Comcast Cybersecurity: Director, Security Operations and Incident Response

ComcastPhiladelphia, PA
$186,640 - $292,685Onsite

About The Position

Comcast is seeking a Director, Security Operations and Incident Response to lead the enterprise cyber defense function. This role is responsible for detecting, analyzing, hunting, escalating, and responding to cybersecurity threats across Comcast. The Director will focus on scaling the Security Operations Center, Security Incident Response Team, threat hunting, and threat detection capabilities to address a changing threat landscape. This includes managing multiple major incidents concurrently, maintaining high-quality response under elevated case volume, proactively identifying emerging threats, and continuously improving detection coverage. The role provides strategic leadership, executive-level incident command, operational transformation, and cross-functional coordination with various departments including Cybersecurity, IT, Legal, Privacy, Communications, Engineering, Product, and business leadership. A key aspect of this role is partnering with engineering teams to enhance the tools, data pipelines, dashboards, automations, and workflows used by cyber operators.

Requirements

  • 10+ years of relevant cybersecurity experience, including leadership experience in cybersecurity operations, security incident response, threat hunting, threat detection, or enterprise SOC functions in a large, complex environment with at least 5 years of experience managing leaders of people
  • Demonstrated experience managing high-severity cybersecurity incidents, including executive communications, cross functional coordination, containment strategy, remediation oversight, and post-incident improvement.
  • This role supports a 24x7 cybersecurity operation and requires availability outside of standard business hours, including nights, weekends, and holidays, during critical incidents and high-severity security events.
  • Strong leadership experience building, managing, and scaling technical security teams, including managers, incident responders, SOC analysts, threat hunters, detection engineers, and specialized security professionals.
  • Deep technical understanding of modern security operations, including SIEM, EDR, threat intelligence, malware analysis, digital forensics, cloud security, identity security, network security, automation, and detection engineering.
  • Experience partnering with engineering teams to build, improve, and operationalize security tools, data platforms, dashboards, automations, telemetry pipelines, and analyst workflows.
  • Proven ability to make high-impact decisions under pressure and lead teams through ambiguous, fast-moving security events.
  • Experience developing incident response operating models, playbooks, escalation procedures, readiness exercises, metrics, and continuous improvement programs.
  • Strong understanding of adversary tradecraft, threat hunting methodologies, detection lifecycle management, and frameworks such as MITRE ATT&CK.
  • Strong executive communication skills, including the ability to brief senior leaders on risk, impact, operational status, capacity gaps, and recommended actions.
  • Ability to collaborate effectively across Cybersecurity, IT, Legal, Privacy, Compliance, Communications, Engineering, Product, and business leadership.
  • Artificial Intelligence (AI), Cyber Operations, Executive Presence, People Leadership, Security Incident Response

Nice To Haves

  • Relevant industry certifications preferred, such as CISSP, CISM, GCIH, GCIA, GCFA, GNFA, GMON, or other GIAC certifications.
  • The ideal candidate is a senior cyber operations leader who can operate at both strategic and tactical levels. They should be comfortable leading during crisis conditions, scaling incident response, maturing threat hunting and detection programs, and partnering with engineering teams to build the operational tools required for enterprise-scale cyber defense.
  • This leader must be able to translate threat activity, operational pain points, analyst needs, and business risk into durable platforms, automations, detections, workflows, and operating models that improve speed, quality, resilience, and readiness across the SOC.

Responsibilities

  • Lead and scale Comcast’s SOC, Security Incident Response Team, threat hunting, and threat detection functions, ensuring the organization is trained, equipped, and structured to respond effectively to routine security events and major incidents.
  • Build the operating model, staffing approach, escalation paths, runbooks, and surge capacity required to manage multiple concurrent major incidents.
  • Serve as a senior incident commander for high-severity cybersecurity events, coordinating response across technical teams, business stakeholders, legal, privacy, communications, and executive leadership.
  • Lead Comcast’s threat hunting function to proactively identify adversary behavior, emerging attack patterns, control gaps, and high-risk activity before it becomes a major incident. Including leading Purple Team activities.
  • Own and mature the enterprise threat detection strategy, including detection coverage, alert fidelity, tuning, detection lifecycle management, and alignment to threat intelligence, adversary tradecraft, and business risk.
  • Partner with security engineering, data engineering, platform engineering, and product teams to design and improve the tools, pipelines, dashboards, automations, and case management workflows used by cyber operations teams.
  • Drive continuous improvement across SIEM use cases, endpoint detections, cloud detections, identity detections, network telemetry, enrichment pipelines, automation, and analyst workflows.
  • Ensure lessons learned from incidents and hunts directly inform new detections, improved runbooks, stronger controls, and better response procedures.
  • Develop and continuously improve incident response strategy, severity models, communications protocols, after-action reviews, and remediation tracking.
  • Establish executive reporting on incident trends, SOC performance, detection quality, threat hunting outcomes, operational capacity, readiness gaps, and enterprise risk.
  • Define and track metrics for mean time to detect, mean time to respond, alert quality, false-positive reduction, detection coverage, incident conversion, hunting outcomes, case volume, backlog, and major-incident readiness.
  • Manage relationships with external incident response providers, security vendors, technology partners, and strategic service providers to ensure effective support during critical incidents.
  • Ensure SOC, incident response, threat hunting, and detection practices align with regulatory expectations, internal policies, industry frameworks, and enterprise risk management requirements.
  • Provide leadership to managers and technical teams, including goal setting, performance management, workforce planning, coaching, and career development.
  • Represent Comcast as a senior subject matter expert in security operations, incident response, threat hunting, and threat detection.

Benefits

  • Base pay is one part of the Total Rewards that Comcast provides to compensate and recognize employees for their work.
  • Most sales positions are eligible for a Commission under the terms of an applicable plan, while most non-sales positions are eligible for a Bonus.
  • Additionally, Comcast provides best-in-class Benefits to eligible employees.
  • We believe that benefits should connect you to the support you need when it matters most, and should help you care for those who matter most.
  • That’s why we provide an array of options, expert guidance and always-on tools, that are personalized to meet the needs of your reality – to help support you physically, financially and emotionally through the big milestones and in your everyday life.
  • Please visit the compensation and benefits summary on our careers site for more details.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service