Comcast Cybersecurity: Director, Security Operations and Incident Response
Core
Lead enterprise cyber defense, scaling SOC, incident response, threat hunting, and detection capabilities to protect Comcast's network and customers from high-impact threats.
Role type
Director, Security Operations and Incident Response
Builds
Enterprise threat detection strategy, incident response operating models, automated workflows, and detection pipelines for cyber operators.
Domain
Cybersecurity, Enterprise Security Operations, Threat Intelligence
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Strategic leadership in security operations, managing high-severity incidents, building and scaling technical security teams, deep technical understanding of SIEM/EDR/cloud security, adversary tradecraft knowledge, executive communication, incident response strategy design, metrics definition for detection/response times.
Preferred skills
CISSP, CISM, GCIH, GCIA, GCFA, GNFA, GMON certifications.
Technologies
SIEM, EDR, Cloud Security, Identity Security, Network Telemetry, MITRE ATT&CK, Automation, Data Pipelines.
Responsibilities
Lead and scale SOC and threat hunting functions; serve as senior incident commander for high-severity events; build operating models and surge capacity; partner with engineering to improve tools and workflows; establish executive reporting on security metrics; manage external IR providers and vendors.
Seniority
Director, strategic leadership with hands-on operational oversight