Director, Cyber Security Detection Engineering

AstraZeneca plc
Gaithersburg, United States of America
4 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 254K

Job location

Gaithersburg, United States of America

Tech stack

Artificial Intelligence
Cloud Computing
Cloud Computing Security
Cloud Engineering
Computer Security
Computer Telephony Integration
Information Engineering
Data Retention
Logic Synthesis of Circuits
Intrusion Detection and Prevention
Machine Learning
Network Architecture
Query Optimization
Security Information and Event Management
Systems Integration
Software Vulnerability Management
EndPointSecurity
Data Processing
Mitre Att&ck
Multi-Cloud
HybridCloud
Information Technology
Process Control Systems
Purple Team (Cyber Security)
Cyber Warfare
Software Version Control
Data Pipelines

Job description

The Director, Cyber Security Detection Engineering is a senior leader in the Cyber Operations function, based in Gaithersburg, Maryland, working with the Head of Cyber Operations. The role encompasses command of enterprise detection capabilities across cloud, on-premises, and OT/ICS environments, ownership of detection governance and validation, and delivery of executive reporting, coverage assessments, and capability maturation in partnership with GSOC, CTI, Vulnerability Management, Offensive Security, IT, Legal, Risk and Compliance, and business customers.

What You'll Do:

Detection strategy and roadmap: Direct the development and execution of comprehensive detection engineering programmes aligned to interpersonal risk appetite and threat landscape; establish capability roadmaps spanning data engineering, detection development, purple teaming, and automation/AI.

Data engineering oversight: Ensure robust data pipelines support detection activities through telemetry collection, normalization, and quality assurance across hybrid and OT environments; define data retention, schema standards, and platform configuration to enable effective threat detection.

Detection content development: Oversee creation, testing, and deployment of detection logic across SIEM, EDR, and cloud-native tooling; enforce detection standards, naming conventions, and MITRE ATT&CK mapping; prioritise coverage based on threat intelligence and risk assessments.

Purple Team Exercising: Oversee purple team operations to validate detection efficacy systematically; orchestrate adversary emulation exercises across technology domains; drive remediation of detection gaps identified through testing and operational feedback.

Automation and AI integration: Operationalise AI agents, machine learning models, and orchestration workflows to enhance detection accuracy, reduce false positives, and augment GSOC analyst capabilities; oversee development of automated enrichment, triage, and investigation playbooks.

Metrics and reporting: Own detection engineering targets (e.g., MITRE ATT&CK coverage, mean time to detect, false positive rates, purple team success metrics) and deliver executive-ready briefings, dashboards, and quarterly maturity assessments.

Policy and governance: Develop and enforce detection engineering policies, standards, and quality frameworks; maintain detection content libraries with version control and organizational change field; ensure regulatory compliance in data handling.

People Leadership:

Strategy and planning: Develop and maintain detection engineering area plans aligned to Cyber Operations strategy; set direction and goals with autonomy across data engineering, detection development, purple teaming, and automation functions.

Performance and tiers: Define and review reporting and team targets; align objectives to detection outcomes, coverage improvements, and operational efficiency.

Requirements

Detection engineering lifecycle: Proven leadership across detection development, testing, deployment, and tuning at enterprise scale; deep understanding of detection logic design, coverage mapping, and efficacy validation.

Threat detection frameworks: Extensive knowledge of MITRE ATT&CK, Cyber Kill Chain, and detection engineering methodologies; experience mapping organisational coverage and prioritising development based on threat intelligence.

Purple team operations: Experienced in designing and accomplishing adversary emulation exercises; skilled in translating purple team findings into actionable detection improvements and coverage enhancements.

Automation and AI: Experience operationalizing modern detection platforms (SIEM, XDR, SOAR) including integration of artificial intelligence, machine learning models, and agentic features to enable detection at scale.

Data engineering and platforms: Proficient with data pipeline architecture, log aggregation, normalisation, and query optimisation; solid grasp of data quality requirements for effective detection.

Cloud, identity, and endpoint detection: Deep understanding of detection approaches across multi-cloud environments, identity systems, endpoints, and network infrastructure; familiar with cloud-native security services and integration patterns.

Manufacturing Operational Technology/Industrial Control Systems: Coordinating detection engineering in industrial/OT environments with safety, availability, and production continuity considerations; knowledge of industrial protocols and OT-specific threats.

Minimum Skills & Experience Required * Education: Bachelor's degree in information security, computer science, or related field (or equivalent experience).

Enterprise-scale detection leadership: Over 5 years managing detection engineering or security operations in enterprise-sized organisations, commanding capabilities across hybrid cloud, on-premises, and OT environments.

Global coordination with distributed teams: Experience integrating and working alongside global, 24×7, geographically dispersed teams to deliver detection capabilities and support security operations missions.

Communication and facilitation: Well-developed skills to explain complex technical concepts in clear business terms; produce concise written material (executive updates, coverage reports); and lead briefings to diverse stakeholders.

Analytical decision making: Ability to analyse complex threat landscapes, assess detection gaps, and balance strategic capability development with tactical operational requirements, risk appetite, and resource constraints.

Customer orientation and cross-cultural working: Demonstrated ability to collaborate across regions and functions (GSOC, IT, Legal, GRC, business units) with a strong service approach and commitment to enabling organisational resilience.

Preferred Skills & Experience:

Certifications: Security certifications preferred (e.g., CISSP, CISM, GIAC such as GCIA/GCDA/GMON; cloud certifications; ITIL).

When we put unexpected teams in the same room, we unleash bold thinking with the power to encourage life-changing medicines. In-person working gives us the platform we need to connect, work at pace and challenge perceptions. That's why we work, on average, a minimum of three days per week from the office. But that doesn't mean we're not flexible. We balance the expectation of being in the office while respecting individual flexibility. Join us in our unique and ambitious world.

Benefits & conditions

The annual base pay for this position ranges from $169,320.00 - $253,980.00 USD Annual. Hourly and salaried non-exempt employees will also be paid overtime pay when working qualifying overtime hours. Base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. In addition, our positions offer a short-term incentive bonus opportunity; eligibility to participate in our equity-based long-term incentive program (salaried roles), to receive a retirement contribution (hourly roles), and commission payment eligibility (sales roles). Benefits offered included a qualified retirement program [401(k) plan]; paid vacation and holidays; paid leaves; and, health benefits including medical, prescription drug, dental, and vision coverage in accordance with the terms and conditions of the applicable plans. Additional details of participation in these benefit plans will be provided if an employee receives an offer of employment. If hired, employee will be in an "at-will position" and the Company reserves the right to modify base pay (as well as any other discretionary payment or compensation program) at any time, including for reasons related to individual performance, Company or individual department/team performance, and market factors.

About the company

AstraZeneca is a global, science-led, patient-focused biopharmaceutical company that focuses on the discovery, development and commercialization of prescription medicines for some of the world's most serious disease. But we're more than one of the world's leading pharmaceutical companies. At AstraZeneca, we're dedicated to being a Great Place to Work., We're a network of high-reaching self-starters who contribute to something far bigger. We enable AstraZeneca to perform at its peak by delivering premier technology and data solutions. We're not afraid to take ownership and run with it. Empowered with unrivalled freedom. Put simply, it's because we make a significant impact. Everything we do matters.

Apply for this position