Sr. Staff Security Analyst- Eng

UKG

United States

On-site

USD 145,600 - 209,300

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Performance-based bonus
Restricted stock units (RSUs)

Job summary

UKG is seeking a Senior Staff SOC Analyst to join the Global Security Operations team. You will lead incident response, digital forensics, and threat hunting across endpoints, cloud, and workloads, coordinating major incidents and mentoring junior staff.

Strong scripting and GenAI-enabled investigation work are expected. You will collaborate with Legal, Privacy, and business stakeholders, translating findings into executive-ready summaries and durable detections to improve overall security

Qualifications

  • 5+ years of direct hands-on digital forensics and incident response experience.
  • Experience leading or supporting major cyber incident command and coordination.
  • Hands-on threat hunting across SIEM, EDR, cloud telemetry, networks, and endpoints.
  • Strong scripting skills in Python, PowerShell, or Bash for automation.
  • Ability to mentor, train, and influence technical analysts.
  • Experience applying GenAI-assisted workflows to investigations and hunt development.
  • Knowledge of forensic collection standards and executive-ready reporting.
  • Experience with one or more major cloud providers.

Responsibilities

  • Provide hands-on digital forensics and incident response across endpoints, cloud, and networks.
  • Lead major incident command activities: coordinating response, tracking actions, and briefing stakeholders.
  • Perform threat hunting across SIEM, EDR, cloud, identity, and network sources.
  • Support and lead complex investigations as a technical contributor across SOC teams.
  • Mentor analysts during incidents, post-incident reviews, and exercises.
  • Develop incident strategies, timelines, and technical summaries for leadership.
  • Create training materials, playbooks, and exercises for command and response.
  • Utilize scripting to accelerate investigations and standardize responses.

Skills

Digital forensics
Incident response
Threat hunting
Scripting (Python/PowerShell/Bash)
Leadership / mentoring
Forensic artifacts knowledge
GenAI-assisted workflows
Executive communication

Tools

SIEM
EDR
SOAR
Cloud telemetry tools

Job description

Description

As a Senior Staff SOC Analyst, you will be part of UKG’s Global Security Operations team. This global team is responsible for detecting, investigating, responding to, and leading containment of sophisticated cyber threats and major security incidents. In your role you will leverage a variety of tools, forensic techniques, threat hunting methods, and incident command practices to proactively investigate, respond to, and drive resolution for emerging and/or persistent threats impacting UKG and/or its customers.

Responsibilities
  • Provide hands‑on digital forensics and incident response expertise across endpoint disk, memory, network, cloud, Windows, Linux, and runtime environments.
  • Lead major cyber incident command activities, including coordinating technical response, guiding investigative workstreams, tracking actions, briefing stakeholders, and driving incidents through containment and recovery.
  • Perform hands‑on keyboard threat hunting with and without GenAI assistance across SIEM, EDR, cloud, identity, network, and forensic data sources.
  • Support and lead complex incident response investigations as a technical contributor and collaborator across Security Operations Center, Threat Intelligence, Detection Engineering, Cloud Security, Infrastructure, Legal, Privacy, and business stakeholder teams.
  • Guide, mentor, and train analysts during active incidents, post‑incident reviews, tabletop exercises, and proactive hunting engagements.
  • Create and present incident strategies, investigation plans, findings, timelines, and technical summaries to audiences of technical and executive leadership levels when asked.
  • Develop and maintain training materials, playbooks, procedures, and practical exercises for incident command, digital forensics, incident response, and threat hunting capabilities.
  • Use mid‑level scripting and automation to accelerate investigations, enrich forensic analysis, standardize response actions, and improve repeatability across the SOC.
  • Support continuous improvement of incident handling processes, forensic collection methods, threat hunting tradecraft, and analyst readiness.
  • Partner with Detection Engineering and Threat Intelligence teams to convert investigative findings into durable detections, response logic, hunting hypotheses, and operational improvements.
  • Support reverse engineering or malware analysis activities when needed, including triage of suspicious binaries, scripts, payloads, and attacker tooling where skillsets apply.
Qualifications
  • Ability to lead complex security incidents, guide technical teams, influence response direction, and support building strategic and technical SOC initiatives.
  • 5+ years of direct hands‑on digital forensics and incident response experience supporting major enterprise environments.
  • Advanced knowledge of forensic artifact areas across network, cloud, Windows, Linux, endpoint, identity, and runtime environments.
  • Demonstrated experience leading or supporting major cyber incident command, including technical coordination, action tracking, decision support, stakeholder updates, and post‑incident improvement activities.
  • Deep hands‑on experience performing endpoint disk, memory, cloud, and host‑based forensic analysis in active incident response scenarios.
  • Demonstrated hands‑on threat hunting experience using SIEM, EDR, cloud telemetry, identity logs, network data, and forensic artifacts.
  • Experience applying GenAI‑assisted workflows to investigation, summarization, hunt development, scripting, or analyst enablement, while maintaining strong technical validation and judgment.
  • Ability to lead, mentor, train, and influence technical analysts during investigations, hunting activities, and operational readiness efforts.
  • Demonstrable hands‑on skills in a scripting language such as Python, PowerShell, Bash, or similar for use in investigation, automation, parsing, enrichment, and response workflows.
  • Strong understanding of SOC operations, incident response lifecycle, forensic collection standards, evidence handling, investigation documentation, and executive‑ready incident reporting.
  • Ability to develop practical training content for incident command, digital forensics, incident response, and threat hunting programs.
  • Experience with one or more major public cloud service provider environment required.
  • Reverse engineering and malware analysis experience preferred, including static or dynamic triage of malware, scripts, payloads, or attacker tooling.
  • Hands‑on keyboard investigative analysis experience with one or more major SIEM, EDR, SOAR, cloud security, case management, and forensic tooling platforms.
Benefits

