570,882open jobs
23,625companies
78,041added this week
Browse all
Salary
$183k – $341k per year (Estimated)
Location
In office (Gaithersburg)
Seniority
Senior · 10+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
AstraZeneca is a British-Swedish pharmaceutical company formed in 1999 by the merger of Astra of Sweden and Zeneca of the United Kingdom, and now one of the largest drug makers in the world by revenue. Its portfolio is concentrated in oncology with Tagrisso, Imfinzi and Enhertu, alongside cardiovascular, renal and metabolic products including Farxiga, respiratory and immunology medicines, and a rare disease business built on the acquisition of Alexion. Headquartered in Cambridge in England and listed in London, Stockholm and New York, it reports in United States dollars.

Senior Director, Cyber Exposure Management

Introduction to role:

Are you ready to turn exposure data into decisive action that protects the science, manufacturing and digital platforms patients rely on every day? Based in Gaithersburg, Maryland, you will own our enterprise understanding of vulnerabilities and weaknesses-and drive closure before an attacker finds them. You will lead three complementary capabilities: Vulnerability Management, Application Security and Penetration Testing/Red Team, operating between builders and defenders to ensure our technology and platforms are resilient when it matters most.

This is a build-and-uplift mandate. You will move us from scan-and-ticket to modern, risk-based exposure management; stand up application security as a true assurance function; and evolve offensive testing into a continuous, intelligence-led capability. How would you partner across engineering, cloud, product and operations to prioritize real-world risk at machine speed and validate that our defenses work when it counts?

Accountabilities:

Unified Exposure Strategy: Own and deliver a multi-year strategy across Vulnerability Management, Application Security and Penetration Testing, with clear roadmaps, budgets and capability plans; set direction with a high degree of autonomy.

Risk-Based Vulnerability Management: Evolve from volume-based scanning to prioritized exposure management using asset criticality, exploitability and threat intelligence; implement enterprise remediation governance and SLAs.

Attack Surface and Exposure Visibility: Maintain continuous visibility of internal and external attack surfaces-including cloud, SaaS and third-party exposure-and focus effort where real-world risk is highest.

Application Security Assurance: Run a secure development assurance program covering SAST, DAST and SCA; drive developer enablement and behaviors for software we build and buy.

Software Supply Chain Governance: Oversee software composition risk, SBOM practices and rapid response to widely exploited components; guide investment and policy.

Continuous Offensive Testing: Operate a continuous program of penetration testing and adversary emulation across applications, infrastructure, cloud and OT; run purple-team exercises with Threat Management to harden detection and response.

AI-Era Exposure Readiness: Prepare for machine-speed exploit generation by automating discovery, prioritization and validation; assess the security of AI and large language model systems.

Remediation Through Partners: Drive fixes through accountable asset owners; escalate and govern risk acceptance; keep the reporting honest and defensible.

Metrics and Executive Reporting: Own exposure KRIs-mean time to remediate, SLA attainment, recurrence, coverage, critical exposure ageing-and report credibly to senior leadership and risk committees.

Assurance Integration: Feed findings from offensive testing and cyber intelligence into prioritization; incorporate incident learnings so testing reflects how we are actually being attacked.

Executive Communication and Influence: Translate technical exposure into business risk the CISO, IT leadership and the Board can act on; defend prioritization decisions under scrutiny.

Build and Uplift the Function: Lead and uplift a multi-disciplinary team of roughly eighteen across regions; raise posture from operational scanning to strategic exposure management while preserving independence and integrity.

Lead Through Leaders: Manage the leaders of Vulnerability Management, Application Security and Penetration Testing; set objectives, review performance and build succession.

Talent, Culture and Capability: Recruit inclusively; develop career paths and upskilling in exposure management, cloud and application security, offensive testing and automation; leverage regional and external partnerships.

Budget and Tooling Ownership: Own budgets for scanning, application security and offensive tooling and specialist partners; build the investment cases that maximize business risk reduction.

Essential Skills/Experience:

  • Risk-based vulnerability management: Prioritization using asset criticality, exploitability and intelligence; remediation governance and SLA management at enterprise scale.
  • Application security: Secure SDLC, SAST/DAST/SCA, threat modelling, API and cloud-native application security, and developer enablement that changes behavior rather than just reporting findings.
  • Offensive security: Penetration testing and adversary emulation across applications, infrastructure, cloud and OT, and the use of purple teaming to improve detection.
  • Attack surface and cloud: External and internal attack surface management across cloud, SaaS and third-party exposure.
  • Software supply chain: Open-source and third-party component risk, SBOM practice and rapid response to widely exploited components.
  • AI-era exploitation: How machine-speed vulnerability discovery and weaponization change prioritization, and the security considerations of the organization’s own AI systems.
  • Regulated and OT context: Exposure management in GxP and OT/ICS environments where patching and testing are constrained by validation, safety and uptime.
  • Remediation through others: Driving fixes through asset-owning teams, governing risk acceptance and keeping reporting defensible.
  • Education: Bachelor's degree or equivalent experience in information security, computer science or a related field, or equivalent practical experience.
  • Depth: Ten or more years in cybersecurity, including significant experience across vulnerability, application or offensive security.
  • Leadership scale: Five or more years leading exposure, application security or offensive functions in a large enterprise, including at least two years managing other people leaders.
  • Program credibility: Demonstrable record of maturing a vulnerability or application security program and measurably reducing risk.
  • Cross-functional delivery: Proven track record to drive remediation through teams you do not control, across IT, Cloud, Engineering and business units.
  • Communication and facilitation: Ability to explain exposure and prioritization in clear business terms and to brief senior executives and risk committees.
  • Analytical decision making: Ability to prioritize finite remediation capacity against real-world risk and business pragmatism.
  • Global coordination: Experience leading distributed teams across multiple regions and cultures.

