Comcast Cybersecurity: Principal Penetration Tester
Job Description
Comcast's Technology, Product & Experience organization works at the intersection of media and technology. Our innovative teams are continually developing and delivering products that transform the customer experience. From creating apps like TVGo to new features such as the Talking Guide on the X1 platform, we work every day to make a positive impact through innovation in the pursuit of building amazing products that are enjoyable, easy to use and accessible across all platforms. The team also develops and supports our evolving network architecture, including next-generation consumer systems and technologies, infrastructure and engineering, network integration and management tools, and technical standards. In most cases, Comcast prefers to have employees on-site collaborating unless the team has been designated as virtual due to the nature of their work. If a position is listed with both office locations and virtual offerings, Comcast may be willing to consider candidates who live greater than 100 miles from the office for the remote option.
Job Summary
WHO WE ARE
Founded in 1963, and headquartered in Philadelphia, Pennsylvania, Comcast Corporation (NASDAQ: CMCSA, CMCSK) is a global media and technology company with two primary businesses: NBCUniversal and Comcast Cable.
NBCUniversal operates 30 news and entertainment cable networks, the NBC and Telemundo broadcast networks, television production operations, television station groups, Universal Pictures, and Universal Parks & Resorts.
Comcast Cable Communications, LLC ("Comcast Cable") is the nation's largest video, highspeed internet, and phone provider to residential and business customers under the XFINITY brand.
Comcast has invested in technology to build a sophisticated network that delivers the fastest broadband speeds, and brings customers personalized video, communications, home management offerings, and business services.
As part of shifting Security to the left, the work that this Team does in assessing and identifying vulnerabilities before an application goes live, helps application owners address and deploy secure applications/ products all across Comcast
Job Description
This role will work primarily in performing offensive security assessments (application, network, mobile, Wi-Fi penetration testing, red teaming, specialty security assessments) and support ongoing offensive operations and infrastructure.
Perform application penetration tests. Application pen tests often include thick client, API, mobile SDK, and web applications from open, and closed box perspectives.
Perform network penetration tests. External, internal, and wifi network penetration testing. Capable of penetrating multiple platforms in enterprise environments.
Contribute towards team tool kit, lab, and attack infrastructure. Become regular contributor to team wiki and git repositories.
Follow primary source cyber security feeds, publications, and articles to remain current on trade craft and vulnerabilities.
Interface with team members and stakeholders with professionalism and an overall positive attitude. A variety of problems will arise and will be dealt with, but senior staff will pro-actively construct solutions.
WHO YOU ARE/ WHAT YOU BRING:
The person that takes this role will first and foremost be deeply technical, able to oversee and execute high quality penetration tests. We believe that there are no "rock stars" or "ninjas" on our team - we collaborate to be the best we can collectively be at breaking into networks and applications.
• Strong spear-phishing skills (both credential harvesting and remote code execution), ability to customize an attack.
• Effective communications - Writing and presenting are a large part of professional penetration testing. Senior penetration testers are expected to excel at communicating with application teams (executive and technical audiences) and be a good communicator within the team while collaborating on projects.
• Ability to train/mentor other Team members in adversary techniques.
• Experience in at least 3 of the following: Use of vulnerability management and Penetration Testing tools such as Burp Suite, Nmap, Metasploit, Nessus, Sqlmap, etc.
• Experience at Senior/Principal level with one or more public cloud platforms: AWS, GCP or Azure.
• Mobile app security testing a plus
• Understanding of the CVSS scoring system.
• Scripting using one or more of the following: Python, Ruby, Bash, C/C++, C#, or Java. Establishing/improving PenTest policies, procedures, exceptions and operations.
• Senior level experience with enterprise penetration testing. Must be strong at network and application testing for this position.
• Seniority with Linux and Windows. Must have strong practical experience in both environments.
• Senior level network experience. IPv4/IPv6, PCAP interpretation and parsing, understanding of all layers of the network stack.
• Strong with pivoting and tunneling to traverse network segments and chains of compromise.
• Leading or participating in cross functional efforts for managing organization wide risks.
• Collecting, analyzing, reporting, and briefing discovered vulnerabilities.
• Experience in penetration testing simulations (e.g., Hack the Box, Capture the Flag)
REQUIRED:
Bachelor's degree, preferably in Computer Science or Information Security or equivalent experience.
7-10 years of related experience either on the job or in demonstrable projects.
WHAT WE BRING:
Competitive package including base, bonus, comprehensive benefits, RSU's, 401k matching, Comcast perks and much more
We also offer a
Cool and casual work environment with chances to showcase your skills.
Team-centric culture of collaboration, innovation, and continuous learning.
Training, support, and mentoring to expand and evolve your expertise.
Opportunity to impact the security of Comcast products.
Employees at all levels are expected to:
- Understand our Operating Principles; make them the guidelines for how you do your job.
- Own the customer experience - think and act in ways that put our customers first, give them seamless digital options at every touchpoint, and make them promoters of our products and services.
- Know your stuff - be enthusiastic learners, users and advocates of our game-changing technology, products and services, especially our digital tools and experiences.
- Win as a team - make big things happen by working together and being open to new ideas.
- Be an active part of the Net Promoter System - a way of working that brings more employee and customer feedback into the company - by joining huddles, making call backs and helping us elevate opportunities to do better for our customers.
- Drive results and growth.
- Respect and promote inclusion & diversity.
- Do what's right for each other, our customers, investors and our communities.
Disclaimer
- This information has been designed to indicate the general nature and level of work performed by employees in this role. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications.
Comcast is an EOE/Veterans/Disabled/LGBT employer.
#2023BENgineersConference
We believe that benefits should connect you to the support you need when it matters most, and should help you care for those who matter most. That's why we provide an array of options, expert guidance and always-on tools that are personalized to meet the needs of your reality-to help support you physically, financially and emotionally through the big milestones and in your everyday life.
Please visit the benefits summary on our careers site for more details.
Education
Bachelor's Degree
While possessing the stated degree is preferred, Comcast also may consider applicants who hold some combination of coursework and experience, or who have extensive related professional experience.
Certifications (if applicable)
Relative Work Experience
10 Years +
Comcast is proud to be an equal opportunity workplace. We will consider all qualified applicants for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other basis protected by applicable law.
Explore More
Date Posted
05/09/2023
Views
10
Neutral
Subjectivity Score: 0.7
Similar Jobs
Director of CCME Program Development - City of Philadelphia
Views in the last 30 days - 0
View DetailsAssistant Director for Avenue of the Arts KinderCare - KinderCare Learning Companies
Views in the last 30 days - 0
View Details