Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Comcast Cybersecurity: Director, Security Operations and Incident Response

Comcast Service Center

Make your mark at Comcast -- a Fortune 30 global media and technology company. From the connectivity and platforms we provide, to the content and experiences we create, we reach hundreds of millions of customers, viewers, and guests worldwide. Become part of our award-winning technology team that turns big ideas into cutting-edge products, platforms, and solutions that our customers love. We create space to innovate, and we recognize, reward, and invest in your ideas, while ensuring you can proudly bring your authentic self to the workplace. Join us. You’ll do the best work of your career right here at Comcast. (In most cases, Comcast prefers to have employees on-site collaborating unless the team has been designated as virtual due to the nature of their work. If a position is listed with both office locations and virtual offerings, Comcast may be willing to consider candidates who live greater than 100 miles from the office for the remote option.)Job SummaryAt Comcast, we are committed to providing secure and reliable services for our customers, employees, and business partners. As the Director, Security Operations and Incident Response, you will lead the enterprise cyber defense function responsible for detecting, analyzing, hunting, escalating, and responding to cybersecurity threats across Comcast. This role is accountable for scaling Comcast’s Security Operations Center, Security Incident Response Team, threat hunting, and threat detection capabilities to meet a materially changed threat environment. Comcast must be prepared to manage multiple major incidents concurrently, maintain high-quality response under elevated case volume, proactively identify emerging threats, and continuously improve detection coverage across enterprise environments. The Director will provide strategic leadership, executive-level incident command, operational transformation, and cross-functional coordination across Cybersecurity, IT, Legal, Privacy, Communications, Engineering, Product, and business leadership. This leader will also partner closely with engineering teams to improve the tools, data pipelines, dashboards, automations, and workflows used by cyber operators every day. This is a critical leadership role responsible for protecting Comcast, our customers, our workforce, and our network from high-impact cyber threats.Job DescriptionThis position is ineligible for visa sponsorship. To be considered for this role, you must be legally authorized to work in the United States and not require sponsorship for employment now or in the future.Core Responsibilities: Lead and scale Comcast’s SOC, Security Incident Response Team, threat hunting, and threat detection functions, ensuring the organization is trained, equipped, and structured to respond effectively to routine security events and major incidents. Build the operating model, staffing approach, escalation paths, runbooks, and surge capacity required to manage multiple concurrent major incidents. Serve as a senior incident commander for high-severity cybersecurity events, coordinating response across technical teams, business stakeholders, legal, privacy, communications, and executive leadership. Lead Comcast’s threat hunting function to proactively identify adversary behavior, emerging attack patterns, control gaps, and high-risk activity before it becomes a major incident. Including leading Purple Team activities. Own and mature the enterprise threat detection strategy, including detection coverage, alert fidelity, tuning, detection lifecycle management, and alignment to threat intelligence, adversary tradecraft, and business risk. Partner with security engineering, data engineering, platform engineering, and product teams to design and improve the tools, pipelines, dashboards, automations, and case management workflows used by cyber operations teams. Drive continuous improvement across SIEM use cases, endpoint detections, cloud detections, identity detections, network telemetry, enrichment pipelines, automation, and analyst workflows. Ensure lessons learned from incidents and hunts directly inform new detections, improved runbooks, stronger controls, and better response procedures. Develop and continuously improve incident response strategy, severity models, communications protocols, after-action reviews, and remediation tracking. Establish executive reporting on incident trends, SOC performance, detection quality, threat hunting outcomes, operational capacity, readiness gaps, and enterprise risk. Define and track metrics for mean time to detect, mean time to respond, alert quality, false-positive reduction, detection coverage, incident conversion, hunting outcomes, case volume, backlog, and major-incident readiness. Manage relationships with external incident response providers, security vendors, technology partners, and strategic service providers to ensure effective support during critical incidents. Ensure SOC, incident response, threat hunting, and detection practices align with regulatory expectations, internal policies, industry frameworks, and enterprise risk management requirements. Provide leadership to managers and technical teams, including goal setting, performance management, workforce planning, coaching, and