368,611open jobs
9,439companies
50,719added this week
Browse all
Salary
$163k – $244k per year
Location
In office (Gaithersburg)
Seniority
Architect
Employment
Full-Time
Overview
Company
Impact
Profile match
AstraZeneca is a global, science-led biopharmaceutical giant headquartered at the Cambridge Biomedical Campus in Cambridge, United Kingdom. Formed in 1999 through the merger of Sweden's Astra AB and the UK's Zeneca Group, the company researches, manufactures, and commercializes prescription medicines across core therapeutic areas, including Oncology, Cardiovascular, Renal & Metabolism (CVRM), Respiratory & Immunology, and Rare Diseases.

About AstraZeneca

AstraZeneca is a global, science-led, patient-focused biopharmaceutical company dedicated to discovering, developing, and commercialising prescription medicines for serious disease.We’recommitted to being a Great Place to Work.

About the Role

The Director of Cyber Threat Intelligence will lead a highly technical CTI function withinAstraZeneca’sCybersecurity Operationsdivision, managing a team of analysts to deliver strategic, operational, and tactical intelligence that measurably reduces risk acrossthe enterprise, includingmanufacturing, clinical trial platforms, and R&D environments. This role anchors CTI to “intel-to-action” outcomes, partnering closely with Vulnerability Management, Detection Engineering, and Incident Response to harden controls, prioritize patching, improve detections, and accelerate response.

Key Responsibilities

  • Program Leadership and Strategy: Define CTI vision, operating model, and roadmap aligned toAstraZeneca’s cyber risk reduction strategy, with special emphasis onmanufacturing continuity, clinical data integrity, and R&D IP protection.

  • Adversary Prioritization Framework: Design andoperateascoring rubric that ranks actors based on intent/capability/relevance, TTP emergence and prevalence, organization-specific exposure to known vulnerabilities/CVEs, and global “viral” events,maintainingdynamic watchlists and escalation triggers.

  • MTTI Metric and Analytics: Implement analytic methods to estimate mean time-to-impact per adversary (frominitialaccess to material businessimpact) using internal telemetry, historical incidents, industry reporting, and confidence levels, performingcomparisons with IR’s MTTC to drive control improvements.

  • Attack Path Modeling: Build and maintain end-to-end attack path models from initial access to material impact across IT-to-OT pivots, clinical platforms, and R&D environments,mappingsteps to MITRE ATT&CK (Enterprise/ICS), identify control gaps and choke points, derive detections-as-code and hunt hypotheses, andsupportvalidationefforts includingpurple-team exercises and adversary emulation to ensureenterprisehardening and measurable risk reduction.

  • Dark Web and Closed-Source Monitoring: Establish collection and monitoring across dark web forums, marketplaces, breach dumps, and closed channels to identify emerging TTPs, credential leaks, data exposure, access-broker listings, and targeting of manufacturing, clinical, or R&D assets,integratingvalidated findings into TIP/SIEM pipelines, trigger takedown requests where feasible, and deliver rapid advisories with confidence ratings andspecific actionsfor Vulnerability Management, Detection Engineering, and IR.

  • Third-Party and Ecosystem Intelligence: Deliver risk insights for CROs/CMOs/logistics/technology vendors,monitorcredential leakage and domain spoofing, and support/coordinate takedown operations when needed.

  • Structured Threat Actor Attribution (Diamond Model): Lead disciplined attribution using the Diamond Model (adversary, capability, infrastructure, victim) and complementary frameworks,correlatingTTPs, tooling lineage, code-reuse, infrastructure overlaps, and victimology with confidence levels and analytic caveats,documentinghypotheses, alternative explanations, and disconfirming evidence, andproducingreusable actor profiles and pivot paths that inform prioritization, detections, hunts, and incident response playbooks.

  • Support Vulnerability Management: Partner with Vulnerability Management to contextualize CVEs (exploitability, weaponization, external scanning telemetry, compensating controls) and deliver risk-based patching prioritization across AstraZeneca’s estate including IT/OT, clinical platforms, and lab environments.

  • SupportDetection Engineering: Develop detection use cases to feed our detection-as-code pipeline and support detection ATT&CK coverage mapping, content tuning, and false-positive reduction, ensuring feedback loops from hunts and incidents continuously improve detection quality.

  • Support GSOC/Incident Response: Provide real-time adversary context that is highly technical including kill-chain reconstruction, containment recommendations, and countermeasures, producing post-incident intelligence retrospectives and detection/architecture improvements.

  • Operationaland Executive Reporting: Producedaily threat intelligence highlights,threatactor/campaign profiles,quarterly threat briefings,andother ad hoc intelligence products, ensuring products includequantified risk narratives for senior leadershipthat alsoalignfindings to regulatory expectations and business impact.

  • Tooling and Automation:Optimizeintegrations across TIP, SIEM, EDR, case management, and telemetry; manage indicator lifecycle, automate enrichment, and measure source fidelity/bias.

  • External Engagement: Lead participation with sector bodies (e.g., H-ISAC), peer sharing groups, and government/industry partners; track and assess global events and rapidly translate into actionable enterprise guidance.

