CareerMoonshot

Director, Cyber Security Detection Engineering

AstraZeneca · Maryland

📍 US - Gaithersburg - MDvia workdayFirst listed here 2026-09-13
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to AstraZeneca.
Leverage technology to   impact   patients and   ultimately save   lives Do you have   expertise   in, and passion   for,   information technology ? Would you like to apply your   expertise   to   impact   the IT strategy in a company that follows   the   science   and turns ideas into life changing medicines? If so, AstraZeneca might be the one for you!   ABOUT ASTRAZENECA   AstraZeneca is a global, science-led, patient-focused biopharmaceutical company that focuses on the discovery,   development   and   commercialization   of prescription medicines for some of the world’s most serious   disease . But   we’re   more than one of the world’s leading pharmaceutical companies. At AstraZeneca, we're   dedicated to being a Great Place to Work.   ABOUT ROLE: The Director, Cyber Security Detection Engineering   is a senior leader in the Cyber Operations function, based in Gaithersburg, Maryland, working with the Head of   Cyber Operations . The role encompasses command of enterprise detection capabilities across cloud, on-premises, and OT/ICS environments, ownership of detection governance and validation, and delivery of executive reporting, coverage assessments, and capability maturation in partnership with   GSOC , CTI, Vulnerability Management, Offensive Security, IT, Legal, Risk and Compliance, and business customers.   What You'll Do: Detection strategy and roadmap : Direct the development and execution of comprehensive detection engineering programmes aligned to interpersonal risk appetite and threat landscape;   establish   capability roadmaps spanning data engineering, detection development, purple teaming, and automation/AI.   Data engineering oversight : Ensure robust data pipelines support detection activities through telemetry collection, normali z ation, and quality assurance across hybrid and OT environments; define data retention, schema standards, and platform configuration to enable effective threat detection.   Detection content development : Oversee creation, testing, and deployment of detection logic across SIEM, EDR, and cloud-native tooling; enforce detection standards, naming conventions, and MITRE ATT&CK mapping; prioritise coverage based on threat intelligence and risk assessments.   Purple   T eam   Exercising :   Oversee   purple team operations to   validate   detection efficacy systematically; orchestrate adversary emulation exercises across technology domains; drive remediation of detection gaps   identified   through testing and operational feedback.   Automation and AI integration : Operationalise AI agents, machine learning models, and orchestration workflows to enhance detection accuracy, reduce false positives, and augment GSOC analyst capabilities; oversee development of automated enrichment, triage, and investigation playbooks.   Metrics and reporting : Own detection engineering targets (e.g., MITRE ATT&CK coverage,   mean time to detect , false positive rates, purple team success metrics) and deliver executive-ready briefings, dashboards, and quarterly maturity assessments.   Policy and governance : Develop and enforce detection engineering policies, standards, and quality frameworks;   maintain   detection content libraries with version control and organizational change field; ensure regulatory compliance in data handling.   People Leadership: Strategy and planning : Develop and   maintain   detection engineering area plans aligned to   Cyber Operations   strategy; set direction and goals with autonomy across data engineering, detection development, purple teaming, and automation functions.   Performance and tiers : Define and review reporting and team targets; align   objectives   to detection outcomes, coverage improvements, and operational efficiency.   Talent and capability : Lead inclusive recruitment; build career paths and targeted upskilling in detection development, threat hunting, cloud security, OT/ICS detection, and SOAR/AI through multi-functional, regional, and external partnerships.   Knowledge, Experience, and Understanding Of:   Detection engineering lifecycle : Proven leadership across detection development, testing, deployment, and tuning at enterprise scale; deep understanding of detection logic design, coverage mapping, and efficacy validation.   Threat detection frameworks : Extensive knowledge of MITRE ATT&CK, Cyber Kill Chain, and detection engineering methodologies; experience mapping organisational coverage and prioritising development based on threat intelligence.   Purple team operations : Experienced in designing and accomplishing adversary emulation exercises; skilled in translating purple team findings into actionable detection improvements and coverage enhancements.   Automation and AI : Experience operationalizing modern detection platforms (SIEM, XDR, SOAR) including integration of artificial intelligence, machine learning models, and agentic features to enable detection at scale.   Data engineering and platforms : Proficient with data pipeline architecture, log aggregation, normalisation, and query optimisation; solid grasp of data quality requirements for effective detection.   Cloud, identity, and endpoint detection : Deep understanding of detection approaches across multi-cloud environments, identity systems, endpoints, and network infrastructure; familiar with cloud-native security services and integration patterns.   Manufacturing Operational Technology/Industrial Control Systems : Coordinating detection engineering in industrial/OT environments with safety, availability, and production continuity considerations; knowledge of industrial protocols and OT-specific threats.   Minimum Skills & Experience Required   Education : Bachelor's degree in information security, computer science, or related field (or equivalent experience).   Enterprise-scale detection leadership : Over 5 years managing detection engineering or security operations

More Maryland jobs

Maryland jobs · Browse all locations