Cyber Incident Response Triage Analyst
Job Description
Join a high-volume SOC environment where you will monitor security signals, investigate real incidents, and close cases with strong documentation and SLA discipline. This hybrid role in Philadelphia, PA supports 24x7 operations, with nights, weekends, or on-call rotations as needed. You will own the incident lifecycle from intake through closure, applying analytical judgment to separate benign activity and false positives from true threats, while contributing to detection tuning and response process improvements.
What you will do
- Monitor security tools and platforms for alerts, suspicious activity, and potential threats
- Triage, investigate, and resolve a high volume of security events and incidents
- Independently open, manage, and close incidents with accurate classification and documentation aligned to SLA requirements
- Perform deeper analysis beyond entry-level triage, including event correlation and alert enrichment
- Determine alert validity, impact, and appropriate response actions
- Execute containment, eradication, and recovery steps using established playbooks
- Identify intrusion methods, affected systems, and potential scope during investigations
- Escalate complex, ambiguous, or high-risk incidents to senior analysts as appropriate
- Maintain working knowledge of common threats, vulnerabilities, attack techniques, and adversary behaviors
- Identify false positives and recommend opportunities for detection tuning and process improvement
- Assist with audits, reporting, and investigative support activities
- Prepare clear and concise incident documentation and summaries for operational tracking and reporting
- Participate in After Action Reviews (AARs) and contribute to response and process improvements
- Follow standard operating procedures, playbooks, and escalation paths
- Operate effectively in a high-volume incident handling environment and maintain consistent case accuracy
Tools and technologies you will work with
- SIEM, SOAR, EDR
- Python, PowerShell
- LLMs, AI agents, GPT, Claude, Anthropic
What you bring
- 2–4 years of experience in cybersecurity, SOC, or incident response
- Experience monitoring and responding to security alerts in a production environment
- Familiarity with SIEM, SOAR, EDR, and related security tools
- Understanding of networking fundamentals, operating systems, and common security controls
- Knowledge of common attack techniques, including phishing, malware, credential abuse, and lateral movement
- Strong analytical, problem-solving, and decision-making skills
- Basic knowledge of AI fundamentals, including LLMs, AI agents, skills, and differences between leading AI models and platforms such as GPT, Claude, and Anthropic
Preferred qualifications
- Experience working in a 24x7 SOC or Incident Response environment
- Familiarity with threat intelligence platforms and alert enrichment processes
- Exposure to scripting or automation (Python, PowerShell)
- Experience supporting audits or compliance-driven environments
- Knowledge aligned to incident response frameworks (including NIST lifecycle concepts)
Eligibility and notice
This position is ineligible for visa sponsorship. To be considered, you must be legally authorized to work in the United States and not require sponsorship for employment now or in the future.
Education
Bachelor’s Degree. Possessing the stated degree is preferred, and Comcast may also consider applicants with some combination of coursework and experience, or extensive related professional experience.
Compensation
National Pay Range: $59,512.60 USD - $139,482.65 USD
Additional pay ranges vary by location (including IL, CO, HI, DC, MD, MN, NY, WA, NJ, VT, MA, VA, ME, CT, and CA).
EEO statement: Comcast is an EOE/Veterans/Disabled/LGBT employer.