Director of Cyber Threat Intelligence (CTI) job opportunity at AstraZeneca.



DateMore Than 30 Days Ago bot
AstraZeneca Director of Cyber Threat Intelligence (CTI)
Experience: 10-years
Pattern: full-time
apply Apply Now
Salary:
Status:

Job

Copy Link Report
degreeOND
loacation US - Gaithersburg - MD, United States Of America
loacation US - Gaithersb..........United States Of America

About AstraZeneca   AstraZeneca is a global, science-led, patient-focused biopharmaceutical company dedicated to discovering, developing, and commercialising prescription medicines for serious disease.   We’re   committed to being a Great Place to Work.   About the Role   The Director of Cyber Threat Intelligence will lead a highly technical CTI function within   AstraZeneca’s   Cybersecurity Operations   division , managing a team of analysts to deliver strategic, operational, and tactical intelligence that measurably reduces risk across   the enterprise, including   manufacturing, clinical trial platforms, and R&D environments. This role anchors CTI to “intel-to-action” outcomes, partnering closely with Vulnerability Management, Detection Engineering, and Incident Response to harden controls, prioritize patching, improve detections, and accelerate response.   Key Responsibilities   Program Leadership and Strategy: Define CTI vision, operating model, and roadmap aligned to   AstraZeneca’s cyber risk reduction strategy, with special emphasis on   manufacturing continuity, clinical data integrity, and R&D IP protection .   Adversary Prioritization Framework: Design and   operate   a   scoring rubric that ranks actors based on intent/capability/relevance, TTP emergence and prevalence, organization-specific exposure to known vulnerabilities/CVEs, and global “viral” events ,   maintain ing   dynamic watchlists and escalation triggers.   MTTI Metric and Analytics: Implement analytic methods to estimate mean time-to-impact per adversary (from   initial   access to material business   impact ) using internal telemetry, historical incidents, industry reporting, and confidence levels , performing   comparisons with IR’s MTTC to drive control improvements.   Attack Path Modeling: Build and maintain end-to-end attack path models from initial access to material impact across IT-to-OT pivots, clinical platforms, and R&D environments ,   map ping   steps to MITRE ATT&CK (Enterprise/ICS), identify control gaps and choke points, derive detections-as-code and hunt hypotheses, and   support   validat ion   efforts including   purple-team exercises and adversary emulation to ensure   enterprise   hardening and measurable risk reduction.   Dark Web and Closed-Source Monitoring: Establish collection and monitoring across dark web forums, marketplaces, breach dumps, and closed channels to identify emerging TTPs, credential leaks, data exposure, access-broker listings, and targeting of manufacturing, clinical, or R&D assets ,   integrat ing   validated findings into TIP/SIEM pipelines, trigger takedown requests where feasible, and deliver rapid advisories with confidence ratings and   specific actions   for Vulnerability Management, Detection Engineering, and IR.   Third-Party and Ecosystem Intelligence: Deliver risk insights for CROs/CMOs/ logistics /technology vendors,   monitor   credential leakage and domain spoofing, and support/coordinate takedown operations when needed.   Structured Threat Actor Attribution (Diamond Model): Lead disciplined attribution using the Diamond Model (adversary, capability, infrastructure, victim) and complementary frameworks ,   correlat ing   TTPs, tooling lineage, code-reuse, infrastructure overlaps, and victimology with confidence levels and analytic caveats ,   document ing   hypotheses, alternative explanations, and disconfirming evidenc e, and   produc ing   reusable actor profiles and pivot paths that inform prioritization, detections, hunts, and incident response playbooks.   Support Vulnerability Management: Partner with Vulnerability Management to contextualize CVEs (exploitability, weaponization, external scanning telemetry, compensating controls) and deliver risk-based patching prioritization across AstraZeneca’s estate including IT/OT, clinical platforms, and lab environments.   Support   Detection Engineering: Develop detection use cases to feed our detection-as-code pipeline and support detection ATT&CK coverage mapping, content tuning, and false-positive reduction, ensuring feedback loops from hunts and incidents continuously improve detection quality.   Support GSOC/ Incident Response: Provide real-time adversary context that is highly technical including kill-chain reconstruction, containment recommendations, and countermeasures, producing post-incident intelligence retrospectives and detection/architecture improvements.   Operational   and Executive Reporting: Produce   daily threat intelligence highlights ,   threat   actor/campaign profiles,   quarterly threat briefings,   and   other ad hoc intelligence products, ensuring products include   quantified risk narratives for senior leadership   that also   alig n   findings to regulatory expectations and business impact.   Tooling and Automation:   Optimize   integrations across TIP, SIEM, EDR, case management, and telemetry; manage indicator lifecycle, automate enrichment, and measure source fidelity/bias.   External Engagement: Lead participation with sector bodies (e.g., H-ISAC), peer sharing groups, and government/industry partners; track and assess global events and rapidly translate into actionable enterprise guidance.   Team Leadership and Development: Recruit, mentor, and grow a diverse team of CTI analysts; build career paths, training plans, and knowledge-sharing practices; foster a culture of technical excellence and clear, actionable communication.   Minimum Qualifications   Leadership and Strategic Impact: 10+ years in cyber threat intelligence, detection engineering, incident response, or related domains; 5+ years leading technical CTI teams in global enterprises. Demonstrated ability to set vision, influence strategy, and deliver outcomes tied to enterprise risk reduction.   Decision Making and Accountability: Proven ownership of adversary-centric CTI programs that directly drive vulnerability prioritization, detections-as-code, hunts, and incident response. Comfortable making data-driven decisions with clear trade-offs and confidence levels.   Technical Depth (ATT&CK Enterprise/ICS): Deep   expertise   mapping TTPs to MITRE ATT&CK, defining coverage strategies, and translating gaps into high-fidelity detections and hunt hypotheses; skilled in industrial/OT contexts.   Attack Path Modeling and Risk Translation: Hands-on delivery of end-to-end attack paths across IT-to-OT pivots, clinical platforms, and R&D environments; validation via purple-team/adversary emulation; ability to convert findings into prioritized control roadmaps and measurable risk reduction.   