Comcast Cybersecurity: Director, Security Operations and Incident Response
Comcast
Make your mark at Comcast -- a Fortune 30 global media and technology company. From the connectivity and platforms we provide, to the content and experiences we create, we reach hundreds of millions of customers, viewers, and guests worldwide. Become part of our award-winning technology team that turns big ideas into cutting-edge products, platforms, and solutions that our customers love. We create space to innovate, and we recognize, reward, and invest in your ideas, while ensuring you can proudly bring your authentic self to the workplace. Join us. You’ll do the best work of your career right here at Comcast. (In most cases, Comcast prefers to have employees on-site collaborating unless the team has been designated as virtual due to the nature of their work. If a position is listed with both office locations and virtual offerings, Comcast may be willing to consider candidates who live greater than 100 miles from the office for the remote option.)Job SummaryAt Comcast, we are committed to providing secure and reliable services for our customers, employees, and business partners. As the Director, Security Operations and Incident Response, you will lead the enterprise cyber defense function responsible for detecting, analyzing, hunting, escalating, and responding to cybersecurity threats across Comcast. This role is accountable for scaling Comcast’s Security Operations Center, Security Incident Response Team, threat hunting, and threat detection capabilities to meet a materially changed threat environment. Comcast must be prepared to manage multiple major incidents concurrently, maintain high-quality response under elevated case volume, proactively identify emerging threats, and continuously improve detection coverage across enterprise environments. The Director will provide strategic leadership, executive-level incident command, operational transformation, and cross-functional coordination across Cybersecurity, IT, Legal, Privacy, Communications, Engineering, Product, and business leadership. This leader will also partner closely with engineering teams to improve the tools, data pipelines, dashboards, automations, and workflows used by cyber operators every day. This is a critical leadership role responsible for protecting Comcast, our customers, our workforce, and our network from high-impact cyber threats.Job DescriptionThis position is ineligible for visa sponsorship. To be considered for this role, you must be legally authorized to work in the United States and not require sponsorship for employment now or in the future.Core Responsibilities: Lead and scale Comcast’s SOC, Security Incident Response Team, threat hunting, and threat detection functions, ensuring the organization is trained, equipped, and structured to respond effectively to routine security events and major incidents. Build the operating model, staffing approach, escalation paths, runbooks, and surge capacity required to manage multiple concurrent major incidents. Serve as a senior incident commander for high-severity cybersecurity events, coordinating response across technical teams, business stakeholders, legal, privacy, communications, and executive leadership. Lead Comcast’s threat hunting function to proactively identify adversary behavior, emerging attack patterns, control gaps, and high-risk activity before it becomes a major incident. Including leading Purple Team activities. Own and mature the enterprise threat detection strategy, including detection coverage, alert fidelity, tuning, detection lifecycle management, and alignment to threat intelligence, adversary tradecraft, and business risk. Partner with security engineering, data engineering, platform engineering, and product teams to design and improve the tools, pipelines, dashboards, automations, and case management workflows used by cyber operations teams. Drive continuous improvement across SIEM use cases, endpoint detections, cloud detections, identity detections, network telemetry, enrichment pipelines, automation, and analyst workflows. Ensure lessons learned from incidents and hunts directly inform new detections, improved runbooks, stronger controls, and better response procedures. Develop and continuously improve incident response strategy, severity models, communications protocols, after-action reviews, and remediation tracking. Establish executive reporting on incident trends, SOC performance, detection quality, threat hunting outcomes, operational capacity, readiness gaps, and enterprise risk. Define and track metrics for mean time to detect, mean time to respond, alert quality, false-positive reduction, detection coverage, incident conversion, hunting outcomes, case volume, backlog, and major-incident readiness. Manage relationships with external incident response providers, security vendors, technology partners, and strategic service providers to ensure effective support during critical incidents. Ensure SOC, incident response, threat hunting, and detection practices align with regulatory expectations, internal policies, industry frameworks, and enterprise risk management requirements. Provide leadership to managers and technical teams, including goal setting, performance management, workforce planning, coaching, and career development. Represent Comcast