TELECOMMUTE Staff Vulnerability Management Analyst- AI Automation Security Researcher

UKG Inc.
United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$115,100.0 - $165,450.0
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) JavaScript (Programming Language) .NET Framework Artificial Intelligence Amazon Web Services Software System Penetration Testing Microsoft Azure C Sharp (Programming Language) C++ (Programming Language) Software as a Service Cloud Computing Security Static Program Analysis
+28 more
Cyber Security Data Deduplication Firmware Python (Programming Language) Lightweight Directory Access Protocols (LDAP) Open Source Technology Pattern Recognition Reverse Engineering SQL Databases Systems Integration TypeScript Software Vulnerability Management Google Cloud Delivery Pipeline Large Language Models Software Security Mttr GWAPT Kubernetes Bug Reporting Information Technology Machine Learning Operations Service Stack Plan of Action and Milestones Static Application Security Testing Vulnerability Analysis Golang Dynamic Application Security Testing

Job description

Vulnerability Discovery & Security Research (40%)

  • Conduct deep-dive source code audits of UKG products (Java, .NET, Python, JavaScript) to discover novel vulnerabilities - examples could be hardcoded secrets, authentication bypasses, injection flaws, cryptographic weaknesses, access control gaps, unsafe deserialization, etc.
  • Develop working proof-of-concept exploits that demonstrate real impact - not theoretical risk, but provable exploitation with clear data exposure or access escalation
  • Perform variant analysis: when you find a bug, systematically search the entire codebase for every instance of the same root cause pattern
  • Triage and validate findings from automated scanners (SAST, DAST, SCA) - separate real vulnerabilities from false positives using source-level analysis
  • Investigate and reproduce externally reported vulnerabilities (bug bounty, CVEs, vendor advisories) to assess actual exploitability in UKG’s environment
  • Collaborate with engineering teams on remediation - not just filing tickets, but working with developers to design, validate fixes, and drive to remediation.

AI-Powered Vulnerability Automation (35%)

  • Build AI-assisted vulnerability discovery tools using automation (Claude, MCP servers, custom models, etc.) for automated source code analysis, vulnerability pattern matching, and exploit generation
  • Develop autonomous security scanning agents that can analyze codebases, identify vulnerability patterns, and produce validated findings with minimal human intervention
  • Create AI-powered remediation tools - automation that generates fix recommendations, patches, and pull requests for discovered vulnerabilities, accelerating the path from finding to fix
  • Build automated vulnerability lifecycle pipelines: intake from scanners, AI-assisted triage and deduplication, intelligent ticket routing, SLA tracking, and remediation verification
  • Contribute to the team’s shared automation repositories and Claude Code skills store - every tool you build should be reusable by the rest of the team

Vulnerability Management & Remediation Driving (20%)

  • Own vulnerability remediation outcomes for assigned product areas - track findings from discovery through verified fix, holding engineering teams accountable to SLAs
  • Produce clear, actionable vulnerability reports that engineering teams can act on immediately - root cause, impact, reproduction steps, and recommended fix
  • Drive mean time to remediate (MTTR) down through better automation, better reports, and direct collaboration with development teams
  • Support vulnerability management program metrics and dashboards - contribute to reporting that gives leadership real-time visibility into risk posture
  • Support compliance-driven vulnerability management requirements, including FedRAMP continuous monitoring and POA&M processes, as UKG expands into federal markets

Research & Knowledge Sharing (5%)

  • Publish internal/external research on novel vulnerability classes, AI-assisted discovery techniques, and lessons learned from audits
  • Stay current on emerging vulnerability classes, exploitation techniques, and defensive patterns relevant to UKG’s technology stack
  • Mentor other team members on vulnerability research methodology, source code analysis, and AI-augmented security tooling

