ForgeApply · Job listing
Director of Cyber Threat Intelligence (CTI)
AstraZeneca
See all 249 open roles at AstraZeneca →
Tailor your resume for this AstraZeneca job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for AstraZeneca's site. Free trial, no card required.
About this role
About AstraZeneca
AstraZeneca is a global, science-led, patient-focused biopharmaceutical company dedicated to discovering, developing, and commercialising prescription medicines for serious disease. We’re committed to being a Great Place to Work.
About the Role
The Director of Cyber Threat Intelligence will lead a highly technical CTI function within AstraZeneca’s Cybersecurity Operations division , managing a team of analysts to deliver strategic, operational, and tactical intelligence that measurably reduces risk across the enterprise, including manufacturing, clinical trial platforms, and R&D environments. This role anchors CTI to “intel-to-action” outcomes, partnering closely with Vulnerability Management, Detection Engineering, and Incident Response to harden controls, prioritize patching, improve detections, and accelerate response.
Key Responsibilities
• Program Leadership and Strategy: Define CTI vision, operating model, and roadmap aligned to AstraZeneca’s cyber risk reduction strategy, with special emphasis on manufacturing continuity, clinical data integrity, and R&D IP protection .
• Adversary Prioritization Framework: Design and operate a scoring rubric that ranks actors based on intent/capability/relevance, TTP emergence and prevalence, organization-specific exposure to known vulnerabilities/CVEs, and global “viral” events , maintain ing dynamic watchlists and escalation triggers.
• MTTI Metric and Analytics: Implement analytic methods to estimate mean time-to-impact per adversary (from initial access to material business impact ) using internal telemetry, historical incidents, industry reporting, and confidence levels , performing comparisons with IR’s MTTC to drive control improvements.
• Attack Path Modeling: Build and maintain end-to-end attack path models from initial access to material impact across IT-to-OT pivots, clinical platforms, and R&D environments , map ping steps to MITRE ATT&CK (Enterprise/ICS), identify control gaps and choke points, derive detections-as-code and hunt hypotheses, and support validat ion efforts including purple-team exercises and adversary emulation to ensure enterprise hardening and measurable risk reduction.
• Dark Web and Closed-Source Monitoring: Establish collection and monitoring across dark web forums, marketplaces, breach dumps, and closed channels to identify emerging TTPs, credential leaks, data exposure, access-broker listings, and targeting of manufacturing, clinical, or R&D assets , integrat ing validated findings into TIP/SIEM pipelines, trigger takedown requests where feasible, and deliver rapid advisories with confidence ratings and specific actions for Vulnerability Management, Detection Engineering, and IR.
• Third-Party and Ecosystem Intelligence: Deliver risk insights for CROs/CMOs/ logistics /technology vendors, monitor credential leakage and domain spoofing, and support/coordinate takedown operations when needed.
• Structured Threat Actor Attribution (Diamond Model): Lead disciplined attribution using the Diamond Model (adversary, capability, infrastructure, victim) and complementary frameworks , correlat ing TTPs, tooling lineage, code-reuse, infrastructure overlaps, and victimology with confidence levels and analytic caveats , document ing hypotheses, alternative explanations, and disconfirming evidenc e, and produc ing reusable actor profiles and pivot paths that inform prioritization, detections, hunts, and incident response playbooks.
• Support Vulnerability Management: Partner with Vulnerability Management to contextualize CVEs (exploitability, weaponization, external scanning telemetry, compensating controls) and deliver risk-based patching prioritization across AstraZeneca’s estate including IT/OT, clinical platforms, and lab environments.
• Support Detection Engineering: Develop detection use cases to feed our detection-as-code pipeline and support detection ATT&CK coverage mapping, content tuning, and false-positive reduction, ensuring feedback loops from hunts and incidents continuously improve detection quality.
• Support GSOC/ Incident Response: Provide real-time adversary context that is highly technical including kill-chain reconstruction, containment recommendations, and countermeasures, producing post-incident intelligence retrospectives and detection/architecture improvements.
• Operational and Executive Reporting: Produce daily threat intelligence highlights , threat actor/campaign profiles, quarterly threat briefings, and other ad hoc intelligence products, ensuring products include quantified risk narratives for senior leadership that also alig n findings to regulatory expectations and business impact.
• Tooling and Automation: Optimize integrations across TIP, SIEM, EDR, case management, and telemetry; manage indicator lifecycle, automate enrichment, and measure source fidelity/bias.
• External Engagement: Lead participation with sector bodies (e.g., H-ISAC), peer sharing groups, and government/industry partners; track and assess global events and rapidly translate into actionable enterprise guidance.
• Team Leadership and Development: Recruit, mentor, and grow a diverse team of CTI analysts; build career paths, training plans, and knowledge-sharing practices; foster a culture of technical excellence and clear, actionable communication.
Minimum Qualifications
• Leadership and Strategic Impact: 10+ years in cyber threat intelligence, detection engineering, incident response, or related domains; 5+ years leading technical CTI teams in global enterprises. Demonstrated ability to set vision, influence strategy, and deliver outcomes tied to enterprise risk reduction.
• Decision Making and Accountability: Proven ownership of adversary-centric CTI programs that directly drive vulnerability prioritization, detections-as-code, hunts, and in
Tailor your resume for this AstraZeneca role before you apply.
Tailor my resume for this jobSimilar jobs
- Sr. Director, Cyber Threat Detection & Response — McKesson · Richmond, VA
- Cyber Threat Hunt (CTH) Lead — Accenturefederalservices · Arlington, VA
- Cyber Threat Intelligence - Technical Analysis and Investigations Lead – VP — Morgan Stanley · Baltimore, Maryland, United States
- Director, Cyber Operations — Draper · Cambridge, MA
- Cyber Threat Inteligence Analyst — Intersystems · Boston, MA
- Director of Cybersecurity — Stand Out For Good · Remote
- Director of Cybersecurity — Aloyoga · Beverly Hills, California, United States; San Ramon, California, United States
- Cyber Threat Operations & Intelligence Analyst — Parsons · US - MD, Annapolis Junction
Free ATS checker · No Salary on the Job Posting? How to Find the Number Before You Interview