Leverage technology toĀ impactĀ patients andĀ ultimately saveĀ livesĀ
Do you haveĀ expertiseĀ in, and passionĀ for,Ā information technology? Would you like to apply yourĀ expertiseĀ toĀ impactĀ the IT strategy in a company that followsĀ the scienceĀ and turns ideas into life changing medicines? If so, AstraZeneca might be the one for you!Ā
ABOUT ASTRAZENECA
AstraZeneca is a global, science-led, patient-focused biopharmaceutical company that focuses on the discovery,Ā developmentĀ andĀ commercializationĀ of prescription medicines for some of the worldās most seriousĀ disease. ButĀ weāreĀ more than one of the worldās leading pharmaceutical companies. At AstraZenecaĀ weāreĀ dedicated to being a Great Place to Work.Ā
ABOUT ROLE
TheāÆDirector, CSIRTāÆis a seniorĀ individual contributorĀ leader in theāÆGlobal Cybersecurity Operations Center (GSOC), based in Gaithersburg, Maryland, reporting to the Head of GSOC. You will command enterprise response to material cyber incidents across cloud,Ā onāpremises, and OT/ICS environments, own incident governance and readiness, and drive executive reporting, lessons learned, and control hardening in partnership with Detection Engineering, CTI, Vulnerability Management, Offensive Security, IT, Legal, Risk and Compliance, and Physical Security.
WhatĀ YouāllĀ Do:
IncidentĀ Command:Ā Lead execution of the Incident Response (IR) plan to rapidly scope,Ā contain, eradicate, and investigate incidents across hybrid and OT environments.Ā
IncidentĀ Governance:Ā Define andĀ maintainĀ incident categories, severity, decision authorities, activation criteria, and crisis management handoffs.Ā
Forensics evidence handling:Ā Coordinate preservation, collection, and analysis withĀ chaināofācustodyĀ rigor;Ā in collaboration with Legal,Ā manageĀ assetĀ litigation holdĀ andĀ retentionĀ as well as facilitation ofĀ artifact sharing for malware analysis and CTI.Ā
Exercises andĀ readiness:Ā Run regular tabletop andĀ purpleāteamĀ exercises; ensure 24x7 coverage, seamlessĀ followātheāsunĀ handoffs with Regional SOCs, and retainer surge playbooks.Ā
Automation and AI: Operationalize agentic SIEM features,Ā XDRĀ and SOAR playbooks, LLMāassistedĀ runbooks, and automated triage packages to reduce MTTD/MTTC/MTTR.Ā
Metrics and reporting: Own IR targets/KRIs (e.g.,Ā MTTD, MTTC, MTTR, dwell time, business impact) and deliver executiveāready briefings, dashboards, and quarterly lessons learned.Ā
Stakeholder coordination: Orchestrate IR with IT, Legal, Privacy, Risk, Comms, PhysicalĀ Security, and Insurance for notification obligations, privilege, and crisis communications.Ā
ControlsĀ Hardening:Ā DriveĀ postāincidentĀ detection and control improvements with Detection Engineering, Identity, Cloud, Endpoint, and OT teams.Ā
Assurance integration: Partner with Vulnerability Management and Offensive Security to prioritize testing and remediation informed by incident findings and CTI.Ā
Ā
People Leadership:
Strategy and planning:Ā DevelopĀ and maintainĀ CSIRT area plans aligned to GSOC strategy; set direction and goals with autonomy.Ā
Performance and tiers:Ā Define and review reporting and team targets; alignĀ objectivesĀ to incident outcomes and customer experience.Ā
Coverage and onācall:Ā MaintainĀ 24x7 onācall rotations, surge models, and crossāregional handoff standards.Ā
Talent and capability:Ā Lead inclusive recruitment; build career paths and targeted upskilling in DFIR, cloud identity, OT/ICS, and automation/SOAR through regional/external partnerships.Ā Provide mentorship to junior CSIRT resources.Ā
Ā
Knowledge, Experience, and Understanding of:
Incident command & IR lifecycle:āÆProven commandāÆacrossĀ cyberĀ incidentĀ lifecycles,Ā plansĀ andĀ playbooks.Ā Deep understanding of the incident lifecycle, from preparation to scoping, containment,Ā eradicationĀ and remediation at enterprise scale.Ā
DFIR evidence handling:āÆExperiencedĀ in managing the collection, preservation and analysis of digital evidence and chain of custody; timeline reconstruction; attacker attribution; concise executive reporting.Ā
Attacker tradecraft (MITRE ATT&CK):Ā Deep knowledgeĀ of the attack lifecycle (i.e.Ā MITRE ATT&CK), timeline construction and familiarity with attribution and common threat actor TTPsĀ
Automation & AI:Ā Experience with operationalization of modern security tools (SIEM, SOAR, XDR) including integration of artificial intelligence, large languageĀ modelsĀ and agentic features to enable triage,Ā analysisĀ and eradication at scale.Ā
Cloud, identity, and endpoint visibility:Ā ProficiencyĀ with logging prioritization and telemetry from industry standard cloud platforms, identity providers, operatingĀ systemsĀ and security tools.Ā
Manufacturing Operational Technology/Industrial Control Systems: Coordinating IR ināÆindustrial/OTāÆenvironments with safety andĀ production continuity considerations.Ā
