Director, Cyber Security Incident Response Team (CSIRT)

Posted Yesterday
Be an Early Applicant
Gaithersburg, MD, USA
In-Office
169K-254K Annually
Senior level
Biotech • Pharmaceutical
The Role
Lead enterprise incident response for hybrid cloud, on-premises, and OT/ICS environments. Own incident command, governance, forensics evidence handling, exercises/readiness, automation/AI operationalization, metrics/reporting, stakeholder coordination, and post-incident control hardening. Develop CSIRT strategy, maintain 24x7 coverage, hire and mentor staff, and integrate global regional SOCs and external retainers.
Summary Generated by Built In

Leverage technology to impact patients and ultimately save lives 

Do you have expertise in, and passion for, information technology? Would you like to apply your expertise to impact the IT strategy in a company that follows the science and turns ideas into life changing medicines? If so, AstraZeneca might be the one for you! 

ABOUT ASTRAZENECA

AstraZeneca is a global, science-led, patient-focused biopharmaceutical company that focuses on the discovery, development and commercialization of prescription medicines for some of the world’s most serious disease. But we’re more than one of the world’s leading pharmaceutical companies. At AstraZeneca we’re dedicated to being a Great Place to Work. 

ABOUT ROLE

The Director, CSIRT is a senior individual contributor leader in the Global Cybersecurity Operations Center (GSOC), based in Gaithersburg, Maryland, reporting to the Head of GSOC. You will command enterprise response to material cyber incidents across cloud, onpremises, and OT/ICS environments, own incident governance and readiness, and drive executive reporting, lessons learned, and control hardening in partnership with Detection Engineering, CTI, Vulnerability Management, Offensive Security, IT, Legal, Risk and Compliance, and Physical Security.

What You’ll Do:

  • Incident Command: Lead execution of the Incident Response (IR) plan to rapidly scope, contain, eradicate, and investigate incidents across hybrid and OT environments. 

  • Incident Governance: Define and maintain incident categories, severity, decision authorities, activation criteria, and crisis management handoffs. 

  • Forensics evidence handling: Coordinate preservation, collection, and analysis with chainofcustody rigor; in collaboration with Legal, manage asset litigation hold and retention as well as facilitation of artifact sharing for malware analysis and CTI. 

  • Exercises and readiness: Run regular tabletop and purpleteam exercises; ensure 24x7 coverage, seamless followthesun handoffs with Regional SOCs, and retainer surge playbooks. 

  • Automation and AI: Operationalize agentic SIEM features, XDR and SOAR playbooks, LLMassisted runbooks, and automated triage packages to reduce MTTD/MTTC/MTTR. 

  • Metrics and reporting: Own IR targets/KRIs (e.g., MTTD, MTTC, MTTR, dwell time, business impact) and deliver executiveready briefings, dashboards, and quarterly lessons learned. 

  • Stakeholder coordination: Orchestrate IR with IT, Legal, Privacy, Risk, Comms, Physical Security, and Insurance for notification obligations, privilege, and crisis communications. 

  • Controls Hardening: Drive postincident detection and control improvements with Detection Engineering, Identity, Cloud, Endpoint, and OT teams. 

  • Assurance integration: Partner with Vulnerability Management and Offensive Security to prioritize testing and remediation informed by incident findings and CTI. 

 

People Leadership:

  • Strategy and planning: Develop and maintain CSIRT area plans aligned to GSOC strategy; set direction and goals with autonomy. 

  • Performance and tiers: Define and review reporting and team targets; align objectives to incident outcomes and customer experience. 

  • Coverage and oncall: Maintain 24x7 oncall rotations, surge models, and crossregional handoff standards. 

  • Talent and capability: Lead inclusive recruitment; build career paths and targeted upskilling in DFIR, cloud identity, OT/ICS, and automation/SOAR through regional/external partnerships. Provide mentorship to junior CSIRT resources. 

 

Knowledge, Experience, and Understanding of:

  • Incident command & IR lifecycle: Proven command across cyber incident lifecycles, plans and playbooks. Deep understanding of the incident lifecycle, from preparation to scoping, containment, eradication and remediation at enterprise scale. 

