Comcast Cybersecurity: Product Security - Engineer 3
PA - Philadelphia, 1800 Arch St, United States
Comcast
Comcast NBCUniversal creates incredible technology and entertainment that connects millions of people to the moments and experiences that matter most.Job Summary
Comcast is seeking a Product Security Engineer to join its dynamic Bug Bounty team. In this pivotal role, you will collaborate with security researchers and ethical hackers to identify, assess, and remediate vulnerabilities across the organization. You will work closely with product teams to ensure thorough and prompt resolution of security issues, gaining deep technical insights into Comcast's infrastructure and operations.As a key member of the security team, you will leverage your technical expertise and leadership skills to drive the expansion of Comcast's Bug Bounty Program by assessing the overall security maturity and systems architecture of products to launch bug bounty programs.
Your responsibilities will also include conducting web application pen testing, developing vulnerability detection tools and process improvements. The ideal candidate will demonstrate resilience, a passion for continuous learning, and a proactive security mindset, ultimately working to uphold the highest standards of customer trust and safety.
Job Description
Core Responsibilities
- Assess, research, prioritize, and escalate reported vulnerabilities as appropriate, often involving web application testing.
- Identify trends in security research methods and develop tools for proactive vulnerability detection
- Coordinate security incident response and vulnerability management activities with product teams
- Partner with other teams in the security organization to build and test remediation strategies
- Attend technical calls with internal or external parties regarding reported vulnerabilities
- Identify gaps within existing internal security practices and propose enhancements where necessary
- Participate in a weekend rotation that includes your peers on the team
Basic Qualifications -
- Masters or Bachelor's degree in computer science or equivalent
- Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent
- Experience applying threat modeling or other risk identification techniques or equivalent
- 3+ years' experience in web application security and vulnerability management roles
Must-Have Skills:
- Technical background, Linux, Burpsuite, Python, OWASP Top 10, hand-on experience in security projects
- Excellent written and oral communication skills
- Ability to convey technical concepts relating to vulnerability details to a non-technical audience.
Preferred:
- Certifications- OSCP, PNPT, eJPT
- Contributions to the security community (public research, blogging, presentations, bug bounty, etc.)
Skills
Infrastructure Penetration Testing, Penetration Testing, Security ResearchWe believe that benefits should connect you to the support you need when it matters most, and should help you care for those who matter most. That's why we provide an array of options, expert guidance and always-on tools that are personalized to meet the needs of your reality—to help support you physically, financially and emotionally through the big milestones and in your everyday life.
Please visit the benefits summary on our careers site for more details.
Education
Bachelor's DegreeWhile possessing the stated degree is preferred, Comcast also may consider applicants who hold some combination of coursework and experience, or who have extensive related professional experience.Certifications (if applicable)
Relative Work Experience
5-7 YearsComcast is proud to be an equal opportunity workplace. We will consider all qualified applicants for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, disability, veteran status, genetic information, or any other basis protected by applicable law.* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Application security Burp Suite Computer Science Exploits Incident response Linux OSCP OWASP Pentesting Product security Python Vulnerabilities Vulnerability management Web application testing
Perks/benefits: Career development
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.