career development. Represent Comcast as a senior subject matter expert in security operations, incident response, threat hunting, and threat detection.Required Qualifications:10+ years of relevant cybersecurity experience, including leadership experience in cybersecurity operations, security incident response, threat hunting, threat detection, or enterprise SOC functions in a large, complex environment with at least 5 years of experience managing leaders of people Demonstrated experience managing high-severity cybersecurity incidents, including executive communications, cross functional coordination, containment strategy, remediation oversight, and post-incident improvement. This role supports a 24x7 cybersecurity operation and requires availability outside of standard business hours, including nights, weekends, and holidays, during critical incidents and high-severity security events.Strong leadership experience building, managing, and scaling technical security teams, including managers, incident responders, SOC analysts, threat hunters, detection engineers, and specialized security professionals. Deep technical understanding of modern security operations, including SIEM, EDR, threat intelligence, malware analysis, digital forensics, cloud security, identity security, network security, automation, and detection engineering. Experience partnering with engineering teams to build, improve, and operationalize security tools, data platforms, dashboards, automations, telemetry pipelines, and analyst workflows. Proven ability to make high-impact decisions under pressure and lead teams through ambiguous, fast-moving security events. Experience developing incident response operating models, playbooks, escalation procedures, readiness exercises, metrics, and continuous improvement programs. Strong understanding of adversary tradecraft, threat hunting methodologies, detection lifecycle management, and frameworks such as MITRE ATT&CK. Strong executive communication skills, including the ability to brief senior leaders on risk, impact, operational status, capacity gaps, and recommended actions. Ability to collaborate effectively across Cybersecurity, IT, Legal, Privacy, Compliance, Communications, Engineering, Product, and business leadership. Relevant industry certifications preferred, such as CISSP, CISM, GCIH, GCIA, GCFA, GNFA, GMON, or other GIAC certifications. The ideal candidate is a senior cyber operations leader who can operate at both strategic and tactical levels. They should be comfortable leading during crisis conditions, scaling incident response, maturing threat hunting and detection programs, and partnering with engineering teams to build the operational tools required for enterprise-scale cyber defense. This leader must be able to translate threat activity, operational pain points, analyst needs, and business risk into durable platforms, automations, detections, workflows, and operating models that improve speed, quality, resilience, and readiness across the SOC. Employees at all levels are expected to:Understand our Operating Principles; make them the guidelines for how you do your job.Own the customer experience think and act in ways that put our customers first, give them seamless digital options at every touchpoint, and make them promoters of our products and services.Know your stuff be enthusiastic learners, users and advocates of our game-changing technology, products and services, especially our digital tools and experiences.Win as a team make big things happen by working together and being open to new ideas.Be an active part of the Net Promoter System a way of working that brings more employee and customer feedback into the company by joining huddles, making call backs and helping us elevate opportunities to do better for our customers.Drive results and growth.Support a culture of inclusion in how you work and leadDo what's right for each other, our customers, investors and our communitiesDisclaimer: This information has been designed to indicate the general nature and level of work performed by employees in this role. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications.SkillsArtificial Intelligence (AI), Cyber Operations, Executive Presence, People Leadership, Security Incident ResponseWe believe that benefits should connect you to the support you need when it matters most, and should help you care for those who matter most. That's why we provide an array of options, expert guidance and always-on tools that are personalized to meet the needs of your reality—to help support you physically, financially and emotionally through the big milestones and in your everyday life.Please visit the benefits summary on our careers site for more details.EducationBachelor's DegreeWhile possessing the stated degree is preferred, Comcast also may consider applicants who hold some combination of coursework and experience, or who have extensive related professional experience.Certifications (if applicable)Relevant Work Experience10 Years +Comcast is an equal opportunity workplace. We will consider all qualified applicants for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, disability, veteran status, genetic information, or any other basis protected by applicable law.SummaryLocation: PA - Philadelphia, 1701 John F Kennedy Blvd; VA - Reston, 11951 Freedom Dr Ste 900Type: Full time

