Lead Incident Response Analyst
4 weeks ago
Company Overview:
With 80,000 customers across 150 countries, UKG is the largest U.S.-based private software company in the world. And we're only getting started. Ready to bring your bold ideas and collaborative mindset to an organization that still has so much more to build and achieve? Read on.
At UKG, you get more than just a job. You get to work with purpose. Our team of U Krewers are on a mission to inspire every organization to become a great place to work through our award-winning HR technology built for all.
Here, we know that you're more than your work. That's why our benefits help you thrive personally and professionally, from wellness programs and tuition reimbursement to U Choose - a customizable expense reimbursement program that can be used for more than 200+ needs that best suit you and your family, from student loan repayment, to childcare, to pet insurance. Our inclusive culture, active and engaged employee resource groups, and caring leaders value every voice and support you in doing the best work of your career. If you're passionate about our purpose - people - then we can't wait to support whatever gives you purpose. We're united by purpose, inspired by you.
About the role:
As a Lead Incident Response Analyst, you will be part of UKG's Global Security Operations Center (GSOC) team investigating events of interest and incidents as they are validated, prioritised, and categorised by UKG's 24x7 L1 and L2 analyst teams. You will facilitate and follow UKG's standard processes to investigate, contain, eradicate, and respond in a continued and unified effort to protect the confidentiality, integrity, and availability of UKG, our partners' and customers' data and services.
You will be an escalation point for all incidents, either regionally or during shift assignment; analyzing, confirming, re-prioritizing if necessary and/or escalating/remediating those identified threats within the UKG computing environment. You will work closely with UKG's GSOC teams in the US, Singapore, and India to promote an integrated, uniform, and holistic threat detection and response capability to facilitate and enable a robust and proactive security posture.
You will leverage your skills, experience, and creativity to perform initial, forensically sound collection and analysis, methodologies to contain, eradicate, and recover from realised threats such as zero-day, ransomware, malware and other APT's. You will be responsible for Leading incident response activities as the Cyber Incident Commander (CIC), as the Cyber Incident Response Lead (CIRL) or as a subject matter expert on the Cyber Incident Response Team (CIRT).
You will lead and/or participate in post incident reporting including developing and validating After Action Reports (AAR) and Root Cause Analysis (RCA) and using your experience, knowledge, and creativity to identify and offer continuous improvement recommendations to enhance UKG's security posture through process development, tool rationalisation, detection technique and automation enhancement opportunities and enablement/training possibilities.
This is a hybrid position requiring 3 days a week in our Kilkenny office and 2 days a week working from home. Due to the nature of the work, you are required to have occasional on-call duties on weekends and/or holidays. Additional work hours may also be required during an incident investigation.
Key Responsibilities:
- Identify, develop, and operationalise security operations metrics to assist in maturing and enhancing UKG's visibility and global security capabilities.
- Continuously improve UKG's incident response processes through automations, standardisation, and tools development, customisation and/or controls deployments.
- Collaborate with cross-functional and geographically dispersed teams to identify, develop, and implement containment, eradication, and recovery strategies.
- Lead and provide subject matter expertise during active investigations of events of interest and security incidents escalated to and as identified within the regional Security Operations Center.
- Escalate tickets as required to GSOC Director for additional scrutiny and incident declaration.
- Identify, approve, and implement blocking, listing and other mechanisms to promote a robust security posture.
- Keep up to date with the latest security and technology developments, research/evaluate emerging cyber security threats and ways to manage them to proactively enhance UKG's security posture.
- Participate in threat hunts, blue team/purple team activities by simulating real-world cyber-attacks to evaluate the effectiveness of security defenses and recommend improvements.
- Be the escalation point for all junior analysts to aid and facilitate the accurate and expedient identification, verification, and remediation of security incidents.
- Mentor, coach and facilitate enablement opportunities to develop and enhance UKG's junior security analysts.
Qualifications:
- Bachelor's degree in computer science or a related discipline.
- CISSP, CCSP, GIAC or other relevant cyber security certifications.
- Working professional with 6+ years of relevant Security/SOC experience.
- Practical experience in leading incident response investigations, performing analysis, and implementing containment strategies.
- Experience in conducting investigations involving network forensics, malware analysis, and disk and memory forensics, focusing on any combination of Windows, macOS, or Linux platforms.
- Experience conducting incident response and forensic investigations in major Cloud Service Providers (CSP).
