Director, Cyber Security Detection Engineering
AI summary of the role
Senior leadership role commanding enterprise detection capabilities across cloud, on-premises, and OT/ICS environments at a global biopharmaceutical company.
No longer in the current catalog. Last included 2026-09-09. Check the employer’s posting for availability.
What you’ll do
- Direct development and execution of comprehensive detection engineering programmes aligned to risk appetite and threat landscape.
- Oversee data pipelines, telemetry collection, normalization, and quality assurance across hybrid and OT environments.
- Oversee creation, testing, and deployment of detection logic across SIEM, EDR, and cloud-native tooling; enforce MITRE ATT&CK mapping.
- Oversee purple team operations to validate detection efficacy and drive remediation of gaps.
What you’ll bring
- Bachelor's degree in information security, computer science, or related field (or equivalent experience).
- Over 5 years managing detection engineering or security operations in enterprise-sized organisations across hybrid cloud, on-premises, and OT environments.
- Experience integrating and working alongside global, 24×7, geographically dispersed teams.
- Ability to explain complex technical concepts in clear business terms and produce concise executive updates.
Technologies
SIEM · EDR · XDR · SOAR · MITRE ATT&CK · Cyber Kill Chain · OT/ICS · cloud-native security · AI agents · machine learning
About AstraZeneca
Science-led biopharma developing and commercializing prescription medicines across oncology, chronic disease, respiratory/immunology, infectious disease, and rare disease, with AI-enabled R&D and global launch scale.
Public · 5000+ people
Source and classification
Internal deployment & tooling · Evidence for this classification:
role encompasses command of enterprise detection capabilities across cloud, on-premises, and OT/ICS environments, ownership of detection governance and validation, and delivery of executive reporting, coverage assessments, and capability maturation in partnership with GSOC, CTI, Vulnerability Management, Offensive Security, IT, Legal, Risk and Compliance, and business customers. What You'll Do: Detection strategy and roadmap: Direct the development and execution of comprehensive detection engineering programmes aligned to interpersonal risk appetite and threat landscape; establish capability roadmaps spanning data engineering, detection development, purple teaming, and automation/AI. Data engineering oversight: Ensure robust data pipelines support detection activities through telemetry collection, normalization, and quality assurance across hybrid and OT environments; define data
More from the job description
Leverage technology to impact patients and ultimately save lives Do you have expertise in, and passion for, information technology? Would you like to apply your expertise to impact the IT strategy in a company that follows the science and turns ideas into life changing medicines? If so, AstraZeneca might be the one for you! ABOUT ASTRAZENECA AstraZeneca is a global, science-led, patient-focused biopharmaceutical company that focuses on the discovery, development and commercialization of prescription medicines for some of the world’s most serious disease. But we’re more than one of the world’s leading pharmaceutical companies. At AstraZeneca, we're dedicated to being a Great Place to Work. ABOUT ROLE: The Director, Cyber Security Detection Engineering is a senior leader in the Cyber Operations function, based in Gaithersburg, Maryland, working with the Head of Cyber Operations. The role encompasses command of enterprise detection capabilities across cloud, on-premises, and OT/ICS environments, ownership of detection governance and validation, and delivery of executive reporting, coverage assessments, and capability maturation in partnership with GSOC, CTI, Vulnerability Management, Offensive Security, IT, Legal, Risk and Compliance, and business customers. What You'll Do: Detection strategy and roadmap: Direct the development and execution of comprehensive detection engi [... source excerpt omitted ...] etection at scale. Data engineering and platforms: Proficient with data pipeline architecture, log aggregation, normalisation, and query optimisation; solid grasp of data quality requirements for effective detection. Cloud, identity, and endpoint detection: Deep understanding of detection approaches across multi-cloud environments, identity systems, endpoints, and network infrastructure; familiar with cloud-native security services and integration patterns. Manufacturing Operational Technology/Industrial Control Systems: Coordinating detection engineering in industrial/OT environments with safety, availability, and production continuity considerations; knowledge of industrial prot [... source excerpt omitted ...] keholders. Analytical decision making: Ability to analyse complex threat landscapes, assess detection gaps, and balance strategic capability development with tactical operational requirements, risk appetite, and resource constraints. Customer orientation and cross-cultural working: Demonstrated ability to collaborate across regions and functions (GSOC, IT, Legal, GRC, business units) with a strong service approach and commitment to enabling organisational resilience. Preferred Skills & Experience: Certifications: Security certifications preferred (e.g., CISSP, CISM, GIAC such as GCIA/GCDA/GMON; cloud certifications; ITIL). When we put unexpected teams in the same room, we unleas
Employer postings · Data from · Sources