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Comcast Cybersecurity: Director, Security Operations and Incident Response in Reston, VA vacancy
  •  ...Phase2 Technology is looking for a Cyber Incident Response Business Development Senior Manager to lead and grow its Incident Response business. This role involves driving business development initiatives, engaging key stakeholders, and managing strategic partner relationships... 
    Suggested
    Work at office
    Remote work

    Phase2 Technology

    McLean, VA
    3 days ago
  • $184k - $270k

    As Sr. Director, National Security Operations, you’ll be in a critical leadership role responsible for overseeing the daily operations and ensuring the efficiency and effectiveness of our portfolio. This role requires a strategic thinker with a proven track record of leading... 
    Suggested
    Full time
    Local area

    MetroStar Systems

    Reston, VA
    2 days ago
  • $114.6k - $190.2k

     ...Cyber Incident Response Analyst Unlock the secrets of intelligence with...  ...the forefront of national security, providing advanced...  ...in Digital Transformation, Cybersecurity, IT, Data Analytics and Software...  ...methodologies. ~ Knowledge of operating systems, network protocols,... 
    Suggested
    Hourly pay
    Contract work
    Temporary work
    Work experience placement
    Local area
    Remote work
    Shift work
    Night shift
    Day shift
    Afternoon shift

    ManTech

    McLean, VA
    19 hours ago
  • $134.5k - $265.1k

     ...Cyber Services help our clients to be secure, vigilant, and resilient in the face of...  ...enabling ongoing, secure, and reliable operations across the enterprise. Recruiting for this...  ...have extensive experience in Cyber Incident Response. This role involves supporting our client... 
    Suggested
    Local area
    Visa sponsorship

    Deloitte

    McLean, VA
    1 day ago
  • $135k - $405k

     ...Management team is actively seeking a Director of Product Management for Security Operations to join our passionate,...  ..., threat hunting and/or incident response and is excited to innovate....  ...agentic AI through the lens of cybersecurity use cases is preferred, though... 
    Suggested
    Full time
    Live in
    Flexible hours

    Tanium

    Reston, VA
    more than 2 months ago
  • $142.9k - $266k

    Cyber Incident Response Business Development Senior ManagerThe Opportunity:Join a team to contribute...  ...marketing, thought leadership, operations, events, and logistics, which...  ...counsel, incident response retainers, and cybersecurity service providersExperience with presenting... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    1 day ago
  •  ...Bridge Core (BCore) is seeking a Cybersecurity Analyst in McLean, VA. The ideal candidate should have at least 1 year of experience...  ...roles and possess an active TS/SCI clearance with polygraph. Responsibilities include utilizing SIEM systems for threat analysis,... 
    Shift work
    Afternoon shift

    Bridge Core

    McLean, VA
    4 days ago
  • $250k - $338.2k

     ...not academic or generalist but operationally focused on continuously raising the bar of our security posture worldwide across all...  ...platforms, evaluate security incidents to identify patterns...  ...industry experience of increasing responsibility leading teams, driving technology... 
    Worldwide
    Flexible hours

    Amazon

    Herndon, VA
    2 days ago
  • $158.82k - $269.99k

     ...seeking an experienced Cybersecurity Manager to lead...  ...compliance coordination, and security integration for a...  ...program. This role will be responsible for ensuring...  ...product delivery, and operational support functions.The...  ...vulnerability management, incident response coordination... 
    Full time
    Contract work
    Work experience placement
    Work at office
    Remote work

    ICF

    Reston, VA
    3 days ago
  • $140k - $180k

     ...Senior Cybersecurity Manager Akima Global Technology (AGT) is seeking a Senior Cybersecurity...  ...to lead enterprise cybersecurity operations, incident response, and compliance activities across...  ...compliance with DHS Information Security Vulnerability Management (ISVM) directives... 
    Full time
    Part time
    For contractors
    Remote work

