Jobs and Careers
VE

Manager, Information Security - Threat Vulnerability & Risk Management

Versant Health
UKRemotefull_timeVerifiedPosted 1 Dec 2025

About the role

Manager, Information Security (Threat, Vulnerability, and Risk Management)


Manager, Information Security (Threat, Vulnerability, and Risk Management)

Who are we?
Versant Health is one of the nation’s leading administrators of managed vision care, serving millions of our clients’ members nationwide. We are driven by our mission to help members enjoy the wonders of sight through healthy eyes and vision.

As a Versant Health associate, you can enjoy a comprehensive Total Rewards package, which includes health and dental insurance, tuition reimbursement, 401(k) with company match, pet insurance, no-cost-to-you vision insurance for you and your qualified dependents. We are also invested in your success. There are many opportunities for advancement and development throughout all stages of your career with us.

See how you can make a difference with the support of strong leadership and a team environment.

See Everything, Be Anything™.

What are we looking for?
The Manager, Information Security (Threat, Vulnerability and Risk Management) is a strategic, people-focused leader responsible for overseeing the cyber risk and threat landscape across Versant Health. This leader is accountable for the maturity, governance, and performance of the enterprise cyber risk management program—owning the risk scoring framework, threat identification, vulnerability analysis, risk register governance, and the full lifecycle of risk identification, prioritization, treatment planning, mitigation, monitoring, and executive-level reporting. The Manager, Information Security (Threat, Vulnerability, and Risk Management) reports to the Director, Information Security (Governance, Risk, and Compliance) and will manage a team of vulnerability and risk analysts, guiding their work, developing their capabilities, and ensuring consistent execution across threat monitoring, risk assessment, scoring, reporting, and remediation oversight. This is a hands-on “working manager” role that requires strong technical depth in vulnerability management and threat analysis, combined with the ability to translate technical issues into business-aligned risk decisions. This leader will also work closely with several teams across the organization.

The successful candidate will have expertise in running vulnerability scans, determining appropriate risk and response levels as well as proactively identifying zero-day vulnerabilities and ensuring an appropriate response. This leader will have expertise in uncovering gaps in our security posture and make recommendations on how to resolve those identified gaps. They will also have demonstrated experience leading governance processes, facilitating risk acceptance discussions, influencing cross-functional remediation plans, and presenting risk insights to senior leadership. This person will also have experience leading and conducting information security risk assessments of new and existing vendor tools and solutions and consulting engagements which impact our network, data and system assets and identify methods to reduce risks associated with them where necessary.

Success requires strong business acumen, the ability to contextualize risk in terms of operational and strategic business impact, and the confidence to advocate for risk-based decisions at all levels of the organization.

Where you will have an impact
• Conduct recurring scans and audit and track mitigation activities through to completion
• Conduct both self-assessments and coordinate third party risk assessments of technology infrastructure and operational processes and controls for assigned areas
• Conduct scheduled, targeted (in response to advisories and remediation verification) and ad-hoc IT compliance checks and vulnerability scans for the Versant Health global enterprise
• Investigate and validate risk levels associated with vulnerabilities identified via vulnerability scanning tools (Tenable, Qualys, Kenna, etc.)
• Provide remediation guidance and recommendations and coordinate with Development Operations, IT and other teams as needed to provide oversight to the remediation and/or mitigation of enterprise vulnerabilities
• Maintain and improve upon, as necessary, the existing IT and vulnerability management infrastructure, including maintenance of scanning tools, licensing, procedures, reporting, and associated communications (downtimes, upgrades, report changes, etc.)
• Find security gaps within our enterprise and systems that would not otherwise be detected by a scanning solution in target systems, networks, and applications in order to help organization to improve existing security controls and mechanisms.
• Create processes and workflows for all aspects of IT compliance auditing and vulnerability management. Work with cross-functional teams to improve processes, workflows and operational efficiencies

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Versant Health

View company profile →