Director, Cyber Security Detection Engineering
AstraZeneca
Leverage technology to impact patients and ultimately save lives Do you have expertise in, and passion for, information technology ? Would you like to apply your expertise to impact the IT strategy in a company that follows the science and turns ideas into life changing medicines? If so, AstraZeneca might be the one for you! ABOUT ASTRAZENECA AstraZeneca is a global, science-led, patient-focused biopharmaceutical company that focuses on the discovery, development and commercialization of prescription medicines for some of the world’s most serious disease .
But we’re more than one of the world’s leading pharmaceutical companies. At AstraZeneca, we're dedicated to being a Great Place to Work. ABOUT ROLE: The Director, Cyber Security Detection Engineering is a senior leader in the Cyber Operations function, based in Gaithersburg, Maryland, working with the Head of Cyber Operations . The role encompasses command of enterprise detection capabilities across cloud, on-premises, and OT/ICS environments, ownership of detection governance and validation, and delivery of executive reporting, coverage assessments, and capability maturation in partnership with GSOC , CTI, Vulnerability Management, Offensive Security, IT, Legal, Risk and Compliance, and business customers.
What You'll Do: Detection strategy and roadmap : Direct the development and execution of comprehensive detection engineering programmes aligned to interpersonal risk appetite and threat landscape; establish capability roadmaps spanning data engineering, detection development, purple teaming, and automation/AI. Data engineering oversight : Ensure robust data pipelines support detection activities through telemetry collection, normali z ation, and quality assurance across hybrid and OT environments; define data retention, schema standards, and platform configuration to enable effective threat detection.
Detection content development : Oversee creation, testing, and deployment of detection logic across SIEM, EDR, and cloud-native tooling; enforce detection standards, naming conventions, and MITRE ATT&CK mapping; prioritise coverage based on threat intelligence and risk assessments. Purple T eam Exercising : Oversee purple team operations to validate detection efficacy systematically; orchestrate adversary emulation exercises across technology domains; drive remediation of detection gaps identified through testing and operational feedback.
Automation and AI integration : Operationalise AI agents, machine learning models, and orchestration workflows to enhance detection accuracy, reduce false positives, and augment GSOC analyst capabilities; oversee development of automated enrichment, triage, and investigation playbooks. Metrics and reporting : Own detection engineering targets (e.g., MITRE ATT&CK coverage, mean time to detect , false positive rates, purple team success metrics) and deliver executive-ready briefings, dashboards, and quarterly maturity assessments.
Policy and governance : Develop and enforce detection engineering policies, standards, and quality frameworks; maintain detection content libraries with version control and organizational change field; ensure regulatory compliance in data handling. People Leadership: Strategy and planning : Develop and maintain detection engineering area plans aligned to Cyber Operations strategy; set direction and goals with autonomy across data engineering, detection development, purple teaming, and automation functions.
Performance and tiers : Define and review reporting and team targets; align objectives to detection outcomes, coverage improvements, and operational efficiency. Talent and capability : Lead inclusive recruitment; build career paths and targeted upskilling in detection development, threat hunting, cloud security, OT/ICS detection, and SOAR/AI through multi-functional, regional, and ex