    Akima

    Herndon, VA
    2 days ago
  • $88.8k - $101.3k

     ...Sr. Associate Process Manager, Incident Management - Hybrid The Enterprise Payments organization...  ...for our end-to-end payments strategy, operations and risk management for all payment...  ..., analysis and reporting. You will be responsible for assessing data to provide top notch... 
    Full time
    Part time
    Work at office
    Local area
    3 days per week

    Capital One

    McLean, VA
    19 hours ago
  • $130k - $180k

     ...domain. Umbra’s ecosystem operates through three business...  ...the Job The Program Security Manager is responsible for leading and managing...  ...industrial, operational, and cybersecurity activities are integrated...  ...Investigate and report security incidents, violations, and... 
    Permanent employment
    Contract work
    For contractors
    For subcontractor
    Work at office
    Local area
    Remote work
    Worldwide
    Flexible hours

    Umbra

    Reston, VA
    3 days ago
  • $105k - $190k

     ...Senior Manager, Information Security is a key leadership role responsible for overseeing the day‑...  ...for evolving global cybersecurity regulations, including...  ...across security operations, governance, and product...  ...vulnerability management, incident response, root‑cause analysis... 
    Full time

    ST Engineering iDirect

    Herndon, VA
    9 hours ago
  • $264.1k - $350k

    Amazon Foundational Security Services (AFSS) delivers internal cross-Amazon security...  .... AFSS is looking for an experienced Director of Software Development to help us...  ...controls across Amazon. You will be responsible for operating Tier-1 services that are foundational... 
    Flexible hours

    Amazon

    Herndon, VA
    3 days ago
  • $150.2k - $203.3k

     ...seeking an experienced Physical Security Engineering Manager to lead...  ...team. In this role, you will be responsible for building and managing a...  ...response to physical security incidents and drive continuous improvement in security operations and monitoringInnovation: Stay... 
    Flexible hours

    Amazon

    Herndon, VA
    2 days ago
  • $220k - $270k

    Director of IP OperationsCooley is seeking a Director of IP Operations to join Cooley's IP team.About Cooley: Cooley is a global law firm with an expansive practice...  ...summary: The Director of IP Operations is responsible for oversight of all aspects of IP operations... 
    Full time
    Temporary work
    Traineeship
    Work at office
    Local area
    Remote work
    Work from home
    Worldwide
    Flexible hours
    Weekend work

    Cooley

    Reston, VA
    4 days ago
  •  ...Overview:This individual will serve as the Manager of the Security Intelligence and Operations team within the Exostar Security Office (ESO) and...  ...evolution of Exostar’s security monitoring, incident response, vulnerability management, and cloud security capabilities... 
    Full time
    Contract work
    For contractors
    Work at office
    Flexible hours

    Exostar

    Herndon, VA
    9 hours ago
  • $92.3k - $166.85k

     ...innovative solutions that strengthen national security. The preferred location for this...  ...fast-paced environment. Primary Responsibilities As a Contracts Manager, you will...  ...your local law enforcement and report the incident to the . Commitment to Non-... 
    Contract work
    Local area
    Immediate start

    Leidos

    Reston, VA
    2 days ago
  • $116.35k - $210.33k

     ...Shape the Future of National Security Leidos is seeking a...  ...environment. Primary Responsibilities As a Senior Contracts...  ...contractual, financial, and operational risks while ensuring compliance...  ...enforcement and report the incident to the . Commitment to... 
    Contract work
    Local area
    Immediate start

    Leidos

    Reston, VA
    20 hours ago
  • $134.5k - $265.1k

     ...Are you an experienced cybersecurity professional looking...  ...to strengthen security, enable innovation, and...  ...CTEM) team, you will be responsible for… Managing exposure...  ...and patch management operations across infrastructure...  ...exception management, incident-driven response... 
    Local area

