ForgeApply
Try it free

ForgeApply · Job listing

Director of Cyber Threat Intelligence (CTI)

AstraZeneca

MD, Gaithersburg, USonsite

See all 249 open roles at AstraZeneca

Tailor your resume for this AstraZeneca job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for AstraZeneca's site. Free trial, no card required.

About this role

About AstraZeneca  

AstraZeneca is a global, science-led, patient-focused biopharmaceutical company dedicated to discovering, developing, and commercialising prescription medicines for serious disease.   We’re   committed to being a Great Place to Work.  

About the Role  

The Director of Cyber Threat Intelligence will lead a highly technical CTI function within   AstraZeneca’s   Cybersecurity Operations   division , managing a team of analysts to deliver strategic, operational, and tactical intelligence that measurably reduces risk across   the enterprise, including   manufacturing, clinical trial platforms, and R&D environments. This role anchors CTI to “intel-to-action” outcomes, partnering closely with Vulnerability Management, Detection Engineering, and Incident Response to harden controls, prioritize patching, improve detections, and accelerate response.  

Key Responsibilities  

• Program Leadership and Strategy: Define CTI vision, operating model, and roadmap aligned to   AstraZeneca’s cyber risk reduction strategy, with special emphasis on   manufacturing continuity, clinical data integrity, and R&D IP protection .  

• Adversary Prioritization Framework: Design and   operate   a   scoring rubric that ranks actors based on intent/capability/relevance, TTP emergence and prevalence, organization-specific exposure to known vulnerabilities/CVEs, and global “viral” events ,   maintain ing   dynamic watchlists and escalation triggers.  

• MTTI Metric and Analytics: Implement analytic methods to estimate mean time-to-impact per adversary (from   initial   access to material business   impact ) using internal telemetry, historical incidents, industry reporting, and confidence levels , performing   comparisons with IR’s MTTC to drive control improvements.  

• Attack Path Modeling: Build and maintain end-to-end attack path models from initial access to material impact across IT-to-OT pivots, clinical platforms, and R&D environments ,   map ping   steps to MITRE ATT&CK (Enterprise/ICS), identify control gaps and choke points, derive detections-as-code and hunt hypotheses, and   support   validat ion   efforts including   purple-team exercises and adversary emulation to ensure   enterprise   hardening and measurable risk reduction.  

• Dark Web and Closed-Source Monitoring: Establish collection and monitoring across dark web forums, marketplaces, breach dumps, and closed channels to identify emerging TTPs, credential leaks, data exposure, access-broker listings, and targeting of manufacturing, clinical, or R&D assets ,   integrat ing   validated findings into TIP/SIEM pipelines, trigger takedown requests where feasible, and deliver rapid advisories with confidence ratings and   specific actions   for Vulnerability Management, Detection Engineering, and IR.  

• Third-Party and Ecosystem Intelligence: Deliver risk insights for CROs/CMOs/ logistics /technology vendors,   monitor   credential leakage and domain spoofing, and support/coordinate takedown operations when needed.  

• Structured Threat Actor Attribution (Diamond Model): Lead disciplined attribution using the Diamond Model (adversary, capability, infrastructure, victim) and complementary frameworks ,   correlat ing   TTPs, tooling lineage, code-reuse, infrastructure overlaps, and victimology with confidence levels and analytic caveats ,   document ing   hypotheses, alternative explanations, and disconfirming evidenc e, and   produc ing   reusable actor profiles and pivot paths that inform prioritization, detections, hunts, and incident response playbooks.  

• Support Vulnerability Management: Partner with Vulnerability Management to contextualize CVEs (exploitability, weaponization, external scanning telemetry, compensating controls) and deliver risk-based patching prioritization across AstraZeneca’s estate including IT/OT, clinical platforms, and lab environments.  

• Support   Detection Engineering: Develop detection use cases to feed our detection-as-code pipeline and support detection ATT&CK coverage mapping, content tuning, and false-positive reduction, ensuring feedback loops from hunts and incidents continuously improve detection quality.  

• Support GSOC/ Incident Response: Provide real-time adversary context that is highly technical including kill-chain reconstruction, containment recommendations, and countermeasures, producing post-incident intelligence retrospectives and detection/architecture improvements.  

• Operational   and Executive Reporting: Produce   daily threat intelligence highlights ,   threat   actor/campaign profiles,   quarterly threat briefings,   and   other ad hoc intelligence products, ensuring products include   quantified risk narratives for senior leadership   that also   alig n   findings to regulatory expectations and business impact.  

• Tooling and Automation:   Optimize   integrations across TIP, SIEM, EDR, case management, and telemetry; manage indicator lifecycle, automate enrichment, and measure source fidelity/bias.  

• External Engagement: Lead participation with sector bodies (e.g., H-ISAC), peer sharing groups, and government/industry partners; track and assess global events and rapidly translate into actionable enterprise guidance.  

• Team Leadership and Development: Recruit, mentor, and grow a diverse team of CTI analysts; build career paths, training plans, and knowledge-sharing practices; foster a culture of technical excellence and clear, actionable communication.  

Minimum Qualifications  

• Leadership and Strategic Impact: 10+ years in cyber threat intelligence, detection engineering, incident response, or related domains; 5+ years leading technical CTI teams in global enterprises. Demonstrated ability to set vision, influence strategy, and deliver outcomes tied to enterprise risk reduction.  

• Decision Making and Accountability: Proven ownership of adversary-centric CTI programs that directly drive vulnerability prioritization, detections-as-code, hunts, and in

Tailor your resume for this AstraZeneca role before you apply.

Tailor my resume for this job

Similar jobs

Free ATS checker · No Salary on the Job Posting? How to Find the Number Before You Interview