Senior Incident Commander & Security Analytics Lead

UKG (Ultimate Kronos Group)

Charleston (WV)

On-site

USD 146,000 - 209,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

UKG seeks a Senior Staff Security Analyst - Incident Commander to join its Global Security Operations team. You will lead major cyber incident command activities, coordinate technical response, and guide investigations across endpoints, cloud, and identity.

You will mentor analysts and drive containment, recovery, and post-incident improvements. You will develop incident strategies, publish timelines, and deliver technical summaries to leadership, while advancing playbooks and threat-hunting

Qualifications

  • 5+ years of direct hands-on digital forensics and incident response experience supporting major enterprise environments
  • Advanced knowledge of forensic artifact areas across network, cloud, Windows, Linux, endpoint, identity, and runtime environments
  • Experience leading or supporting major cyber incident command, including technical coordination, action tracking, decision support, stakeholder updates, and post-incident improvement activities
  • Hands-on endpoint disk, memory, cloud, and host-based forensic analysis in active IR scenarios
  • Threat hunting experience using SIEM, EDR, cloud telemetry, identity logs, network data, and artifacts
  • GenAI-assisted workflows in investigation, summarization, hunt development, scripting, or analyst enablement
  • Ability to mentor, train, and influence analysts during investigations and readiness
  • Scripting skills in Python/PowerShell/Bash for automation and enrichment
  • Strong understanding of SOC operations and IR lifecycle
  • Ability to develop training content for IR and threat hunting programs
  • Experience with one or more major cloud providers
  • Reverse engineering and malware analysis experience preferred
  • Hands-on investigation across SIEM/EDR/SOAR/cloud tooling platforms

Responsibilities

  • Provide hands-on digital forensics and incident response across endpoints, memory, network, cloud, Windows, Linux, and runtime environments
  • Lead major cyber incident command activities, coordinate response, track actions, brief stakeholders, and drive containment and recovery
  • Perform threat hunting with and without GenAI across SIEM, EDR, cloud, identity, and network data
  • Support and lead complex IR investigations as a technical contributor across SOC, Threat Intelligence, Detection Engineering, Cloud Security, and Legal
  • Guide, mentor, and train analysts during incidents, post-incident reviews, tabletop exercises, and proactive hunting
  • Create incident strategies, investigations plans, findings, timelines, and technical summaries for technical and executive audiences
  • Develop and maintain training materials, playbooks, procedures, and exercises for incident command and forensics
  • Use mid-level scripting to accelerate investigations and standardize responses across SOC
  • Contribute to continuous improvement of incident handling, forensic methods, and hunter tradecraft
  • Collaborate with Detection Engineering and Threat Intelligence to convert findings into detections and improvements
  • Assist in reverse engineering or malware analysis as needed, including triage of binaries and tooling

Skills

Digital forensics
Incident response
Threat hunting
GenAI workflows
Mentoring
Python/PowerShell/Bash
SOC operations
Cloud security
Malware analysis
Disaster recovery planning

Tools

SIEM
EDR
SOAR
Forensic tools
Threat intelligence platforms

Job description

UKG seeks a Senior Staff Security Analyst - Incident Commander to join its Global Security Operations team. You will lead major cyber incident command activities, coordinate technical response, and guide investigations across endpoints, cloud, and identity.

You will mentor analysts and drive containment, recovery, and post-incident improvements. You will develop incident strategies, publish timelines, and deliver technical summaries to leadership, while advancing playbooks and threat-hunting

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Incident Commander: Lead Cyber IR & Forensics
Senior Incident Commander: Lead Cyber IR & Forensics

UKG (Ultimate Kronos Group) • Jefferson City (MO)

On-site
USD 146,000 - 209,000
Senior Incident Commander - Cyber Defense & Forensics Lead
Senior Incident Commander - Cyber Defense & Forensics Lead

UKG (Ultimate Kronos Group) • Concord (NH)

On-site
USD 146,000 - 209,000
Performance bonus
Restricted stock units (RSUs)
Benefits package
Senior Incident Commander — Cybersecurity & Forensics
Senior Incident Commander — Cybersecurity & Forensics

UKG (Ultimate Kronos Group) • Tallahassee (FL)

On-site
USD 146,000 - 209,000
Bonus plan
Restricted stock units
Senior Cyber Incident Commander — Lead & Respond
Senior Cyber Incident Commander — Lead & Respond

UKG (Ultimate Kronos Group) • Little Rock (AR)

On-site
USD 146,000 - 209,000
Senior Incident Commander: Cybersecurity Forensics Lead
Senior Incident Commander: Cybersecurity Forensics Lead

UKG (Ultimate Kronos Group) • Springfield (IL)

On-site
USD 146,000 - 209,000
Senior Cyber Incident Commander & Digital Forensics Lead
Senior Cyber Incident Commander & Digital Forensics Lead

UKG (Ultimate Kronos Group) • Oklahoma City (OK)

On-site
USD 126,000 - 209,000
Senior Incident Commander, Global Security Operations
Senior Incident Commander, Global Security Operations

UKG (Ultimate Kronos Group) • Baton Rouge (LA)

On-site
USD 146,000 - 209,000
Senior Cyber Incident Commander & IR Leader
Senior Cyber Incident Commander & IR Leader

UKG (Ultimate Kronos Group) • Indianapolis (IN)

On-site
USD 146,000 - 209,000
Lead SOC Incident Commander & Threat Hunter
Lead SOC Incident Commander & Threat Hunter

UKG • United States

On-site
USD 145,000 - 210,000
Performance-based bonus
Restricted stock units (RSUs)
Senior Security Operations Analyst
Senior Security Operations Analyst

Prosegur Security USA, Inc • Lowell (MA), Northern (KY)

Hybrid
USD 90,000 - 140,000