Versant Health logo
Versant Health

Versant Health is one of the nation’s leading administrators of managed vision care, serving millions of our clients’ members nationwide. We are driven by our mission to help members enjoy the wonders of sight through healthy eyes and vision. As a Versant Health associate, you can enjoy a comprehensive Total Rewards package, which includes health and dental insurance, tuition reimbursement, 401(k) with company match, pet insurance, no-cost-to-you vision insurance for you and your qualified dependents. We are also invested in your success. There are many opportunities for advancement and development throughout all stages of your career with us.

Cybersecurity Operations Analyst

Security OperationsSecurity OperationsFull TimeRemoteMid LevelTeam 1,001-5,000

Location

United States

Posted

33 days ago

Salary

0

Seniority

Mid Level

No structured requirement data.

Job Description

Cybersecurity Operations Analyst

Versant Health

Role Description The Cybersecurity Operations Analyst supports and advances the organization’s Information Security program by protecting the enterprise against evolving cyber threats. This role is responsible for participating in incident response activities, investigating and analyzing security events, optimizing security controls, and collaborating cross-functionally to strengthen the organization’s overall security posture. The Cybersecurity Operations Analyst provides hands-on technical leadership through proactive threat hunting and the continuous enhancement of detection and response capabilities. This position contributes to the ongoing evolution of Versant Health’s cybersecurity operations by leveraging leading security technologies, partnering with internal stakeholders, and staying current on emerging threats and attack methodologies. Where you will have an impact - Security Hygiene & Control Validation - Routinely audit and validate security control coverage (e.g., XDR, ZTNA, DLP) to ensure tools are operating effectively and protect 100% of intended assets. - Partner with the SOC to ensure log integrity across security and non-security systems; validate alert scope, fidelity, and thresholds. - Monitor the health and performance of security tools, performing root cause analysis when agents fail or policies are not properly applied. - Incident Response, Event Monitoring, & Threat Hunting - Serve as the Tier 2 escalation point for the SOC and lead the full incident response lifecycle, from containment through recovery. - Conduct proactive threat hunting using threat intelligence, SOC findings, and behavioral analysis to identify threats that bypass automated controls. - Analyze threat intelligence to inform defensive strategies and continuously improve detection capabilities. - Collaborate with the SOC to develop, refine, and maintain incident response playbooks aligned to business context. - Monitor and analyze security alerts from SIEM, EDR, and other tools to identify and respond to potential threats. - Implement and enforce security controls, policies, and procedures to protect organizational assets. - Blue, Red, and Purple Team Activities - Engage in the development and execution of recurring security wargames, including scenario design and cross functional participation. - Actively participate in blue team activities focused on defensive security, detection, and incident response. - Collaborate in purple team exercises to validate detection and response effectiveness against real world attack scenarios. - Participate in internal red team exercises, penetration tests, and simulated attacks to identify security gaps and control weaknesses. - Perform adversary emulation by modeling tactics, techniques, and procedures (TTPs) of known threat actors. - Share insights, lessons learned, and intelligence across teams to continuously improve security posture. - Use findings from offensive testing to optimize SIEM rules, EDR/CASB/SWG policies, firewall configurations, and other security controls. - Security Tool Management - Configure, maintain, and optimize a broad portfolio of security technologies, including: - Security Information and Event Management (SIEM): Log aggregation, correlation, tuning, and alerting. - Endpoint Detection and Response (EDR): Threat detection and response across endpoint environments. - Attack Surface & Exposure Management (ASM/AEM): Continuous discovery and prioritization of vulnerabilities and exposures. - Cloud Access Security Broker (CASB): Enforcement of security controls for cloud applications and services. - Secure Web Gateway (SWG): Inspection of web traffic and protection against web-based threats. - Data Loss Prevention (DLP): Design, implementation, and management of policies to prevent unauthorized data exfiltration across endpoints, networks, and cloud environments. - Security Operations & Support - Respond to and resolve security related tickets and user inquiries. - Provide guidance and best practice recommendations to end users and IT partners. - Troubleshoot security tool issues and perform root cause analysis. - Documentation, Reporting, & Communication - Create and maintain detailed documentation for incident response procedures, security tool configurations, and security advisories. - Generate and present reports on security incidents, trends, and overall security posture to management. - Communicate clearly and effectively with stakeholders during and after security incidents. Qualifications - 3+ years of experience in cybersecurity, with a focus on security operations and incident response. - Bachelor’s degree from an accredited college or university or equivalent professional experience. - Hands-on experience administering and maintaining SIEM, EDR, and related security tools. - Understanding of networking concepts, TCP/IP, Active Directory, DNS, DHCP, and network defense technologies. - Proficiency with Windows, Linux, and macOS operating systems. - Experience with cloud security platforms (e.g., AWS, Azure). - Knowledge of secure engineering principles and technical security testing methodologies. Requirements - All Associates must comply with the Health Insurance Portability Accountability Act of 1996 (HIPAA) as it pertains to disclosures of protected health information (PHI). - Associates may have access to covered information, cardholder data or other confidential customer information which must be protected at all times. - Associates must explicitly adhere to all data security guidelines established within the Company’s Privacy & Security Training Program. Benefits - Comprehensive and competitive total rewards package designed to support your health, financial well-being, and work-life balance. - Medical, dental, and paid vision coverage. - Paid time off and company holidays. - Retirement savings with employer contribution. - Employee wellness resources. - Professional development opportunities. - Flexible work arrangements. - Employee assistance programs.

Related Categories

Related Job Pages

More Security Operations Jobs

Lincoln Financial logo

IT Security Operations Center Specialist

Lincoln Financial

We help people confidently plan for their version of a successful financial future.

