Director, Cyber Security Incident Response Team (CSIRT)
Gaithersburg, MD - USA
Job Summary
Leverage technology toimpactpatients andultimately savelives
Do you haveexpertisein and passionforinformation technology Would you like to apply yourexpertisetoimpactthe IT strategy in a company that followsthe scienceand turns ideas into life changing medicines If so AstraZeneca might be the one for you!
ABOUT ASTRAZENECA
AstraZeneca is a global science-led patient-focused biopharmaceutical company that focuses on the discoverydevelopmentandcommercializationof prescription medicines for some of the worlds most seriousdisease. Butweremore than one of the worlds leading pharmaceutical companies. At AstraZenecawerededicated to being a Great Place to Work.
ABOUT ROLE
TheDirector CSIRTis a seniorindividual contributorleader in theGlobal Cybersecurity Operations Center (GSOC) based in Gaithersburg Maryland reporting to the Head of GSOC. You will command enterprise response to material cyber incidents across cloudonpremises and OT/ICS environments own incident governance and readiness and drive executive reporting lessons learned and control hardening in partnership with Detection Engineering CTI Vulnerability Management Offensive Security IT Legal Risk and Compliance and Physical Security.
WhatYoullDo:
IncidentCommand:Lead execution of the Incident Response (IR) plan to rapidly scopecontain eradicate and investigate incidents across hybrid and OT environments.
IncidentGovernance:Define andmaintainincident categories severity decision authorities activation criteria and crisis management handoffs.
Forensics evidence handling:Coordinate preservation collection and analysis withchainofcustodyrigor;in collaboration with Legalmanageassetlitigation holdandretentionas well as facilitation ofartifact sharing for malware analysis and CTI.
Exercises andreadiness:Run regular tabletop andpurpleteamexercises; ensure 24x7 coverage seamlessfollowthesunhandoffs with Regional SOCs and retainer surge playbooks.
Automation and AI: Operationalize agentic SIEM featuresXDRand SOAR playbooks LLMassistedrunbooks and automated triage packages to reduce MTTD/MTTC/MTTR.
Metrics and reporting: Own IR targets/KRIs (e.g.MTTD MTTC MTTR dwell time business impact) and deliver executiveready briefings dashboards and quarterly lessons learned.
Stakeholder coordination: Orchestrate IR with IT Legal Privacy Risk Comms PhysicalSecurity and Insurance for notification obligations privilege and crisis communications.
ControlsHardening:Drivepostincidentdetection and control improvements with Detection Engineering Identity Cloud Endpoint and OT teams.
Assurance integration: Partner with Vulnerability Management and Offensive Security to prioritize testing and remediation informed by incident findings and CTI.
People Leadership:
Strategy and planning:Developand maintainCSIRT area plans aligned to GSOC strategy; set direction and goals with autonomy.
Performance and tiers:Define and review reporting and team targets; alignobjectivesto incident outcomes and customer experience.
Coverage and oncall:Maintain24x7 oncall rotations surge models and crossregional handoff standards.
Talent and capability:Lead inclusive recruitment; build career paths and targeted upskilling in DFIR cloud identity OT/ICS and automation/SOAR through regional/external partnerships.Provide mentorship to junior CSIRT resources.
Knowledge Experience and Understanding of:
Incident command & IR lifecycle:Proven commandacrosscyberincidentlifecyclesplansandplaybooks.Deep understanding of the incident lifecycle from preparation to scoping containmenteradicationand remediation at enterprise scale.
DFIR evidence handling:Experiencedin managing the collection preservation and analysis of digital evidence and chain of custody; timeline reconstruction; attacker attribution; concise executive reporting.
Attacker tradecraft (MITRE ATT&CK):Deep knowledgeof the attack lifecycle (i.e.MITRE ATT&CK) timeline construction and familiarity with attribution and common threat actor TTPs
Automation & AI:Experience with operationalization of modern security tools (SIEM SOAR XDR) including integration of artificial intelligence large languagemodelsand agentic features to enable triageanalysisand eradication at scale.
Cloud identity and endpoint visibility:Proficiencywith logging prioritization and telemetry from industry standard cloud platforms identity providers operatingsystemsand security tools.
