ForgeApply
Try it free

ForgeApply · Job listing

Director, Cyber Security Incident Response Team (CSIRT)

AstraZeneca

MD, Gaithersburg, US$169k – $254konsite

Tailor your resume for this AstraZeneca job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for AstraZeneca's site. Free trial, no card required.

About this role

Leverage technology to   impact   patients and   ultimately save   lives  

Do you have   expertise   in, and passion   for,   information technology ? Would you like to apply your   expertise   to   impact   the IT strategy in a company that follows   the science   and turns ideas into life changing medicines? If so, AstraZeneca might be the one for you!  

ABOUT ASTRAZENECA

AstraZeneca is a global, science-led, patient-focused biopharmaceutical company that focuses on the discovery,   development   and   commercialization   of prescription medicines for some of the world’s most serious   disease . But   we’re   more than one of the world’s leading pharmaceutical companies. At AstraZeneca   we’re   dedicated to being a Great Place to Work.  

ABOUT ROLE

The  Director, CSIRT  is a senior   individual contributor   leader in the  Global Cybersecurity Operations Center (GSOC) , based in Gaithersburg, Maryland, reporting to the Head of GSOC. You will command enterprise response to material cyber incidents across cloud,   on ‑ premises , and OT/ICS environments, own incident governance and readiness, and drive executive reporting, lessons learned, and control hardening in partnership with Detection Engineering, CTI, Vulnerability Management, Offensive Security, IT, Legal, Risk and Compliance, and Physical Securit y.

What  Y ou’ll  D o:

• Incident   C ommand:   Lead execution of the Incident Response (IR) plan to rapidly scope,   contain , eradicate, and investigate incidents across hybrid and OT environments.  

• Incident   G overnance:   Define and   maintain   incident categories, severity, decision authorities, activation criteria, and crisis management handoffs.  

• Forensics evidence handling:   Coordinate preservation, collection, and analysis with   chain ‑ of ‑ custody   rigor;   in collaboration with Legal,   manage   asset   litigation hold   and   retention   as well as facilitation of   artifact sharing for malware analysis and CTI.  

• Exercises and   readiness :   Run regular tabletop and   purple ‑ team   exercises; ensure 24x7 coverage, seamless   follow ‑ the ‑ sun   handoffs with Regional SOCs, and retainer surge playbooks.  

• Automation and AI : Operationalize agentic SIEM features,   XDR   and SOAR playbooks, LLM ‑ assisted   runbooks, and automated triage packages to reduce MTTD/MTTC/MTTR.  

• Metrics and reporting : Own IR targets/KRIs (e.g.,   MTTD , MTTC, MTTR, dwell time, business impact) and deliver executive ‑ ready briefings, dashboards, and quarterly lessons learned.  

• Stakeholder coordination : Orchestrate IR with IT, Legal, Privacy, Risk, Comms, Physical   Security, and Insurance for notification obligations, privilege, and crisis communications.  

• Controls   H ardening:   Drive   post ‑ incident   detection and control improvements with Detection Engineering, Identity, Cloud, Endpoint, and OT teams.  

• Assurance integration: Partner with Vulnerability Management and Offensive Security to prioritize testing and remediation informed by incident findings and CTI.  

People Leadership:

• Strategy and planning:   Develop   and maintain   CSIRT area plans aligned to GSOC strategy; set direction and goals with autonomy.  

• Performance and tiers:   Define and review reporting and team targets; align   objectives   to incident outcomes and customer experience.  

• Coverage and on ‑ call:   Maintain   24x7 on ‑ call rotations, surge models, and cross ‑ regional handoff standards.  

• Talent and capability:   Lead inclusive recruitment; build career paths and targeted upskilling in DFIR, cloud identity, OT/ICS, and automation/SOAR through regional/external partnerships.   Provide mentorship to junior CSIRT resources.  

Knowledge, Experience, and Understanding of:

• Incident command & IR lifecycle :  Proven command  across   c yber   i ncident   l ifecycles ,   p lans   and   p laybooks.   Deep understanding of the incident lifecycle, from preparation to scoping, containment,   eradication   and remediation at enterprise scale .  

• DFIR evidence handling :  Experienced   in managing the collection, preservation and analysis of digital evidence and chain of custody ; timeline reconstruction; attacker attribution; concise executive reporting.  

• Attacker tradecraft (MITRE ATT&CK) :   Deep knowledge   of the attack lifecycle ( i.e.   MITRE ATT&CK), timeline construction and familiarity with attribution and common threat actor TTPs  

• Automation & AI :   Experience with operationalization of modern security tools (SIEM, SOAR, XDR) including integration of artificial intelligence, large language   models   and agentic features to enable triage,   analysis   and eradication at scale .  

• Cloud, identity, and endpoint visibility :   Prof iciency   with logging prioritization and telemetry from industry standard cloud platforms, identity providers, operating   systems   and security tools.  

• Manufacturing Operational Technology/ Industrial Control Systems : Coordinating IR in  industrial/OT  environments with safety and   production continuity considerations.  

• Legal/regulatory & crisis communications :   C omfortable building partnerships outside of cyber operations with legal, risk & compliance, physical security and other business collaborators relevant to incident response .  

• Retainer and vendor readiness :   Maintaining   IR retainer partner  readiness; knowing when to escalate and how to integrate external specialists during major incidents.  

Minimum   Skills & Experience   Required  

• Education:   Bachelor’s degree in information security, computer science, or related field (or equivalent experience).  

• Enterprise-scale SOC/IR leadership :   Over   five ( 5 )   years m anaging Cyber Security Operations Centre   Incident   R esponse in enterprise-sized organizations, commanding events across hybrid cloud,   onprem , and OT.  

• Global coordination with R egional   SOCs :   Experience integrating and working alongsi

Tailor your resume for this AstraZeneca role before you apply.

Tailor my resume for this job

Similar jobs

More like this: More jobs at AstraZeneca · Browse all jobs

Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)