Adversary Emulation Engineer

Comcast
Suffolk, VA, United States
4 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$134,449.0 - $210,840.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Software System Penetration Testing Build Automation Bash Shell Big Data Software as a Service Cloud Computing Cyber Security Continuous Integration Query Languages Emulators Intrusion Detection and Prevention
+18 more
Python (Programming Language) Windows PowerShell Red Team (Cyber Security) Kusto Query Language Security Information and Event Management SQL Databases Test Execution Engine Data Logging Scripting Software Security Mitre Att&ck Advanced Reports Cyber Threat Analysis Information Technology Cybercrime Purple Team (Cyber Security) Cyber Warfare Epic Prelude

Job description

Comcast Cybersecurity protects Comcast, our customers, our workforce, our partners, and our technology platforms from increasingly sophisticated cyber threats. We are seeking a Senior Adversary Emulation Engineer to help establish and mature adversary emulation as a repeatable capability within Threat Detection.

This role sits at the intersection of adversary emulation, threat detection engineering, threat hunting, telemetry validation, and purple team operations. The successful candidate will design and execute controlled, threat-informed emulation scenarios; validate detection coverage across enterprise telemetry sources; generate high-fidelity data for threat hunting; and translate findings into improved detections, hunt content, logging requirements, automations, and actionable reporting.

This is a hands-on senior engineering role for someone who can operate safely in complex enterprise environments, partner across cyber and engineering teams, and help Comcast continuously prove and improve its ability to detect real-world adversary behavior., * Help establish and mature Comcast’s adversary emulation capability, including operating model, rules of engagement, approval workflows, success metrics, reporting standards, and repeatable validation processes.

  • Design, plan, and execute controlled adversary emulation scenarios based on current threat intelligence, priority adversary behaviors, emerging attack techniques, and Comcast-relevant risk scenarios.
  • Emulate real-world attacker tactics, techniques, and procedures using frameworks such as MITRE ATT&CK, while maintaining strict safety, deconfliction, and operational controls.
  • Build automation and AI-assisted workflows to streamline emulation planning, evidence collection, test execution, detection validation, reporting, and metrics tracking, with appropriate human review, auditability, and governance.
  • Partner with Threat Detection Engineering to validate detection coverage, alert fidelity, enrichment quality, triage workflows, and detection lifecycle effectiveness.
  • Partner with Threat Hunting to generate high-fidelity telemetry, validate hunt hypotheses, and convert emulation outcomes into reusable hunt content.
  • Identify and document logging gaps, telemetry quality issues, detection blind spots, enrichment deficiencies, and control weaknesses across endpoint, identity, cloud, network, email, SaaS, application, and data-platform sources.
  • Develop repeatable emulation playbooks, test cases, validation workflows, and reporting artifacts that can be reused across priority threats and enterprise environments.
  • Evaluate adversary emulation, breach-and-attack simulation, security validation, and emerging AI-enabled security technologies for use within Comcast’s threat operations environment.
  • Support purple team exercises, threat-informed defense initiatives, after-action reviews, and continuous improvement efforts across cyber operations.
  • Produce clear technical reports and executive-ready summaries that translate emulation results into prioritized recommendations, measurable detection improvements, and risk-informed remediation actions.
  • Collaborate across Cybersecurity, Security Operations, Security Incident Response, Threat Intelligence, Threat Hunting, Detection Engineering, Security Engineering, Cloud, Identity, Endpoint, Network, Product, and other technical teams., * Comcast has a repeatable adversary emulation operating model with clear rules of engagement, test plans, approval workflows, metrics, and reporting.
  • Priority threat scenarios are translated into safe, repeatable emulation exercises mapped to MITRE ATT&CK and Comcast-relevant risk areas.
  • Detection Engineering receives clear validation results that improve detection coverage, alert fidelity, enrichment, and response workflows.
  • Threat Hunting receives high-quality telemetry and validated hypotheses that improve hunt effectiveness.
  • Logging gaps, blind spots, and data quality issues are documented, prioritized, and converted into actionable remediation work.
  • Emulation outcomes are consistently converted into detections, hunts, dashboards, reports, and measurable improvements to Comcast’s cyber defense posture.
  • Cross-functional partners view adversary emulation as a trusted, safe, and valuable capability that improves enterprise readiness against real-world threats.

