Director, Cyber Security Detection Engineering
AstraZeneca · Gaithersburg, MD · Yesterday
Full-time
About the role
Leverage technology to impact patients and ultimately save lives. Would you like to apply your expertise to impact the IT strategy in a company that follows the science and turns ideas into life-changing medicines?
Responsibilities
- Direct the development and execution of comprehensive detection engineering programs aligned to interpersonal risk appetite and threat landscape.
- Establish capability roadmaps spanning data engineering, detection development, purple teaming, and automation/AI.
- Ensure robust data pipelines support detection activities through telemetry collection, normalization, and quality assurance across hybrid and OT environments.
- Define data retention, schema standards, and platform configuration to enable effective threat detection.
- Oversee creation, testing, and deployment of detection logic across SIEM, EDR, and cloud-native tooling.
- Enforce detection standards, naming conventions, and MITRE ATT&CK mapping; prioritize coverage based on threat intelligence and risk assessments.
- Oversee purple team operations to validate detection efficacy systematically; orchestrate adversary emulation exercises across technology domains; drive remediation of detection gaps identified through testing and operational feedback.
- Operationalise AI agents, machine learning models, and orchestration workflows to enhance detection accuracy, reduce false positives, and augment GSOC analyst capabilities.
- Own detection engineering targets (e.g., MITRE ATT&CK coverage, mean time to detect, false positive rates, purple team success metrics) and deliver executive-ready briefings, dashboards, and quarterly maturity assessments.
- Develop and enforce detection engineering policies, standards, and quality frameworks; maintain detection content libraries with version control and organizational change field; ensure regulatory compliance in data handling.
- Develop and maintain detection engineering area plans aligned to Cyber Operations strategy; set direction and goals with autonomy across data engineering, detection development, purple teaming, and automation functions.
- Define and review reporting and team targets; align objectives to detection outcomes, coverage improvements, and operational efficiency.
- Lead inclusive recruitment; build career paths and targeted upskilling in detection development, threat hunting, cloud security, OT/ICS detection, and SOAR/AI through multi-functional, regional, and external partnerships.
Requirements
- Proven leadership across detection development, testing, deployment, and tuning at enterprise scale.
- Deep understanding of detection logic design, coverage mapping, and efficacy validation.
- Extensive knowledge of MITRE ATT&CK, Cyber Kill Chain, and detection engineering methodologies; experience mapping organizational coverage and prioritizing development based on threat intelligence.
- Experienced in designing and accomplishing adversary emulation exercises; skilled in translating purple team findings into actionable detection improvements and coverage enhancements.
- Experience operationalizing modern detection platforms (SIEM, XDR, SOAR) including integration of artificial intelligence, machine learning models, and agent features to enable detection at scale.
- Proficient with data pipeline architecture, log aggregation, normalisation, and query optimisation; solid grasp of data quality requirements for effective detection.
- Deep understanding of detection approaches across multi-cloud environments, identity systems, endpoints, and network infrastructure; familiar with cloud-native security services and integration patterns.
- Knowledge of industrial protocols and OT-specific threats; coordinating detection engineering in industrial/OT environments with safety, availability, and production continuity considerations.
Qualifications
- Bachelor's degree in information security, computer science, or related field (or equivalent experience).
- Over 5 years managing detection engineering or security operations in enterprise-sized organizations, commanding capabilities across hybrid cloud, on-premises, and OT environments.
- Experience integrating and working alongside global, 24×7, geographically dispersed teams to deliver detection capabilities and support security operations missions.
- Well-developed skills to explain complex technical concepts in clear business terms; produce concise written material (executive updates, coverage reports); and lead briefings to diverse stakeholders.
- Ability to analyse complex threat landscapes, assess detection gaps, and balance strategic capability development with tactical operational requirements, risk appetite, and resource constraints.
- Demonstrated ability to collaborate across regions and functions (GSOC, IT, Legal, GRC, business units) with a strong service approach and commitment to enabling organizational resilience.
Skills
- Security certifications preferred (e.g., CISSP, CISM, GCIA/GCDA/GMON).
- Cloud certifications.
- ITIL.
Benefits
- Retirement program [401(k) plan].
- Paid vacation and holidays.
- Paid leaves.
- Health benefits including medical, prescription drug, dental, and vision coverage.
Pay
The annual base pay for this position ranges from $169,320.00 - $253,980.00 USD.
Schedule
Our mission is to build an inclusive environment where equal employment opportunities are available to all applicants and employees. In furtherance of that mission, we welcome and consider applications from all qualified candidates, regardless of their protected characteristics. If you have a disability or special need that requires accommodation, please complete the corresponding section in the application form.