Desirable Skills/Experience:

Certifications: CISSP, CISM, OSCP, GIAC (GWAPT, GPEN, GXPN, GCPN) or equivalent.

Sector experience: Pharmaceutical, life sciences, healthcare or another highly regulated industry with manufacturing OT exposure.

Board exposure: Experience briefing an audit committee, board or risk committee on exposure and remediation.

Commercial: Experience selecting and governing scanning, application security and offensive tooling and specialist testing partners.

Language: Working proficiency in a second language relevant to our delivery hubs.

When we put unexpected teams in the same room, we unleash bold thinking with the power to inspire life-changing medicines. In-person working gives us the platform we need to connect, work at pace and challenge perceptions. That's why we work, on average, a minimum of three days per week from the office. But that doesn't mean we're not flexible. We balance the expectation of being in the office while respecting individual flexibility. Join us in our unique and ambitious world.

Why AstraZeneca:

Here, technology and data power scientific discovery and the delivery of life-changing medicines to patients worldwide. You will join at a pivotal moment as we scale a modern, digital enterprise-one that pairs pioneering platforms with a culture that values curiosity, kindness and ambition in equal measure. Expect the room, the resources and the partnerships to move fast: from collaborating with diverse experts to experimenting with new approaches, learning every day and turning bold ideas into impact at global scale. Your leadership will directly shape how we protect critical research, manufacturing and supply so our teams can focus on transforming patient outcomes.

If you are ready to build a modern exposure program that measurably reduces risk and safeguards vital science, step forward and show us how you will lead this mission now!

Date Posted

11-Sept-2026

Closing Date

25-Sept-2026

Our mission is to build an inclusive environment where equal employment opportunities are available to all applicants and employees. In furtherance of that mission, we welcome and consider applications from all qualified candidates, regardless of their protected characteristics. If you have a disability or special need that requires accommodation, please complete the corresponding section in the application form.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
570,882 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Gaithersburg
$20k – $45k per year (Estimated) • In office • Full-Time • 5+ years exp • Bengaluru • Tlaquepaque
DevOps
SLI/SLO/SLA
Analytics
Power BI
Microsoft Excel
Management
Agile
Apply
$95k – $190k per year (Estimated) • In office • Full-Time • 6+ years exp • Bachelor's Degree • Durham
DevOps
SLI/SLO/SLA
Analytics
Power BI
Apply
Remote/Hybrid • Full-Time • Bachelor's Degree • Bengaluru
AI/ML
AI Agents
Edge AI
DevOps
Azure
SLI/SLO/SLA
Analytics
Tableau
Power BI
Master Data Management
Apply
$23k – $48k per year (Estimated) • Remote/Hybrid • Full-Time • Bachelor's Degree • Bucharest
AI/ML
AI Agents
Edge AI
DevOps
SLI/SLO/SLA
Apply
$64k – $172k per year (Estimated) • In office • Full-Time • United Kingdom
DevOps
SLI/SLO/SLA
Apply
$23k – $57k per year (Estimated) • In office • Full-Time • 2+ years exp • Bachelor's Degree • Hanoi
Apply
$23k – $57k per year (Estimated) • In office • Full-Time • 2+ years exp • Bachelor's Degree • Hanoi
Apply
MR-RB&I-武汉 2 hours ago
In office • Full-Time • Bachelor's Degree • China
Apply
$81k – $161k per year (Estimated) • In office • Contractor • 5+ years exp • Hamburg
Management
Agile
Apply
Financial Accountant 2 hours ago
$56k – $136k per year (Estimated) • Remote/Hybrid • Full-Time • Bachelor's Degree • Amsterdam
Apply
$175k – $262k per year • In office • Full-Time • Bachelor's Degree • Gaithersburg
Apply
In office • Full-Time • Gaithersburg
Apply
$166k – $249k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • Gaithersburg
Apply
$127k – $167k per year • Remote/Hybrid • Full-Time • 5+ years exp • Gaithersburg
JavaScript
Java
TypeScript
Node JS
AI/ML
AI Agents
Frontend
GraphQL
React.js
Mobile
React Native
DevOps
Azure DevOps
CI/CD
Git
Incident Management
Design
Figma
Management
Scrum
QA
Jest
Apply
$232k – $348k per year • In office • Full-Time • 10+ years exp • Bachelor's Degree • Gaithersburg
Apply
See all jobs
This is one of many
570,882 more open roles from verified company boards, updated every day.