Hiring.Camp

Senior Director, Digital Forensics & Incident Response

AstraZeneca is

·

Yesterday

Salary
$191k – $286k
Location
US - Gaithersburg - MD, United States of America
Workplace
Hybrid
Type
Full-time
Department
IT
Seniority
Senior
Closing date
Today
Source
Workday

Description

About the Role:

The Senior Director, Digital Forensics & Incident Response owns AstraZeneca’s global capability to respond to and investigate cyber incidents. This role commands the enterprise response to material incidents across cloud, on-premises and OT/ICS environments; owns incident governance, readiness and the forensic defensibility of all collected evidence; and is accountable for executive reporting, lessons learned and the control hardening that follows.

This is a build role as AstraZeneca matures its internal incident response capability. The successful candidate will compose the function, hire the team and establish the standards under which it operates. The role leads through a Director, Forensics & Malware Analysis, and a global CSIRT working follow-the-sun alongside Regional Security Operations Centers in Macclesfield, Guadalajara, Chennai and Shanghai.

The role partners closely with Detection Engineering, Cyber Threat Intelligence, Threat Exposure Management, Insider Risk & DLP, IT, Legal, Privacy, Risk & Compliance, Corporate Communications, Insurance and Physical Security. Because AstraZeneca’s research and development intellectual property is a primary target for nation-state actors, and its manufacturing estate carries safety and supply consequences, the judgement exercised during an incident has consequences well beyond IT.

What You’ll Do:

  • Incident Command: Act as the accountable commander for material and crisis-level cyber incidents, driving scoping, containment, eradication, recovery and investigation across hybrid cloud, on-premises and OT/ICS environments.

  • Service Line Ownership: Own the Incident Response strategy, multi-year roadmap, operating budget and capability plan, setting direction and standards with a high degree of autonomy.

  • Incident Governance: Define and maintain incident categories, severity definitions, activation criteria, decision authorities, delegation of authority during out-of-hours events and the handoff into enterprise crisis management.

  • Forensic Defensibility: Through the Director, Forensics & Malware Analysis, ensure that evidence is preserved, collected and analysed with chain-of-custody rigor that stands up to legal and regulatory scrutiny. Own the relationship with Legal regarding litigation hold, privilege and retention.

  • Readiness and Exercises: Run a calendar of tabletop, functional and purple-team exercises reaching from analyst level to the Executive Committee. Close findings and evidence improvement.

  • Coverage Model: Guarantee 24x7 response coverage with credible follow-the-sun handoffs, issue paths and surge capacity, including in-country arrangements where data-localisation or sanctions constraints apply.

  • Automation and AI: Operationalise agentic SIEM capability, XDR and SOAR playbooks, LLM-assisted runbooks and automated triage packages to compress mean time to detect, mean time to contain and mean time to respond without eroding evidentiary quality or human accountability.

  • Metrics and Reporting: Own Incident Response targets and key risk indicators, including mean time to detect, contain and respond, dwell time, containment quality and business impact. Report these credibly to senior leadership.

  • Executive and Board Communication: Deliver incident briefings, written updates and quarterly lessons-learned reviews to the CISO and IT leadership and, where warranted, the Audit Committee.

  • Regulatory and Notification Support: Work with Legal, Privacy and Compliance to support breach-notification assessments and regulatory obligations across the countries in which AstraZeneca operates, including material-incident disclosure considerations.

  • Controls Hardening: Drive post-incident detection and control improvements with Detection Engineering, Identity, Cloud, Endpoint, Network and OT teams.

Leading the Function:

  • Build and Organization Design: Design and staff the DFIR function from a near-zero baseline, defining roles, levels, sourcing locations and the balance of permanent and retained capacity.

  • Leading Through Leaders: Manage a Director-level leader and incident managers; set objectives, review performance and develop successors capable of commanding an incident in the Senior Director’s absence.

  • Coverage and On-Call: Maintain on-call rotations, surge models and cross-regional handoff standards, and act as the senior critical issue point when severity demands it.

  • Talent and Capability: Lead inclusive recruitment and build genuine career paths and upskilling in DFIR, cloud and identity forensics, OT/ICS, malware analysis and automation, using regional and external partnerships.

  • Team Sustainability: Protect the team from the burnout that can follow sustained high-tempo response. Design rotations, recovery and workload distribution deliberately.

  • Budget and Commercial Management: Own the service line budget, tooling and retainer spend, and build the case for further investment.

Knowledge, Experience and Understanding:

  • Incident Command and the Incident Response Lifecycle: Proven command across the full lifecycle at enterprise scale, including preparation, detection, scoping, containment, eradication, recovery and post-incident review, supported by appropriate plans and playbooks.

  • Digital Forensics and Evidence Handling: Experience managing the collection, preservation and analysis of digital evidence; chain of custody; timeline reconstruction; attribution; and concise executive reporting of forensic findings.

