Jobs and Careers
VE

Sr Incident Responder

Versant
Englewood Cliffs, United StatesRemotefull_timeVerifiedPosted 1 Apr 2026
💰 $160,000/yr($120,000/yr$160,000/yr)

About the role

Company Description

VERSANT is a leading force in news, sports and entertainment - home to iconic and trusted brands that inspire, inform, and delight audiences. Our unique combination of content, technology and services enriches the cultural fabric, igniting passions, sparking conversations, and connecting people to what they love most.

As an independent, publicly traded company, VERSANT brings together powerhouse cable networks - including USA Network, CNBC, MS NOW (formerly MSNBC), Oxygen, E!, SYFY, and Golf Channel - with dynamic digital and direct-to-consumer brands such as Fandango, Rotten Tomatoes, GolfNow, GolfPass, and SportsEngine. Together, these businesses reflect our commitment to delivering exceptional experiences across every screen and service.

VERSANT is an industry-changing media company fueled by innovation and an entrepreneurial spirit. With a strong foundation and a forward-looking vision, VERSANT empowers creativity, embraces change, and drives connection in an ever-evolving world.

Job Description

The Senior Security Incident Response Analyst leads complex security investigations, drives automated response workflows, and works alongside a managed SOC to raise the quality and speed of day-to-day security operations. This is a senior individual contributor role: you will own the hardest cases, serve as the escalation point for investigations that go beyond standard triage, and build the automation and tooling that makes the entire operation more effective. Success requires independence — the ability to make sound decisions in ambiguous situations, operate without constant direction, and drive work forward in an environment that is still maturing. 

We are an automation-first team, and this role is central to that. You will work closely with SOAR and automation engineers to translate investigative insight into scalable response workflows — identifying inefficiencies, eliminating manual processes, and building the tools that reduce toil for the entire team. The right candidate cares deeply about investigative quality and is equally driven to automate, scale, and continuously improve how that work gets done. Strong judgment, a builder's mindset, and high-quality written communication are essential. 

RESPONSIBILITIES 

  • Lead high-severity and complex investigations alongside the managed SOC — serving as the senior escalation point for cases that require deeper analysis, cross-platform pivoting, or containment decisions beyond standard playbook scope 

  • Perform host-based triage and forensic analysis across Windows, Linux, and macOS, and conduct cloud-native IR across AWS and Azure — pivoting fluently between endpoint, identity, infrastructure, and network telemetry.  

  • Integrate threat intelligence into active investigations and operationalize it proactively — use adversary TTPs, IOC context, and external monitoring to sharpen scope, accelerate attribution, and surface threats before they become incidents 

  • Make and execute containment decisions — account disabling, host isolation, infrastructure blocking — and drive those actions through coordination with relevant teams 

  • Partner with SOAR and automation engineers to design and build automated response workflows — translate what you learn in investigations into playbooks, enrichment pipelines, and containment automations the SOC can execute at scale 

  • Identify repetitive investigative tasks and own their elimination — write the scripts, build the integrations, and design the workflow tools that reduce toil for the entire team 

  • Define what automated response should look like for specific threat categories; work with engineering to implement it and validate that it holds up against how investigations actually unfold 

  • Contribute detection logic informed by investigation findings — close the loop between what you observe in cases and what the team catches next time 

  • Calibrate the SOC's triage thresholds and escalation criteria; raise the floor on case documentation quality through direct review and feedback 

  • Produce case notes, post-incident summaries, and leadership briefs that are reproducible, defensible, and readable by a non-technical audience 

 

Qualifications

QUALIFICATIONS & REQUIREMENTS 

  • 5+ years of hands-on incident response experience with direct investigation ownership — candidates should understand the difference between owning an investigation and working a SOC queue 

  • Proven ability to operate independently: prioritize without direction, drive investigations to closure, and make sound judgment calls under ambiguity 

  • Experience working alo

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Versant

View company profile →