    Deloitte

    McLean, VA
    9 hours ago
  •  ...clients address evolving cybersecurity challenges and...  ...implement, and optimize secure, outcome-focused solutions...  ...efficient security operations capabilities. In this...  ...team, you will be responsible for:Leading the design...  ...crisis and cyber incident response. Through this... 
    Local area

    Deloitte

    McLean, VA
    4 days ago
  • $126.2k - $264.1k

     ...Oracle Cloud Infrastructure’s (OCI) Security Operations organization, you will be at the...  ...(IOCs), investigating security incidents, managing incident responses, and conducting digital...  ...driving improvements in operational cybersecurity teams. You should possess a strong... 
    Temporary work
    Flexible hours

    Oracle Corporation

    Reston, VA
    4 days ago
  • $134.5k - $265.1k

     ...on role in delivering security engineering solutions...  ...modernizing security operations through security...  ...orchestration automation and response, detection...  ...in Computer Science, Cybersecurity, Information Systems,...  ...Certification Certified Incident Handler, Certified Information... 
    Local area
    Visa sponsorship

    Deloitte

    McLean, VA
    3 days ago
  • $134.6k - $230.8k

     ...the health and well-being of the nation's citizens.The Director of Payment Model Operations will oversee day to day operational execution for...  ...in the office a minimum of four days per week.Primary Responsibilities:Engage, develop, and sustain client relationships through... 
    Minimum wage
    Full time
    For contractors
    Work experience placement
    For subcontractor
    Work at office
    Local area
    Remote work

    UnitedHealth Group

    Reston, VA
    3 days ago
  • $55k - $65k

     ...Job Overview The Janitorial Operations Manager will support porter services...  ...and Ashburn), reporting to the Director of Janitorial Services. This role is responsible for overseeing day-to-day janitorial...  ...requiring escalation. Completes incident forms as necessary and... 
    For contractors
    Shift work
    Weekend work

    Comstock Companies

    Reston, VA
    2 days ago
  • $230k - $270k

     ...missions in every domain. Umbra’s ecosystem operates through three business units: Remote...  ...constellation, our team delivers secure, resilient systems tailored to exacting...  ...About the Job The National Security Director is responsible for growing and leading a portfolio... 
    Permanent employment
    Part time
    Work at office
    Local area
    Remote work
    Worldwide
    Flexible hours

    Umbra

    Reston, VA
    4 days ago
  • $116.9k - $243.1k

     ...clients across defense, national security, public safety, civilian,...  ...and execution of a cybersecurity program supporting one of our...  ...seamless delivery of Security Operations Support Services across 16...  ...the highest quality. Key responsibilities: Assist the Project Lead... 
    Contract work
    For contractors
    Live in
    Work at office
    Local area

    Accenture

    Reston, VA
    3 days ago
  •  ...an International Government Security Compliance and Supply Chain...  .... In this role, you will be responsible for U.S. government supply chain...  ...strategic and tactical operations for Honeywell’s non-U.S. government...  ...inspections, audits, and incident investigations, maintaining... 
    Temporary work
    For contractors
    Flexible hours

    Honeywell Technologies

    Herndon, VA
    4 days ago
  •  ...and staffing services. Responsibilities Position Summary: CTP,...  ...seeking a Chief Information Security Officer (CISO) responsible...  ...and overseeing enterprise cybersecurity strategy, ensuring the...  ...policies Lead security operations, incident response, and vulnerability... 
    Temporary work
    Remote work
    Flexible hours

    Socket.dev

    Herndon, VA
    2 days ago
  • $134.4k - $260.4k

     ...The Director of Privacy Operations is a key member of Enterprise Data Privacy Office’s (EDPO) leadership team and is responsible for the development, implementation and maintenance of the organization...  ...risks. Leads and manages privacy incident response operations, including... 
    Temporary work
    Work at office
    Local area
    Immediate start

    FINRA

    Falls Church, VA
    19 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Comcast Cybersecurity: Director, Security Operations and Incident Response. Be the first to apply!