  • Attacker Tradecraft: Deep working knowledge of the attack lifecycle and MITRE ATT&CK, common threat actor tactics, techniques and procedures, and the different behaviours of nation-state and ransomware operators once inside an environment.

  • Automation and AI in Operations: Experience operationalising modern security tooling, including SIEM, SOAR and XDR, together with artificial intelligence, large language model and agentic capabilities to enable triage, analysis and eradication at scale, with clear human accountability for consequential decisions.

  • Cloud, Identity and Endpoint Visibility: Understanding of telemetry and logging priorities across major cloud platforms, identity providers, operating systems and security tooling, including the forensic limitations of each.

  • Operational Technology: Experience coordinating response in manufacturing OT/ICS environments where safety, validated systems and production continuity constrain responder actions.

  • Regulated-Industry Constraints: Experience working within GxP and validated-system requirements, clinical and patient data sensitivities and third-party exposure considerations.

  • Legal, Regulatory and Crisis Communications: Ability to build durable partnerships with Legal, Privacy, Risk and Compliance, Communications and Physical Security, and to operate comfortably under privilege.

  • Vendor and Retainer Readiness: Experience maintaining retainer partner readiness and integrating external specialists during major incidents without losing command of the response.

Minimum Skills and Experience Required

  • Education: Bachelor’s degree in information security, computer science or a related field, or equivalent practical experience.

  • Professional Experience: Ten or more years of experience in cybersecurity, including seven or more years in incident response or digital forensics.

  • Leadership Experience: Five or more years leading incident response in a large, complex enterprise, including at least two years managing other people leaders or managers.

  • Command Experience: Demonstrable record as the accountable commander for high-severity incidents spanning hybrid cloud, on-premises and OT environments.

  • Global Coordination: Experience running or integrating distributed 24x7 teams across multiple regions and cultures, including follow-the-sun handoffs.

  • Communication and Facilitation: Ability to explain complex technical situations in clear business terms, produce concise written material under time pressure and lead briefings for senior executives.

  • Analytical Decision-Making: Ability to assess incomplete information, weigh risk and balance strategic and tactical demands against business pragmatism and risk appetite.

  • Cross-Functional Credibility: Demonstrated ability to collaborate across IT, Legal, GRC and Physical Security, with a strong service orientation.

  • Availability: Willingness to serve as the senior escalation point outside business hours and to travel internationally as incidents and readiness activities require.

Desirable Skills and Experience

  • Certifications: CISSP, CISM, GIAC certifications such as GCIH, GCFA, GREM or GNFA, and CCSP.

  • Sector Experience: Experience in pharmaceutical, life sciences, healthcare or another highly regulated industry with significant manufacturing OT exposure.

  • Board and Regulator Exposure: Experience briefing an audit committee or board, or engaging directly with regulators or law enforcement during a significant incident.

  • Commercial Experience: Experience negotiating and governing Incident Response retainers and forensic vendor arrangements across multiple jurisdictions.

  • Language Skills: Working proficiency in a second language relevant to AstraZeneca’s delivery hubs.

When we put unexpected teams in the same room, we unleash bold thinking with the power to encourage life-changing medicines. In-person working gives us the platform we need to connect, work at pace and challenge perceptions. That's why we work, on average, a minimum of three days per week from the office. But that doesn't mean we're not flexible. We balance the expectation of being in the office while respecting individual flexibility. Join us in our unique and ambitious world.

The annual base pay for this position ranges from $190,957 - $286,435 USD Annual. Hourly and salaried non-exempt employees will also be paid overtime pay when working qualifying overtime hours. Base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. In addition, our positions offer a short-term incentive bonus opportunity; eligibility to participate in our equity-based long-term incentive program (salaried roles), to receive a retirement contribution (hourly roles), and commission payment eligibility (sales roles). Benefits offered included a qualified retirement program [401(k) plan]; paid vacation and holidays; paid leaves; and, health benefits including medical, prescription drug, dental, and vision coverage in accordance with the terms and conditions of the applicable plans. Additional details of participation in these benefit plans will be provided if an employee receives an offer of employment. If hired, employee will be in an “at-will position” and the Company reserves the right to modify base pay (as well as any other discretionary payment or compensation program) at any time, including for reasons related to individual performance, Company or individual department/team performance, and market factors.

Are you ready to bring new insights and fresh thinking to the table? Fantastic! We have one seat available, and we hope it’s yours. Apply today.

AstraZeneca embraces diversity and equality of opportunity. We are committed to building an inclusive and diverse team representing all backgrounds, with as wide a range of perspectives as possible, and harnessing industry-leading skills. We believe that the more inclusive we are, the better our work will be. We welcome and consider applications to join our team from all qualified candidates, regardless of their characteristics. We follow all applicable laws and regulations on non-discrimination in employment (and recruitment), as well as work authorization and employment eligibility verification requirements.