Full TimeRemoteTeam 10,001+Since 1905H1B No Sponsor

• Monitor and defend network perimeter interfaces against malicious traffic. • Analyze inbound and outbound network traffic for anomalies and threats. • Perform real-time security event analysis using SIEM and other advanced security tools. • Correlate and triage security alerts and indicators generated by monitoring systems. • Investigate and respond to suspected phishing emails and related incidents. • Manage and resolve cybersecurity-related requests received via phone, email, or internal ticketing systems promptly and accurately. • Execute routine assignments and projects while applying deep knowledge of security operations. • Identify and recommend process improvements to enhance efficiency and quality within the SOC. • Ensure availability and proper functioning of security technologies, including IDS/IPS, Web Application Firewalls, DLP, syslog servers, and vulnerability scanners. • Stay current on emerging cybersecurity trends and technologies; assess their impact and collaborate with leadership to integrate improvements into security operations. • Support organizational and departmental initiatives by promoting best practices and contributing to change management efforts.

North Carolina + 1 moreAll locations: North Carolina | Pennsylvania
$86.3K - $120K / year
Sunshine Enterprise USA logo

SOC Analyst – Contract

Sunshine Enterprise USA

Our commitment to creating American jobs

ContractRemoteTeam 51-200Since 2001H1B No Sponsor

• Monitor, analyze, and correlate security events across SIEM platforms, EDR/XDR solutions, IDS/IPS systems, Threat intelligence feeds • Investigate and validate security incidents, determine root cause • Perform deep-dive analysis of suspicious activity • Conduct incident response activities including containment, eradication, and recovery support • Develop detailed incident reports, timelines, post-incident summaries • Recommend improvements to SOC playbooks, detection rules • Perform proactive threat hunting using MITRE ATT&CK framework • Collaborate with engineering teams to tune and optimize security tools • Support dashboard creation, reporting, and SOC performance metrics • Serve as a subject matter expert (SME) interacting with stakeholders • Document SOC processes, runbooks, incident handling procedures • Coordinate with SOC teams, engineering teams, and agency stakeholders

South Carolina
Job Closed
Trustly logo

SecOps Engineer, AppSec

Trustly

Fast, simple and secure online banking payments

Full TimeRemoteTeam 1,001-5,000Since 2008H1B No Sponsor

• Protect the confidentiality, integrity, and availability of applications, services, data, and cloud infrastructure. • Identify, analyze, and mitigate vulnerabilities. • Provide support, guidance, and training to the DevOps team, application owners, and other stakeholders. • Plan, coordinate, and execute remediation efforts. • Assist in developing application security test plans. • Research, evaluate, and recommend new and existing tools and techniques. • Collaborate with threat detection and incident response teams when responding to security incidents. • Prepare documentation on vulnerability and risk analysis for security audits. • Develop and implement application security processes, including identifying weaknesses, defining security strategies, and conducting penetration tests. • Develop and implement security-related standards, policies, and procedures. • Analyze security data to identify and mitigate potential threats. • Perform internal security audits. • Conduct internal penetration tests and vulnerability assessments and develop remediation plans for findings. • Create and manage risk analysis documentation. • Manage the development of security metrics and reports. • Lead the architecture and implementation of information security best practices. • Maintain a security engineering knowledge base.

Brazil
RapDev logo

Security Operations Center (SOC) Analyst, Hawaii

RapDev

Datadog Premier Partner | ServiceNow Elite Partner

Full TimeRemoteTeam 51-200Since 2017H1B Sponsor

About RapDev We specialize in modern ITOM & DevOps ServiceNow delivery and implementations as well as integrations and services for Datadog. Our experienced team of SREs and DevOps engineers powerfully brings together these two ecosystems to drive better observability, availability, and deployment velocity across your organization. About the job Are you a security professional looking for a Security Operations Center role in IR? We are the leading Datadog partner and are embarking on building a security managed services offering from the ground up. This is a unique opportunity to work with cutting edge cloud security solutions and be involved in major infrastructure migration projects. This position requires you to be based in Hawaii with the working hours of Wednesday-Sunday, 5pm-1am HST. What you'll do: - Monitor security events and logs from a variety of systems and networks in Datadog - Identify potential security incidents and threats - Perform analysis and investigations, correlating events and data to detect security incidents - Develop, document, and evolve processes and procedures for responding to security incidents - Provide technical guidance, training, and support to other members of the security team - Maintain an up-to-date knowledge of security threats, vulnerabilities, and countermeasures - Work independently with customers on implementations and remote services - Troubleshoot basic configuration/script issues - Attend requirements review and validation sessions as needed - Utilize strong written and verbal communication skills - Stay on time and on task with assigned customer work Who you are: - Bachelor's degree or equivalent experience in Cyber Security or related field - SIEM experience with Splunk, SumoLogic, Datadog, or similar. - Experience with security monitoring, incident response, and threat analysis - Experience with Cloud Native Technologies - Excellent problem-solving and analytical skills - Knowledge of security best practices and standards - Excellent communication and interpersonal skills - Experience/willingness working on multiple projects simultaneously - Self-Learner and eager to understand new technologies Compensation: - Base Salary: $75,000-$95,000 annually, depending on experience Benefits - 100% Employee Healthcare Coverage (Medical, Dental & Vision) - Retirement Plan (5% 401k Match, IRA) - Unlimited Paid Time Off (4-week minimum) (Vacation, Sick & Public Holidays) - Family Leave (Maternity, Paternity) - Equity - Hybrid Work Opportunities - Fitness & Commuter Subsidies available - SL & LT Disability RapDev is an Equal Opportunity Employer. We are committed to providing equal employment opportunities to all applicants and employees without regard to race, color, religion, sex, national origin, age, disability, veteran status, or any other protected characteristic.

Hawaii
$75K - $95K / year