Skip to main content
CareerApp
Comcast

Principal Adversary Emulation Engineer

Comcast

Philadelphia, PA · Senior

Listed on Comcast’s own careers site. You apply with them directly — we never stand between you and the employer.

What this role is

This role leads the design and execution of controlled adversary emulation exercises to validate and improve Comcast's detection capabilities across its enterprise security infrastructure. It suits experienced security professionals who can safely orchestrate realistic attack scenarios, partner across detection and hunting teams, and translate findings into measurable improvements to the company's defensive posture.

Our summary, not Comcast’s wording. The full posting is on their site.

Skills this role names

Log in to see which of these are already on your profile.

What they ask for

Required

  • Bachelor's degree or equivalent experience in cybersecurity, computer science, information technology, engineering, or related field
  • 7+ years of cybersecurity experience including adversary emulation, red teaming, purple teaming, detection engineering, threat hunting, incident response, or security operations
  • Understanding of adversary tradecraft, attacker lifecycle, MITRE ATT&CK, threat-informed defense, and enterprise security telemetry
  • Experience safely planning and executing controlled security testing in large enterprise environments
  • Proficiency with Python and at least one additional scripting language such as PowerShell or Bash
  • Experience with AI-assisted workflows or agentic automation in cybersecurity with appropriate safety and governance controls
  • Experience working with SIEM, XDR, EDR, and various enterprise telemetry sources
  • Ability to write, review, or validate detection and hunting logic using query languages like SPL, KQL, SQL, Sigma, or YARA
  • Strong analytical, documentation, and communication skills
  • Ability to work independently and collaborate across multiple teams

Nice to have

  • Experience building or maturing an adversary emulation, purple team, or detection validation function
  • Experience with adversary emulation tools such as Atomic Red Team, MITRE Caldera, Mandiant Security Validation, Cymulate, AttackIQ, or Prelude Operator
  • Experience converting emulation results into production detections, hunt content, and logging requirements
  • Experience with cloud, SaaS, identity, container, CI/CD, endpoint, network, or data-platform security testing
  • Relevant certifications such as GCIH, GCIA, GPEN, GXPN, GREM, GCFA, OSCP, OSEP, CRTO, or CISSP

Turn on analytics and we load Google Analytics: Google gets the pages you open and what you do here — searches, jobs you view, jobs you apply to — and sets its own cookies. Leave it off and the only cookies we set are your login, your theme, and this answer. Accept All also records a yes to advertising, which nothing uses yet. Privacy Policy.