Incident Response Lead

2 weeks ago


Dublin, Dublin City, Ireland UKG, Inc. Full time

Company Overview:

With 80,000 customers across 150 countries, UKG is the largest U.S.-based private software company in the world. And we're only getting started. Ready to bring your bold ideas and collaborative mindset to an organization that still has so much more to build and achieve? Read on.

At UKG, you get more than just a job. You get to work with purpose. Our team of U Krewers are on a mission to inspire every organization to become a great place to work through our award-winning HR technology built for all.

Here, we know that you're more than your work. That's why our benefits help you thrive personally and professionally, from wellness programs and tuition reimbursement to U Choose - a customizable expense reimbursement program that can be used for more than 200+ needs that best suit you and your family, from student loan repayment, to childcare, to pet insurance. Our inclusive culture, active and engaged employee resource groups, and caring leaders value every voice and support you in doing the best work of your career. If you're passionate about our purpose - people - then we can't wait to support whatever gives you purpose. We're united by purpose, inspired by you.

About the role:

As a Incident Response Lead, you will be part of UKG's Global Security Operations Center (GSOC) team investigating events of interest and incidents as they are validated, prioritised, and categorised by UKG's 24x7 L1 and L2 analyst teams. You will facilitate and follow UKG's standard processes to investigate, contain, eradicate, and respond in a continued and unified effort to protect the confidentiality, integrity, and availability of UKG, our partners' and customers' data and services.

You will be an escalation point for all incidents, either regionally or during shift assignment; analyzing, confirming, re-prioritizing if necessary and/or escalating/remediating those identified threats within the UKG computing environment. You will work closely with UKG's GSOC teams in the US, Singapore, and India to promote an integrated, uniform, and holistic threat detection and response capability to facilitate and enable a robust and proactive security posture.

You will leverage your skills, experience, and creativity to perform initial, forensically sound collection and analysis, methodologies to contain, eradicate, and recover from realised threats such as zero-day, ransomware, malware and other APT's. You will be responsible for Leading incident response activities as the Cyber Incident Commander (CIC), as the Cyber Incident Response Lead (CIRL) or as a subject matter expert on the Cyber Incident Response Team (CIRT).

You will lead and/or participate in post incident reporting including developing and validating After Action Reports (AAR) and Root Cause Analysis (RCA) and using your experience, knowledge, and creativity to identify and offer continuous improvement recommendations to enhance UKG's security posture through process development, tool rationalisation, detection technique and automation enhancement opportunities and enablement/training possibilities.

This is a hybrid position requiring 3 days a week in our Kilkenny office and 2 days a week working from home. Due to the nature of the work, you are required to have occasional on-call duties on weekends and/or holidays. Additional work hours may also be required during an incident investigation.

Key Responsibilities:

  1. Identify, develop, and operationalise security operations metrics to assist in maturing and enhancing UKG's visibility and global security capabilities.
  2. Continuously improve UKG's incident response processes through automations, standardisation, and tools development, customisation and/or controls deployments.
  3. Collaborate with cross-functional and geographically dispersed teams to identify, develop, and implement containment, eradication, and recovery strategies.
  4. Lead and provide subject matter expertise during active investigations of events of interest and security incidents escalated to and as identified within the regional Security Operations Center.
  5. Escalate tickets as required to GSOC Director for additional scrutiny and incident declaration.
  6. Identify, approve, and implement blocking, listing and other mechanisms to promote a robust security posture.
  7. Keep up to date with the latest security and technology developments, research/evaluate emerging cyber security threats and ways to manage them to proactively enhance UKG's security posture.
  8. Participate in threat hunts, blue team/purple team activities by simulating real-world cyber-attacks to evaluate the effectiveness of security defenses and recommend improvements.
  9. Be the escalation point for all junior analysts to aid and facilitate the accurate and expedient identification, verification, and remediation of security incidents.
  10. Mentor, coach and facilitate enablement opportunities to develop and enhance UKG's junior security analysts.

Qualifications:

  1. Bachelor's degree in computer science or a related discipline.
  2. CISSP, CCSP, GIAC or other relevant cyber security certifications.
  3. Working professional with 6+ years of relevant Security/SOC experience.
  4. Practical experience in leading incident response investigations, performing analysis, and implementing containment strategies.
  5. Experience in conducting investigations involving network forensics, malware analysis, and disk and memory forensics, focusing on any combination of Windows, macOS, or Linux platforms.
  6. Experience conducting incident response and forensic investigations in major Cloud Service Providers (CSP).
  7. Experience with tools such as Splunk, Elastic Search, EDR solutions.
  8. Excellent verbal and written communication skills.
  9. Experience working in a global organization is a plus.

