Senior Cybersecurity Operations Analyst
Versant HealthAbout the role
Senior Cybersecurity Operations Analyst
Senior Cybersecurity Operations Analyst
Who are we?
Versant Health is one of the nation's leading administrators of managed vision care, serving over 35 million of our clients' members across the United States. Our purpose is to make healthy vision a reality for everyone by improving access to care and education in the communities we serve. Fueled by our mission to improve members' lives with easy-to-use vision solutions rooted in choice value, and care, we believe that everyone has the power to become anything they set their sights on.
See how you can make a difference with the support of strong leadership and a team environment.
Versant Health: Making Healthy Vision a Reality for Everyone
What are we looking for?
The Senior Cybersecurity Operations Analyst supports and advances the organization’s Information Security program by protecting the enterprise against evolving cyber threats. This role is responsible for leading incident response activities, investigating and analyzing security events, optimizing security controls, and collaborating cross functionally to strengthen the organization’s overall security posture.
The Senior Cybersecurity Operations Analyst provides hands on technical leadership through proactive threat hunting and the continuous enhancement of detection and response capabilities. This position contributes to the ongoing evolution of Versant Health’s cybersecurity operations by leveraging leading security technologies, partnering with internal stakeholders, and staying current on emerging threats and attack methodologies.
Where you will have an impact
Security Hygiene & Control Validation
• Routinely audit and validate security control coverage (e.g., XDR, ZTNA, DLP) to ensure tools are operating effectively and protect 100% of intended assets.
• Partner with the SOC to ensure log integrity across security and non-security systems; validate alert scope, fidelity, and thresholds.
• Monitoring the health and performance of security tools, performing root cause analysis when agents fail or policies are not properly applied.
Incident Response, Event Monitoring, & Threat Hunting
• Serve as the Tier 2 escalation point for the SOC and lead the full incident response lifecycle, from containment through recovery.
• Conduct proactive threat hunting using threat intelligence, SOC findings, and behavioral analysis to identify threats that bypass automated controls.
• Analyze threat intelligence to inform defensive strategies and continuously improve detection capabilities.
• Collaborate with the SOC to develop, refine, and maintain incident response playbooks aligned to business context.
• Monitor and analyze security alerts from SIEM, EDR, and other tools to identify and respond to potential threats.
• Implement and enforce security controls, policies, and procedures to protect organizational assets.
Blue, Red, and Purple Team Activities
• Lead the development and execution of recurring security wargames, including scenario design and cross functional participation.
• Actively participate in and lead blue team activities focused on defensive security, detection, and incident response.
• Collaborate in purple team exercises to validate detection and response effectiveness against real world attack scenarios.
• Participate in internal red team exercises, penetration tests, and simulated attacks to identify security gaps and control weaknesses.
• Perform adversary emulation by modeling tactics, techniques, and procedures (TTPs) of known threat actors.
• Share insights, lessons learned, and intelligence across teams to continuously improve security posture.
• Use findings from offensive testing to optimize SIEM rules, EDR/CASB/SWG policies, firewall configurations, and other security controls.
Security Tool Management
Configure, maintain, and optimize a broad portfolio of security technologies, including:
Security Information and Event Management (SIEM): Log aggregation, correlation, tuning, and alerting.
Endpoint Detection and Response (EDR): Threat detection and response across endpoint environments.
Attack Surface & Exposure Management (ASM/AEM): Continuous discovery and prioritization of vulnerabilities and exposures.
Cloud Access Security Broker (CASB): Enforcement of security controls for cloud applications and services.
Secure Web Gateway (SWG): Inspection of web traffic and protection against web-based threats.
Data Loss Prevention (DLP): Design, implementation, and management of policies to prevent unauthorized data exfiltration across endpoints, networks, and cloud environments.
Security Operations & Support
Respond to and resolve security related tickets and user inquiries.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s