Director, Cyber Security Incident Response Team (CSIRT)

AstraZeneca
Gaithersburg, MD
Category Security
Job Description
Role Overview

The Director, CSIRT is a senior individual contributor leader in the Global Cybersecurity Operations Center (GSOC), based in Gaithersburg, Maryland, reporting to the Head of GSOC. You will command enterprise response to material cyber incidents across cloud, on-premises, and OT/ICS environments, own incident governance and readiness, and drive executive reporting, lessons learned, and control hardening in partnership with Detection Engineering, CTI, Vulnerability Management, Offensive Security, IT, Legal, Risk and Compliance, and Physical Security.

What You Will Do

Incident Command: Lead execution of the Incident Response (IR) plan to rapidly scope, contain, eradicate, and investigate incidents across hybrid and OT environments. Incident Governance: Define and maintain incident categories, severity, decision authorities, activation criteria, and crisis management handoffs. Forensics evidence handling: Coordinate preservation, collection, and analysis with chain-of-custody rigor; in collaboration with Legal, manage asset litigation hold and retention as well as facilitation of artifact sharing for malware analysis and CTI.

Why It Might Be a Fit

The ideal candidate will have a proven command across cyber incident lifecycles, plans and playbooks, and deep understanding of the incident lifecycle, from preparation to scoping, containment, eradication, and remediation at enterprise scale. Experience with operationalization of modern security tools (SIEM, SOAR, XDR) including integration of artificial intelligence, large language models, and agentic features to enable triage, analysis, and eradication at scale is also required.

Requirements

  • Bachelor's degree in information security, computer science, or related field (or equivalent experience)
  • Over five (5) years managing Cyber Security Operations Centre Incident Response in enterprise-sized organizations, commanding events across hybrid cloud, on-prem, and OT.
  • Global coordination with Regional SOCs: Experience integrating and working alongside global, 24x7, distributed teams to complete incident response and cyber operations missions.
  • Communication and facilitation: Well-developed skills to explain complex technical issues in clear business terms; produce concise written material (executive updates, IR reports); and lead briefings.
  • Analytical decision making: Ability to analyze complex situations, assess risk, and balance strategic and tactical security requirements with business pragmatism, risk appetite, and innovation.

Benefits

  • qualified retirement program (401(k) plan)
  • paid vacation and holidays
  • paid leaves
  • health benefits including medical, prescription drug, dental, and vision coverage
]]>