The pay range for this position is $145,600 to $209,300. The actual base pay offered may vary depending on skills, experience, job‑related knowledge and work location. In addition to base pay, employees may be eligible to participate in a performance‑based bonus plan and to receive restricted stock unit awards as part of total compensation.

UKG participates in E‑Verify.

Equal Opportunity Employer

UKG is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, disability, religion, sex, age, national origin, veteran status, genetic information, and other legally protected categories.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Staff Security Analyst- Incident Commander
Sr. Staff Security Analyst- Incident Commander

UKG (Ultimate Kronos Group) • Salem (OR)

On-site
USD 126,000 - 209,000
Sr. Staff Security Analyst- Incident Commander
Sr. Staff Security Analyst- Incident Commander

UKG (Ultimate Kronos Group) • Cheyenne (WY)

On-site
USD 146,000 - 209,000
Sr. Staff Security Analyst- Incident Commander
Sr. Staff Security Analyst- Incident Commander

UKG (Ultimate Kronos Group) • Boise (ID)

On-site
USD 146,000 - 209,000
Lead SOC Incident Commander & Threat Hunter
Lead SOC Incident Commander & Threat Hunter

UKG • United States

On-site
USD 145,000 - 210,000
Performance-based bonus
Restricted stock units (RSUs)
Sr. Staff Security Analyst- Incident Commander
Sr. Staff Security Analyst- Incident Commander

UKG (Ultimate Kronos Group) • Jackson (MS)

On-site
USD 146,000 - 209,000
Sr. Staff Security Analyst- Incident Commander
Sr. Staff Security Analyst- Incident Commander

UKG (Ultimate Kronos Group) • Juneau (AK)

Hybrid
USD 146,000 - 209,000
Sr. Staff Security Analyst- Incident Commander
Sr. Staff Security Analyst- Incident Commander

UKG (Ultimate Kronos Group) • Hagåtña (GU)

On-site
USD 146,000 - 209,000
Sr. Staff Security Analyst- Incident Commander
Sr. Staff Security Analyst- Incident Commander

UKG (Ultimate Kronos Group) • Frankfort (KY)

On-site
USD 146,000 - 209,000
Sr. Staff Security Analyst- Incident Commander
Sr. Staff Security Analyst- Incident Commander

UKG (Ultimate Kronos Group) • Honolulu (HI)

Hybrid
USD 146,000 - 209,000
Performance bonus
Restricted stock units (RSUs)
Benefits package
Sr. Staff Security Analyst- Incident Commander
Sr. Staff Security Analyst- Incident Commander

UKG (Ultimate Kronos Group) • Helena (MT)

On-site
USD 146,000 - 209,000