Listed on Comcast’s own careers site. You apply with them directly — we never stand between you and the employer.
What this role is
This role leads the design and execution of controlled adversary emulation exercises to validate and improve Comcast's detection capabilities across its enterprise security infrastructure. It suits experienced security professionals who can safely orchestrate realistic attack scenarios, partner across detection and hunting teams, and translate findings into measurable improvements to the company's defensive posture.
Our summary, not Comcast’s wording. The full posting is on their site.
Skills this role names
Log in to see which of these are already on your profile.
What they ask for
Required
- Bachelor's degree or equivalent experience in cybersecurity, computer science, information technology, engineering, or related field
- 7+ years of cybersecurity experience including adversary emulation, red teaming, purple teaming, detection engineering, threat hunting, incident response, or security operations
- Understanding of adversary tradecraft, attacker lifecycle, MITRE ATT&CK, threat-informed defense, and enterprise security telemetry
- Experience safely planning and executing controlled security testing in large enterprise environments
- Proficiency with Python and at least one additional scripting language such as PowerShell or Bash
- Experience with AI-assisted workflows or agentic automation in cybersecurity with appropriate safety and governance controls
- Experience working with SIEM, XDR, EDR, and various enterprise telemetry sources
- Ability to write, review, or validate detection and hunting logic using query languages like SPL, KQL, SQL, Sigma, or YARA
- Strong analytical, documentation, and communication skills
- Ability to work independently and collaborate across multiple teams
Nice to have
- Experience building or maturing an adversary emulation, purple team, or detection validation function
- Experience with adversary emulation tools such as Atomic Red Team, MITRE Caldera, Mandiant Security Validation, Cymulate, AttackIQ, or Prelude Operator
- Experience converting emulation results into production detections, hunt content, and logging requirements
- Experience with cloud, SaaS, identity, container, CI/CD, endpoint, network, or data-platform security testing
- Relevant certifications such as GCIH, GCIA, GPEN, GXPN, GREM, GCFA, OSCP, OSEP, CRTO, or CISSP