ForgeApply
Try it free

ForgeApply · Job listing

Director, Cyber Security Detection Engineering

AstraZeneca

MD, Gaithersburg, US$169k – $254konsite

Tailor your resume to this posting in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for AstraZeneca's site. Free trial, no card required.

About this role

Leverage technology to   impact   patients and   ultimately save   lives

Do you have   expertise   in, and passion   for,   information technology ? Would you like to apply your   expertise   to   impact   the IT strategy in a company that follows   the   science   and turns ideas into life changing medicines? If so, AstraZeneca might be the one for you!  

ABOUT ASTRAZENECA  

AstraZeneca is a global, science-led, patient-focused biopharmaceutical company that focuses on the discovery,   development   and   commercialization   of prescription medicines for some of the world’s most serious   disease .

But   we’re   more than one of the world’s leading pharmaceutical companies. At AstraZeneca, we're   dedicated to being a Great Place to Work.  

ABOUT ROLE:

The Director, Cyber Security Detection Engineering   is a senior leader in the Cyber Operations function, based in Gaithersburg, Maryland, working with the Head of   Cyber Operations . The role encompasses command of enterprise detection capabilities across cloud, on-premises, and OT/ICS environments, ownership of detection governance and validation, and delivery of executive reporting, coverage assessments, and capability maturation in partnership with   GSOC , CTI, Vulnerability Management, Offensive Security, IT, Legal, Risk and Compliance, and business customers.  

What You'll Do:

• Detection strategy and roadmap : Direct the development and execution of comprehensive detection engineering programmes aligned to interpersonal risk appetite and threat landscape;   establish   capability roadmaps spanning data engineering, detection development, purple teaming, and automation/AI.  

• Data engineering oversight : Ensure robust data pipelines support detection activities through telemetry collection, normali z ation, and quality assurance across hybrid and OT environments; define data retention, schema standards, and platform configuration to enable effective threat detection.  

• Detection content development : Oversee creation, testing, and deployment of detection logic across SIEM, EDR, and cloud-native tooling; enforce detection standards, naming conventions, and MITRE ATT&CK mapping; prioritise coverage based on threat intelligence and risk assessments.  

• Purple   T eam   Exercising :   Oversee   purple team operations to   validate   detection efficacy systematically; orchestrate adversary emulation exercises across technology domains; drive remediation of detection gaps   identified   through testing and operational feedback.  

• Automation and AI integration : Operationalise AI agents, machine learning models, and orchestration workflows to enhance detection accuracy, reduce false positives, and augment GSOC analyst capabilities; oversee development of automated enrichment, triage, and investigation playbooks.  

• Metrics and reporting : Own detection engineering targets (e.g., MITRE ATT&CK coverage,   mean time to detect , false positive rates, purple team success metrics) and deliver executive-ready briefings, dashboards, and quarterly maturity assessments.  

• Policy and governance : Develop and enforce detection engineering policies, standards, and quality frameworks;   maintain   detection content libraries with version control and organizational change field; ensure regulatory compliance in data handling.  

People Leadership:

• Strategy and planning : Develop and   maintain   detection engineering area plans aligned to   Cyber Operations   strategy; set direction and goals with autonomy across data engineering, detection development, purple teaming, and automation functions.  

• Performance and tiers : Define and review reporting and team targets; align   objectives   to detection outcomes, coverage improvements, and operational efficiency.  

• Talent and capability : Lead inclusive recruitment; build career paths and targeted upskilling in detection development, threat hunting, cloud security, OT/ICS detection, and SOAR/AI through multi-functional, regional, and external partnerships.  

Knowledge, Experience, and Understanding Of:  

• Detection engineering lifecycle : Proven leadership across detection development, testing, deployment, and tuning at enterprise scale; deep understanding of detection logic design, coverage mapping, and efficacy validation.  

• Threat detection frameworks : Extensive knowledge of MITRE ATT&CK, Cyber Kill Chain, and detection engineering methodologies; experience mapping organisational coverage and prioritising development based on threat intelligence.  

• Purple team operations : Experienced in designing and accomplishing adversary emulation exercises; skilled in translating purple team findings into actionable detection improvements and coverage enhancements.  

• Automation and AI : Experience operationalizing modern detection platforms (SIEM, XDR, SOAR) including integration of artificial intelligence, machine learning models, and agentic features to enable detection at scale.  

• Data engineering and platforms : Proficient with data pipeline architecture, log aggregation, normalisation, and query optimisation; solid grasp of data quality requirements for effective detection.  

• Cloud, identity, and endpoint detection : Deep understanding of detection approaches across multi-cloud environments, identity systems, endpoints, and network infrastructure; familiar with cloud-native security services and integration patterns.  

• Manufacturing Operational Technology/Industrial Control Systems : Coordinating detection engineering in industrial/OT environments with safety, availability, and production continuity considerations; knowledge of industrial protocols and OT-specific threats.  

Minimum Skills & Experience Required  

• Education : Bachelor's degree in information security, computer science, or related field (or equivalent experience).  

• Enterprise-scale detection leadership : Over 5 years managing detection engineering or security operations in enterprise-si

Ready to apply to AstraZeneca?

Tailor my resume for this role

Similar jobs

More like this: More jobs at AstraZeneca · Browse all jobs