Sr. Staff Security Analyst- Eng
UKG · Denver, CO
$145,600–$209,300from the description
Jul 6, 2026
Denver, CO
Jul 21, 2026
What this job asks for AI summary
A senior-level role within a global security operations team, focused on hands-on digital forensics, incident response, and threat hunting across endpoint, cloud, network, and identity environments. The position involves leading major cyber incident command activities, mentoring analysts, developing playbooks and training materials, and collaborating with detection and threat intelligence teams. It suits an experienced DFIR practitioner with strong technical depth and the ability to operate at both investigative and leadership levels.
Staff level · 5+ years · Remote · Full-time
Advertised as Senior, but the requirements read as Staff.
“or” means any one of them counts — you don't need all of them.
Posted 8 times — it's one opening, so apply once.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (9)
The title is 'Senior Staff SOC Analyst' — a compound level. 'Senior' is the level advertised in the title drawn from the title's first modifier, but the actual scope (cross-team technical leadership, org-wide SOC initiative ownership, mentoring analysts, executive briefings) and the 'Staff' designation in the title itself support a Staff-level classification.
No specific work location is stated in the posting; the role appears to be US-based given the E-Verify notice and Massachusetts legal disclosure, but no city or metro is identified. CBSA is left blank.
The JD does not specify remote vs. on-site; remote is set to false as a conservative default given no explicit remote statement.
Python, PowerShell, and Bash are listed as interchangeable scripting options ('such as Python, PowerShell, Bash, or similar') under the required qualifications — emitted as one skill with alternatives.
SIEM, EDR, SOAR, cloud security, and case management platforms are referenced generically without naming specific products. SOAR and case management appear in a list of preferred hands-on experience ('one or more major SIEM, EDR, SOAR…') rather than as standalone hard gates, so SOAR is marked preferred. SIEM and EDR are firmly required throughout the qualifications section.
Malware analysis and reverse engineering are explicitly marked 'preferred' in the qualifications section.
GenAI-assisted workflows are explicitly required in the qualifications ('Experience applying GenAI-assisted workflows…').
Cloud experience with 'one or more major public cloud service provider' is required but no specific provider is named; captured as 'Cloud security' with no alternatives listed since the requirement is provider-agnostic.
Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Digital Forensics and Incident Response, Malware analysis.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.