  • Team Leadership and Development: Recruit, mentor, and grow a diverse team of CTI analysts; build career paths, training plans, and knowledge-sharing practices; foster a culture of technical excellence and clear, actionable communication.

Minimum Qualifications

  • Leadership and Strategic Impact: 10+ years in cyber threat intelligence, detection engineering, incident response, or related domains; 5+ years leading technical CTI teams in global enterprises. Demonstrated ability to set vision, influence strategy, and deliver outcomes tied to enterprise risk reduction.

  • Decision Making and Accountability: Proven ownership of adversary-centric CTI programs that directly drive vulnerability prioritization, detections-as-code, hunts, and incident response. Comfortable making data-driven decisions with clear trade-offs and confidence levels.

  • Technical Depth (ATT&CK Enterprise/ICS): Deepexpertisemapping TTPs to MITRE ATT&CK, defining coverage strategies, and translating gaps into high-fidelity detections and hunt hypotheses; skilled in industrial/OT contexts.

  • Attack Path Modeling and Risk Translation: Hands-on delivery of end-to-end attack paths across IT-to-OT pivots, clinical platforms, and R&D environments; validation via purple-team/adversary emulation; ability to convert findings into prioritized control roadmaps and measurable risk reduction.

  • Adversary Prioritization and Scoring: Designed andoperatedtailored actor scoring incorporating intent/capability, TTP emergence/prevalence, org exposure to CVEs, and global/viral events;maintaineddynamic watchlists and escalation triggers.

  • Structured Attribution Tradecraft: Applied the Diamond Model and complementary frameworks with documented hypotheses, caveats, disconfirming evidence, and confidence statements; produced reusable actor profiles and pivot paths.

  • Metrication (MTTI vs. MTTC): Built mean time-to-impact metrics per actor and operationalized comparisons to IR's mean time-to-containment to guide control improvements and track program effectiveness.

  • Vulnerability Intelligence for Hardening: Delivered contextual CVE analysis (exploitability, weaponization, external scanning telemetry, compensating controls) and risk-based patch recommendations across IT, OT/ICS, clinical, and lab environments.

  • Detection Engineering Collaboration: Co-developed detections-as-code (e.g., Sigma, KQL, SPL), tuned content to reduce false positives, and closed ATT&CK coverage gaps with feedback loops from hunts/incidents.

  • Incident Intelligence Support: Provided real-time adversary context, kill-chain reconstruction, containment recommendations, and post-incident retrospectives that inform detection and architectural improvements.

  • Collection, Tooling, and Automation: Operated dark web/closed-source monitoring; integrated findings into TIP/SIEM/EDR pipelines; managed indicator lifecycle, automated enrichment, and measured source fidelity/bias.

  • Stakeholder Partnership and Communication: Clear, concise communication of complex technical intelligence to executives and cross-functional partners (Vulnerability Management, Detection Engineering, SOC/IR, OT Security, Clinical Ops, Research IT); ability to influence without authority.

  • Education: Bachelor's degree in a relevant field (Computer Science, Information Security, Intelligence Studies, or equivalent experience).

Preferred Qualifications

  • Sector Experience and Regulatory Context: Experience in pharmaceuticals, life sciences, healthcare, or manufacturing; familiarity with GMP/CSV, clinical data obligations, and R&D IP protection.

  • OT/ICS and Critical Operations: Hands-on work with MES, SCADA, PLC ecosystems; ATT&CK for ICS usage; understanding of OT-safe response practices and production continuity implications.

  • Clinical/R&D Platforms: Exposure to CTMS, EDC, IRT, ELN, LIMS, HPC, and data lake environments; experience safeguarding data integrity and sensitive research/IP.

  • Program Metrics and Outcomes: Built dashboards tracking MTTI by actor, ATT&CK coverage indices, intel-informed patch SLAs, hunter ROI, and executive risk narratives; experiencepresenting tosenior leadership and risk committees.

  • Advanced Tooling/Automation: TIP administration, SIEM/EDR content engineering, enrichment/orchestration pipelines, case management integration, and indicator lifecycle automation at enterprise scale.

  • Threat Modeling and Quantification: Ability to translate attack paths into quantified risk scenarios and prioritized control investments aligned to businessobjectivesand crown jewels.

  • External Partnerships: Active engagement with H-ISAC/ISAOs and government/industry partners;track recordof rapidly converting global/viral cyber events into enterprise defenses and executive guidance.

  • Certifications: One ormore ofGCTI, GREM, GRID, GCIH, CISSP, or equivalentdemonstratedexpertise.

  • People Leadership: Built diverse, high-performing teams; established career paths, coaching frameworks, and a culture of analytic rigor, technical excellence, and continuous improvement.

All roles in IT are expected to demonstrate a mindset of embracing, adopting and appropriately using AI and digital tools in day-to-day work to improve outcomes and ways of working.

Location

  • Gaithersburg, Maryland.

