Staff Vulnerability Management Analyst- AI Automation Security Researcher Job at UKG, Remote

bXhNa25pWmRZRWZtTFd1d29EblBCSzFhT0E9PQ==
  • UKG
  • Remote

Job Description

Role Description

We are seeking a Vulnerability Management engineer to join our team as both a vulnerability management practitioner and an automation builder. This role combines traditional vulnerability analysis and remediation coordination with a strong emphasis on developing AI-powered tools and automations that scale the team's effectiveness. You will analyze vulnerabilities across infrastructure, cloud, and application layers, coordinate remediation with engineering teams, and build automation that makes the entire program faster and smarter.

Key Responsibilities

  • Vulnerability Discovery & Security Research (40%)
    • Conduct deep-dive source code audits of UKG products (Java, .NET, Python, JavaScript) to discover novel vulnerabilities.
    • Develop working proof-of-concept exploits that demonstrate real impact.
    • Perform variant analysis to systematically search the entire codebase for every instance of the same root cause pattern.
    • Triage and validate findings from automated scanners (SAST, DAST, SCA).
    • Investigate and reproduce externally reported vulnerabilities to assess actual exploitability in UKG's environment.
    • Collaborate with engineering teams on remediation.
  • AI-Powered Vulnerability Automation (35%)
    • Build AI-assisted vulnerability discovery tools using automation.
    • Develop autonomous security scanning agents.
    • Create AI-powered remediation tools.
    • Build automated vulnerability lifecycle pipelines.
    • Contribute to the team's shared automation repositories.
  • Vulnerability Management & Remediation Driving (20%)
    • Own vulnerability remediation outcomes for assigned product areas.
    • Produce clear, actionable vulnerability reports.
    • Drive mean time to remediate (MTTR) down through better automation.
    • Support vulnerability management program metrics and dashboards.
    • Support compliance-driven vulnerability management requirements.
  • Research & Knowledge Sharing (5%)
    • Publish internal/external research on novel vulnerability classes.
    • Stay current on emerging vulnerability classes and exploitation techniques.
    • Mentor other team members on vulnerability research methodology.

Qualifications

  • 7+ years of hands-on experience in vulnerability research, application security, or penetration testing.
  • Demonstrated ability to read and audit source code in at least two of: Java, C#/.NET, Python, JavaScript/TypeScript, Go, C/C++.
  • Experience developing working proof-of-concept exploits.
  • Strong proficiency in Python for building security tools.
  • Experience with AI/ML tools for security.
  • Deep understanding of common vulnerability classes.
  • Experience with vulnerability management programs.
  • Ability to work directly with development teams.
  • Excellent written communication.
  • Bachelor's degree in Computer Science, Cybersecurity, or equivalent experience.

Preferred Qualifications

  • Published CVEs, security advisories, or bug bounty findings.
  • Experience in SaaS/multi-tenant environments processing sensitive data.
  • Familiarity with SAST/DAST/SCA tooling.
  • Experience with cloud security assessment.
  • Familiarity with FedRAMP, NIST SP 800-53, or federal compliance frameworks.
  • Security certifications that demonstrate hands-on skill.
  • Conference presentations, published research, or open-source security tool contributions.
  • Experience with reverse engineering, binary analysis, or firmware security.

Benefits

  • Competitive base salary.
  • Annual bonus.
  • Equity.
  • Full medical/dental/vision.
  • 401(k) match.
  • Unlimited PTO.
  • Professional development budget.
  • Remote work eligibility anywhere in the US.

Company Description

UKG is the Workforce Operating Platform that puts workforce understanding to work. With the world's largest collection of workforce insights, and people-first AI, our ability to reveal unseen ways to build trust, amplify productivity, and empower talent, is unmatched.

Job Tags

Full time, Remote work

Similar Jobs

CIMP-3D

Part Time - Psychology - Research Assistants Job at CIMP-3D

 ...State Applicants . POSITION SPECIFICS The Department of Psychology in the College of the Liberal Arts seeks to hire numerous part...  .... Duties may include: Office Support Lab Support Research Support Applications will be received on an ongoing basis and... 

Skilled Trades Partners

Heavy Equipment Operator Job at Skilled Trades Partners

 ...to talk to you. Job Responsibilities: Operate Heavy Equipment(Excavator, Dozer, Loaders, Backhoes, etc.) Perform work on demolition, excavation, dredging, utility installation, and hardscaping projects Read and interpret construction plans and grade stakes... 

-

Safety and Security Officer - up to $2500 BONUS Job at -

 ...keeping customer service top of mind! What You'll Do Prioritize safety in our stores to create a positive shopping and working...  ...leadership Requirements 5+ years full-time experience as a sworn police officer with arrest authority in a military, municipal, county, state,... 

Kyo

Behavior Technician Job at Kyo

 ...Kyo is a leading provider of Applied Behavior Analysis (ABA) therapy, dedicated to empowering children with autism and their families...  ...superior results. KYO'S BEHAVIOR THERAPISTS (aka BEHAVIOR TECHNICIANS): Provide 1:1 play-based instruction to clients using... 

Wegmans

Entry Level Manager Job at Wegmans

Schedule: Full time Availability: Morning, Afternoon, Evening (Includes Weekends). Age Requirement: Must be 18 years or older Location: Charlottesville, VA Address: 100 Wegmans Way Pay: $21.75 - $22.50 / hour Job Posting: 06/08/2026 Job Posting End: 07/06/2026 Job ID: R...