> Markdown version of [/jobs/ext/2862999-manager-cyber-threat-management](https://www.wearedevelopers.com/jobs/ext/2862999-manager-cyber-threat-management). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Manager, Cyber Threat Management - **Company:** WPS Health Solutions - **Location:** Monona, WI, United States (Remote available) - **Experience:** Expert - **Salary:** $140,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cyber Security, Information Systems, Data Security, Intrusion Detection and Prevention, Security Software, Security Information and Event Management, Software Vulnerability Management, Data Logging, Cloud Platform System, Software Security, Mitre Att&ck, Cyber Threat Analysis, Information Technology, Security Orchestration, Automation & Response, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 12, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88296062/1 ## About the Role * U.S. Citizenship is required for this position due to Department of Defense restrictions. * Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology OR equivalent combination of education and work experience. * 7 or more years of progressive experience in cybersecurity operations, incident response, vulnerability management, application security, or a related technical security discipline. * 3 or more years of people-management experience leading technical security staff. * Expertise and hands-on experience with security monitoring, detection, and incident-response processes and technologies, such as SIEM, EDR, or comparable platforms. * Expertise in vulnerability management and application-security practices, including risk-based prioritization and remediation coordination. * Ability to lead through high-pressure, time-sensitive situations, including active incident response. * Strong leadership and stakeholder management skills with ability to influence and drive change across diverse teams and complex organizations and coordinate detection, response, and remediation activities. * Strong written and verbal communication skills, including the ability to brief technical findings to non-technical stakeholders and leadership., * Experience with Security Automation Orchestration and Response (SOAR) and application-security testing tooling (SAST, DAST, SCA). * Experience leading or operating a security operations center (SOC) or equivalent 24x7 / on-call detection and response function. * Experience within healthcare, insurance, or another highly regulated environment. * Working knowledge of the NIST Cybersecurity Framework, NIST SP 800-61 (incident handling), and MITRE ATT&CK. * Professional certification such as CISSP, GCIH, GCFA, or CISM. * Familiarity using AI and ML to facilitate automated security workflows. Remote Work Requirements * High speed cable or fiber * Minimum of 10 Mbps downstream and at least 1 Mbps upstream internet connection (can be checked at https://speedtest.net). ## Description * Enjoy leading endtoend cyber incident management-including detection, triage, containment, eradication, and recovery. And can serving as incident commander for significant events and continuously mature incidenthandling playbooks, workflows, and escalation practices. * Can own enterprise threat detection and security monitoring by managing logging, behavioral analytics, endpoint security tooling, and threatprevention technologies. * Have advanced security automation and operational analytics, including SOAR and detection engineering, to improve detection and response speed and translate operational security data into actionable metrics. * Want to ensure visibility across systems, applications, cloud environments, and network activity. * Can provide leadership and program oversight for Application Security by driving adoption of secure-development standards owned by Cyber Trust & Architecture and oversee developer security training and application-security testing tooling and coordinating remediation with development teams. * Would enjoy owning enterprise vulnerability management by overseeing scanning, riskbased prioritization, and remediation tracking across system and application owners. * Have reduced tooling sprawl and eliminate overlapping coverage to streamline the capability. * Thrive when leading and mentoring Cyber Threat Management teams, establishing clear responsibilities, coverage/on-call models, accountability, career paths, performance expectations, and workforce capacity planning while fostering collaboration and continuous improvement. * Want to partner with Cyber Trust & Architecture, Cyber Risk & Assurance, and Cyber Business Enablement teams to align detection and response priorities with architecture standards and risk findings and deliver concise reporting and escalation to cybersecurity leadership. * Can partner with technology and businesscontinuity teams to strengthen cyberrelated impact analysis and recovery capabilities. * Have ensured response plans and recovery procedures remain current, validated, and tested. * Want to play a key role in establish Cyber Threat Management operational priorities independently within established playbooks and escalation thresholds; report significant threats, incidents, and risk trends to the CISO, and escalate risk-acceptance decisions beyond established thresholds or requiring architecture changes to the CISO or Cyber Trust & Architecture., This position may from time to time provide support to federal health care programs and other governmental or regulated industries. In accordance with law and/or contractual requirements, individuals in this role are or may be subject to all applicable federal regulations, agency contract requirements, and WPS internal policies, including but not limited to standards for data security, privacy, confidentiality, and program integrity. WPS and its personnel are subject to mandatory enhanced screening and background investigation prior to being granted access to information systems and/or sensitive data in order to safeguard regulated information and government resources that provide critical services. ## Related Videos - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Web-based Information Visualization](https://www.wearedevelopers.com/videos/84-web-based-information-visualization) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Best Paying Remote Jobs](https://www.wearedevelopers.com/magazine/255-best-paying-remote-jobs)