Manufacturing Operational Technology/Industrial Control Systems: Coordinating IR inindustrial/OTenvironments with safety andproduction continuity considerations.
Legal/regulatory & crisis communications:Comfortable building partnerships outside of cyber operations with legal risk & compliance physical security and other business collaborators relevant to incident response.
Retainer and vendor readiness:MaintainingIR retainer partnerreadiness; knowing when to escalate and how to integrate external specialists during major incidents.
MinimumSkills & Experience
Education:Bachelors degree in information security computer science or related field (or equivalent experience).
Enterprise-scale SOC/IR leadership:Overfive (5)years managing Cyber Security Operations CentreIncidentResponse in enterprise-sized organizations commanding events across hybrid cloudonprem and OT.
Global coordination with RegionalSOCs:Experience integrating and working alongside global 24x7 distributed teams to complete incident response and cyber operations missions.
Communication and facilitation:Well developedskills to explain complex technical issues in clear business terms; produce concise written material (executive updates IR reports); and lead briefings.
Analytical decisionmaking: Ability to analyze complex situations assess risk and balance strategic and tactical security requirements with business pragmatism risk appetite and innovation.
Customer orientation andcross-culturalworking:Demonstratedability to collaborate across regions and functions (IT Legal GRC Physical Security) with a strong service outlook.
Preferred Skills & Experience:
Certifications: Security certifications preferred (e.g. CISSP CISM GIAC such as GCIH/GCFA/GREM; CCSP; ITIL).
When we put unexpected teams in the same room we unleash bold thinking with the power to encourage life-changing -person working gives us the platform we need to connect work at pace and challenge perceptions. Thats why we work on average a minimum of three days per week from the office. But that doesnt mean were not flexible. We balance the expectation of being in the office while respecting individual flexibility. Join us in our unique and ambitious world.
The annual base pay for this position ranges from $169320.00 - $253980.00 USD Annual. Hourly and salaried non-exempt employees will also be paid overtime pay when working qualifying overtime hours. Base pay offered may vary depending on multiple individualized factors including market location job-related knowledge skills and addition our positions offer a short-term incentive bonus opportunity; eligibility to participate in our equity-based long-term incentive program (salaried roles) to receive a retirement contribution (hourly roles) and commission payment eligibility (sales roles). Benefits offered included a qualified retirement program 401(k) plan; paid vacation and holidays; paid leaves; and health benefits including medical prescription drug dental and vision coverage in accordance with the terms and conditions of the applicable plans. Additional details of participation in these benefit plans will be provided if an employee receives an offer of employment. If hired employee will be in an at-will position and the Company reserves the right to modify base pay (as well as any other discretionary payment or compensation program) at any time including for reasons related to individual performance Company or individual department/team performance and market factors.
Are you ready to bring new insights and fresh thinking to the tableFantastic! We have one seat available and we hope its yours. Apply today.
AstraZeneca embraces diversity and equality of opportunity. We are committed to building an inclusive and diverse team representing all backgrounds with as wide a range of perspectives as possible and harnessing industry-leading skills. We believe that the more inclusive we are the better our work will be. We welcome and consider applications to join our team from all qualified candidates regardless of their characteristics. We follow all applicable laws and regulations on non-discrimination in employment (and recruitment) as well as work authorization and employment eligibility verification requirements.
WHYJOINUS
Werea network of high-reaching self-starters who contribute to something far bigger. We enable AstraZeneca to perform at its peak by delivering premier technology and data solutions.
Werenot afraid to take ownership and run with it. Empowered with unrivalled freedom. Put simplyitsbecause we make a significant impact. Everything we do matters.
Date Posted
28-May-2026Closing Date
16-Jun-2026Our mission is to build an inclusive environment where equal employment opportunities are available to all applicants and furtherance of that mission we welcome and consider applications from all qualified candidates regardless of their protected characteristics. If you have a disability or special need that requires accommodation please complete the corresponding section in the application form.
Required Experience:
Director
About Company
AstraZeneca is an equal opportunity employer. AstraZeneca will consider all qualified applicants for employment without discrimination on grounds of disability, sex or sexual orientation, pregnancy or maternity leave status, race or national or ethnic origin, age, religion or belief, ... View more