Principal AI Threat Detection Engineer - Insider Threat
Listed on 2026-08-03
-
IT/Tech
Cybersecurity, Information Security & Data Protection
About the Role We are looking for a savvy, high-performing Principal AI Threat Detection Engineer – Insider Threat to lead the strategy, design, and day-to-day management of Blackbaud’s Insider Threat program as it matures into an AI-augmented capability, protecting Blackbaud’s and our clients’ information. As a technical leader within Security Engineering, this individual will direct AI-driven and agentic tooling to investigate anomalous events and alerts, detect malicious and anomalous insider activity, and reverse engineer malware, while personally applying the contextual judgment, escalation authority, and accountability that AI cannot provide on its own.
The Principal AI Threat Detection Engineer serves as the subject matter expert for Insider Threat tooling, User and Entity Behavior Analytics (UEBA), Security Orchestration Automation and Response (SOAR) platforms, and the AI/ML models underpinning them, validating model outputs, tuning detection logic, and partnering with leadership to report on the business impact of theft, destruction, alteration, or denial of access to information.
As the program shifts more first-pass analysis to AI, this role increasingly focuses human effort where it matters most: resolving ambiguous or high-stakes cases, overseeing AI-assisted decisions, and troubleshooting complex threats that impact the information security infrastructure at the data, application, service, operating system, and network levels.
- Lead the maturation of Blackbaud’s Insider Threat detection program toward an AI-augmented capability, including administration, tuning, and optimization of Insider Threat tools, UEBA platforms, and the AI/ML models underneath them
- Perform intrusion and insider risk analysis using SIEM technology, UEBA behavioral analytics, AI-generated insights, reports, data visualization, log analysis, and pattern analysis, applying human judgment to validate AI findings and separate true signal from noise
- Direct AI-driven hunting tools and agents to identify threat actor groups (external and insider) and their respective tactics, techniques, and procedures, personally leading the investigation of cases that require nuanced human judgment
- Serve as the human escalation point and first responder for security events that AI and automated tooling flag but cannot fully resolve, via email, phone, and tickets across corporate user networks, data centers, and cloud environments
- Own remediation of information security incidents, including insider threat investigations, ensuring AI-assisted findings are verified and contextualized before action is taken
- Document and communicate findings, elevate critical incidents, and interact with lines of business, HR, Legal, and other stakeholders on sensitive insider matters, exercising the discretion and judgment that AI systems cannot provide
- Design and build AI-driven and SOAR-based automated workflows within Detection Engineering, defining the guardrails, escalation thresholds, and human checkpoints that keep automation safe, effective, and improve analyst performance
- Champion responsible use of AI-driven analysis and automation to enhance detection accuracy and accelerate triage, while evaluating model accuracy, bias, and drift to keep detection logic explainable and trustworthy
- Document automation and AI model deployment processes, to include defining pre-build requirements, validation criteria, and human review checkpoints for high-risk decisions
- Utilize AI and automation to build metrics and dashboards supporting the Insider Threat and broader detection program, applying human interpretation to translate outputs into decisions leadership can act on
- Serve as a thought leader on the evolving division of labor between AI and human analysts – determining which decisions should be automated, which require human review, and how that boundary should shift as the program matures – as well as on new alert content, data correlation, and anomaly thresholds
- Improve and challenge existing processes and procedures in a very agile and fast-paced cyber security environment
- Keep current on the threat landscape, insider risk trends, cyber…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).