Jobs and Careers
CO
Comcast Cybersecurity: Principal Engineer, Advanced Threat Response
ComcastPhiladelphia, United Statesfull_timeVerifiedPosted 2 Jun 2025
About the role
Make your mark at Comcast -- a Fortune 30 global media and technology company. From the connectivity and platforms we provide, to the content and experiences we create, we reach hundreds of millions of customers, viewers, and guests worldwide. Become part of our award-winning technology team that turns big ideas into cutting-edge products, platforms, and solutions that our customers love. We create space to innovate, and we recognize, reward, and invest in your ideas, while ensuring you can proudly bring your authentic self to the workplace. Join us. You’ll do the best work of your career right here at Comcast. (In most cases, Comcast prefers to have employees on-site collaborating unless the team has been designated as virtual due to the nature of their work. If a position is listed with both office locations and virtual offerings, Comcast may be willing to consider candidates who live greater than 100 miles from the office for the remote option.)
Job Summary
Responsible for acting as a team lead and providing internal expertise in collaboration with various cross-functional project teams. Directs and develops long-term objectives and plans related to the company's technical vision. Provides innovative solutions for complex cyber engineering developmental problems that are competitive with industry and company standards. Responsible for monitoring, identifying, investigating and analyzing all response activities related to cybersecurity incidents within an organization. Identifies security flaws and vulnerabilities; responds to cybersecurity incidents, conducts threat analysis as directed and addresses detected incidents. Conducts network or software vulnerability assessments and penetration testing utilizing reverse engineering techniques. Perform vulnerability analysis and exploitation of applications, operating systems or networks. Identifies intrusion or incident path and method. Isolates, blocks or removes threat access. Evaluates system security configurations. Evaluates findings and performs root cause analysis. Performs analysis of complex software systems to determine both functionality and intent of software systems. Resolves highly complex malware and intrusion issues. Contributes to the design, development and implementation of countermeasures, system integration, and tools specific to Cyber and Information Operations. Acts as a technical expert in own area within the organization. May work independently or as part of a team on more complex projects. Provides mentoring and guidance to more junior team members. May be responsible for leading a team, but does not directly manage people.Job Description
Responsibilities
- Lead response to Cyber Security Incidents of varying complexity levels – including all steps from identification to final closeout
- Identify activity of investigative interest based on a review of system and application logs – differentiating likely malicious activity from benign false positives.
- Assist the team in prioritizing threat detection alerts and related signals into the Security Operations Center.
- Serve as a technical subject matter expert for highly complex incidents, tracking and documenting existing status for leadership – and proposing next steps for all stakeholders.
- Ensure that full containment and eradication has occurred for all incidents.
- Partner with impacted teams (e.g. business owners, application owners, IT Teams, legal/comms) – to ensure all incident needs are being met as well as timely restoration of service occurs as risk allows.
- Provide clear and concise technical or executive level incident briefings as required.
- Document all relevant incident data using approved case notes standards and propose improvements where appropriate.
- Oversee activities of more junior team members during key incidents.
- Mentor junior team members in incident response best practices.
- Recommend continual process improvements and advocate on behalf of the team to other key cyber operations teams (e.g. detection, hunting, digital forensics, intelligence etc).
- Support related projects with critical delivery deadlines as needed.
Qualifications
Required:
- Bachelor’s Degree in Computer Science, Computer Engineering, Cyber Security, or related industry/military experience.
- 7+ years’ experience in Cyber Security, of which at least 5 or more years should be in the Incident Response space with a focus on significant, large scale incident investigations.
- Demonstrated experience leading and owning accountability for incidents of significant complexity levels for all phases of response.
- Strong technical understanding of the Incident Response process and ability to speak with other business units from a technical perspective.
- Familiarity with major threat actor g
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s