HomeSearchSecurity Engineer Jobs › Director, Cyber Security Detection Engineering

Director, Cyber Security Detection Engineering

AstraZeneca

US - Gaithersburg - MD · director
More Security Engineer jobs: Security Engineer jobsSecurity Engineer salary

Leverage technology to   impact   patients and   ultimately save   lives Do you have   expertise   in, and passion   for,   information technology ? Would you like to apply your   expertise   to   impact   the IT strategy in a company that follows   the   science   and turns ideas into life changing medicines? If so, AstraZeneca might be the one for you! ABOUT ASTRAZENECA   AstraZeneca is a global, science-led, patient-focused biopharmaceutical company that focuses on the discovery,   development   and   commercialization   of prescription medicines for some of the world’s most serious   disease .

But   we’re   more than one of the world’s leading pharmaceutical companies. At AstraZeneca, we're   dedicated to being a Great Place to Work. ABOUT ROLE: The Director, Cyber Security Detection Engineering   is a senior leader in the Cyber Operations function, based in Gaithersburg, Maryland, working with the Head of   Cyber Operations . The role encompasses command of enterprise detection capabilities across cloud, on-premises, and OT/ICS environments, ownership of detection governance and validation, and delivery of executive reporting, coverage assessments, and capability maturation in partnership with   GSOC , CTI, Vulnerability Management, Offensive Security, IT, Legal, Risk and Compliance, and business customers.

What You'll Do: Detection strategy and roadmap : Direct the development and execution of comprehensive detection engineering programmes aligned to interpersonal risk appetite and threat landscape;   establish   capability roadmaps spanning data engineering, detection development, purple teaming, and automation/AI. Data engineering oversight : Ensure robust data pipelines support detection activities through telemetry collection, normali z ation, and quality assurance across hybrid and OT environments; define data retention, schema standards, and platform configuration to enable effective threat detection.

Detection content development : Oversee creation, testing, and deployment of detection logic across SIEM, EDR, and cloud-native tooling; enforce detection standards, naming conventions, and MITRE ATT&CK mapping; prioritise coverage based on threat intelligence and risk assessments. Purple   T eam   Exercising :   Oversee   purple team operations to   validate   detection efficacy systematically; orchestrate adversary emulation exercises across technology domains; drive remediation of detection gaps   identified   through testing and operational feedback.

Automation and AI integration : Operationalise AI agents, machine learning models, and orchestration workflows to enhance detection accuracy, reduce false positives, and augment GSOC analyst capabilities; oversee development of automated enrichment, triage, and investigation playbooks. Metrics and reporting : Own detection engineering targets (e.g., MITRE ATT&CK coverage,   mean time to detect , false positive rates, purple team success metrics) and deliver executive-ready briefings, dashboards, and quarterly maturity assessments.

Policy and governance : Develop and enforce detection engineering policies, standards, and quality frameworks;   maintain   detection content libraries with version control and organizational change field; ensure regulatory compliance in data handling. People Leadership: Strategy and planning : Develop and   maintain   detection engineering area plans aligned to   Cyber Operations   strategy; set direction and goals with autonomy across data engineering, detection development, purple teaming, and automation functions.

Performance and tiers : Define and review reporting and team targets; align   objectives   to detection outcomes, coverage improvements, and operational efficiency. Talent and capability : Lead inclusive recruitment; build career paths and targeted upskilling in detection development, threat hunting, cloud security, OT/ICS detection, and SOAR/AI through multi-functional, regional, and ex

Search all live jobs — free, no account →