Jobs and Careers
AS

Director, Security Consulting — Business Information Security Officer (BISO) Commercial IT

AstraZeneca
Gaithersburg, United Statesfull_timeVerifiedPosted 17 Jun 2026

About the role

At AstraZeneca, we pride ourselves on crafting a collaborative culture that champions knowledge-sharing, ambitious thinking and innovation – ultimately providing employees with the opportunity to work across teams, functions and even the globe.

Recognizing the importance of individualized flexibility, our ways of working allow employees to balance personal and work commitments while ensuring we continue to create a strong culture of collaboration and teamwork by engaging face-to-face in our offices 3 days a week. Our head office and BlueSky Hub in downtown Toronto are purposely designed with collaboration in mind, providing space where teams can come together to strategize, brainstorm and connect on key projects.

Our dedication to sustainability is also central to our culture and part of what makes AstraZeneca a great place to work. We know the health of people, the planet and our business are interconnected which is why we’re taking ambitious action to tackle some of the biggest challenges of our time, from climate change to access to healthcare and disease prevention.

Introduction to role:

Are you ready to shape enterprise security strategy where it matters most—protecting innovation and enabling life-changing medicines to reach patients faster? Do you want to influence VP and executive stakeholders while embedding secure-by-design practices into transformative platforms, AI/ML programs, M&A, and regulated digital products?

As Director, Security Consulting, you will serve as a senior, trusted advisor embedded with product, platform, and business leaders. You will own the strategy, standards, and delivery of security consulting for a complex, global portfolio, translating business goals, threat intelligence, and regulatory obligations into scalable patterns and policy-aligned architectures. Your work will accelerate risk-informed decisions, reduce systemic risk, and improve control effectiveness without slowing innovation.

Based in Gaithersburg and reporting into the Commercial IT BISO, you will operate across a highly matrixed environment to set the guardrails that enable speed with confidence. You will partner closely with architects, engineers, data and AI leaders, and security operations to drive measurable improvements in resilience, audit readiness, and time-to-value.

Accountabilities:

  • Strategy and Function Ownership: Own the strategy, operating model, standards, and roadmap for security consulting across the assigned portfolio; align with CISO priorities, product and platform roadmaps, and enterprise architecture, and represent the function in executive governance to drive risk reduction at scale.

  • Executive Engagement and Influence: Advise VP/SVP business and technology leaders; translate threat intelligence, regulatory drivers, and commercial strategy into clear, defensible priorities and investment decisions that balance risk, cost, and speed.

  • Governance Integration: Embed security into program and product lifecycles with traceable requirements, clear ownership, escalation paths, and measurable outcomes, minimizing friction while maintaining strong control health.

  • Secure-by-Design Standards: Define and enforce secure patterns, guardrails, threat models, and reference architectures; champion shift-left practices and continuous security testing integrated into CI/CD.

  • Security Consulting and Major Assessments: Lead high-impact assessments across transformative platforms, M&A, AI/ML, major SaaS adoptions, and regulated digital products; document risks, exceptions, and treatments aligned to risk appetite and business objectives.

  • Orchestration: Direct deep architecture reviews, red/blue team consultations, and threat modeling accelerators; convert findings into prioritized, funded remediation and durable architectural uplift.

  • Program and Portfolio Leadership: Sponsor multi-team security initiatives such as cloud control baselines, AppSec uplift, identity modernization, and third-party assurance; define success metrics and change management to land adoption that lasts.

  • Control Assurance and Compliance: Provide executive oversight of control health, testing, and audit readiness across ISO 27001, SOC 2, SOx ITGC, and GxP/GMP where applicable; ensure durable remediation and continuous improvement.

  • Third-Party and Supply Chain Security: Set the standard for supplier risk management, security clauses, due diligence, and continuous monitoring; manage concentration and systemic risks and own executive escalations.

  • Data, AI, and Privacy Enablement: Partner with data, AI, and privacy leaders to safeguard sensitive and regulated data; enable compliant analytics and AI/ML through classification, encryption, DLP, monitoring, and model-risk controls.

  • Incident

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

AstraZeneca

View company profile →