Cybersecurity Incident Response Engineer in Comcast's Security Incident Response Team mitigating threats and restoring environments following incidents. Working with advanced technologies to safeguard customers and infrastructure.
Responsibilities
Monitors networks for security events and alerts to potential/active threats, intrusions, and/or compromises
Restores environment after an incident and ensures that the managed security service has thorough detection capabilities in place for emerging threats
Performs service requests from internal/external teams
Maintains an advanced understanding of cyber security threats, vulnerabilities, attacks, responsible groups, motivations and techniques
Continues to assess the evolving threats and new technologies, solutions, and services to stay ahead of them through research
May perform documentation, vetting and weaponization of identified vulnerabilities for operational use
Evaluates event flows to identify common risks and vulnerabilities to develop and implement solutions
Assists with security audits, risk analysis, network forensics and penetration testing
Provides assistance in monitoring the security of all designated networks and systems
May prepare detailed incident reports and technical briefs for the IT security team
Conducts After Action Reviews (AAR) to improve the response process including updating playbooks
Familiarizes self with company goals and strategies in order to achieve short-term goals with resolution
Strives to achieve personal goals and those set forth by management
Consistent exercise of independent judgment and discretion in matters of significance
Regular, consistent and punctual attendance
Must be able to work nights and weekends, variable schedule(s) as necessary
Requirements
2–5 years of experience leading or supporting incident response activities
Ability to review and interpret logs to identify potential attacks or anomalies
Strong analytical skills to recognize evolving attack patterns and adapt response strategies
Hands-on experience identifying and mitigating phishing attempts
Skilled in interpreting different types of attacks across various log sources
Ability to validate and assess Indicators of Compromise for accuracy and relevance
Solid understanding of network protocols and architecture
Experience analyzing Windows and Linux environments for security threats
Familiarity with securing cloud platforms and services
Experience with Security Information and Event Management (SIEM) platforms for monitoring and analysis
Knowledge of Endpoint Detection and Response (EDR) tools and processes for endpoint security
Understanding of authentication mechanisms and identity management
Ability to analyze and secure endpoints across diverse environments
Strong verbal and written communication skills for clear reporting and collaboration
Ability to work effectively within cross-functional teams in fast-paced environments
Benefits
Best-in-class Benefits to eligible employees
Array of options, expert guidance, and always-on tools
Support you physically, financially, and emotionally through big milestones and in everyday life
Information Security Analyst supporting information security function at Ten, a trusted service provider. Ensuring compliance with global standards and managing security risks within the organization.
Security Operations Center Analyst managing incidents and security alerts for 7 - Eleven stores. Focusing on in - depth analysis and proactive monitoring within a state - of - the - art Security Operations Center.
Security Operations Manager at Qnity managing physical security programs across global sites. Overseeing operations and collaborating with cross - functional teams to mitigate risk and maintain secure facilities.
SOC Analyst monitoring security events and responding to incidents at Junglee Games. Collaborating on security protocols to ensure protection of digital assets.
Senior Director of Global Security Operations at CyrusOne strategizing and managing security across global data centers. Driving execution, governance, and operational excellence in a high - availability environment.
Cybersecurity generalist at PwC providing security solutions and maintaining the protection of client systems. Involves monitoring security alerts, incident response, and collaboration with stakeholders.
Security Operations Manager overseeing safety measures for corporate office locations and events at Whatnot. Responsible for developing security frameworks and managing vendor relationships across global operations.
Manager overseeing technical security operations for the Protection Services department. Responsible for managing security systems, staff training, and interdepartmental collaboration.
Principal in Security Monitoring Response at Mastercard managing global crises and resilience operations. Leading incident response efforts and ensuring the safety of people and assets.
SOC Analyst II providing real time security monitoring and threat hunting services for clients in various industries. Assisting in identifying security incidents and managing vulnerabilities.