Senior Incident Commander & Threat Hunting Lead

UKG (Ultimate Kronos Group)

Sacramento (CA)

On-site

USD 146,000 - 209,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

UKG is seeking a Senior Staff Security Analyst - Incident Commander to join our Global Security Operations team. The role focuses on detecting, investigating, and leading containment of sophisticated cyber threats and major security incidents across enterprise environments.

You will perform hands-on forensics, lead incident command activities, and mentor analysts while coordinating with Security Operations, Threat Intelligence, and Cloud Security teams to drive containment and recovery.

Qualifications

  • Must lead complex security incidents and guide technical teams.
  • Advanced knowledge of forensic artifact areas across network, cloud, Windows, Linux, and endpoints.

Responsibilities

  • Provide hands-on digital forensics and incident response across endpoints, memory, network, cloud, Windows, Linux.
  • Lead major cyber incident command activities with technical coordination and stakeholder updates.
  • Perform threat hunting across SIEM, EDR, cloud telemetry, identity logs, and network data.
  • Support and lead complex investigations as a technical contributor across SOC, Threat Intelligence, and Cloud Security teams.
  • Mentor analysts during active incidents and post-incident reviews; develop training materials and playbooks.

Skills

Incident response
Digital forensics
Threat hunting
GenAI workflows
Python scripting
Leadership / mentoring

Tools

SIEM
EDR
SOAR
Cloud telemetry
Forensic tooling

Job description

UKG is seeking a Senior Staff Security Analyst - Incident Commander to join our Global Security Operations team. The role focuses on detecting, investigating, and leading containment of sophisticated cyber threats and major security incidents across enterprise environments.

You will perform hands-on forensics, lead incident command activities, and mentor analysts while coordinating with Security Operations, Threat Intelligence, and Cloud Security teams to drive containment and recovery.

Get your free, confidential resume review.

or drag and drop your file here.