More jobs:
Cybersecurity: Director, Security Operations and Incident Response
Job in
Reston, Fairfax County, Virginia, 22090, USA
Listed on 2026-07-20
Listing for:
Comcast
Full Time
position Listed on 2026-07-20
Job specializations:
-
IT/Tech
Cybersecurity
Job Description & How to Apply Below
Make your mark at Comcast -- a Fortune 30 global media and technology company. From the connectivity and platforms we provide, to the content and experiences we create, we reach hundreds of millions of customers, viewers, and guests worldwide. Become part of our award-winning technology team that turns big ideas into cutting-edge products, platforms, and solutions that our customers love.
We create space to innovate, and we recognize, reward, and invest in your ideas, while ensuring you can proudly bring your authentic self to the workplace. Join us. You'll do the best work of your career right here at Comcast. (In most cases, Comcast prefers to have employees on-site collaborating unless the team has been designated as virtual due to the nature of their work.
If a position is listed with both office locations and virtual offerings, Comcast may be willing to consider candidates who live greater than 100 miles from the office for the remote option.)
Job Summary
At Comcast, we are committed to providing secure and reliable services for our customers, employees, and business partners. As the
Director, Security Operations and Incident Response, you will lead the enterprise cyber defense function responsible for detecting, analyzing,
hunting, escalating, and responding to cybersecurity threats across Comcast.
This role is accountable for scaling Comcast's Security Operations Center, Security Incident Response Team, threat hunting, and threat
detection capabilities to meet a materially changed threat environment. Comcast must be prepared to manage multiple major incidents
concurrently, maintain high-quality response under elevated case volume, proactively identify emerging threats, and continuously improve detection coverage across enterprise environments.
The Director will provide strategic leadership, executive-level incident command, operational transformation, and cross-functional coordination
across Cybersecurity, IT, Legal, Privacy, Communications, Engineering, Product, and business leadership. This leader will also partner
closely with engineering teams to improve the tools, data pipelines, dashboards, automations, and workflows used by cyber operators every
day.
This is a critical leadership role responsible for protecting Comcast, our customers, our workforce, and our network from high-impact cyber
threats.
Job Description
This position is ineligible for visa sponsorship. To be considered for this role, you must be legally authorized to work in the United States and not require sponsorship for employment now or in the future.
Core Responsibilities:
* Lead and scale Comcast's SOC, Security Incident Response Team, threat hunting, and threat detection functions, ensuring the organization is trained, equipped, and structured to respond effectively to routine security events and major incidents.
* Build the operating model, staffing approach, escalation paths, runbooks, and surge capacity required to manage multiple concurrent major incidents.
* Serve as a senior incident commander for high-severity cybersecurity events, coordinating response across technical teams, business stakeholders, legal, privacy, communications, and executive leadership.
* Lead Comcast's threat hunting function to proactively identify adversary behavior, emerging attack patterns, control gaps, and high-risk activity before it becomes a major incident. Including leading Purple Team activities.
* Own and mature the enterprise threat detection strategy, including detection coverage, alert fidelity, tuning, detection lifecycle management, and alignment to threat intelligence, adversary tradecraft, and business risk.
* Partner with security engineering, data engineering, platform engineering, and product teams to design and improve the tools, pipelines, dashboards, automations, and case management workflows used by cyber operations teams.
* Drive continuous improvement across SIEM use cases, endpoint detections, cloud detections, identity detections, network telemetry, enrichment pipelines, automation, and analyst workflows.
* Ensure lessons learned from incidents and hunts directly inform new detections, improved runbooks, stronger controls,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×