UKG logo
UKG

HR, Pay, & Workforce Management

Principal Vulnerability Management Analyst- Eng

Location

United States

Posted

67 days ago

Salary

$163K - $235K / year

Seniority

Lead

No structured requirement data.

Job Description

Principal Vulnerability Management Analyst- Eng

UKG

Why UKG: At UKG, the work you do matters. The code you ship, the decisions you make, and the care you show a customer all add up to real impact. Today, tens of millions of workers start and end their days with our workforce operating platform. Helping people get paid, grow in their careers, and shape the future of their industries. That’s what we do. We never stop learning. We never stop challenging the norm. We push for better, and we celebrate the wins along the way. Here, you’ll get flexibility that’s real, benefits you can count on, and a team that succeeds together. Because at UKG, your work matters—and so do you. About the Team The Security Research & Innovation (SRI) team within Global Security is a high-impact, automation-first security organization responsible for vulnerability management, security research, and red team operations. This team has an exceptional automation culture — all team members build production automation that eliminates manual work at scale. Our security researchers conduct deep-dive source code audits, discover novel vulnerabilities in UKG products, build AI-powered tools that find and help fix bugs at scale, and drive measurable risk reduction across the entire product portfolio. This team has produced findings that protected thousands of customer environments and built automation platforms that multiply the team's impact far beyond headcount. **This position may perform work with the U.S. government therefore: ** - UKG is unable to offer sponsorship for this position. - Ideal candidate should be a U.S. Citizen Role Summary We are seeking a Sr. Staff Security Researcher who finds and fixes security vulnerabilities — and builds AI-powered automation to do it at scale. This is a hands-on technical role. You will audit source code, discover novel vulnerabilities in UKG's products and infrastructure, develop working proof-of-concept exploits, drive remediation with engineering teams, and build AI-assisted tools that accelerate every phase of that lifecycle. The ideal candidate is someone who has found real bugs in real products, written real exploits, and built real tools — not someone who writes policies about how other people should do those things. You will be expected to produce tangible security outcomes: vulnerabilities found, vulnerabilities fixed, and automation that makes the next round faster. Key Responsibilities Vulnerability Discovery & Security Research (35%) - Conduct deep-dive source code audits of UKG products (Java, .NET, Python, JavaScript) to discover novel vulnerabilities — examples could be hardcoded secrets, authentication bypasses, injection flaws, cryptographic weaknesses, access control gaps, unsafe deserialization, etc. - Develop working proof-of-concept exploits that demonstrate real impact — not theoretical risk, but provable exploitation with clear data exposure or access escalation - Perform variant analysis: when you find a bug, systematically search the entire codebase for every instance of the same root cause pattern - Triage and validate findings from automated scanners (SAST, DAST, SCA) — separate real vulnerabilities from false positives using source-level analysis - Investigate and reproduce externally reported vulnerabilities (bug bounty, CVEs, vendor advisories) to assess actual exploitability in UKG's environment - Collaborate with engineering teams on remediation — not just filing tickets, but working with developers to design, validate fixes, and drive to remediation. AI-Powered Vulnerability Automation (40%) - Build AI-assisted vulnerability discovery tools using automation (Claude, MCP servers, custom models, etc) for automated source code analysis, vulnerability pattern matching, and exploit generation - Develop autonomous security scanning agents that can analyze codebases, identify vulnerability patterns, and produce validated findings with minimal human intervention - Create AI-powered remediation tools — automation that generates fix recommendations, patches, and pull requests for discovered vulnerabilities, accelerating the path from finding to fix - Build automated vulnerability lifecycle pipelines: intake from scanners, AI-assisted triage and deduplication, intelligent ticket routing, SLA tracking, and remediation verification - Contribute to the team's shared automation repositories and Claude Code skills store — every tool you build should be reusable by the rest of the team Vulnerability Management & Remediation Driving (20%) - Own vulnerability remediation outcomes for assigned product areas — track findings from discovery through verified fix, holding engineering teams accountable to SLAs - Produce clear, actionable vulnerability reports that engineering teams can act on immediately — root cause, impact, reproduction steps, and recommended fix - Drive mean time to remediate (MTTR) down through better automation, better reports, and direct collaboration with development teams - Support vulnerability management program metrics and dashboards — contribute to reporting that gives leadership real-time visibility into risk posture - Support compliance-driven vulnerability management requirements, including FedRAMP continuous monitoring and POA&M processes, as UKG expands