Office Working Requirements

When we put unexpected teams in the same room, we unleash bold thinking with the power to inspire life-changing medicines. In-person working gives us the platform we need to connect, work at pace and challenge perceptions. That’s why we work, on average, a minimum of three days per week from the office. But that doesn’t mean we’re not flexible. We balance the expectation of being in the office while respecting individual flexibility. Join us in our unique and ambitious world.

The annual base pay for this position ranges from $162.536,00- $243.804,00USD Our positions offer eligibility for various incentives-an opportunity to receive short-term incentive bonuses, equity-based awards for salaried roles and commissions for sales roles. Benefits offered include qualified retirement programs, paid time off (i.e., vacation, holiday, and leaves), as well as health, dental, and vision coverage in accordance with the terms of the applicable plans.

Date Posted

25-ago-2026

Closing Date

13-sept-2026

Our mission is to build an inclusive environment where equal employment opportunities are available to all applicants and employees. In furtherance of that mission, we welcome and consider applications from all qualified candidates, regardless of their protected characteristics. If you have a disability or special need that requires accommodation, please complete the corresponding section in the application form.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,611 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Gaithersburg
$26k – $64k per year (Estimated) • In office • Full-Time • 12+ years exp • Bachelor's Degree • Hyderabad
DevOps
AWS
Azure
GCP
Cybersecurity
Cyber Kill Chain
Diamond Model
MITRE ATT&CK
Apply
$90k – $184k per year (Estimated) • Equity • Remote • Full-Time • 3+ years exp • United States
AI/ML
Red Teaming
Cybersecurity
Burp Suite
Cobalt Strike
Crowdstrike
Metasploit
MITRE ATT&CK
Nessus
Nmap
Apply
$152k per year • Equity • Remote • 8+ years exp
Lua
Python
Ruby
Rust
YARA
Databases
ElasticSearch
DevOps
Amazon ECS
Splunk
Cybersecurity
Cyber Kill Chain
Scapy
Snort
Suricata
Tcpdump
Wireshark
YARA
Zeek
Apply
Cybersecurity Manager 5 hours ago
$113k – $227k per year • In office • Full-Time • 10+ years exp • Bachelor's Degree • Lake Forest • Saint Paul • Chicago
Cybersecurity
CVSS
FedRAMP
GDPR
ISO 27001
MITRE ATT&CK
SOC 2
Apply
$60k – $149k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Ottobrunn • Ulm
Python
AI/ML
Red Teaming
Cybersecurity
MITRE ATT&CK
Apply
$35k – $79k per year (Estimated) • In office • Full-Time • 12+ years exp • Mumbai
Management
ServiceNow
Apply
$22k – $51k per year (Estimated) • Remote/Hybrid • Full-Time • Bengaluru
Analytics
Power BI
Management
Power Apps
Apply
$58k – $139k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Guadalajara
Python
AI/ML
Knowledge Graph
Kubeflow
Apply
$6k – $33k per year (Estimated) • In office • Full-Time • 3+ years exp • Chennai
PowerShell
SQL
C#
C#
.NET
Databases
Oracle
AI/ML
Anomaly Detection
DevOps
AWS
Azure
Azure DevOps
CI/CD
Docker
Grafana
Jenkins
Kubernetes
Nagios
Windows Server
Amazon CloudWatch
GitHub
GitLab
Management
Power Automate
ServiceNow
Apply
$72k – $154k per year (Estimated) • In office • Full-Time • Barcelona
Databases
Databricks
Snowflake
DevOps
AWS
Azure
Apply
Software Developer 1 day ago
$87k – $157k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • Gaithersburg
Bash
Python
DevOps
Ansible
CI/CD
Configuration Management
Docker
Git
KVM
Podman
Red Hat
VMWare
Apply
Software Developer 1 day ago
$70k – $126k per year • In office • Full-Time • 2+ years exp • Bachelor's Degree • Gaithersburg
Bash
Python
DevOps
Ansible
CI/CD
Configuration Management
Docker
Git
KVM
Podman
Red Hat
VMWare
Apply
$108k – $195k per year • In office • Full-Time • 8+ years exp • Bachelor's Degree • Gaithersburg
DevOps
AWS
Azure
CI/CD
Docker
Kubernetes
Rest API
Management
Confluence
Jira
Apply
$87k – $157k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • Gaithersburg
JavaScript
TypeScript
Frontend
Angular
React.js
DevOps
CI/CD
Grafana
Rest API
Design
Adobe XD
Figma
Sketch
Apply
$145k – $217k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • Gaithersburg
C++
Python
Rust
C++
PyTorch C++
TensorFlow C++
Databases
OpenSearch
AI/ML
AI Agents
AWS Bedrock
CrewAI
CUDA
CUDA Toolkit
Explainable AI
Few-Shot Learning
Google ADK
LangChain
LlamaIndex
LLM
Multimodal AI
NLP
Prompt Engineering
PyTorch
Reinforcement Learning
TensorFlow
Amazon SageMaker
Function Calling
DevOps
Amazon EKS
AWS
Kubernetes
Amazon ECS
Apply
See all jobs
This is one of many
368,611 more open roles from verified company boards, updated every day.