Senior Director, Digital Forensics & Incident Response

AstraZeneca GmbH

Gaithersburg (MD)

On-site

USD 191,000 - 286,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

AstraZeneca is seeking a Senior Director, Digital Forensics & Incident Response to own the global cyber-incident capability across cloud, on-premises and OT/ICS environments. You’ll build the function, hire the team and set the standards, reporting to senior IT leadership and coordinating with regional CSIRTs.

Lead incident governance, forensic defensibility, readiness exercises and 24x7 coverage, while partnering with Legal, Privacy and Compliance to manage regulatory obligations and risk

Qualifications

  • Bachelor’s degree in information security, computer science or related field.
  • Ten+ years in cybersecurity with 7+ years in IR or digital forensics.
  • 5+ years leading incident response in a large enterprise.
  • Experience coordinating across hybrid cloud, on-prem, and OT/ICS.
  • Ability to communicate complex risks to executives.

Responsibilities

  • Act as the accountable commander for material and crisis-level cyber incidents.
  • Own the Incident Response strategy, roadmap, and budget.
  • Define incident categories, severity, and activation criteria.
  • Ensure forensic defensibility and chain-of-custody.
  • Run tabletop and functional exercises; report to leadership.

Skills

Incident Command & IR
Digital Forensics
Cloud & OT/ICS
Leadership of large teams
Regulatory awareness

Education

Bachelor’s degree in information security, CS or related

Tools

SIEM
SOAR
XDR

Job description

About the Role:

The Senior Director, Digital Forensics & Incident Response owns AstraZeneca's global capability to respond to and investigate cyber incidents. This role commands the enterprise response to material incidents across cloud, on-premises and OT/ICS environments; owns incident governance, readiness and the forensic defensibility of all collected evidence; and is accountable for executive reporting, lessons learned and the control hardening that follows.


This is a build role as AstraZeneca matures its internal incident response capability. The successful candidate will compose the function, hire the team and establish the standards under which it operates. The role leads through a Director, Forensics & Malware Analysis, and a global CSIRT working follow-the-sun alongside Regional Security Operations Centers in Macclesfield, Guadalajara, Chennai and Shanghai.


The role partners closely with Detection Engineering, Cyber Threat Intelligence, Threat Exposure Management, Insider Risk & DLP, IT, Legal, Privacy, Risk & Compliance, Corporate Communications, Insurance and Physical Security. Because AstraZeneca's research and development intellectual property is a primary target for nation-state actors, and its manufacturing estate carries safety and supply consequences, the judgement exercised during an incident has consequences well beyond IT.


What You’ll Do:


  • Incident Command:Act as the accountable commander for material and crisis-level cyber incidents, driving scoping, containment, eradication, recovery and investigation across hybrid cloud, on-premises and OT/ICS environments.


  • Service Line Ownership:Own the Incident Response strategy, multi-year roadmap, operating budget and capability plan, setting direction and standards with a high degree of autonomy.


  • Incident Governance:Define and maintain incident categories, severity definitions, activation criteria, decision authorities, delegation of authority during out-of-hours events and the handoff into enterprise crisis management.


  • Forensic Defensibility:Through the Director, Forensics & Malware Analysis, ensure that evidence is preserved, collected and analysed with chain-of-custody rigor that stands up to legal and regulatory scrutiny. Own the relationship with Legal regarding litigation hold, privilege and retention.


  • Readiness and Exercises:Run a calendar of tabletop, functional and purple-team exercises reaching from analyst level to the Executive Committee. Close findings and evidence improvement.


  • Coverage Model:Guarantee 24x7 response coverage with credible follow-the-sun handoffs, issue paths and surge capacity, including in-country arrangements where data-localisation or sanctions constraints apply.


  • Automation and AI:Operationalise agentic SIEM capability, XDR and SOAR playbooks, LLM-assisted runbooks and automated triage packages to compress mean time to detect, mean time to contain and mean time to respond without eroding evidentiary quality or human accountability.


  • Metrics and Reporting:Own Incident Response targets and key risk indicators, including mean time to detect, contain and respond, dwell time, containment quality and business impact. Report these credibly to senior leadership.


  • Executive and Board Communication:Deliver incident briefings, written updates and quarterly lessons-learned reviews to the CISO and IT leadership and, where warranted, the Audit Committee.


  • Regulatory and Notification Support:Work with Legal, Privacy and Compliance to support breach-notification assessments and regulatory obligations across the countries in which AstraZeneca operates, including material-incident disclosure considerations.