as a senior subject matter expert in security operations, incident response, threat hunting, and threat detection.Required Qualifications:10+ years of relevant cybersecurity experience, including leadership experience in cybersecurity operations, security incident response, threat hunting, threat detection, or enterprise SOC functions in a large, complex environment with at least 5 years of experience managing leaders of people Demonstrated experience managing high-severity cybersecurity incidents, including executive communications, cross functional coordination, containment strategy, remediation oversight, and post-incident improvement. This role supports a 24x7 cybersecurity operation and requires availability outside of standard business hours, including nights, weekends, and holidays, during critical incidents and high-severity security events.Strong leadership experience building, managing, and scaling technical security teams, including managers, incident responders, SOC analysts, threat hunters, detection engineers, and specialized security professionals. Deep technical understanding of modern security operations, including SIEM, EDR, threat intelligence, malware analysis, digital forensics, cloud security, identity security, network security, automation, and detection engineering. Experience partnering with engineering teams to build, improve, and operationalize security tools, data platforms, dashboards, automations, telemetry pipelines, and analyst workflows. Proven ability to make high-impact decisions under pressure and lead teams through ambiguous, fast-moving security events. Experience developing incident response operating models, playbooks, escalation procedures, readiness exercises, metrics, and continuous improvement programs. Strong understanding of adversary tradecraft, threat hunting methodologies, detection lifecycle management, and frameworks such as MITRE ATT&CK. Strong executive communication skills, including the ability to brief senior leaders on risk, impact, operational status, capacity gaps, and recommended actions. Ability to collaborate effectively across Cybersecurity, IT, Legal, Privacy, Compliance, Communications, Engineering, Product, and business leadership. Relevant industry certifications preferred, such as CISSP, CISM, GCIH, GCIA, GCFA, GNFA, GMON, or other GIAC certifications. The ideal candidate is a senior cyber operations leader who can operate at both strategic and tactical levels. They should be comfortable leading during crisis conditions, scaling incident response, maturing threat hunting and detection programs, and partnering with engineering teams to build the operational tools required for enterprise-scale cyber defense. This leader must be able to translate threat activity, operational pain points, analyst needs, and business risk into durable platforms, automations, detections, workflows, and operating models that improve speed, quality, resilience, and readiness across the SOC. Employees at all levels are expected to:Understand our Operating Principles; make them the guidelines for how you do your job.Own the customer experience think and act in ways that put our customers first, give them seamless digital options at every touchpoint, and make them promoters of our products and services.Know your stuff be enthusiastic learners, users and advocates of our game-changing technology, products and services, especially our digital tools and experiences.Win as a team make big things happen by working together and being open to new ideas.Be an active part of the Net Promoter System a way of working that brings more employee and customer feedback into the company by joining huddles, making call backs and helping us elevate opportunities to do better for our customers.Drive results and growth.Support a culture of inclusion in how you work and leadDo what's right for each other, our customers, investors and our communitiesDisclaimer: This information has been designed to indicate the general nature and level of work performed by employees in this role. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications.SkillsArtificial Intelligence (AI), Cyber Operations, Executive Presence, People Leadership, Security Incident ResponseWe believe that benefits should connect you to the support you need when it matters most, and should help you care for those who matter most. That's why we provide an array of options, expert guidance and always-on tools that are personalized to meet the needs of your reality—to help support you physically, financially and emotionally through the big milestones and in your everyday life.Please visit the benefits summary on our careers site for more details.EducationBachelor's DegreeWhile possessing the stated degree is preferred, Comcast also may consider applicants who hold some combination of coursework and experience, or who have extensive related professional experience.Certifications (if applicable)Relevant Work Experience10 Years +Comcast is an equal opportunity workplace. We will consider all qualified applicants for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, disability, veteran status, genetic information, or any other basis protected by applicable law.SummaryLocation: PA - Philadelphia, 1701 John F Kennedy Blvd; VA - Reston, 11951 Freedom Dr Ste 900Type: Full time