Adversary Prioritization and Scoring: Designed and   operated   tailored actor scoring incorporating intent/capability, TTP emergence/prevalence, org exposure to CVEs, and global/viral events;   maintained   dynamic watchlists and escalation triggers.   Structured Attribution Tradecraft: Applied the Diamond Model and complementary frameworks with documented hypotheses, caveats, disconfirming evidence, and confidence statements; produced reusable actor profiles and pivot paths.   Metrication (MTTI vs. MTTC): Built mean time-to-impact metrics per actor and operationalized comparisons to IR's mean time-to-containment to guide control improvements and track program effectiveness.   Vulnerability Intelligence for Hardening: Delivered contextual CVE analysis (exploitability, weaponization, external scanning telemetry, compensating controls) and risk-based patch recommendations across IT, OT/ICS, clinical, and lab environments.   Detection Engineering Collaboration: Co-developed detections-as-code (e.g., Sigma, KQL, SPL), tuned content to reduce false positives, and closed ATT&CK coverage gaps with feedback loops from hunts/incidents.   Incident Intelligence Support: Provided real-time adversary context, kill-chain reconstruction, containment recommendations, and post-incident retrospectives that inform detection and architectural improvements.   Collection, Tooling, and Automation: Operated dark web/closed-source monitoring; integrated findings into TIP/SIEM/EDR pipelines; managed indicator lifecycle, automated enrichment, and measured source fidelity/bias.   Stakeholder Partnership and Communication: Clear, concise communication of complex technical intelligence to executives and cross-functional partners (Vulnerability Management, Detection Engineering, SOC/IR, OT Security, Clinical Ops, Research IT); ability to influence without authority.   Education: Bachelor's degree in a relevant field (Computer Science, Information Security, Intelligence Studies, or equivalent experience).   Preferred Qualifications   Sector Experience and Regulatory Context: Experience in pharmaceuticals, life sciences, healthcare, or manufacturing; familiarity with GMP/CSV, clinical data obligations, and R&D IP protection.   OT/ICS and Critical Operations: Hands-on work with MES, SCADA, PLC ecosystems; ATT&CK for ICS usage; understanding of OT-safe response practices and production continuity implications.   Clinical/R&D Platforms: Exposure to CTMS, EDC, IRT, ELN, LIMS, HPC, and data lake environments; experience safeguarding data integrity and sensitive research/IP.   Program Metrics and Outcomes: Built dashboards tracking MTTI by actor, ATT&CK coverage indices, intel-informed patch SLAs, hunter ROI, and executive risk narratives; experience   presenting to   senior leadership and risk committees.   Advanced Tooling/Automation: TIP administration, SIEM/EDR content engineering, enrichment/orchestration pipelines, case management integration, and indicator lifecycle automation at enterprise scale.   Threat Modeling and Quantification: Ability to translate attack paths into quantified risk scenarios and prioritized control investments aligned to business   objectives   and crown jewels.   External Partnerships: Active engagement with H-ISAC/ISAOs and government/industry partners;   track record   of rapidly converting global/viral cyber events into enterprise defenses and executive guidance.   Certifications: One or   more of   GCTI, GREM, GRID, GCIH, CISSP, or equivalent   demonstrated   expertise .   People Leadership: Built diverse, high-performing teams; established career paths, coaching frameworks, and a culture of analytic rigor, technical excellence, and continuous improvement.   Location and Working Model   Location: Gaithersburg, Maryland.   Working Model: Hybrid-three days per week in office, two days remote. Occasional travel for key meetings, plant/partner engagements, conferences, or incident support may be   required .   WHY JOIN   US ?   We’re   a network of high-reaching self-starters who contribute to something far bigger. We enable AstraZeneca to perform at its peak by delivering premier technology and data solutions.   We’re   not afraid to take ownership and run with it. Empowered with unrivalled freedom. Put simply,   it’s   because we make a significant impact. Everything we do matters.   When we put unexpected teams in the same room, we unleash bold thinking with the power to encourage life-changing medicines. In-person working gives us the platform we need to connect, work at pace and challenge   perceptions .   That's   why we work, on average, a minimum of three days per week from the office. But that   doesn't   mean   we're   not flexible. We balance the expectation of being in the office while respecting individual flexibility. Join us in our unique and ambitious world.   The annual base pay for this position ranges from $ 162.536,00  - $ 243.804,00   USD Annual. Hourly and salaried non-exempt employees will also be paid overtime pay when working qualifying overtime hours. Base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. In addition, our positions offer a short-term incentive bonus opportunity; eligibility to   participate   in our equity-based long-term incentive program (salaried roles), to receive a retirement contribution (hourly roles), and commission payment eligibility (sales roles). Benefits offered included a qualified retirement program [401(k) plan]; paid vacation and holidays; paid leaves; and, health benefits including medical, prescription drug, dental, and vision coverage   in accordance with   the terms and conditions of the applicable plans.   Additional   details of participation in these benefit plans will be provided if an employee receives an offer of employment. If hired, employee will be in an “at-will position” and the Company reserves the right to modify base pay (as well as any other discretionary payment or compensation program) at any time, including for reasons related to individual performance, Company or individual department/team performance, and market factors.     SO, WHAT’S NEXT?    Are you already envisioning yourself joining our team? Good, because   we’d   love to hear from you! Click the link to apply and   we’ll   be in touch as soon as we can.   WHERE CAN I FIND OUT MORE?    Our   Social Media , Follow AstraZeneca on LinkedIn   https://www.linkedin.com/company/1603/   We are an equal opportunity employer and value diversity at our company. We do not discriminate   on the basis of   race, religion,   color , national origin, sex, gender, gender expression, sexual orientation, age, marital status, veteran status, or disability status.   Date Posted 14-ene-2026 Closing Date 13-ene-2026 Our mission is to build an inclusive environment where equal employment opportunities are available to all applicants and employees. In furtherance of that mission, we welcome and consider applications from all qualified candidates, regardless of their protected characteristics. If you have a disability or special need that requires accommodation, please complete the corresponding section in the application form.