into federal markets Research & Knowledge Sharing (5%) - Publish internal/external research on novel vulnerability classes, AI-assisted discovery techniques, and lessons learned from audits - Stay current on emerging vulnerability classes, exploitation techniques, and defensive patterns relevant to UKG's technology stack - Mentor other team members on vulnerability research methodology, source code analysis, and AI-augmented security tooling Required Qualifications - 7+ years of hands-on experience in vulnerability research, application security, or penetration testing — with a track record of finding real vulnerabilities in production software - Demonstrated ability to read and audit source code in at least two of: Java, C#/.NET, Python, JavaScript/TypeScript, Go, C/C++ - Experience developing working proof-of-concept exploits — not just scanning, but understanding root causes and proving exploitability - Strong proficiency in Python for building security tools, automation pipelines, and integrations - Experience with AI/ML tools for security — using LLMs for code analysis, building AI-assisted security tooling, or developing autonomous security agents - Deep understanding of common vulnerability classes: injection (SQL, command, LDAP), broken authentication, cryptographic failures, SSRF, deserialization, path traversal, access control, and their variants - Experience with vulnerability management programs — triaging, tracking, and driving remediation of vulnerabilities across engineering organizations - Ability to work directly with development teams — explaining vulnerabilities, reviewing proposed fixes, and validating remediations - Excellent written communication — ability to produce clear vulnerability reports, technical documentation, and executive summaries - Bachelor's degree in Computer Science, Cybersecurity, or equivalent experience Preferred Qualifications - Published CVEs, security advisories, or bug bounty findings in production software - Experience in SaaS/multi-tenant environments processing sensitive data (HCM, payroll, healthcare, financial) - Familiarity with SAST/DAST/SCA tooling and how to reduce false positive rates through source-level validation - Experience with cloud security assessment (AWS, GCP, Azure) including container and Kubernetes vulnerability analysis - Familiarity with FedRAMP, NIST SP 800-53, or federal compliance frameworks — enough to understand vulnerability remediation timelines and reporting requirements in regulated environments - Security certifications that demonstrate hands-on skill: OSCP, OSWE, GWAPT, GXPN, BSCP, or equivalent - Conference presentations, published research, or open-source security tool contributions - Experience with reverse engineering, binary analysis, or firmware security What Sets This Role Apart This is a role for someone who finds bugs, fixes bugs, and builds tools that find more bugs. You will: - Work on a team where every member builds production automation — this is an engineering-first security team, not a compliance shop - Have access to enterprise AI infrastructure (Claude Code, LiteLLM, MCP servers) to build next-generation vulnerability discovery and remediation tools - Audit one of the largest HCM/payroll platforms in the world — protecting tens of thousands of customer organizations and millions of workers' sensitive data - Have direct, measurable impact — your findings directly prevent issues across UKG's entire customer base - Pioneer the use of AI for vulnerability discovery and automated remediation — building tools that change how security research is done at scale - Grow your career in an environment that values builders and doers over process managers and policy writers Compensation & Benefits UKG offers a comprehensive total rewards package including competitive base salary, annual bonus, equity, full medical/dental/vision, 401(k) match, unlimited PTO, and professional development budget. This role is eligible for remote work anywhere in the US. Company Overview: UKG is the Workforce Operating Platform that puts workforce understanding to work. With the world's largest collection of workforce insights, and people-first AI, our ability to reveal unseen ways to build trust, amplify productivity, and empower talent, is unmatched. It's this expertise that equips our customers with the intelligence to solve any challenge in any industry — because great organizations know their workforce is their competitive edge. Learn more at ukg.com. Equal Opportunity Employer UKG is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, disability, religion, sex, age, national origin, veteran status, genetic information, and other legally protected categories. View The EEO Know Your Rights poster UKG participates in E-Verify. View the E-Verify posters here. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability. Disability Accommodation in the Application and Interview Process For individuals with disabilities that need additional assistance at any point in the application and interview process, please email UKGCareers@ukg.com. The pay range for this position is $163,900 to $235,550. The actual base pay offered may vary depending on skills, experience, job-related knowledge and work location. In addition to base pay, employees may be eligible to participate in a performance-based bonus plan and to receive restricted stock unit awards as part of total compensation. Learn more about UKG’s benefits and rewards at https://www.ukg.com/about-us/careers/benefits

