Our Manager, Cyber Threat Management leads WPS’s detection, prevention, and response capabilities and reports directly to the Chief Information Security Officer. This Manager owns cyber incident management, threat detection and prevention, application security leadership, vulnerability management coordination, and security automation and analytics. They align security operations, analyst workflows, and application‑security activities within the Enterprise Cyber Resilience operating model. This Manager builds and leads the Cyber Threat Management team - our Security Operations Center (SOC) and partners with Cyber Trust & Architecture, Cyber Risk & Assurance, and Cyber Business Enablement to reduce technical risk across the enterprise.
Salary Range $140,000 ~ $180,000
The base pay offered for this position may vary within the posted range based on your job-related knowledge, skills, experience and may fall outside of this range.
Work Location
Our first consideration will be to have this employee be able to take advantage of Hybrid work and collaboration, living within the state of Wisconsin. Employees within 45 miles of WPS Headquarters (1717 W. Broadway in Madison, WI, 53713) will be expected to be able to work in office 3 days a week on a regular basis.
How do I know this opportunity is right for me? If you:
- Enjoy leading end‑to‑end cyber incident management—including detection, triage, containment, eradication, and recovery. And can serving as incident commander for significant events and continuously mature incident‑handling playbooks, workflows, and escalation practices.
- Can own enterprise threat detection and security monitoring by managing logging, behavioral analytics, endpoint security tooling, and threat‑prevention technologies.
- Have advanced security automation and operational analytics, including SOAR and detection engineering, to improve detection and response speed and translate operational security data into actionable metrics.
- Want to ensure visibility across systems, applications, cloud environments, and network activity.
- Can provide leadership and program oversight for Application Security by driving adoption of secure-development standards owned by Cyber Trust & Architecture and oversee developer security training and application-security testing tooling and coordinating remediation with development teams.
- Would enjoy owning enterprise vulnerability management by overseeing scanning, risk‑based prioritization, and remediation tracking across system and application owners.
- Have reduced tooling sprawl and eliminate overlapping coverage to streamline the capability.
- Thrive when leading and mentoring Cyber Threat Management teams, establishing clear responsibilities, coverage/on-call models, accountability, career paths, performance expectations, and workforce capacity planning while fostering collaboration and continuous improvement.
- Want to partner with Cyber Trust & Architecture, Cyber Risk & Assurance, and Cyber Business Enablement teams to align detection and response priorities with architecture standards and risk findings and deliver concise reporting and escalation to cybersecurity leadership.
- Can partner with technology and business‑continuity teams to strengthen cyber‑related impact analysis and recovery capabilities.
- Have ensured response plans and recovery procedures remain current, validated, and tested.
- Want to play a key role in establish Cyber Threat Management operational priorities independently within established playbooks and escalation thresholds; report significant threats, incidents, and risk trends to the CISO, and escalate risk-acceptance decisions beyond established thresholds or requiring architecture changes to the CISO or Cyber Trust & Architecture.
Minimum Qualifications
- U.S. Citizenship is required for this position due to Department of Defense restrictions.
- Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology OR equivalent combination of education and work experience.
- 7 or more years of progressive experience in cybersecurity operations, incident response, vulnerability management, application security, or a related technical security discipline.
- 3 or more years of people-management experience leading technical security staff.
- Expertise and hands-on experience with security monitoring, detection, and incident-response processes and technologies, such as SIEM, EDR, or comparable platforms.
- Expertise in vulnerability management and application-security practices, including risk-based prioritization and remediation coordination.
- Ability to lead through high-pressure, time-sensitive situations, including active incident response.
- Strong leadership and stakeholder management skills with ability to influence and drive change across diverse teams and complex organizations and coordinate detection, response, and remediation activities.
- Strong written and verbal communication skills, including the ability to brief technical findings to non-technical stakeholders and leadership.
Preferred Qualifications
- Experience with Security Automation Orchestration and Response (SOAR) and application-security testing tooling (SAST, DAST, SCA).
- Experience leading or operating a security operations center (SOC) or equivalent 24x7 / on-call detection and response function.
- Experience within healthcare, insurance, or another highly regulated environment.
- Working knowledge of the NIST Cybersecurity Framework, NIST SP 800-61 (incident handling), and MITRE ATT&CK.
- Professional certification such as CISSP, GCIH, GCFA, or CISM.
- Familiarity using AI and ML to facilitate automated security workflows.
