Director of Cyber Threat Intelligence

AstraZeneca

Confirmed live yesterday High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Gaithersburg, MD
Employment
Full-time
Posted
14 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

How this pay compares to similar roles

Similar $213k
$142k most similar roles pay here $270k

This listing doesn't post a salary. Most similar roles pay $171,012–$255,156.

Based on 240 similar postings.

Employer

About AstraZeneca

AstraZeneca is a global biopharmaceutical company focused on the research, development, and commercialization of prescription medicines in oncology, cardiovascular, respiratory, and rare disease areas. Industry: Biopharmaceuticals

View all roles at AstraZeneca

At a glance

TL;DR · Director of Cyber Threat Intelligence

The Director of Cyber Threat Intelligence leads a highly technical CTI function within the Cybersecurity Operations division to protect manufacturing, clinical trial platforms, and R&D environments. You will manage a team of analysts to deliver strategic, operational, and tactical intelligence that reduces enterprise risk by partnering with Vulnerability Management, Detection Engineering, and Incident Response teams. Key responsibilities include developing adversary prioritization frameworks, modeling attack paths across IT-to-OT pivots, performing structured threat actor attribution using the Diamond Model, and monitoring dark web forums for credential leaks or infrastructure overlaps. You will utilize tools including TIP, SIEM, EDR, and Sigma/KQL/SPL to automate enrichment and develop detections-as-code. The role requires expertise in MITRE ATT&CK (Enterprise/ICS) and specialized knowledge of pharmaceutical manufacturing continuity, clinical data integrity, and R&D intellectual property protection within a complex global infrastructure.

What you'll do

  • Define the CTI vision, operating model, and roadmap to reduce risks across manufacturing, clinical trials, and R&D environments.
  • Develop an adversary prioritization framework based on intent, capability, and specific organizational exposure to vulnerabilities.
  • Build end-to-end attack path models mapping IT-to-OT pivots to MITRE ATT&CK to identify control gaps and inform hunt hypotheses.
  • Monitor dark web forums and closed channels to identify credential leaks and threats against manufacturing or research assets.
  • Provide technical context for incident response, including kill-chain reconstruction and containment recommendations during active security events.
  • Partner with Vulnerability Management to provide risk-based patching prioritization based on exploitability and weaponization data.
  • Collaborate with Detection Engineering to develop "detections-as-code" and improve the accuracy of automated security alerts.
  • Produce executive reports that translate complex technical threat intelligence into quantified risk narratives for senior leadership.

What we're looking for

  • Bachelor's degree in a relevant field such as Computer Science, Information Security, or Intelligence Studies.
  • One or more of GCTI, GREM, GRID, GCIH, CISSP, or equivalent demonstrated expertise.
  • 10+ years of experience in cyber threat intelligence, detection engineering, incident response, or related domains.
  • 5+ years of experience leading technical CTI teams in global enterprises.
  • Expertise mapping TTPs to MITRE ATT&CK (Enterprise/ICS) and developing detections-as-code.
  • Experience with dark web monitoring, TIP/SIEM integration, and automated indicator lifecycle management.
  • Ability to communicate complex technical intelligence to executive leadership and cross-functional partners.
  • Experience in pharmaceuticals, life sciences, or manufacturing; familiarity with OT/ICS ecosystems (preferred).

More like this

Similar roles

Principal Applied Threat Intelligence Manager

Microsoft

Redmond, WA +1 61 days ago $142,800–$274,800
Threat Intelligence AI Large Language Models MITRE ATT&CK Cyber Kill Chain Diamond Model Python PowerShell C# C++ Reverse-engineering Anomaly Detection Vulnerability Research Network Protocols Incident Response
10+ yrs exp

Senior Manager, Cyber Threat Research & Intelligence

Adobe

San Jose, CA +2 19 days ago $150,700–$306,625
MITRE ATT&CK YARA Sigma Rules SIEM SOAR TIP OSINT Malware Analysis Dark Web Monitoring Incident Response Detection Engineering Intelligence Lifecycle Structured Analytic Techniques Diamond Model
8+ yrs exp

Director, Cyber Threat Intelligence

Target

Brooklyn Park, MN 29 days ago $149,000–$268,000
Cyber Threat Intelligence SIEM SOAR EDR Vulnerability Management Malware Research Passive DNS Virus Total Machine Learning Artificial Intelligence Phishing DDoS Information Security
7+ yrs exp Hybrid

Cybersecurity Insider Threat Director

Citi

Tampa, FL +1 42 days ago $170,000–$300,000
Artificial Intelligence Cybersecurity Insider Threat Data Analytics Threat Intelligence Incident Response Risk Management Governance, Risk, and Compliance Information Security Security Operations Digital Transformation
10+ yrs exp Hybrid