strategies to protect sensitive patient data, including Protected Health Information (PHI), Personally Identifiable Information (PII), and clinical data. - Ensure compliance with healthcare data security and privacy regulations, including HIPAA and HITECH, as well as state-specific privacy laws. - Oversee data governance, encryption, identity management, and secure data exchange across clinical systems (EHR/EMR), patient platforms, and third-party partners. - Lead enterprise-wide data protection initiatives, including breach prevention, detection, and response. - Compliance & Controls - Own and manage IT risk, compliance, and IT General Controls (ITGC) programs in support of SOX and healthcare regulatory requirements. - Partner with internal audit, compliance, legal, and finance teams to ensure audit readiness and timely remediation of control deficiencies. - Maintain compliance with standards such as HIPAA, HITRUST, SOC 2, PCI-DSS (as applicable), and other healthcare-specific regulatory frameworks. - Support regulatory audits, accreditation processes, and third-party risk management programs. - Infrastructure Security & Digital Transformation - Lead security architecture across enterprise infrastructure, including cloud, hybrid, and on-premise environments supporting clinical and digital health platforms. - Drive secure cloud transformation initiatives, ensuring appropriate controls across IaaS, PaaS, and SaaS environments. - Partner with engineering, IT, and DevOps teams to implement DevSecOps practices and secure software development lifecycle (SDLC). - Oversee identity and access management (IAM), role-based access controls, and privileged access governance across clinical and enterprise systems. - Incident Response & Cyber Resilience - Lead enterprise incident response strategy, including preparedness, detection, containment, and recovery from cyber incidents. - Coordinate breach investigations, root cause analysis, regulatory reporting, and post-incident remediation. - Develop and maintain business continuity and disaster recovery plans with a strong focus on clinical and operational resilience. - Leadership & Strategy - Build, lead, and scale a high-performing information security organization, including security operations, risk, IT compliance functions. - Serve as a key advisor to executive leadership, the Board, and Audit/Compliance Committees on cybersecurity risk and strategy. - Drive enterprise-wide security awareness and training programs to foster a culture of security and compliance. - Align cybersecurity initiatives with business priorities, digital health innovation, and patient-centric outcomes. Qualifications - 12+ years of progressive leadership in information security, cybersecurity, and risk management, preferably within healthcare, life sciences, or other highly regulated industries. - Experience operating in a publicly traded or highly regulated environment with strong governance and compliance requirements. - Proven track record of leading enterprise security programs in complex environments involving clinical systems, digital platforms, and sensitive patient data. Domain Expertise - Deep knowledge of healthcare regulatory frameworks, including HIPAA, HITECH, HITRUST, and experience managing PHI/PII at scale. - Strong understanding of ITGC, SOX compliance, and audit processes. - Experience securing healthcare technologies, including EHR/EMR systems, patient engagement platforms, telehealth systems, and medical device integrations. Technical & Operational Expertise - Hands-on leadership in cloud security, infrastructure modernization, and enterprise security architecture. - Expertise in identity and access management (IAM), zero trust frameworks, and modern security operations. - Experience implementing and managing GRC platforms and frameworks such as NIST, ISO 27001, and HITRUST. - Demonstrated success in incident response, cyber resilience, and enterprise risk mitigation. Leadership & Interpersonal Skills - Strong executive presence with experience engaging Boards and Audit/Compliance Committees. - Proven ability to lead cross-functional initiatives across technology, clinical, legal, and operational teams. - Ability to operate effectively in a fast-paced, high-stakes healthcare environment where security and patient safety are paramount. Education & Certifications - Bachelor’s or Master’s degree in Computer Science, Information Security, or related field. - Relevant certifications such as CISSP, CISM, CISA, CRISC, or HCISPP preferred. Benefits - Health Care Plan (Medical, Dental & Vision) - Retirement Plan (Roth 401k) - Life Insurance (Basic, Voluntary & AD&D) - Unlimited PTO Policy - Paid Holidays - Short Term & Long Term Disability - Training & Development

United States
Affirm logo

Senior Security Operations Engineer, Incident Response

Affirm

We create honest financial products that improve lives.