  • DFIR evidence handling: Experienced in managing the collection, preservation and analysis of digital evidence and chain of custody; timeline reconstruction; attacker attribution; concise executive reporting. 

  • Attacker tradecraft (MITRE ATT&CK): Deep knowledge of the attack lifecycle (i.e. MITRE ATT&CK), timeline construction and familiarity with attribution and common threat actor TTPs 

  • Automation & AI: Experience with operationalization of modern security tools (SIEM, SOAR, XDR) including integration of artificial intelligence, large language models and agentic features to enable triage, analysis and eradication at scale. 

  • Cloud, identity, and endpoint visibility: Proficiency with logging prioritization and telemetry from industry standard cloud platforms, identity providers, operating systems and security tools. 

  • Manufacturing Operational Technology/Industrial Control Systems: Coordinating IR in industrial/OT environments with safety and production continuity considerations. 

  • Legal/regulatory & crisis communications: Comfortable building partnerships outside of cyber operations with legal, risk & compliance, physical security and other business collaborators relevant to incident response. 

  • Retainer and vendor readiness: MaintainingIR retainer partner readiness; knowing when to escalate and how to integrate external specialists during major incidents. 

 

Minimum Skills & Experience Required 

  • Education: Bachelor’s degree in information security, computer science, or related field (or equivalent experience). 

  • Enterprise-scale SOC/IR leadership: Over five (5) years managing Cyber Security Operations Centre Incident Response in enterprise-sized organizations, commanding events across hybrid cloud, onprem, and OT. 

  • Global coordination with Regional SOCs: Experience integrating and working alongside global, 24x7, distributed teams to complete incident response and cyber operations missions. 

  • Communication and facilitation: Well developed skills to explain complex technical issues in clear business terms; produce concise written material (executive updates, IR reports); and lead briefings. 

  • Analytical decision making: Ability to analyze complex situations, assess risk, and balance strategic and tactical security requirements with business pragmatism, risk appetite, and innovation. 

  • Customer orientation and cross-cultural working: Demonstrated ability to collaborate across regions and functions (IT, Legal, GRC, Physical Security) with a strong service outlook. 

Preferred Skills & Experience:

  • Certifications: Security certifications preferred (e.g., CISSP, CISM, GIAC such as GCIH/GCFA/GREM; CCSP; ITIL). 

 

When we put unexpected teams in the same room, we unleash bold thinking with the power to encourage life-changing medicines. In-person working gives us the platform we need to connect, work at pace and challenge perceptions. That's why we work, on average, a minimum of three days per week from the office. But that doesn't mean we're not flexible. We balance the expectation of being in the office while respecting individual flexibility. Join us in our unique and ambitious world.

The annual base pay for this position ranges from $169,320.00 - $253,980.00 USD Annual. Hourly and salaried non-exempt employees will also be paid overtime pay when working qualifying overtime hours. Base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. In addition, our positions offer a short-term incentive bonus opportunity; eligibility to participate in our equity-based long-term incentive program (salaried roles), to receive a retirement contribution (hourly roles), and commission payment eligibility (sales roles). Benefits offered included a qualified retirement program [401(k) plan]; paid vacation and holidays; paid leaves; and, health benefits including medical, prescription drug, dental, and vision coverage in accordance with the terms and conditions of the applicable plans. Additional details of participation in these benefit plans will be provided if an employee receives an offer of employment. If hired, employee will be in an “at-will position” and the Company reserves the right to modify base pay (as well as any other discretionary payment or compensation program) at any time, including for reasons related to individual performance, Company or individual department/team performance, and market factors.

Are you ready to bring new insights and fresh thinking to the table? Fantastic! We have one seat available, and we hope it’s yours. Apply today.

AstraZeneca embraces diversity and equality of opportunity. We are committed to building an inclusive and diverse team representing all backgrounds, with as wide a range of perspectives as possible, and harnessing industry-leading skills. We believe that the more inclusive we are, the better our work will be. We welcome and consider applications to join our team from all qualified candidates, regardless of their characteristics. We follow all applicable laws and regulations on non-discrimination in employment (and recruitment), as well as work authorization and employment eligibility verification requirements.