Preferred Qualifications:

  1. Knowledge of the common attack vectors on the network layer, different classes of attacks (e.g., passive, active, insider, close-in, distribution attacks).
  2. Knowledge of cyber attackers (e.g., script kiddies, insider threat, non-nation state sponsored, and nation sponsored) and cyber-attack stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks).
  3. Thorough understanding of system and application security threats and vulnerabilities, enabling proactive identification and mitigation strategies to safeguard critical assets and data (e.g. SQL Injection, Cross-Site Scripting (XSS), Malware Infection, Zero-Day Exploits, Phishing Attacks, Denial of Service (DoS) Attacks, Man-in-the-Middle (MitM) Attack, Buffer Overflows, Weak Authentication Mechanism, Unpatched Software: Vulnerability.)

Ireland Benefits:

  • 25 days annual leave, increasing by one day per year to a maximum of 28 days
  • 26 weeks paid maternity leave & 2 weeks paid paternity leave from start of employment
  • Medical/Dental/Vision coverage provided through Laya Healthcare, including spouse and children up to the age of 25
  • Pension plan through Irish Life, with an employer match of 100% of the employee contributions up to a maximum of 6%
  • Life insurance
  • Group Income Protection
  • U choose program - €325 every quarter to be spent on eligible items such as exercise equipment/membership, pet care, child care, home office set-up etc.
  • Tuition Reimbursement program - up to €4,625 per year
  • Employee Assistance Program available 24/7
  • Adoption assistance, Surrogacy Assistance, Fertility Support, Gender Affirming Support

Where we're going:

UKG is on the cusp of something truly special. Worldwide, we already hold the #1 market share position for workforce management and the #2 position for human capital management. Tens of millions of frontline workers start and end their days with our software, with billions of shifts managed annually through UKG solutions today. Yet it's our AI-powered product portfolio designed to support customers of all sizes, industries, and geographies that will propel us into an even brighter tomorrow

UKG is proud to be an equal opportunity employer and is committed to promoting diversity and inclusion in the workplace, including the recruitment process.

Disability Accommodation:

For individuals with disabilities that need additional assistance at any point in the application and interview process, please email UKGCareers@ukg.com

#J-18808-Ljbffr

  • Dublin, Dublin City, Ireland Personio GmbH Full time

    Information Security LeadershipAt Personio, we are seeking an experienced Security Analyst to lead our Security Operations (SecOps) Team. Our intelligent HR platform processes sensitive customer data, requiring robust security measures to protect it.The SecOps Team's mission is to enable Personio to efficiently detect and manage security threats. As part of...


  • Dublin, Dublin City, Ireland Amazon Full time

    About AWS Incident ToolingAWS Incident Tooling plays a critical role in ensuring the high availability of Amazon Web Services (AWS). Our team is responsible for detecting and resolving issues within AWS infrastructure, leveraging automated tooling to minimize downtime and optimize recovery times.As a Software Development Manager on our team, you will lead...


  • Dublin, Dublin City, Ireland UKG, Inc. Full time

    Company Overview:With 80,000 customers across 150 countries, UKG is the largest U.S.-based private software company in the world. And we're only getting started. Ready to bring your bold ideas and collaborative mindset to an organization that still has so much more to build and achieve? Read on.At UKG, you get more than just a job. You get to work with...


  • Dublin, Dublin City, Ireland Amazon Full time

    AWS Infrastructure Services owns the design, planning, delivery, and operation of all AWS global infrastructure. As a Global Incident Response Lead, you will be responsible for leading cross-functional, global project teams to implement operational improvements and automation initiatives. Your expertise in monitoring tools, CI/CD pipelines, and process...


  • Dublin, Dublin City, Ireland Stripe Full time

    About the RoleWe are seeking an Incident Response Manager to join our team. As an Incident Response Manager, you will play a critical role in driving the right level of response from our teams to incidents, determining impact, rallying our teams to mitigate, communicating to users and ensuring appropriate remediations.You will work closely with our incident...


  • Dublin, Dublin City, Ireland Dell GmbH Full time

    About Dell GmbHDell Technologies is a global leader in the technology industry, empowering individuals and organizations to build a future that works for everyone. Our mission is to deliver innovative solutions that meet the evolving needs of our customers.We're seeking an experienced Incident Response Commander to join our Cyber Security Intelligence and...