Legal/regulatory & crisis communications:Ā Comfortable building partnerships outside of cyber operations with legal, risk & compliance, physical security and other business collaborators relevant to incident response.Ā
Retainer and vendor readiness:Ā MaintainingāÆIR retainer partnerāÆreadiness; knowing when to escalate and how to integrate external specialists during major incidents.Ā
Ā
MinimumĀ Skills & ExperienceĀ RequiredĀ
Education:Ā Bachelorās degree in information security, computer science, or related field (or equivalent experience).Ā
Enterprise-scale SOC/IR leadership:Ā OverĀ five (5)Ā years managing Cyber Security Operations CentreĀ IncidentĀ Response in enterprise-sized organizations, commanding events across hybrid cloud,Ā onprem, and OT.Ā
Global coordination with RegionalĀ SOCs:Ā Experience integrating and working alongside global, 24x7, distributed teams to complete incident response and cyber operations missions.Ā
Communication and facilitation:Ā Well developedĀ skills to explain complex technical issues in clear business terms; produce concise written material (executive updates, IR reports); and lead briefings.Ā
Analytical decisionĀ making: Ability to analyze complex situations, assess risk, and balance strategic and tactical security requirements with business pragmatism, risk appetite, and innovation.Ā
Customer orientation andĀ cross-culturalĀ working:Ā DemonstratedĀ ability to collaborate across regions and functions (IT, Legal, GRC, Physical Security) with a strong service outlook.Ā
Preferred Skills & Experience:
Certifications: Security certifications preferred (e.g., CISSP, CISM, GIAC such as GCIH/GCFA/GREM; CCSP; ITIL).Ā
Ā
When we put unexpected teams in the same room, we unleash bold thinking with the power to encourage life-changing medicines. In-person working gives us the platform we need to connect, work at pace and challenge perceptions. That's why we work, on average, a minimum of three days per week from the office. But that doesn't mean we're not flexible. We balance the expectation of being in the office while respecting individual flexibility. Join us in our unique and ambitious world.
The annual base pay for this position ranges from $169,320.00 - $253,980.00 USD Annual. Hourly and salaried non-exempt employees will also be paid overtime pay when working qualifying overtime hours. Base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. In addition, our positions offer a short-term incentive bonus opportunity; eligibility to participate in our equity-based long-term incentive program (salaried roles), to receive a retirement contribution (hourly roles), and commission payment eligibility (sales roles). Benefits offered included a qualified retirement program [401(k) plan]; paid vacation and holidays; paid leaves; and, health benefits including medical, prescription drug, dental, and vision coverage in accordance with the terms and conditions of the applicable plans. Additional details of participation in these benefit plans will be provided if an employee receives an offer of employment. If hired, employee will be in an āat-will positionā and the Company reserves the right to modify base pay (as well as any other discretionary payment or compensation program) at any time, including for reasons related to individual performance, Company or individual department/team performance, and market factors.
Are you ready to bring new insights and fresh thinking to the table?Ā Fantastic! We have one seat available, and we hope itās yours. Apply today.
AstraZeneca embraces diversity and equality of opportunity. We are committed to building an inclusive and diverse team representing all backgrounds, with as wide a range of perspectives as possible, and harnessing industry-leading skills. We believe that the more inclusive we are, the better our work will be. We welcome and consider applications to join our team from all qualified candidates, regardless of their characteristics. We follow all applicable laws and regulations on non-discrimination in employment (and recruitment), as well as work authorization and employment eligibility verification requirements.
WHYĀ JOINĀ US ?Ā
WeāreĀ a network of high-reaching self-starters who contribute to something far bigger. We enable AstraZeneca to perform at its peak by delivering premier technology and data solutions.Ā
WeāreĀ not afraid to take ownership and run with it. Empowered with unrivalled freedom. Put simply,Ā itāsĀ because we make a significant impact. Everything we do matters.Ā
Date Posted
05-Aug-2026Closing Date
18-Aug-2026Our mission is to build an inclusive environment where equal employment opportunities are available to all applicants and employees. In furtherance of that mission, we welcome and consider applications from all qualified candidates, regardless of their protected characteristics. If you have a disability or special need that requires accommodation, please complete the corresponding section in the application form.
Learn more about this Employer on their Career Site
