Director of Product Security Engineering
AstraZenecaAbout the role
Are you ready to be part of the future of healthcare? Are you able to think big, be bold, and harness the power of digital and AI to tackle longstanding life sciences challenges? Then Evinova, a new health tech business part of the AstraZeneca Group might be for you!
As the Director of Product Security Engineering, you have a unique opportunity to join Evinova from the beginning. You will play a key role in implementing innovative cyber security practices that are designed by industry, for industry. You will report directly to the Evinova Head of Cyber Security, and focus collaborating with application development and platform engineering teams to deliver high quality application security services and expertise (e.g., code scanning, remediation prioritization and support). Additionally, you will collaborate across the entire Chief Technology Officer (CTO) organization to define and implement a multi-year application security and DevSecOps roadmap. You will have ample opportunity for program ownership, increased levels of accountability, and significant visibility within the CTO Leadership Team. You will collaborate with globally dispersed technology teams. Success in this role requires leading by influence, strong emotional intelligence, and a natural disposition towards precision and accuracy. The ideal candidate will think holistically and proactively deliver on strategic initiatives to ensure our digital solutions and platform are secured against emerging threats.
Key Responsibilities include:
Develop and operationalize a standardized Application Security and DevSecOps program which encompasses the core activities of Threat Modeling, Security Tools and Testing (e.g., SAST, SCA, DAST, IAST, etc.), and incorporating “privacy by design” and “secure by default” design processes into the CI / CD pipeline.
Leverage a variety of AppSec and DevSecOps oriented tools to identify, assess, and prioritize security vulnerabilities across our products and platform. Additionally, automating, and standardizing system configurations with a secure-by-default disposition. This role will also be a key influencer for the selection of program enabling tools / solutions.
Execute in-depth analysis and provide assurance over application code, infrastructure, architecture, and configuration posturing.
Establish strong and productive relationships to ensure cyber security is viewed as an enabler and market differentiator. Providing expert level advisory and guidance on secure coding practices and addressing potential security risks.
Establish and operationalize an application security vulnerability management program which includes steps to validate, analyze, and prioritize vulnerabilities. Additionally, driving remediation efforts.
Develop secure development standards and related trainings to raise awareness of secure coding practices, threat actor tactics, and regulatory requirements. Leading efforts to automate infrastructure provisioning and application deployments.
Providing cyber expertise in the definition and implementation of Infrastructure as Code patterns and practices.
Partner with cyber security colleagues to deliver on continuous improvement objectives and deepen adjacent team’s awareness of product and application security risks and threat actor trends.
Execute security architecture reviews for major product changes, providing assurance over security standards alignment, and driving security enhancements across existing solutions.
Lead co-sourced engagements to conduct application penetration testing, and other simulated “hacking” activities to proactively identify weaknesses and developing actionable remediation strategies.
Collaborates with the Cyber GRC Lead to develop and report on related Key Performance Indicators and Key Risk Indicators, and the continuous improvement of security controls, processes, policies, standards, and other governing documents.
Together with the Security Operations Lead, manage and respond to product and application security alerts – guiding platform and product teams through high severity incidents.
Provide support to external audit and customer due diligence requests, and providing training to adjacent colleagues on security awareness and best practices.
Essential Skills/Experience:
6 + years of relevant experience and Bachelor’s degree or 10+ years of relevant experience and High School Diploma. Relevant experience may include work in the areas of software development, application and API security, penetration and vulnerability scanning, and ethical hacking.
Prior experience providing AppSec capabilities for a SaaS / cloud service provider.
Expert level understandi
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s