# Principal Adversary Emulation Engineer

Hiring organization: [Comcast](https://career.thegoodapps.co/organizations/comcast)

Canonical page: https://career.thegoodapps.co/jobs/25dda8a8-44e5-44b6-a646-3225287a5d8a

Listed on Comcast's own careers site. Applications go to them directly.

- Seniority: Senior
- Location: Philadelphia, PA

## Summary

This role leads the design and execution of controlled adversary emulation exercises to validate and improve Comcast's detection capabilities across its enterprise security infrastructure. It suits experienced security professionals who can safely orchestrate realistic attack scenarios, partner across detection and hunting teams, and translate findings into measurable improvements to the company's defensive posture.

_Our summary, not Comcast's wording._

## Skills named

Bash (Scripting), Kusto Query Language (KQL), PowerShell, Python, SQL

## Required

- Bachelor's degree or equivalent experience in cybersecurity, computer science, information technology, engineering, or related field
- 7+ years of cybersecurity experience including adversary emulation, red teaming, purple teaming, detection engineering, threat hunting, incident response, or security operations
- Understanding of adversary tradecraft, attacker lifecycle, MITRE ATT&CK, threat-informed defense, and enterprise security telemetry
- Experience safely planning and executing controlled security testing in large enterprise environments
- Proficiency with Python and at least one additional scripting language such as PowerShell or Bash
- Experience with AI-assisted workflows or agentic automation in cybersecurity with appropriate safety and governance controls
- Experience working with SIEM, XDR, EDR, and various enterprise telemetry sources
- Ability to write, review, or validate detection and hunting logic using query languages like SPL, KQL, SQL, Sigma, or YARA
- Strong analytical, documentation, and communication skills
- Ability to work independently and collaborate across multiple teams

## Nice to have

- Experience building or maturing an adversary emulation, purple team, or detection validation function
- Experience with adversary emulation tools such as Atomic Red Team, MITRE Caldera, Mandiant Security Validation, Cymulate, AttackIQ, or Prelude Operator
- Experience converting emulation results into production detections, hunt content, and logging requirements
- Experience with cloud, SaaS, identity, container, CI/CD, endpoint, network, or data-platform security testing
- Relevant certifications such as GCIH, GCIA, GPEN, GXPN, GREM, GCFA, OSCP, OSEP, CRTO, or CISSP

Apply on Comcast's site: https://comcast.wd5.myworkdayjobs.com/en-US/Comcast_Careers/job/PA---Philadelphia-1800-Arch-St/Senior-Adversary-Emulation-Engineer_R441834
