> Markdown version of [/jobs/ext/2602331-director-cyber-security-incident-response-team-csirt](https://www.wearedevelopers.com/jobs/ext/2602331-director-cyber-security-incident-response-team-csirt). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director, Cyber Security Incident Response Team (CSIRT) - **Company:** AstraZeneca plc - **Location:** Gaithersburg, MD, United States - **Experience:** Expert - **Salary:** $169,320.0 - $253,980.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cloud Computing, Cyber Security, Computer Telephony Integration, Intrusion Detection and Prevention, Security Information and Event Management, Software Vulnerability Management, Data Logging, Large Language Models, Mitre Att&ck, Mttr, Malware, HybridCloud, Information Technology, Cyber Warfare - **Published:** August 6, 2026 - **Apply:** https://www.jofdav.com/jobs/59111339-director-cyber-security-incident-response-team-csirt ## About the Role Incident command & IR lifecycle:Proven commandacross cyber incident lifecycles, plans and playbooks. Deep understanding of the incident lifecycle, from preparation to scoping, containment, eradication and remediation at enterprise scale. * DFIR evidence handling:Experienced in managing the collection, preservation and analysis of digital evidence and chain of custody; timeline reconstruction; attacker attribution; concise executive reporting. * Attacker tradecraft (MITRE ATT&CK): Deep knowledge of the attack lifecycle (i.e. MITRE ATT&CK), timeline construction and familiarity with attribution and common threat actor TTPs * Automation & AI: Experience with operationalization of modern security tools (SIEM, SOAR, XDR) including integration of artificial intelligence, large language models and agentic features to enable triage, analysis and eradication at scale. * Cloud, identity, and endpoint visibility: Proficiency with logging prioritization and telemetry from industry standard cloud platforms, identity providers, operating systems and security tools., Education: Bachelor's degree in information security, computer science, or related field (or equivalent experience). * Enterprise-scale SOC/IR leadership: Over five (5) years managing Cyber Security Operations Centre Incident Response in enterprise-sized organizations, commanding events across hybrid cloud, onprem, and OT. * Global coordination with Regional SOCs: Experience integrating and working alongside global, 24x7, distributed teams to complete incident response and cyber operations missions. * Communication and facilitation: Well developed skills to explain complex technical issues in clear business terms; produce concise written material (executive updates, IR reports); and lead briefings. * Analytical decision making: Ability to analyze complex situations, assess risk, and balance strategic and tactical security requirements with business pragmatism, risk appetite, and innovation. * Customer orientation and cross-cultural working: Demonstrated ability to collaborate across regions and functions (IT, Legal, GRC, Physical Security) with a strong service outlook. Preferred Skills & Experience: * Certifications: Security certifications preferred (e.g., CISSP, CISM, GIAC such as GCIH/GCFA/GREM; CCSP; ITIL). When we put unexpected teams in the same room, we unleash bold thinking with the power to encourage life-changing medicines. In-person working gives us the platform we need to connect, work at pace and challenge perceptions. That's why we work, on average, a minimum of three days per week from the office. But that doesn't mean we're not flexible. We balance the expectation of being in the office while respecting individual flexibility. Join us in our unique and ambitious world. ## Description TheDirector, CSIRTis a senior individual contributor leader in theGlobal Cybersecurity Operations Center (GSOC), based in Gaithersburg, Maryland, reporting to the Head of GSOC. You will command enterprise response to material cyber incidents across cloud, on-premises, and OT/ICS environments, own incident governance and readiness, and drive executive reporting, lessons learned, and control hardening in partnership with Detection Engineering, CTI, Vulnerability Management, Offensive Security, IT, Legal, Risk and Compliance, and Physical Security. What You'll Do: * Incident Command: Lead execution of the Incident Response (IR) plan to rapidly scope, contain, eradicate, and investigate incidents across hybrid and OT environments. * Incident Governance: Define and maintain incident categories, severity, decision authorities, activation criteria, and crisis management handoffs. * Forensics evidence handling: Coordinate preservation, collection, and analysis with chain-of-custody rigor; in collaboration with Legal, manage asset litigation hold and retention as well as facilitation of artifact sharing for malware analysis and CTI. * Exercises and readiness: Run regular tabletop and purple-team exercises; ensure 24x7 coverage, seamless follow-the-sun handoffs with Regional SOCs, and retainer surge playbooks. * Automation and AI: Operationalize agentic SIEM features, XDR and SOAR playbooks, LLM-assisted runbooks, and automated triage packages to reduce MTTD/MTTC/MTTR. * Metrics and reporting: Own IR targets/KRIs (e.g., MTTD, MTTC, MTTR, dwell time, business impact) and deliver executive-ready briefings, dashboards, and quarterly lessons learned. * Stakeholder coordination: Orchestrate IR with IT, Legal, Privacy, Risk, Comms, Physical Security, and Insurance for notification obligations, privilege, and crisis communications. * Controls Hardening: Drive post-incident detection and control improvements with Detection Engineering, Identity, Cloud, Endpoint, and OT teams. * Assurance integration: Partner with Vulnerability Management and Offensive Security to prioritize testing and remediation informed by incident findings and CTI. People Leadership: * Strategy and planning: Develop and maintain CSIRT area plans aligned to GSOC strategy; set direction and goals with autonomy. * Performance and tiers: Define and review reporting and team targets; align objectives to incident outcomes and customer experience. ## Related Videos - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Get security done: streamlining application security with Aikido](https://www.wearedevelopers.com/videos/1638-get-security-done-streamlining-application-security-with-aikido) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) - [Training Bots on Deliveroo Data, Alexa Can Swear and Mushroom Electronics - Julia Kordick](https://www.wearedevelopers.com/videos/1839-training-bots-on-deliveroo-data-alexa-can-swear-and-mushroom-electronics-julia-kordick) ## Related Articles - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [The Biggest German Tech Companies](https://www.wearedevelopers.com/magazine/424-the-biggest-german-tech-companies) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Best Companies to Work For in Berlin: Top 14 Companies in 2023 ](https://www.wearedevelopers.com/magazine/188-best-companies-to-work-for-in-berlin-top-14-companies-in-2023)