Senior Network Security Engineer

Comcast
West Chester, United States of America
3 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 176K

Job location

Remote
West Chester, United States of America

Tech stack

Amazon Web Services (AWS)
Azure
Border Gateway Protocol
Cloud Computing
Configuration Management
Computer Security
Dynamic Host Configuration Protocol
Disaster Recovery
DNS
Intrusion Detection Systems
Virtual Private Networks (VPN)
Multi-protocol Systems
Information Systems Security Architecture Professional
Python
Network Security
Network Architecture
Networking Basics
Network Functions Virtualization
Network Monitoring
Routing
Network Segmentation
Open Shortest Path First
PCI Data Security Standards
Public Key Infrastructure
Powershell
Ansible
Zero Trust Network Access
TCP/IP
Test Case Design
Software Vulnerability Management
Data Logging
Network Routing
Scripting (Bash/Python/Go/Ruby)
Computer Networking Systems
Google Cloud Platform
In-Plane Switching (IPS)
Computer Network Technologies
Software Troubleshooting
Firewalls (Computer Science)
Juniper
Information Technology
Fortinet
Tools for Reporting
CIS Benchmarks
TACACS+ Protocol
Terraform
Cisco networks
Vulnerability Analysis

Job description

This job is responsible for executing and advancing the security posture of Comcast's core network platforms through secure architecture, vulnerability remediation, software patch validation, configuration compliance, access control enforcement, and vendor-driven hardening initiatives. This role serves as a platform/domain owner and execution lead for assigned network environments, partnering with architecture, engineering, cybersecurity, compliance, operations, and vendor teams to validate secure solutions in the lab, support production readiness, reduce risk exposure, and ensure network platforms are resilient, continuously patchable, and aligned to Comcast cybersecurity standards., This Engineer 4 can be based in West Chester or Philadelphia, PA; or Mt. Laurel, NJ., * Own the security posture and execution roadmap for Comcast network domains and platforms such as Cisco, Juniper, Arista, Nokia, F5, Fortinet etc.

  • Lead vulnerability remediation, risk mitigation, and patch validation activities for critical vulnerabilities, and vendor security advisories.
  • Validate secure software releases, compensating controls, and configuration changes in lab environments before production implementation, including security review, bug scrub, test case validation, and certification support.
  • Drive secure configuration rollout and compliance enforcement across supported platforms using approved network security standards, audit tooling, ticketing workflows, and remediation tracking.
  • Support audit readiness and closure for PCI, CGA, SOC 2, and internal compliance reviews by validating controls, documenting remediation plans, and coordinating evidence collection.
  • Configure, test, and operationalize new network security solutions and services, including secure authentication & authorization, certificate-based access, secure monitoring, secure logging, and access restrictions.
  • Develop, review, and publish network security and resiliency standards that align with Comcast Cybersecurity Policy, CISA hardening guidance, regulatory expectations, and secure-by-design principles.
  • Maintain continuous compliance by monitoring secure controls, reviewing audit results, validating configuration drift, coordinating remediation with platform teams, and helping define policy checks in network audit and compliance tools.
  • Review network functions, features, software, hardware, and engineering designs to identify security risks, required mitigations, operational impacts, and production readiness requirements.
  • Perform security assessments of network platforms and services to identify threats, vulnerabilities, exposed services, insecure protocols, weak authentication methods, access control gaps, and hardening opportunities.
  • Partner with cross functional organizations/teams such as cybersecurity, architecture, network engineering, operations, and vendor teams to implement least-privilege access, improve auditability, and detect unauthorized or anomalous network changes.
  • Engage vendors to resolve product security issues, validate hardened releases, influence secure-by-default capabilities, and ensure vendor solutions align with Comcast network security requirements.
  • Assist with disaster recovery, technical continuity, incident response preparation, and after-action reviews for network security events, production exposures, and audit findings.
  • Improve team execution by documenting standards, test results, remediation playbooks, operational handoffs, technical decisions, and lessons learned.
  • Track execution progress, risks, blockers, and metrics across remediation initiatives, ensuring work is visible, measurable, and traceable through approved systems of record.
  • Other duties and responsibilities as assigned., * Understand our Operating Principles; make them the guidelines for how you do your job.
  • Own the customer experience think and act in ways that put our customers first, give them seamless digital options at every touchpoint, and make them promoters of our products and services.
  • Know your stuff be enthusiastic learners, users and advocates of our game-changing technology, products and services, especially our digital tools and experiences.
  • Win as a team make big things happen by working together and being open to new ideas.
  • Be an active part of the Net Promoter System a way of working that brings more employee and customer feedback into the company by joining huddles, making call backs and helping us elevate opportunities to do better for our customers.
  • Drive results and growth.
  • Support a culture of inclusion in how you work and lead.
  • Do what's right for each other, our customers, investors and our communities.