  • Controls Hardening:Drive post-incident detection and control improvements with Detection Engineering, Identity, Cloud, Endpoint, Network and OT teams.



Leading the Function:


  • Build and Organization Design:Design and staff the DFIR function from a near-zero baseline, defining roles, levels, sourcing locations and the balance of permanent and retained capacity.


  • Leading Through Leaders:Manage a Director-level leader and incident managers; set objectives, review performance and develop successors capable of commanding an incident in the Senior Director’s absence.


  • Coverage and On-Call:Maintain on-call rotations, surge models and cross-regional handoff standards, and act as the senior critical issue point when severity demands it.


  • Talent and Capability:Lead inclusive recruitment and build genuine career paths and upskilling in DFIR, cloud and identity forensics, OT/ICS, malware analysis and automation, using regional and external partnerships.


  • Team Sustainability:Protect the team from the burnout that can follow sustained high-tempo response. Design rotations, recovery and workload distribution deliberately.


  • Budget and Commercial Management:Own the service line budget, tooling and retainer spend, and build the case for further investment.



Knowledge, Experience and Understanding:


  • Incident Command and the Incident Response Lifecycle:Proven command across the full lifecycle at enterprise scale, including preparation, detection, scoping, containment, eradication, recovery and post-incident review, supported by appropriate plans and playbooks.


  • Digital Forensics and Evidence Handling:Experience managing the collection, preservation and analysis of digital evidence; chain of custody; timeline reconstruction; attribution; and concise executive reporting of forensic findings.


  • Attacker Tradecraft:Deep working knowledge of the attack lifecycle and MITRE ATT&CK, common threat actor tactics, techniques and procedures, and the different behaviours of nation-state and ransomware operators once inside an environment.


  • Automation and AI in Operations:Experience operationalising modern security tooling, including SIEM, SOAR and XDR, together with artificial intelligence, large language model and agentic capabilities to enable triage, analysis and eradication at scale, with clear human accountability for consequential decisions.


  • Cloud, Identity and Endpoint Visibility:Understanding of telemetry and logging priorities across major cloud platforms, identity providers, operating systems and security tooling, including the forensic limitations of each.


  • Operational Technology:Experience coordinating response in manufacturing OT/ICS environments where safety, validated systems and production continuity constrain responder actions.


  • Regulated-Industry Constraints:Experience working within GxP and validated-system requirements, clinical and patient data sensitivities and third-party exposure considerations.


  • Legal, Regulatory and Crisis Communications:Ability to build durable partnerships with Legal, Privacy, Risk and Compliance, Communications and Physical Security, and to operate comfortably under privilege.


  • Vendor and Retainer Readiness:Experience maintaining retainer partner readiness and integrating external specialists during major incidents without losing command of the response.



Minimum Skills and Experience Required


  • Education:Bachelor’s degree in information security, computer science or a related field, or equivalent practical experience.


  • Professional Experience:Ten or more years of experience in cybersecurity, including seven or more years in incident response or digital forensics.


  • Leadership Experience:Five or more years leading incident response in a large, complex enterprise, including at least two years managing other people leaders or managers.


  • Command Experience:Demonstrable record as the accountable commander for high-severity incidents spanning hybrid cloud, on-premises and OT environments.


  • Global Coordination:Experience running or integrating distributed 24x7 teams across multiple regions and cultures, including follow-the-sun handoffs.


  • Communication and Facilitation:Ability to explain complex technical situations in clear business terms, produce concise written material under time pressure and lead briefings for senior executives.


  • Analytical Decision-Making:Ability to assess incomplete information, weigh risk and balance strategic and tactical demands against business pragmatism and risk appetite.


  • Cross-Functional Credibility:Demonstrated ability to collaborate across IT, Legal, GRC and Physical Security, with a strong service orientation.


  • Availability:Willingness to serve as the senior escalation point outside business hours and to travel internationally as incidents and readiness activities require.



Desirable Skills and Experience


  • Certifications:CISSP, CISM, GIAC certifications such as GCIH, GCFA, GREM or GNFA, and CCSP.


  • Sector Experience:Experience in pharmaceutical, life sciences, healthcare or another highly regulated industry with significant manufacturing OT exposure.


  • Board and Regulator Exposure:Experience briefing an audit committee or board, or engaging directly with regulators or law enforcement during a significant incident.