- Experience with tools such as Splunk, Elastic Search, EDR solutions.
- Excellent verbal and written communication skills.
- Experience working in a global organization is a plus.
Preferred Qualifications:
- Knowledge of the common attack vectors on the network layer, different classes of attacks (e.g., passive, active, insider, close-in, distribution attacks).
- Knowledge of cyber attackers (e.g., script kiddies, insider threat, non-nation state sponsored, and nation sponsored) and cyber-attack stages (e.g., reconnaissance, scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks).
- Thorough understanding of system and application security threats and vulnerabilities, enabling proactive identification and mitigation strategies to safeguard critical assets and data (e.g. SQL Injection, Cross-Site Scripting (XSS), Malware Infection, Zero-Day Exploits, Phishing Attacks, Denial of Service (DoS) Attacks, Man-in-the-Middle (MitM) Attack, Buffer Overflows, Weak Authentication Mechanism, Unpatched Software: Vulnerability.)
Where we're going
UKG is on the cusp of something truly special. Worldwide, we already hold the #1 market share position for workforce management and the #2 position for human capital management. Tens of millions of frontline workers start and end their days with our software, with billions of shifts managed annually through UKG solutions today. Yet it's our AI-powered product portfolio designed to support customers of all sizes, industries, and geographies that will propel us into an even brighter tomorrow
UKG is proud to be an equal opportunity employer and is committed to promoting diversity and inclusion in the workplace, including the recruitment process.
Disability Accommodation
For individuals with disabilities that need additional assistance at any point in the application and interview process, please email UKGCareers@ukg.com
#J-18808-Ljbffr-
Senior Cybersecurity Incident Response Analyst
4 weeks ago
ireland Hewlett Packard Enterprise Development LP Full timeSenior Cybersecurity Incident Response AnalystThis role has been designed as 'Onsite' with an expectation that you will primarily work from an HPE office.Who We Are:Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people live and work. We help companies connect, protect, analyze, and act on their data and applications wherever...
-
ireland Yahoo Full timeIt takes powerful technology to connect our brands and partners with an audience of hundreds of millions of people. Whether you're looking to write mobile app code, engineer the servers behind our massive ad tech stacks, or develop algorithms to help us process trillions of data points a day, what you do here will have a huge impact on our business-and the...
-
Support Engineer
4 weeks ago
ireland Amazon Full timeAWS Incident Response is at the heart of high availability of Amazon Web Services. We make customer impacting events shorter and less frequent by providing large scale event and incident management. Our automated tooling quickly identifies the cause of an issue and helps mitigate its impact, and much of our engineer time is spent on projects to improve the...
-
Senior Security Analyst, Detection and Response
3 weeks ago
ireland Google Full timeMinimum qualifications:Bachelor's degree or equivalent practical experience.5 years of experience in incident response or emergency management.2 years of experience as a technical security professional, with digital forensics or systems administration.Experience with executive or customer stakeholder management and communication.Experience with a data-driven...
-
ireland Dell, Inc. Full timeSenior Consultant, Cyber Incident Response CommanderThe Dell Security & Resiliency organization manages the security risk across all aspects of Dell's business. We are currently experiencing incredible growth in order to meet the security needs of the world's largest technology company. With team members located in over 15 countries, you will have an...
-
ireland Amazon Full timeAmazon is seeking qualified Security Engineers to join our innovative, high energy Information Security team. In this role you will work within the Amazon Security Incident Response Team (SIRT). SIRT Security Engineers respond to security events, conduct analysis of threats such as malware and intrusion attempts, and provide security services to safeguard...
-
Associate Detection and Response Analyst
3 weeks ago
ireland Expel Full timeYou know that NOP sleds don’t go down snowbanks, and that IR isn’t just on the electromagnetic spectrum. In fact, you’ve owned a few boxes with Metasploit, maybe even tinkered with exploit code. You were really excited the first time you got a reverse shell. Meterpreter might be your payload of choice, maybe even Beacon. You have a lab where you’re...
-
Senior Detection
4 weeks ago
ireland Expel Full timeImagine yourself as a SOC analyst and a new alert shoots to the top of the queue. You open the alert and all of the relevant facts are laid out for you. You know the who, the what, and the where of what happened and it’s all right there in the alert. You notice the attacker IP immediately and wonder, “Where is that IP located?”. Wonder no more because...
