Jobs and Careers
AS

Director, Cyber Security Incident Response Team (CSIRT)

AstraZeneca
Gaithersburg, United Statesfull_timeVerifiedPosted 28 May 2026
💰 $253,980/yr($169,320/yr$253,980/yr)

About the role

Leverage technology to impact patients and ultimately save lives 

Do you have expertise in, and passion for, information technology? Would you like to apply your expertise to impact the IT strategy in a company that follows the science and turns ideas into life changing medicines? If so, AstraZeneca might be the one for you! 

ABOUT ASTRAZENECA

AstraZeneca is a global, science-led, patient-focused biopharmaceutical company that focuses on the discovery, development and commercialization of prescription medicines for some of the world’s most serious disease. But we’re more than one of the world’s leading pharmaceutical companies. At AstraZeneca we’re dedicated to being a Great Place to Work. 

ABOUT ROLE

The Director, CSIRT is a senior individual contributor leader in the Global Cybersecurity Operations Center (GSOC), based in Gaithersburg, Maryland, reporting to the Head of GSOC. You will command enterprise response to material cyber incidents across cloud, onpremises, and OT/ICS environments, own incident governance and readiness, and drive executive reporting, lessons learned, and control hardening in partnership with Detection Engineering, CTI, Vulnerability Management, Offensive Security, IT, Legal, Risk and Compliance, and Physical Security.

What You’ll Do:

  • Incident Command: Lead execution of the Incident Response (IR) plan to rapidly scope, contain, eradicate, and investigate incidents across hybrid and OT environments. 

  • Incident Governance: Define and maintain incident categories, severity, decision authorities, activation criteria, and crisis management handoffs. 

  • Forensics evidence handling: Coordinate preservation, collection, and analysis with chainofcustody rigor; in collaboration with Legal, manage asset litigation hold and retention as well as facilitation of artifact sharing for malware analysis and CTI. 

  • Exercises and readiness: Run regular tabletop and purpleteam exercises; ensure 24x7 coverage, seamless followthesun handoffs with Regional SOCs, and retainer surge playbooks. 

  • Automation and AI: Operationalize agentic SIEM features, XDR and SOAR playbooks, LLMassisted runbooks, and automated triage packages to reduce MTTD/MTTC/MTTR. 

  • Metrics and reporting

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

AstraZeneca

View company profile →