Date Posted

20-Aug-2026

Closing Date

02-Sep-2026

Our mission is to build an inclusive environment where equal employment opportunities are available to all applicants and employees. In furtherance of that mission, we welcome and consider applications from all qualified candidates, regardless of their protected characteristics. If you have a disability or special need that requires accommodation, please complete the corresponding section in the application form.

Skills

CybersecuritySIEMComplianceCISSP

Similar Jobs

30

Senior Director, Digital Forensics & Incident Response

AstraZeneca · Gaithersburg, MD,US, US · Hybrid

Yesterday

Senior Director, Digital Forensics & Incident Response

Astrazeneca · US - Gaithersburg - MD, United States of America · Hybrid

Yesterday

Senior Digital Infrastructure Design Director

AECOM · Conshohocken, PA, United States · Remote

Yesterday

Senior Director, Digital Workspace

Gapinc · SF - 2 Folsom, United States of America +1 · Remote

2 days ago

Senior Director, Integration and Digital Data Flows

Amgen is committed to unlocking · India - Hyderabad · Onsite

2 days ago

Sr. Director Global Operations Digital Partner

Ingredion · Westchester, IL, United States of America · Hybrid

3 days ago

Senior Director, Nike Direct Digital Commerce (NDDC) Japan

Nike · TOKYO, Japan

1 week ago

Senior Director, Digital Product

Stand Together · Arlington, Virginia · Onsite

1 week ago

Sr. Director, Digital Experience & AI

Acrisure · 401 N Michigan Ave, Ste 2400 - CHICAGO, IL, United States of America +4

1 week ago

Senior Director, Computational Sciences & Digital Engineering

Entegris · Taiwan - Hsinchu · Remote, Hybrid

1 week ago

Digital Technology - Senior Director/Director, Ecommerce Engineering

Aritzia · Seattle, WA, USA (SO - Seattle), United States of America +1

1 week ago

Sr Mgr/Dep Director ASIC Digital Design IP ENGINEERING

Global Foundries · USA - California - Santa Clara, United States of America

1 week ago

Senior Director, Digital Channels, Insurance Tech

Rbc · MEADOWVALE BUSINESS PARK, 6880 FINANCIAL DR:MISSISSAUGA, Canada

2 weeks ago

Senior Director, Digital Operations

Coke · US - GA - Atlanta, United States of America

2 weeks ago

Senior Director, Digital & Technology Operations

Coke · Mexico - Mexico City

2 weeks ago

Custody Risk & Control, Digital Assets Senior Manager - Director

Citi Bank · 3800 CITIGROUP CENTER DRIVE BUILDING B TAMPA, United States of America · Hybrid

2 weeks ago

Custody Risk & Control, Digital Assets Senior Manager - Director

citibank · Tampa, FL,US, US

2 weeks ago

Senior Director, Digital Transformation GCM

Coke · China - Shanghai

2 weeks ago

Senior Director, Digital Transformation - ASEAN & South Pacific

Coke · Singapore - Singapore

2 weeks ago

Senior Director, Digital Transformation Africa

Coke · South Africa - Johannesburg

2 weeks ago

Sr Director Digital Marketing – Zale

Signetjewelers · Support Center - Irving, TX, United States of America

2 weeks ago

Digital Senior Director — Finance Transformation, Financial Services

Huron · Chicago - 550 Van Buren, United States of America · Remote

2 weeks ago

Digital Senior Director — Data & Analytics, Financial Services

Huron · Chicago - 550 Van Buren, United States of America · Remote

2 weeks ago

Senior Director, Digital Experience

Join the team making a genuine difference · USA MOT Alton Rd Campus AL00, United States of America · Onsite

2 weeks ago

Senior Director, Intelligent Equipment - Sensing, Analytics, and Digital Innovation

Danaher · USA - Marlborough Results Way - Multiple OpCo, United States of America +2 · Onsite

2 weeks ago

Sr. Director, Engineering - Digital Video & Audio (DVA)

Adobe · San Jose, United States of America +2 · Hybrid

3 weeks ago

Senior Director - Digital Workplace

3Cloud · Remote - US · Remote

3 weeks ago

Digital Product & eCommerce Senior Director

Whataburger · San Antonio Home Office, United States of America

3 weeks ago

Director/Senior Director, QMS, Digital QA and GxP Compliance

Crescent Biopharma · Waltham, MA · Onsite

3 weeks ago

Senior Director - Digital Engineering and Applications

NCS Australia · Sydney, NSW, Australia · Hybrid

3 weeks ago
Senior Director, Digital Forensics & Incident Response at AstraZeneca is • $191k – $286k | Hiring.Camp