Related Categories

Related Job Pages

More Analyst Jobs

NTT DATA logo

Hyperion Financial Management (HFM) Functional Analyst (remote)

NTT DATA

NTT DATA is a $30 billion business and technology services leader, serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world's leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and application services. Our consulting and industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more than 50 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners. NTT DATA is a part of NTT Group, which invests over $3 billion each year in R&D.

Analyst67 days ago
Full TimeRemoteTeam 10,001+H1B Sponsor

Req ID: 365058 NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now. We are currently seeking a Hyperion Financial Management (HFM) Functional Analyst (remote) to join our team in Toronto, Ontario (CA-ON), Canada (CA). We are currently seeking a Hyperion Financial Management (HFM) Functional Analyst to join our team in Toronto, ON (remote). The HFM Functional Analyst is responsible for supporting the enterprise financial consolidation, reporting, and close processes through expert-level functional and technical knowledge of Oracle Hyperion Financial Management (HFM) along with experience working across financial platforms such as Hyperion Essbase, Kofax OCR and HighRadius. This role partners with Finance, Accounting, and IT stakeholders to support, enhance, and optimize existing financial systems and integrations. Responsibilities - Provide day-to-day functional and technical support for Oracle Hyperion Financial Management (11.x), including metadata management, consolidation rules, workflows, and process monitoring. - Maintain and enhance HFM metadata (Classic, EPMA, or EDM/DRM), scenarios, entities, accounts, and intercompany structures. - Troubleshoot consolidation issues, data discrepancies, and financial reporting variances across source systems. - Manage system operations related to the close process, including running consolidations, translations, calculations, and validations. - Support data integration processes using FDMEE/FDM, including data loads, mappings, validation rules, and error resolution. - Collaborate with source system owners to ensure accurate data transfer from ERP systems (e.g., Oracle EBS/Cloud GL, SAP, or others). - Maintain mapping tables, location setup, import formats, scripts, and load automation schedules. - Ensure seamless data exchange between finance systems such as Hyperion, ERP, BlackLine, HighRadius, and banking interfaces. - Understand and support integrations involving: - PDF data extraction (Kofax OCR) - Banking files (SWIFT, BAI2, ACH formats) - Payment processing (WorldPay / Paymetric) - Tax reporting interfaces (Taxware, EDICOM) - Develop and maintain financial reports using Hyperion Financial Reporting (HFR) and Smart View. - Support business users with ad hoc report creation, troubleshooting, and training. - Ensure reporting aligns with corporate accounting policies, financial structures, and audit requirements. - Document issues, enhancements, and process changes following ITIL standards (ServiceNow or similar). - Assist with application lifecycle activities including patches, upgrades, environment refreshes, and service restarts. - Support internal and external audit activities through documentation, controls, and system evidence. - Recommend technology and process improvements that enhance financial operations efficiency. - Work with cross functional teams to automate manual financial workflows using the appropriate tools. Qualifications - Minimum 5 years of experience supporting Oracle Hyperion Financial Management (11.2.x+). - Minimum 5 years of experience with Hyperion Financial Reporting and Smart View (report development, troubleshooting, ad hoc). - 3–5 years of experience with FDMEE/FDM data integrations. - Strong understanding of financial accounting, consolidations, intercompany eliminations, FX translation, and period-close processes. About NTT DATA NTT DATA is a $30 billion business and technology services leader, serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world's leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and application services. our consulting and Industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more than 50 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners. NTT DATA is a part of NTT Group, which invests over $3 billion each year in R&D. Whenever possible, we hire locally to NTT DATA offices or client sites. This ensures we can provide timely and effective support tailored to each client’s needs. While many positions offer remote or hybrid work options, these arrangements are subject to change based on client requirements. For employees near an NTT DATA office or client site, in-office attendance may be required for meetings or events, depending on business needs. At NTT DATA, we are committed to staying flexible and meeting the evolving needs of both our clients and employees. NTT DATA recruiters will never ask for payment or banking information and will only use @nttdata.com and @talent.nttdataservices.com email addresses. If you are requested to provide payment or disclose banking information, please submit a contact us form, https://us.nttdata.com/en/contact-us. NTT DATA endeavors to make https://us.nttdata.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact us at https://us.nttdata.com/en/contact-us. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications. NTT DATA is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. For our EEO Policy Statement, please click here. If you'd like more information on your EEO rights under the law, please click here. For Pay Transparency information, please click here.

Canada
Job Closed
Eversheds Sutherland logo

Conflicts Analyst

Eversheds Sutherland

Helping our clients, our people and our communities to thrive

Analyst67 days ago
Full TimeRemoteTeam 5,001-10,000H1B Sponsor

• Monitor new business for submissions requiring processing and perform appropriate action; • Review, analyze and summarize conflict reports associated with prospective business to identify potential conflicts of interest; • Initiate conflicts clearance process with other conflicts staff members; • Assist Supervising Partners in clearing potential conflicts of interest; • Review conflict reports for updates and identify potential conflicts; • Establish and maintain ethical screens within firm system; • Perform quarterly client/matter closures as necessary; • Maintain files for Consent and/or Engagement letters; and • Perform other duties, projects and additional responsibilities as assigned.

United States
$62.1K - $119K / year
Job Closed
Level Access logo

Senior Accessibility Analyst

Level Access

A leading provider of digital accessibility solutions, Level Access endeavors to create a world in which individuals with disabilities can readily access digital systems. Founded b

Analyst67 days ago

• Test client’s systems against specific manual and assistive technology tools. • Enter test results into Level Access’s Accessibility Management Platform (AMP). • Provide realistic technical guidance to clients. • Work with the client to determine the boundaries of the testing environment by identifying components found in their system. • Deliver testing results to the client while participating in conference calls and follow-up discussions to improve accessibility and usability.

Mexico
Job Closed
Full TimeRemoteTeam 10,001+Since 1982H1B No Sponsor

• Responsible for coordination and implementation of daily processes related to IFP Risk Adjustment programs • Liaising with the Initial Validation Audit Entity to ensure compliant, efficient, and successful audit processes • Coordinating with Quality Mgmt to effectively and compliantly execute daily RA program operations • Participating in coding reviews of medical documentation for RA programs • Communication and reporting of daily productivity and risks associated with IFP RADV audits

United States
$58.4K - $97.4K / year
Job Closed