Director, Cyber Security Detection Engineering
AstraZeneca · Maryland
📍 US - Gaithersburg - MDvia workdayFirst listed here 2026-09-13
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to AstraZeneca.
Leverage technology to impact patients and ultimately save lives
Do you have expertise in, and passion for, information technology ? Would you like to apply your expertise to impact the IT strategy in a company that follows the science and turns ideas into life changing medicines? If so, AstraZeneca might be the one for you!
ABOUT ASTRAZENECA
AstraZeneca is a global, science-led, patient-focused biopharmaceutical company that focuses on the discovery, development and commercialization of prescription medicines for some of the world’s most serious disease .
But we’re more than one of the world’s leading pharmaceutical companies. At AstraZeneca, we're dedicated to being a Great Place to Work.
ABOUT ROLE:
The Director, Cyber Security Detection Engineering is a senior leader in the Cyber Operations function, based in Gaithersburg, Maryland, working with the Head of Cyber Operations . The role encompasses command of enterprise detection capabilities across cloud, on-premises, and OT/ICS environments, ownership of detection governance and validation, and delivery of executive reporting, coverage assessments, and capability maturation in partnership with GSOC , CTI, Vulnerability Management, Offensive Security, IT, Legal, Risk and Compliance, and business customers.
What You'll Do:
Detection strategy and roadmap : Direct the development and execution of comprehensive detection engineering programmes aligned to interpersonal risk appetite and threat landscape; establish capability roadmaps spanning data engineering, detection development, purple teaming, and automation/AI.
Data engineering oversight : Ensure robust data pipelines support detection activities through telemetry collection, normali z ation, and quality assurance across hybrid and OT environments; define data retention, schema standards, and platform configuration to enable effective threat detection.
Detection content development : Oversee creation, testing, and deployment of detection logic across SIEM, EDR, and cloud-native tooling; enforce detection standards, naming conventions, and MITRE ATT&CK mapping; prioritise coverage based on threat intelligence and risk assessments.
Purple T eam Exercising : Oversee purple team operations to validate detection efficacy systematically; orchestrate adversary emulation exercises across technology domains; drive remediation of detection gaps identified through testing and operational feedback.
Automation and AI integration : Operationalise AI agents, machine learning models, and orchestration workflows to enhance detection accuracy, reduce false positives, and augment GSOC analyst capabilities; oversee development of automated enrichment, triage, and investigation playbooks.
Metrics and reporting : Own detection engineering targets (e.g., MITRE ATT&CK coverage, mean time to detect , false positive rates, purple team success metrics) and deliver executive-ready briefings, dashboards, and quarterly maturity assessments.
Policy and governance : Develop and enforce detection engineering policies, standards, and quality frameworks; maintain detection content libraries with version control and organizational change field; ensure regulatory compliance in data handling.
People Leadership:
Strategy and planning : Develop and maintain detection engineering area plans aligned to Cyber Operations strategy; set direction and goals with autonomy across data engineering, detection development, purple teaming, and automation functions.
Performance and tiers : Define and review reporting and team targets; align objectives to detection outcomes, coverage improvements, and operational efficiency.
Talent and capability : Lead inclusive recruitment; build career paths and targeted upskilling in detection development, threat hunting, cloud security, OT/ICS detection, and SOAR/AI through multi-functional, regional, and external partnerships.
Knowledge, Experience, and Understanding Of:
Detection engineering lifecycle : Proven leadership across detection development, testing, deployment, and tuning at enterprise scale; deep understanding of detection logic design, coverage mapping, and efficacy validation.
Threat detection frameworks : Extensive knowledge of MITRE ATT&CK, Cyber Kill Chain, and detection engineering methodologies; experience mapping organisational coverage and prioritising development based on threat intelligence.
Purple team operations : Experienced in designing and accomplishing adversary emulation exercises; skilled in translating purple team findings into actionable detection improvements and coverage enhancements.
Automation and AI : Experience operationalizing modern detection platforms (SIEM, XDR, SOAR) including integration of artificial intelligence, machine learning models, and agentic features to enable detection at scale.
Data engineering and platforms : Proficient with data pipeline architecture, log aggregation, normalisation, and query optimisation; solid grasp of data quality requirements for effective detection.
Cloud, identity, and endpoint detection : Deep understanding of detection approaches across multi-cloud environments, identity systems, endpoints, and network infrastructure; familiar with cloud-native security services and integration patterns.
Manufacturing Operational Technology/Industrial Control Systems : Coordinating detection engineering in industrial/OT environments with safety, availability, and production continuity considerations; knowledge of industrial protocols and OT-specific threats.
Minimum Skills & Experience Required
Education : Bachelor's degree in information security, computer science, or related field (or equivalent experience).
Enterprise-scale detection leadership : Over 5 years managing detection engineering or security operations
More Maryland jobs
Maryland jobs · Browse all locations