Requirements

  • 7+ years of hands-on experience in vulnerability research, application security, or penetration testing - with a track record of finding real vulnerabilities in production software
  • Demonstrated ability to read and audit source code in at least two of: Java, C#/.NET, Python, JavaScript/TypeScript, Go, C/C++
  • Experience developing working proof-of-concept exploits - not just scanning, but understanding root causes and proving exploitability
  • Strong proficiency in Python for building security tools, automation pipelines, and integrations
  • Experience with AI/ML tools for security - using LLMs for code analysis, building AI-assisted security tooling, or developing autonomous security agents
  • Deep understanding of common vulnerability classes: injection (SQL, command, LDAP), broken authentication, cryptographic failures, SSRF, deserialization, path traversal, access control, and their variants
  • Experience with vulnerability management programs - triaging, tracking, and driving remediation of vulnerabilities across engineering organizations
  • Ability to work directly with development teams - explaining vulnerabilities, reviewing proposed fixes, and validating remediations
  • Excellent written communication - ability to produce clear vulnerability reports, technical documentation, and executive summaries
  • Bachelor’s degree in Computer Science, Cybersecurity, or equivalent experience

Preferred Qualifications

  • Published CVEs, security advisories, or bug bounty findings in production software
  • Experience in SaaS/multi-tenant environments processing sensitive data (HCM, payroll, healthcare, financial)
  • Familiarity with SAST/DAST/SCA tooling and how to reduce false positive rates through source-level validation
  • Experience with cloud security assessment (AWS, Google Cloud Platform, Azure) including container and Kubernetes vulnerability analysis
  • Familiarity with FedRAMP, NIST SP 800-53, or federal compliance frameworks - enough to understand vulnerability remediation timelines and reporting requirements in regulated environments
  • Security certifications that demonstrate hands-on skill: OSCP, OSWE, GWAPT, GXPN, BSCP, or equivalent
  • Conference presentations, published research, or open-source security tool contributions
  • Experience with reverse engineering, binary analysis, or firmware security

Benefits & conditions

This is a role for someone who finds bugs, fixes bugs, and builds tools that find more bugs. You will:

  • Work on a team where every member builds production automation - this is an engineering-first security team, not a compliance shop
  • Have access to enterprise AI infrastructure (Claude Code, MCP servers, etc.) to build next-generation vulnerability discovery and remediation tools
  • Audit one of the largest HCM/payroll platforms in the world - protecting tens of thousands of customer organizations and millions of workers’ sensitive data
  • Have direct, measurable impact - your findings directly prevent issues across UKG’s entire customer base
  • Pioneer the use of AI for vulnerability discovery and automated remediation - building tools that change how security research is done at scale
  • Grow your career in an environment that values builders and doers over process managers and policy writers

Compensation & Benefits

UKG offers a comprehensive total rewards package including competitive base salary, annual bonus, equity, full medical/dental/vision, 401(k) match, unlimited PTO, and professional development budget. This role is eligible for remote work anywhere in the US., The pay range for this position is $115,100.00 to $165,450.00. The actual base pay offered may vary depending on skills, experience, job-related knowledge and work location. In addition to base pay, employees may be eligible to participate in a performance-based bonus plan and to receive restricted stock unit awards as part of total compensation. Learn more about UKG’s benefits and rewards at

About the company

At UKG, the work you do matters. The code you ship, the decisions you make, and the care you show a customer all add up to real impact. Today, tens of millions of workers start and end their days with our workforce operating platform. Helping people get paid, grow in their careers, and shape the future of their industries. That’s what we do.

We never stop learning. We never stop challenging the norm. We push for better, and we celebrate the wins along the way. Here, you’ll get flexibility that’s real, benefits you can count on, and a team that succeeds together. Because at UKG, your work matters-and so do you., UKG is the Workforce Operating Platform that puts workforce understanding to work. With the world’s largest collection of workforce insights, and people-first AI, our ability to reveal unseen ways to build trust, amplify productivity, and empower talent, is unmatched. It’s this expertise that equips our customers with the intelligence to solve any challenge in any industry - because great organizations know their workforce is their competitive edge. Learn more at ukg.com.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

3:08 min

Aligning engineering processes with core business impact metrics

Chris Riley · WWC 2021

1:08 min

Building solutions with open source GoLang infrastructure tools

Jad Wahab · LIVE

3:07 min

Establishing service level agreements directly for internal platforms

Pawel Piwosz · LIVE

1:33 min

Case study on adopting Kubernetes and Golang effectively

Andrew Holway · LIVE

1:29 min

Assisting security analysis using AI code review tools

Matteo Meucci Matteo Meucci · Europe 2026 Virtual

Videos

See all

Related articles

See all