WHY JOIN US ? 

We’re a network of high-reaching self-starters who contribute to something far bigger. We enable AstraZeneca to perform at its peak by delivering premier technology and data solutions. 

We’re not afraid to take ownership and run with it. Empowered with unrivalled freedom. Put simply, it’s because we make a significant impact. Everything we do matters. 

Date Posted

05-Aug-2026

Closing Date

18-Aug-2026

Our mission is to build an inclusive environment where equal employment opportunities are available to all applicants and employees. In furtherance of that mission, we welcome and consider applications from all qualified candidates, regardless of their protected characteristics. If you have a disability or special need that requires accommodation, please complete the corresponding section in the application form.

Skills Required

  • Bachelor's degree in information security, computer science, or related field (or equivalent experience)
  • Over five years managing enterprise-scale SOC/Incident Response across hybrid cloud, on-premises, and OT environments
  • Proven incident command experience and mastery of the IR lifecycle (preparation through remediation) at enterprise scale
  • Experience with DFIR evidence handling, chain-of-custody, timeline reconstruction, and attacker attribution
  • Deep knowledge of attacker tradecraft and MITRE ATT&CK
  • Operational experience with SIEM, SOAR, XDR and integration of AI/LLM features into playbooks and runbooks
  • Proficiency with cloud, identity, and endpoint telemetry and logging prioritization
  • Experience coordinating incident response in OT/ICS/manufacturing environments with safety and production continuity considerations
  • Experience integrating and coordinating with global 24x7 regional SOCs and follow-the-sun handoffs
  • Strong communication, facilitation, executive briefing, and concise written reporting skills
  • Ability to coordinate with Legal, Privacy, Risk, Communications, Physical Security, and Insurance for crisis response
  • Experience maintaining IR retainer/vendor readiness and integrating external specialists during major incidents
  • Security certifications (e.g., CISSP, CISM, GIAC like GCIH/GCFA/GREM, CCSP, ITIL)

AstraZeneca Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about AstraZeneca and has not been reviewed or approved by AstraZeneca.

  • Fair & Transparent Compensation Pay is considered competitive across many roles when total rewards are factored in. Senior scientific and leadership bands are described with high ranges that reinforce competitiveness at upper levels.
  • Strong & Reliable Incentives Bonuses, equity eligibility in many salaried roles, and solid sales on‑target earnings with upside are emphasized as meaningful parts of compensation. These elements boost overall value even where base pay is not the very highest.
  • Retirement Support A 401(k) program with a strong company match and immediate vesting is repeatedly cited as a standout. Generous retirement support is viewed as enhancing the total package relative to peers.

AstraZeneca Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Gaithersburg, MD
70,000 Employees
Year Founded: 1999

What We Do

We're transforming the future of healthcare by unlocking the power of what science can do for people, society and the planet.

Similar Jobs

In-Office
Gaithersburg, MD, USA
90000 Employees
169K-254K Annually

Enverus Logo Enverus

Owner Relations Agent - 25270

Big Data • Information Technology • Software • Analytics • Energy
In-Office or Remote
3 Locations
1800 Employees
43K-58K Annually

Enverus Logo Enverus

Consultant

Big Data • Information Technology • Software • Analytics • Energy
In-Office or Remote
5 Locations
1800 Employees
120K-135K Annually

Applied Systems Logo Applied Systems

Director, Product Marketing - Carrier

Cloud • Insurance • Payments • Software • Business Intelligence • App development • Big Data Analytics
Remote or Hybrid
United States
3079 Employees
150K-180K Annually

Similar Companies Hiring

SOPHiA GENETICS Thumbnail
Software • Healthtech • Biotech • Big Data • Artificial Intelligence
Boston, MA
450 Employees
Pfizer Thumbnail
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
New York, NY
121990 Employees
Cencora Thumbnail
Healthtech • Logistics • Pharmaceutical
Conshohocken, PA
51000 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account