Cybersecurity Trust by Design Senior Engineer
AstraZenecaAbout the role
Leverage technology to impact patients and ultimately save lives!
Do you have expertise in, and passion for, cyber security? Would you like to apply your expertise to impact product security in a company that follows the science and turns ideas into life-changing medicines? If so, AstraZeneca might be the one for you!
Accountabilities:
At AstraZeneca, we are dedicated to building secure, resilient, and credible products for our customers. Our cybersecurity team is a crucial part of this mission, ensuring our systems and solutions are designed with security at their core. We are seeking a Trust by Design Cybersecurity Senior Engineer to join our team and drive the integration of trust and security into every stage of our product development lifecycle.
As a Trust by Design Cybersecurity Senior Engineer, you will apply your expertise in system development, software security, and enterprise architecture to build and maintain security frameworks that enhance the trustworthiness of our products and services. You will collaborate with multi-functional teams to embed security throughout the development lifecycle and ensure that the best standard methodologies, security architecture, and threat modeling are applied consistently.
What you'll do:
- System Development Lifecycle (SDLC) Integration: Work with product development teams to integrate security into each phase of the SDLC, ensuring security is a primary consideration from design to deployment.
- Threat Modeling & Risk Analysis: Identify and assess potential security risks and vulnerabilities within the system architecture, product design, and enterprise systems. Lead threat modeling exercises to proactively detect risks early in the development lifecycle.
- Security Architecture & Design Patterns: Develop and enforce security-focused architecture and design patterns to improve system resilience and security across products and services. Build reusable, scalable security controls that are adaptable to various development teams.
- Attack Patterns & TTPs: Use a deep understanding of attack patterns, techniques, tactics, and procedures (TTPs) to identify security gaps and build compensating and mitigating controls that bolster trust and resilience across enterprise systems and applications.
- OWASP Recommended Patterns: Hands-on experience in implementing OWASP’s recommended secure coding patterns, ensuring that security standard methodologies are embedded into the software development process and aligned with industry standards.
- Security Automation & Resilience: Collaborate with engineering teams to implement automated security testing and monitoring solutions that promote early detection of threats and improve system resilience.
- Multi-functional Collaboration: Work closely with engineering, DevOps, and other collaborators to promote security standard processes and drive a security-first culture across the organization. Provide mentorship and support to other teams on secure coding practices, vulnerability management, and compliance requirements.
- Incident Response & Remediation: Assist in security incident investigations and give to developing remediation strategies that prevent similar incidents in the future.
- Continuous Improvement: Stay up-to-date with industry trends and emerging security technologies. Share knowledge and contribute to continuous improvements in security processes, tools, and frameworks.
Essential Skills/Experience
- Bachelor's Degree
- Minimum 6+ years of relevant experience
- Proven experience in the system development lifecycle (SDLC), software/product development, or software security.
- Deep understanding of security principles, threat modeling, and risk management.
- Expertise in security frameworks, security tooling, and secure coding practices.
- Strong experience in building and maintaining security architectures and reusable security design patterns.
- Hands-on experience with tools and technologies for vulnerability scanning, penetration testing, and security automation.
- Excellent problem-solving skills and the ability to think critically about security threats and mitigation strategies.
- Strong communication skills, with the ability to successfully communicate with technical and non-technical collaborators.
Desirable Skills/Experience
- Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related field (or equivalent experience).
- Deep understanding of attack patterns, techniques, tactics, and procedures (TTPs) and experience developing compensating and mitigating controls to enhance trust and resilience in products and enterprise systems.
- Extensive hands-on experience with OWASP recommended security p
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s