Requirements

  • Bachelor’s degree or equivalent experience in cybersecurity, computer science, information technology, engineering, or a related field.
  • 7+ years of relevant cybersecurity experience, including hands-on experience in adversary emulation, red teaming, purple teaming, detection engineering, threat hunting, incident response, or security operations.
  • Strong understanding of adversary tradecraft, attacker lifecycle, MITRE ATT&CK, threat-informed defense, detection engineering, and enterprise security telemetry.
  • Experience safely planning and executing controlled security testing in large or complex enterprise environments, including rules of engagement, approvals, deconfliction, and evidence handling.
  • Proficiency with scripting or automation using Python and at least one additional language or shell such as PowerShell or Bash.
  • Experience applying AI-assisted workflows or agentic automation to cybersecurity use cases with appropriate safety, review, and governance controls.
  • Experience working with SIEM, XDR, EDR, endpoint telemetry, identity logs, cloud logs, network data, email security telemetry, and/or application security telemetry.
  • Ability to write, review, or validate detection and hunting logic using query languages or formats such as SPL, KQL, SQL, Sigma, YARA, or similar.
  • Strong analytical, documentation, and communication skills, including the ability to explain technical findings, detection gaps, and risk implications to technical and non-technical stakeholders.
  • Ability to work independently, exercise sound judgment, and collaborate across multiple teams in a fast-moving enterprise security environment., * Experience helping build or mature an adversary emulation, purple team, detection validation, or security validation function.
  • Experience with adversary emulation and validation tools such as Atomic Red Team, MITRE Caldera, Mandiant Security Validation, Cymulate, AttackIQ, Prelude Operator, or similar platforms.
  • Experience turning emulation results into production detections, hunt content, logging requirements, dashboards, runbooks, and measurable detection coverage improvements.
  • Experience with cloud, SaaS, identity, container, CI/CD, endpoint, network, or large-scale data-platform security testing.
  • Relevant certifications such as GCIH, GCIA, GPEN, GXPN, GREM, GCFA, OSCP, OSEP, CRTO, CISSP, or equivalent experience., Artificial Intelligence Technologies, Cyber Defense, Cyber Threat Intelligence, Incident Response, Penetration Testing, Security Engineering, Security Testing, Bachelor’s Degree

While possessing the stated degree is preferred, Comcast also may consider applicants who hold some combination of coursework and experience, or who have extensive related professional experience.

Benefits & conditions

This job can be performed in Virginia with a Pay Range of $134,449.01 - $210,840.49

About the company

Make your mark at Comcast – a Fortune 30 global media and technology company. From the connectivity and platforms we provide, to the content and experiences we create, we reach hundreds of millions of customers, viewers, and guests worldwide. Become part of our award-winning technology team that turns big ideas into cutting-edge products, platforms, and solutions that our customers love. We create space to innovate, and we recognize, reward, and invest in your ideas, while ensuring you can proudly bring your authentic self to the workplace. Join us. You’ll do the best work of your career right here at Comcast. (In most cases, Comcast prefers to have employees on-site collaborating unless the team has been designated as virtual due to the nature of their work. If a position is listed with both office locations and virtual offerings, Comcast may be willing to consider candidates who live greater than 100 miles from the office for the remote option.)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 ¡ Coffee With Developers

3:28 min

Defining big data and machine learning fundamentals

Ayon Roy ¡ LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders ¡ LIVE

58 sec

Navigating limitations of local Cosmos DB emulators

Radu Vunvulea Radu Vunvulea ¡ World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:10 min

Why organizations combine big data and machine learning

Ayon Roy ¡ LIVE

Videos

See all

Related articles

See all