Other Ai Matches

Corporate Affairs Generalist – Global Corporate Affairs Applicants are expected to have a solid experience in handling Job related tasks
Finance Intern in Commercial FP&A Team - 12 months Career Starter Program Applicants are expected to have a solid experience in handling Job related tasks
Senior Study Start-up Manager Applicants are expected to have a solid experience in handling Job related tasks
Medical Sales Representative – Respiratory – (South East Hungary) Applicants are expected to have a solid experience in handling Job related tasks
Stage Visiteur Médical IDF (H/F) Applicants are expected to have a solid experience in handling Job related tasks
Key Account Manager CVRM - Timisoara Applicants are expected to have a solid experience in handling Job related tasks
DSM-Hema-杭州 Applicants are expected to have a solid experience in handling Job related tasks
Sr. Pharmaceutical Sales Specialist, Specialty Care Respiratory Biologics-Puerto Rico Applicants are expected to have a solid experience in handling Specialty Care Respiratory Biologics-Puerto Rico related tasks
MR-HEMA-徐州 Applicants are expected to have a solid experience in handling Job related tasks
Principal Enterprise Architect Commercial OBU Applicants are expected to have a solid experience in handling Job related tasks
SAP Business Partner Applicants are expected to have a solid experience in handling Job related tasks
Senior Director Physician, Cardiovascular Safety Knowledge Group Expert, AZ ECG Centre Cardiologist Applicants are expected to have a solid experience in handling Cardiovascular Safety Knowledge Group Expert, AZ ECG Centre Cardiologist related tasks
Senior Manager/Associate Director-Marketing (Neuro TA) Applicants are expected to have a solid experience in handling Job related tasks
Senior Data Programmer CPQP Programming (PKPD / Pharmacometrics / NONMEM / SAS Programmer) Applicants are expected to have a solid experience in handling Job related tasks
District Business Manager (For Pooling) Applicants are expected to have a solid experience in handling Job related tasks
Director, Process Safety and SIF (Serious Injury & Fatality) Prevention Applicants are expected to have a solid experience in handling Process Safety and SIF (Serious Injury & Fatality) Prevention related tasks
Marketing Lead - Oncology - Breast Applicants are expected to have a solid experience in handling Job related tasks
Compliance Director – Regional Assurance Lead – China Applicants are expected to have a solid experience in handling Job related tasks
Key Account Manager Oncology - Lung Cancer - Moravia Applicants are expected to have a solid experience in handling Job related tasks
Senior Manager, Commercial, GBS Process & Analytics Services Applicants are expected to have a solid experience in handling Commercial, GBS Process & Analytics Services related tasks
MR-HEMA-南京 Applicants are expected to have a solid experience in handling Job related tasks
Pharmaceutical Sales Specialist, R&I Primary Care - Glendale South, AZ Applicants are expected to have a solid experience in handling R&I Primary Care - Glendale South, AZ related tasks
District Business Manager - Cebu, Bohol and Dumaguete Applicants are expected to have a solid experience in handling Bohol and Dumaguete related tasks