> Markdown version of [/jobs/ext/1573046-sr-staff-security-analyst-eng](https://www.wearedevelopers.com/jobs/ext/1573046-sr-staff-security-analyst-eng). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Staff Security Analyst- Eng - **Company:** UKG Inc. - **Location:** Phoenix, AZ, United States - **Experience:** Expert - **Salary:** $145,600.0 - $209,300.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Bash Shell, Cloud Computing, Cloud Computing Security, Cyber Security, Decision Support Systems, Linux, Digital Forensics, Intrusion Detection and Prevention, Python (Programming Language), Parsing, Windows PowerShell, Reverse Engineering, Security Information and Event Management, Scripting, Malware, Cyber Threat Analysis, Cybercrime, Security Orchestration, Automation & Response - **Published:** July 7, 2026 - **Apply:** https://dejobs.org/x/x/B2EB853C67804E6CB2DD8867C20F3756/job/ ## About the Role · The ability to lead complex security incidents, guide technical teams, influence response direction, and support building strategic and technical SOC initiatives · 5+ years of direct hands-on digital forensics and incident response experience supporting major enterprise environments · Advanced knowledge of forensic artifact areas across network, cloud, Windows, Linux, endpoint, identity, and runtime environments · Demonstrated experience leading or supporting major cyber incident command, including technical coordination, action tracking, decision support, stakeholder updates, and post-incident improvement activities · Deep hands-on experience performing endpoint disk, memory, cloud, and host-based forensic analysis in active incident response scenarios · Demonstrated hands-on threat hunting experience using SIEM, EDR, cloud telemetry, identity logs, network data, and forensic artifacts · Experience applying GenAI-assisted workflows to investigation, summarization, hunt development, scripting, or analyst enablement, while maintaining strong technical validation and judgment · Ability to lead, mentor, train, and influence technical analysts during investigations, hunting activities, and operational readiness efforts · Demonstratable hands-on skills in a scripting language such as Python, PowerShell, Bash, or similar for use in investigation, automation, parsing, enrichment, and response workflows · Strong understanding of SOC operations, incident response lifecycle, forensic collection standards, evidence handling, investigation documentation, and executive-ready incident reporting · Ability to develop practical training content for incident command, digital forensics, incident response, and threat hunting programs · Experience with one or more major public cloud service provider environment required · Reverse engineering and malware analysis experience preferred, including static or dynamic triage of malware, scripts, payloads, or attacker tooling · Hands-on keyboard investigative analysis experience with one or more major SIEM, EDR, SOAR, cloud security, case management, and forensic tooling platforms ## Description As a Senior Staff SOC Analyst, you will be part of UKG's Global Security Operations team. This global team is responsible for detecting, investigating, responding to, and leading containment of sophisticated cyber threats and major security incidents. In your role you will leverage a variety of tools, forensic techniques, threat hunting methods, and incident command practices to proactively investigate, respond to, and drive resolution for emerging and/or persistent threats impacting UKG and/or its customers., · You will provide hands-on digital forensics and incident response expertise across endpoint disk, memory, network, cloud, Windows, Linux, and runtime environments · You will lead major cyber incident command activities, including coordinating technical response, guiding investigative workstreams, tracking actions, briefing stakeholders, and driving incidents through containment and recovery · You will perform hands-on keyboard threat hunting with and without GenAI assistance across SIEM, EDR, cloud, identity, network, and forensic data sources · You will support and lead complex incident response investigations as a technical contributor and collaborator across Security Operations Center, Threat Intelligence, Detection Engineering, Cloud Security, Infrastructure, Legal, Privacy, and business stakeholder teams · You will guide, mentor, and train analysts during active incidents, post-incident reviews, tabletop exercises, and proactive hunting engagements · You will create and present incident strategies, investigation plans, findings, timelines, and technical summaries to audiences of technical and executive leadership levels when asked · You will develop and maintain training materials, playbooks, procedures, and practical exercises for incident command, digital forensics, incident response, and threat hunting capabilities · You will use mid-level scripting and automation to accelerate investigations, enrich forensic analysis, standardize response actions, and improve repeatability across the SOC · You will support continuous improvement of incident handling processes, forensic collection methods, threat hunting tradecraft, and analyst readiness · You will partner with Detection Engineering and Threat Intelligence teams to convert investigative findings into durable detections, response logic, hunting hypotheses, and operational improvements · You will support reverse engineering or malware analysis activities when needed, including triage of suspicious binaries, scripts, payloads, and attacker tooling where skillsets apply, UKG is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, disability, religion, sex, age, national origin, veteran status, genetic information, and other legally protected categories. View The EEO Know Your Rights poster (https://www.eeoc.gov/sites/default/files/2022-10/EEOC_KnowYourRights_screen_reader_10_20.pdf) UKG participates in E-Verify. View the E-Verify posters here (https://www.e-verify.gov/sites/default/files/everify/posters/EVerifyParticipationPoster.pdf) . It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability. ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Building a Compiler with C#](https://www.wearedevelopers.com/videos/116-building-a-compiler-with-c) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)