  • Dublin, Dublin City, Ireland Hibernia Services Limited Full time

    We are looking for a highly skilled Incident Response Strategist to join our team at Hibernia Services Limited. As an Incident Response Strategist, you will be responsible for developing and implementing incident response playbooks for OT environments.About the Team:Hibernia Services Limited is a leading provider of cybersecurity services to critical...


  • Dublin, Dublin City, Ireland Stripe Full time

    Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means...


  • Dublin, Dublin City, Ireland Amazon Full time

    Incident Response ProfessionalAmazon is seeking an experienced Incident Response Professional to join our Information Security team. In this role, you will be responsible for responding to security incidents, conducting root cause analysis, and developing strategies to prevent similar incidents from occurring in the future. You will also work closely with...


  • Dublin, Dublin City, Ireland TikTok Full time

    ResponsibilitiesThe Incident Manager will be responsible for:Investigating reported incidents across multiple channelsCoordinating our response to global partners inquiriesWorking with cross-functional teams to handle and respond to crisis situationsAnalysing incident trends, systems, and data to develop improvements to the overall incident processes


  • Dublin, Dublin City, Ireland Hibernia Services Limited Full time

    Incident Response Playbook Consultant Operational Technology (OT) Focus We are seeking an experienced Incident Response Playbook Consultant with a strong focus on Operational Technology (OT) security. This is an 8-month contract role, offering a unique opportunity to work within a major industrial organisation operating at scale across critical sectors such...


  • Dublin, Dublin City, Ireland Amazon Full time

    About the OpportunityWe are looking for a talented Security Engineer to join our team at Amazon. In this role, you will work within the Amazon Security Incident Response Team (SIRT) and be responsible for responding to security incidents and coordinating a cohesive response involving multiple teams across Amazon.You will also be expected to provide security...


  • Dublin, Dublin City, Ireland Hibernia Services Limited Full time

    Incident Response Playbook Consultant Operational Technology (OT) Focus We are seeking an experienced Incident Response Playbook Consultant with a strong focus on Operational Technology (OT) security.This is an 8-month contract role, offering a unique opportunity to work within a major industrial organisation operating at scale across critical sectors such...


  • Dublin, Dublin City, Ireland Amazon Full time

    Job Description: Amazon is seeking a highly motivated Incident Response Engineer to join our Information Security team. In this role, you will work within the Amazon Security Incident Response Team (SIRT), responding to security events, conducting analysis of threats, and providing security services to safeguard highly sensitive data.Responsibilities:Develop...


  • Dublin, Dublin City, Ireland ENGINEERINGUK Full time

    As a Cybersecurity Threat Hunter at ENGINEERINGUK, you will play a critical role in protecting our company's assets and ensuring the continuity of our operations. With a strong background in incident response and a passion for staying up-to-date with the latest security trends, you will be responsible for identifying and mitigating potential security threats...


  • Dublin, Dublin City, Ireland Amazon Full time

    About the RoleThis position requires a strong background in incident response and experience with common security monitoring, log analysis, and forensic tools.The successful candidate will be able to perform Digital Forensics and Incident Response (DFIR) and provide incident command at all stages while coordinating with various teams and providing reporting...


  • Dublin, Dublin City, Ireland Amazon Full time

    We are looking for a skilled Security Engineer to join our Information Security team.In this role, you will be part of the Security Incident Response Team (SIRT) and will be responsible for responding to security events, conducting threat analysis, and providing security services to safeguard sensitive data.You will work closely with detection systems and...


  • Dublin, Dublin City, Ireland Amazon Full time

    Role OverviewThe Incident Response Associate plays a vital role in providing 24/7 services, including alarm monitoring and response, incident triage, and crisis management. This position requires strong communication and problem-solving skills to navigate complex situations and resolve security and operational risks effectively.Key Tasks:Triage and...


  • Dublin, Dublin City, Ireland Bank Of America Full time

    Company Overview:At Bank of America, we believe in helping people achieve their financial goals. As a Digital Forensics Investigator, you will play a crucial role in ensuring the security and integrity of our systems and data. In this role, you will conduct and manage individual caseloads across the entire incident response or investigative lifecycle, from...


  • Dublin, Dublin City, Ireland itContracting Full time

    Overview eir evo talent are currently seeking applicants for a Security Incident Response Manager.  This is a permanent  position located with our client in Dublin. Hybrid working options available. Job Specification: Our client have a requirement for a Security Incident Response Manager to join the client's Security Services Team. The...