Remote Work Requirements
- High speed cable or fiber
- Minimum of 10 Mbps downstream and at least 1 Mbps upstream internet connection (can be checked at https://speedtest.net).
- Please review Remote Worker FAQs for additional information.
Benefits
- Hybrid work options available
- Performance bonus and/or merit increase opportunities
- 401(k) with a 100% match for the first 3% of your salary and a 50% match for the next 2% of your salary (100% vested immediately)
- Competitive paid time off
- Health insurance, dental insurance, and telehealth services start DAY 1
- Professional and Leadership Development Programs
- Review additional benefits: (https://www.wpshealthsolutions.com/careers/)
Who We Are
WPS, a health solutions company, is a leading not-for-profit health insurer and federal government contractor headquartered in Madison, Wisconsin. WPS offers health insurance plans for individuals, families, seniors and group health plans for small to large businesses. We process claims and provide customer support for beneficiaries of the Medicare program and manage benefits for millions of active-duty and retired military personnel across the U.S. and abroad. WPS has been making healthcare easier for the people we serve for nearly 80 years. Proud to be military and veteran ready.
Culture Drives Our Success
WPS’ culture is where the great work and innovations of our people are seen, fueled and rewarded. We accomplish this by creating an open and empowering employee experience. We recognize the benefits of employee engagement as an investment in our workforce—both current and future—to effectively seek, leverage, and include differing and unique perspectives that fuel agility and innovation on high-performing teams. This results in people bringing their authentic selves to work every day in an organization that successfully adapts to business changes and new opportunities.
We are proud of the recognition we have received from local and national organization regarding our culture and workplace: WPS Newsroom - Awards and Recognition.
Sign up for Job Alerts
FOLLOW US!
Instagram
LinkedIn
Facebook
WPS Health Blog
This position may from time to time provide support to federal health care programs and other governmental or regulated industries. In accordance with law and/or contractual requirements, individuals in this role are or may be subject to all applicable federal regulations, agency contract requirements, and WPS internal policies, including but not limited to standards for data security, privacy, confidentiality, and program integrity. WPS and its personnel are subject to mandatory enhanced screening and background investigation prior to being granted access to information systems and/or sensitive data in order to safeguard regulated information and government resources that provide critical services.
Equal Opportunity Employer/Protected Veterans/Individuals with DisabilitiesThis employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.
Skills Required
- U.S. citizenship due to Department of Defense restrictions
- Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or equivalent education and work experience
- 7 or more years of progressive experience in cybersecurity operations, incident response, vulnerability management, application security, or related technical security disciplines
- 3 or more years of people-management experience leading technical security staff
- Expertise and hands-on experience with security monitoring, detection, and incident-response technologies such as SIEM or EDR
- Expertise in vulnerability management and application-security practices, including risk-based prioritization and remediation coordination
- Ability to lead high-pressure, time-sensitive active incident-response situations
- Strong leadership, stakeholder management, communication, and change-management skills
- Experience with SOAR and application-security testing tools such as SAST, DAST, or SCA
- Experience leading or operating a SOC or equivalent 24x7/on-call detection and response function
- Experience in healthcare, insurance, or another highly regulated environment
- Working knowledge of NIST Cybersecurity Framework, NIST SP 800-61, and MITRE ATT&CK
- Professional certification such as CISSP, GCIH, GCFA, or CISM
- Familiarity with AI and machine learning for automated security workflows
What We Do
WPS Health Solutions is celebrating 75 years in business as a highly regarded government contractor and leader in the insurance industry. In 2021, the Wisconsin State Journal named WPS as a Top Workplace in the Madison area. WPS has several divisions committed to delivering high-quality service to our customers. - WPS Health Insurance and WPS Health Plan offer affordable health plans for individuals, small businesses, and large businesses, plus benefits administration. - WPS Government Health Administrators administers Part A and Part B Medicare benefits—services we have provided since the program’s inception—for millions of seniors in multiple states. - WPS Military and Veterans Health serves millions more beneficiaries who are active in the U.S. military, veterans, and their families. - EPIC Specialty Benefits has offered voluntary nonmedical benefits, such as term life, disability, dental, and vision, for more than 35 years. WPS also actively partners with nonprofit organizations to help make lasting changes in the communities we serve, with an emphasis on health issues, especially for military and veterans, women, and children.
.png)






