Cybersecurity Incident Response Engineer in Comcast's Security Incident Response Team mitigating threats and restoring environments following incidents. Working with advanced technologies to safeguard customers and infrastructure.
Responsibilities
Monitors networks for security events and alerts to potential/active threats, intrusions, and/or compromises
Restores environment after an incident and ensures that the managed security service has thorough detection capabilities in place for emerging threats
Performs service requests from internal/external teams
Maintains an advanced understanding of cyber security threats, vulnerabilities, attacks, responsible groups, motivations and techniques
Continues to assess the evolving threats and new technologies, solutions, and services to stay ahead of them through research
May perform documentation, vetting and weaponization of identified vulnerabilities for operational use
Evaluates event flows to identify common risks and vulnerabilities to develop and implement solutions
Assists with security audits, risk analysis, network forensics and penetration testing
Provides assistance in monitoring the security of all designated networks and systems
May prepare detailed incident reports and technical briefs for the IT security team
Conducts After Action Reviews (AAR) to improve the response process including updating playbooks
Familiarizes self with company goals and strategies in order to achieve short-term goals with resolution
Strives to achieve personal goals and those set forth by management
Consistent exercise of independent judgment and discretion in matters of significance
Regular, consistent and punctual attendance
Must be able to work nights and weekends, variable schedule(s) as necessary
Requirements
2–5 years of experience leading or supporting incident response activities
Ability to review and interpret logs to identify potential attacks or anomalies
Strong analytical skills to recognize evolving attack patterns and adapt response strategies
Hands-on experience identifying and mitigating phishing attempts
Skilled in interpreting different types of attacks across various log sources
Ability to validate and assess Indicators of Compromise for accuracy and relevance
Solid understanding of network protocols and architecture
Experience analyzing Windows and Linux environments for security threats
Familiarity with securing cloud platforms and services
Experience with Security Information and Event Management (SIEM) platforms for monitoring and analysis
Knowledge of Endpoint Detection and Response (EDR) tools and processes for endpoint security
Understanding of authentication mechanisms and identity management
Ability to analyze and secure endpoints across diverse environments
Strong verbal and written communication skills for clear reporting and collaboration
Ability to work effectively within cross-functional teams in fast-paced environments
Benefits
Best-in-class Benefits to eligible employees
Array of options, expert guidance, and always-on tools
Support you physically, financially, and emotionally through big milestones and in everyday life
Lead the Local Vodafone Business Service Operations Centre in Athens, Greece. Focus on delivering managed security, cloud, and SaaS services with operational excellence.
Associate SOC Analyst at NCC Group monitoring security incidents and collaborating with a cybersecurity team. Contributing to the organisation's cybersecurity posture through analysis and threat mitigation.
SOC Analyst responsible for monitoring threats and vulnerabilities in IT systems. Engaging with clients and providing incident remediation documentation and recommendations.
Security Analyst managing network security tools to protect systems at Riachuelo. Collaborating with teams to ensure operational resilience and security compliance.
Intermediate Security Operations Centre Analyst involved in IT security operations for a dynamic IT provider. Collaborating with internal teams for incident detection and response across various platforms.
Security Operations Centre Analyst for Long View's IGS branch, focused on incident detection and response. Collaborating with teams to monitor, identify, and remediate security incidents.
SOC Engineer at Replit monitoring and assessing emerging threats in cloud infrastructure and AI coding environments. Conducting investigations and collaborating with teams for mitigation strategies.
Security Operations Lead overseeing global SOC operations and AI product integration at Replit. Leading monitoring and incident response across multi - cloud environments and AI workloads.
Director of Security Operations responsible for strategic leadership and operational excellence in security at Abridge. Leading teams focused on preventing, detecting, and responding to security threats.