  • Commercial Experience:Experience negotiating and governing Incident Response retainers and forensic vendor arrangements across multiple jurisdictions.


  • Language Skills:Working proficiency in a second language relevant to AstraZeneca’s delivery hubs.



When we put unexpected teams in the same room, we unleash bold thinking with the power to encourage life-changing medicines. In-person working gives us the platform we need to connect, work at pace and challenge perceptions. That's why we work, on average, a minimum of three days per week from the office. But that doesn't mean we're not flexible. We balance the expectation of being in the office while respecting individual flexibility. Join us in our unique and ambitious world.


The annual base pay for this position ranges from $190,957 - $286,435USD Annual. Hourly and salaried non-exempt employees will also be paid overtime pay when working qualifying overtime hours. Base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. In addition, our positions offer a short-term incentive bonus opportunity; eligibility to participate in our equity-based long-term incentive program (salaried roles), to receive a retirement contribution (hourly roles), and commission payment eligibility (sales roles). Benefits offered included a qualified retirement program [401(k) plan]; paid vacation and holidays; paid leaves; and, health benefits including medical, prescription drug, dental, and vision coverage in accordance with the terms and conditions of the applicable plans. Additional details of participation in these benefit plans will be provided if an employee receives an offer of employment. If hired, employee will be in at-will position and the Company reserves the right to modify base pay (as well as any other discretionary payment or compensation program) at any time, including for reasons related to individual performance, Company or individual department/team performance, and market factors.


Are you ready to bring new insights and fresh thinking to the table? Fantastic! We have one seat available, and we hope it’s yours.


AstraZeneca embraces diversity and equality of opportunity. We are committed to building an inclusive and diverse team representing all backgrounds, with as wide a range of perspectives as possible, and harnessing industry-leading skills. We believe that the more inclusive we are, the better our work will be. We welcome and consider applications to join our team from all qualified candidates, regardless of their characteristics. We follow all applicable laws and regulations on non-discrimination in employment (and recruitment), as well as work authorization and employment eligibility verification requirements.


Date Posted

24-Aug-2026


Closing Date

02-Sep-2026


Our mission is to build an inclusive environment where equal employment opportunities are available to all applicants and employees. In furtherance of that mission, we welcome and consider applications from all qualified candidates, regardless of their protected characteristics. If you have a disability or special need that requires accommodation, please complete the corresponding section in the application form.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Director, Digital Forensics & Incident Response
Senior Director, Digital Forensics & Incident Response

AstraZeneca • Gaithersburg (MD)

On-site
USD 191,000 - 286,000
Director, GTO Digital Transformation
Director, GTO Digital Transformation

AstraZeneca • Gaithersburg (MD)

On-site
USD 172,466 - 258,699
Bonus eligible
Equity incentives
401(k) plan
+2
Insights and Forecasting Director
Insights and Forecasting Director

AstraZeneca GmbH • Wilmington (DE)

Hybrid
USD 140,000 - 220,000
Global / US Senior Director, Insights, Analytics & Forecasting
Global / US Senior Director, Insights, Analytics & Forecasting

AstraZeneca • Wilmington (DE)

Hybrid
USD 218,000 - 327,000
401(k) plan
Health benefits including medical, Rx,
Equity-based long-term incentive (sald
+1
Senior Global Medical Affairs Leader, CardioRenal
Senior Global Medical Affairs Leader, CardioRenal

AstraZeneca • Gaithersburg (MD)

On-site
USD 244,000 - 365,000
Clinical Development Scientist
Clinical Development Scientist

Alexion • Boston (MA)

On-site
USD 183,000 - 306,000
Clinical Development Scientist
Clinical Development Scientist

Alexion Pharmaceuticals, Inc. • Boston (MA)

On-site
USD 204,000 - 306,000
Director, Diagnostics
Director, Diagnostics

AstraZeneca GmbH • Boston (MA), Northern (KY)

Hybrid
USD 181,000 - 271,000
Retirement plan
Paid time off
Health benefits
+1
Head of Commercial Learning, US Biopharmaceutical
Head of Commercial Learning, US Biopharmaceutical

AstraZeneca GmbH • Wilmington (DE)

On-site
USD 180,000 - 280,000
Global / US Senior Director, Insights, Analytics & Forecasting
Global / US Senior Director, Insights, Analytics & Forecasting

AstraZeneca GmbH • Wilmington (DE)

On-site
USD 218,000 - 327,000