- Make your mark at Comcast -- a Fortune 30 global... ...option.)Job SummaryThe Cybersecurity Major Incident Manager leads... ...distributed, follow-the-sun operating model, with accountability for incident response support and... ...engineering, and critical security telemetry to ensure...SuggestedFull timeWork at officeRemote workWorldwide
$124.8k
...million people with regulated operations in 14 states and on 18... ...Description Job Title: Director, Physical Security Operations Posting Start... ...and operational, responsible for the management and delivery... ...ensure effective monitoring, incident response, and escalation protocols...SuggestedFor contractorsWork experience placementLocal area$134.5k - $265.1k
...Cyber Services help our clients to be secure, vigilant, and resilient in the face of... ...enabling ongoing, secure, and reliable operations across the enterprise. Recruiting for this... ...have extensive experience in Cyber Incident Response. This role involves supporting our client...SuggestedLocal areaVisa sponsorship- Make your mark at Comcast -- a Fortune 30 global media... ...high-priority cyber security programs focused on... ...Technology, Product, Operations, Risk, and business... ...now or in the future.Responsibilities:Lead complex cyber security... ...Intelligence (AI), Cybersecurity, Executive Presence,...SuggestedFull timeWork at officeRemote workWorldwide
- ...clients address evolving cybersecurity challenges and... ...implement, and optimize secure, outcome-focused solutions... ...efficient security operations capabilities. In this... ...team, you will be responsible for:Leading the design... ...crisis and cyber incident response. Through this...SuggestedLocal area
$134.5k - $265.1k
...Are you an experienced cybersecurity professional looking... ...to strengthen security, enable innovation, and... ...CTEM) team, you will be responsible for… Managing exposure... ...and patch management operations across infrastructure... ...exception management, incident-driven response...Local area$141.92k - $212.89k
...independent regulator of securities firms doing business... ...at the forefront of cybersecurity resilience in the financial... ...real-world cyber incidents, helping member firms sharpen their response strategies, improve coordination... ...with Regulatory Operations staff and addressing...Full timeTemporary workFor contractorsFor subcontractorLocal areaImmediate start$134.5k - $265.1k
...on role in delivering security engineering solutions... ...modernizing security operations through security... ...orchestration automation and response, detection... ...in Computer Science, Cybersecurity, Information Systems,... ...Certification Certified Incident Handler, Certified Information...Local areaVisa sponsorship- ...Director, IT Operations Bellevue, WA; Newtown Square, PA; New York, NY; San... ...separate the IT function from Security. This senior role serves as... ...and operations leader, responsible for designing and delivering... ...service management practices (incident, problem, change, and...Work at officeFlexible hours
- ...Description: About the Role: The Cybersecurity Manager will lead the security strategy, manage a team of... ...against cyber risks. Responsibilities: Define and implement enterprise... ...security strategy. Lead security incident response and crisis management....
$107k - $214.5k
...has established the Cybersecurity and data protection risk... ...to serving the cyber security and information... ...risk, compliance, and operational capabilities.ResponsibilitiesOversee... ...compliance, breach response, etc.Support clients... ...subject requests)Incident management and breach...Full timeWork experience placementInternshipLocal areaShift work$134.5k - $265.1k
...opportunities businesses face in cybersecurity. Join our team to... ...our clients to operate with resilience, grow... ...manage to secure success.Recruiting for... ...Cyber team, you will be responsible for:Leading the design... ...access-related issues and incidents efficiently.Integrate...Local areaVisa sponsorship$134.5k - $265.1k
...opportunities businesses face in cybersecurity. Join our team to deliver... ..., we enable our clients to operate with resilience, grow with... ..., and proactively manage to secure success.Recruiting for this... ...Transformation team, you will be responsible for...Serving as a subject...Local area$134.5k - $265.1k
...professional growth and new responsibilities? If so, Deloitte & Touche... ...for you. Traditional security and integrated risk programs... ...practices • Assisting in the operation of client insider risk... ...responding to and recovering from cybersecurity incidents • Hands-on experience...Local areaVisa sponsorship- Xumo, a joint venture between Comcast and Charter Communications, was formed to develop... ....Job SummaryThe Sr Manager, Business Operations Analysis role serves as a key partner to... ...and business operations. The position is responsible for developing and automating critical...Full timeContract workWork at officeNight shiftWeekend work
$120k - $180k
...future of automation. And we’ll be proud to have you on the journey.Do we have your attention?Keep reading. The Director of Operations for WLSis responsible for the strategic leadership of the Production group, including but not limited to the manufacture of new, refurbished...Full timeTemporary workLocal area$114.18k - $134.34k