-
SOC Analyst
4 weeks ago
ireland Ll Oefentherapie Full timeWe are looking for professionals with experience protecting critical infrastructure to help us defend cloud infrastructure. Our team is skilled in threat hunting, analyzing indicators of compromise (IOCs), investigating adverse security events, security incident management, and digital forensics across IaaS, PaaS, and SaaS environments.You will be part of a...
-
ireland Amazon Full timeAmazon is seeking qualified Security Engineers to join our innovative, high energy Information Security team. In this role you will work within the Amazon Security Incident Response Team (SIRT). SIRT Security Engineers respond to security events, conduct analysis of threats such as malware and intrusion attempts, and provide security services to safeguard...
-
SOC Analyst
3 weeks ago
ireland Oracle Full timeJob DescriptionWe are looking for professionals with a high level of experience protecting critical infrastructure to help us defend cloud infrastructure. Our team is skilled in threat hunting, analyzing indicators of compromise (IOCs), investigating adverse security events, security incident management, and digital forensics across IaaS, PaaS, and SaaS...
-
Systems and Application Support Analyst
3 weeks ago
ireland Enel Chile S.A Full timeEnel X is a global business line of the Enel Group, combining its own progressive, future-oriented approach with the financial solidity and worldwide reach of the Group. We are leading the energy transformation all over the world, turning complex technologies into simple, approachable, effective solutions that enable everyone to transform energy into new...
-
L2 SOC Analyst
3 weeks ago
ireland Integrity360 Full timeAbout UsIntegrity360 is one of Europe's leading cyber security specialists operating from office locations spread out across Europe, providing a comprehensive range of professional, support and managed cyber security services for our 300+ clients. With four top-class Security Operation Centers, we offer a complete end-to-end security services covering our...
-
Information Security Analyst
3 weeks ago
ireland Pico Full timePico fuels the global capital markets community by providing exceptional market data services and customized managed infrastructure solutions. As financial industry experts at the center of markets and technology, we help our clients efficiently scale their business and quickly access markets. From infrastructure to connectivity, we support our clients...
-
ireland Airbnb Full timeAirbnb was born in 2007 when two Hosts welcomed three guests to their San Francisco home, and has since grown to over 4 million Hosts who have welcomed more than 1 billion guest arrivals in almost every country across the globe. Every day, Hosts offer unique stays and experiences that make it possible for guests to connect with communities in a more...
-
Intermediate Security Analyst
3 weeks ago
ireland Turner & Townsend Full timeCompany DescriptionAt Turner & Townsend we're passionate about making the difference. That means delivering better outcomes for our clients, helping our people to realize their potential, and doing our part to create a prosperous society.Every day we help our major global clients deliver ambitious and highly technical projects, in over 130 countries...
-
ireland airbnb, Inc. Full timeSenior Security Engineer, Threat Detection and ResponseAirbnb was born in 2007 when two Hosts welcomed three guests to their San Francisco home, and has since grown to over 4 million Hosts who have welcomed more than 1 billion guest arrivals in almost every country across the globe. Every day, Hosts offer unique stays and experiences that make it possible...
-
Security Engineer, Detection and Response Team
4 weeks ago
ireland Notion Full timeAbout Us:We're on a mission to make it possible for every person, team, and company to be able to tailor their software to solve any problem and take on any challenge. Computers may be our most powerful tools, but most of us can't build or modify the software we use on them every day. At Notion, we want to change this with focus, design, and craft.We've been...
-
SOC Security Analyst L2
4 weeks ago
ballinglanna, the municipal district of bandon-kinsale, ireland BlueVoyant Full timeSOC Security Analyst L2Location: Cork, IrelandThe schedule will be a Panama schedule: (slow rotating shift pattern that uses 4 teams and two 12-hour shifts to provide 24/7 coverage. The working and non-working days follow this pattern: 2 days on, 2 days off, 3 days on, 2 days off, 2 days on, 3 days off). Every 4 weeks, it will change from the day to the...
-
SOC Security Analyst L2
4 weeks ago
ballinglanna, the municipal district of bandon-kinsale, ireland BlueVoyant Full timeSOC Security Analyst L2Location: Cork, IrelandThe schedule will be a Panama schedule: (slow rotating shift pattern that uses 4 teams and two 12-hour shifts to provide 24/7 coverage. The working and non-working days follow this pattern: 2 days on, 2 days off, 3 days on, 2 days off, 2 days on, 3 days off). Every 4 weeks, it will change from the day to the...