Full TimeRemoteTeam 1,001-5,000Since 2012H1B Sponsor

• Lead security incidents end-to-end, from detection and triage through containment, remediation, and post-incident review. • Act as incident commander, driving clear decisions and alignment across teams during high-pressure situations. • Conduct hands-on investigations across cloud and endpoint environments to determine root cause and impact. • Partner with Observability & Automation to improve detections, reduce noise, and build automated response playbooks. • Contribute to and refine incident response playbooks, runbooks, and documentation to improve readiness and consistency. • Collaborate with Security, Infrastructure, and Product teams to identify gaps and strengthen the incident response lifecycle. • Communicate effectively during incidents, providing clear updates to both technical and non-technical stakeholders.

Canada
$150K - $200K / year

Senior Manager, US Security Operations

UnitedHealth Group

UnitedHealth Group is a healthcare and well-being company that’s dedicated to improving the health outcomes of millions around the world. We are comprised of

Role Description The Senior Manager, U.S. Security Operations, West is accountable for the representation of Corporate Security and its workplace security programs for the business segments in the identified West region of the United States. The Senior Manager will: - Implement the short-to long-term vision, mission, and enterprise strategy of Corporate Security. - Lead security solutioning with business leaders. - Provide business leaders with relevant security incident reporting metrics and actionable data. - Coordinate business requirements with the Global Risk Management CoE to enhance security measures. - Champion security awareness, physical security, and proactive security training initiatives. - Raise potential obstacles/opportunities for enhancing security risk management enterprise-wide. - Ideate and innovate solutions to complex strategic problems. - Cultivate a security culture through security education. - Drive compliance with relevant global security regulations, company standards, values, and industry best practices. The Senior Manager will support the overall Corporate Security mission and enable the success, sustainability, and scalability of the entire enterprise workplace security program. This role includes building and maintaining solid internal partnerships with key stakeholders. Qualifications - 5+ years of relevant security experience in the private and/or public sector. - Experience managing workplace security operations and programs. - Demonstrated experience in managing complex security risks. - Experience dealing with incidents and critical events. - Critical understanding of confidentiality and situational sensitivity. - Proficient using MS Office Suite (Word, Excel, PowerPoint, Outlook, etc). - Proven ability to navigate high levels of ambiguity and make critical decisions rapidly. - Proven superior problem-solving and critical thinking ability. - Proven solid leadership engagement, communication, and presentation skills. - Proven high levels of integrity and credibility. Requirements - Work remotely from anywhere within the U.S. (Minneapolis or Washington, D.C. area requires in-office work a minimum of four days per week). - After hours on-call availability and up to 25% travel. - Other duties as required. Benefits - Comprehensive benefits package. - Incentive and recognition programs. - Equity stock purchase. - 401k contribution (subject to eligibility requirements). - Salary range: $91,700 to $163,700 annually based on full-time employment. Application Deadline This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected.

United States
$91.7K - $163.7K / year
eClerx logo

SOC Analyst

eClerx

Industry-focused specialists who manage and improve complex data-driven processes.

Full TimeRemoteTeam 10,001+Since 2000H1B Sponsor

• Accurately review, validate, and process high-volume sales orders, change requests, and cancellations received from the Sales team or customers into the system (e.g., SAP, Oracle, Salesforce). • Verify all critical order elements, including product codes, pricing, quantity, delivery dates, shipping instructions, and customer account details, ensuring alignment with the sales quote and company policy. • Ensure all necessary contractual documentation, customer-specific terms, and internal approvals (e.g., credit checks, legal review) are attached or referenced before finalizing the order. • Proactively communicate with the Sales team, Finance, and Inventory regarding any discrepancies found in pricing, product availability, delivery timelines, or incomplete documentation to resolve issues quickly and prevent order delays. • Maintain the integrity of customer and order data within the ERP/CRM system, performing regular audits and updates as required. • Identify bottlenecks or inefficiencies in the order creation process and recommend solutions to standardize and streamline workflows for faster processing. • Assist in generating reports related to order volumes, processing times, and common data errors to support Sales Operations analysis.

Philippines