Disclaimer: This information has been designed to indicate the general nature and level of work performed by employees in this role. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications.

Requirements

  • Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, Network Engineering, or a related field; or equivalent combination of education and experience.
  • 5+ years of experience in Network Engineering, Network Security Engineering, Infrastructure Security, or related technical disciplines.
  • 3+ years of hands-on experience securing and supporting enterprise or service provider network environments.
  • Experience with network platforms and technologies including Cisco, Juniper, Arista, Nokia, F5, Fortinet, or equivalent networking technologies.
  • Hands-on experience with routing and switching technologies.
  • Experience performing network vulnerability remediation, security patch validation, configuration hardening, and risk mitigation activities.
  • Strong understanding of networking fundamentals including routing, switching, TCP/IP, DNS, DHCP, BGP, OSPF, MPLS, and network segmentation.
  • Knowledge of network security technologies including AAA, TACACS+, RADIUS, PKI/certificates, access control, IDS/IPS, firewalls, VPNs, and secure management protocols.
  • Experience supporting compliance and audit activities associated with PCI-DSS, SOC 2, NIST, CIS Controls, or similar security frameworks.
  • Experience analyzing vendor security advisories, CVEs, software vulnerabilities, and remediation strategies.
  • Familiarity with network monitoring, logging, configuration management, and compliance validation tools.
  • Experience working within change management, incident management, and operational support processes.
  • Strong troubleshooting, documentation, communication, and cross-functional collaboration skills., * 7+ years of experience in network security engineering within large enterprise, telecommunications, ISP, cable, cloud, or service provider environments.
  • Experience securing carrier-grade network infrastructure supporting large-scale production environments.
  • Hands-on experience with network hardening methodologies aligned to CIS Benchmarks, NIST, CISA guidance, or vendor security best practices.
  • Experience with automation and scripting using Python, Ansible, PowerShell, Terraform, or similar tools.
  • Experience with network compliance, vulnerability scanning, and reporting platforms.
  • Knowledge of Zero Trust, secure-by-design principles, privileged access management, and identity-based network security controls.
  • Experience supporting security incident response, forensic investigations, and post-incident remediation.
  • Familiarity with cloud networking and hybrid infrastructure security (AWS, Azure, GCP).
  • Industry certifications such as: CISSP, CCNP Security, JNCIS/JNCIP, GIAC certifications, Security+, Communication, Network Routing, Network Security, Scripting, Bachelor's Degree

While possessing the stated degree is preferred, Comcast also may consider applicants who hold some combination of coursework and experience, or who have extensive related professional experience.

Certifications (if applicable) Cisco Certified Network Professional (CCNP) - Cisco Systems, Inc.

Benefits & conditions

This job can be performed in New Jersey with a Pay Range of $117,171.70 - $175,757.55

About the company

Make your mark at Comcast -- a Fortune 30 global media and technology company. From the connectivity and platforms we provide, to the content and experiences we create, we reach hundreds of millions of customers, viewers, and guests worldwide. Become part of our award-winning technology team that turns big ideas into cutting-edge products, platforms, and solutions that our customers love. We create space to innovate, and we recognize, reward, and invest in your ideas, while ensuring you can proudly bring your authentic self to the workplace. Join us. You'll do the best work of your career right here at Comcast. (In most cases, Comcast prefers to have employees on-site collaborating unless the team has been designated as virtual due to the nature of their work. If a position is listed with both office locations and virtual offerings, Comcast may be willing to consider candidates who live greater than 100 miles from the office for the remote option.)

Apply for this position