...management position, with a focus on facility operations, financial management, risk management... ...experience, and vendor management. Responsibilities include overseeing the day-to-day... ...Provide regular monthly reviews of center incident reports and trends, and implements...Minimum wagePermanent employmentFull timeContract workFor contractorsWork at officeLocal areaFlexible hoursShift work- DescriptionRobert Half is looking for an experienced Director of Operations to lead and optimize the operational functions of our client'... ...risk management, business planning, and team development.Responsibilities:Oversee daily operations and guide the Operations team, including...Contract workWork at office
$125k - $135k
...OverviewCity Year Philadelphia (CYP) is seeking a Managing Director of People and Operations (MD POps) who is responsible for strategically maximizing the alignment and... ...and external opportunities; ability to secure commitments to organization. WORKING CONDITIONS Occasional...Full timeTemporary workWork at officeLocal areaVisa sponsorshipWork visaFlexible hoursAfternoon shift- ...SummaryFree People is looking for a Wholesale Operations Coordinator to be a Free People... ...member of the Wholesale Operations Team is responsible for maintaining a subset of accounts on... ...to ensure they are rectified for the incident and corrected going forward.Order...Full timeFlexible hours
$70k
...Now Hiring: Security Operations Manager Location: Philadelphia, PA Employment Type: Full... ...area. This leadership role is responsible for ensuring exceptional client service... ...Managers and Security Officers. Review incident reports, payroll, timekeeping, and scheduling...Full timeWork at officeImmediate startAll shiftsFlexible hoursAfternoon shift- ...The CISO will be responsible for implementing... ...running the enterprise cybersecurity program. That... ...in which we operate. A key element... ...to the board of directors and other senior... ...fully functional and secure mode and are compliant... ..., findings, incidents and cybersecurity...Full timeContract workPart timeFor contractorsWork at officeFlexible hours
- ...Description Position OverviewThe Security Manager leads the planning,... ..., and execution of security operations across the Highmark Mann... ...Center. The position is responsible for managing security staff... ...emergency response procedures and incident documentation, and...Seasonal workWork at officeLocal areaImmediate start
$152k - $220k
...including both stealth and overt operations.The Director will shape an automation-... ...-driven offensive security program, leveraging AI-enabled... ...Description Roles and Responsibilities People leadership &... ...coordination with detection and incident response teams. Defense...Permanent employmentContract workRemote workRelocation package$155.6k - $306.8k
...engineering team, you will be responsible for:• Designing and hands-on... ...observability, reliability, security, and cost/performance... ...and continuity and recovery operations• Building AI-enabled control... ...audit-ready evidence across cybersecurity, continuity, and third-party...Local areaRemote work$189.2k - $372.9k
...engineering team, you will be responsible for:• Designing and hands-... ..., reliability, security, and cost/performance management... ...across multiple workstreams or operational domains for a client or portfolio... ...programs that demonstrate cybersecurity and continuity posture to...Local areaRemote work$134.5k - $265.1k
...strategies across business, technology, and operational environments while guiding teams and... ..., and Transformation team, you will be responsible for: Leading the assessment, design,... ...Institute, Certified Information Systems Security Professional, or Certified Information...Local areaVisa sponsorship- ...Title: Director, Operations Location: Cherry Hill NJ Job Type :Fulltime Job Id: 1219 Job Summary Director, Operations provides strategic... ...standards of quality, safety, and regulatory compliance. Responsibilities include optimizing the use of personnel, equipment, and materials...Full time
- ...seeking someone to join our team as a Director within the Alternative Investment Services... ...Solutions Group (PSG), you oversee operational and portfolio management support for multi... ...Support & Services IM, which is responsible for providing transaction support and managing...Contract work
- ...Responsible for the planning, coordination and direction of the clinical operations of in support of policies, goals and objectives established by and with the CAO. The Director of Clinical Operations reports directly to the CAO. Directly supervises all of the clinical...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Comcast Cybersecurity: Director, Security Operations and Incident Response. Be the first to apply!
- cyber security lead Philadelphia, PA
- director - cyber security Philadelphia, PA
- cybersecurity manager Philadelphia, PA
- director information security Philadelphia, PA
- security manager Philadelphia, PA
- surveillance manager Philadelphia, PA
- security systems manager Philadelphia, PA
- corporate security manager Philadelphia, PA
- security operations manager Philadelphia, PA
- workplace operations manager Philadelphia, PA


