Senior Director, Cyber Exposure Management

AstraZenecaGaithersburg, MD
Hybrid

About The Position

This role owns the enterprise understanding of vulnerabilities and weaknesses, driving their closure before attackers can exploit them. Based in Gaithersburg, Maryland, the Senior Director will lead three key capabilities: Vulnerability Management, Application Security, and Penetration Testing/Red Team. The position is a build-and-uplift mandate, aiming to transition from a scan-and-ticket approach to modern, risk-based exposure management, establish application security as a true assurance function, and evolve offensive testing into a continuous, intelligence-led capability. The role requires partnering across engineering, cloud, product, and operations to prioritize real-world risk at machine speed and validate defense effectiveness.

Requirements

  • Risk-based vulnerability management: Prioritization using asset criticality, exploitability, and intelligence; remediation governance and SLA management at enterprise scale.
  • Application security: Secure SDLC, SAST/DAST/SCA, threat modeling, API and cloud-native application security, and developer enablement that changes behavior rather than just reporting findings.
  • Offensive security: Penetration testing and adversary emulation across applications, infrastructure, cloud, and OT, and the use of purple teaming to improve detection.
  • Attack surface and cloud: External and internal attack surface management across cloud, SaaS, and third-party exposure.
  • Software supply chain: Open-source and third-party component risk, SBOM practice, and rapid response to widely exploited components.
  • AI-era exploitation: Understanding how machine-speed vulnerability discovery and weaponization change prioritization, and the security considerations of the organization’s own AI systems.
  • Regulated and OT context: Exposure management in GxP and OT/ICS environments where patching and testing are constrained by validation, safety, and uptime.
  • Remediation through others: Driving fixes through asset-owning teams, governing risk acceptance, and keeping reporting defensible.
  • Education: Bachelor's degree or equivalent experience in information security, computer science, or a related field, or equivalent practical experience.
  • Depth: Ten or more years in cybersecurity, including significant experience across vulnerability, application, or offensive security.
  • Leadership scale: Five or more years leading exposure, application security, or offensive functions in a large enterprise, including at least two years managing other people leaders.
  • Program credibility: Demonstrable record of maturing a vulnerability or application security program and measurably reducing risk.
  • Cross-functional delivery: Proven track record to drive remediation through teams you do not control, across IT, Cloud, Engineering, and business units.
  • Communication and facilitation: Ability to explain exposure and prioritization in clear business terms and to brief senior executives and risk committees.
  • Analytical decision making: Ability to prioritize finite remediation capacity against real-world risk and business pragmatism.
  • Global coordination: Experience leading distributed teams across multiple regions and cultures.

Nice To Haves

  • Certifications: CISSP, CISM, OSCP, GIAC (GWAPT, GPEN, GXPN, GCPN) or equivalent.
  • Sector experience: Pharmaceutical, life sciences, healthcare, or another highly regulated industry with manufacturing OT exposure.
  • Board exposure: Experience briefing an audit committee, board, or risk committee on exposure and remediation.
  • Commercial: Experience selecting and governing scanning, application security, and offensive tooling and specialist testing partners.
  • Language: Working proficiency in a second language relevant to our delivery hubs.

Responsibilities

  • Own and deliver a multi-year strategy across Vulnerability Management, Application Security, and Penetration Testing, with clear roadmaps, budgets, and capability plans.
  • Evolve from volume-based scanning to prioritized exposure management using asset criticality, exploitability, and threat intelligence; implement enterprise remediation governance and SLAs.
  • Maintain continuous visibility of internal and external attack surfaces, including cloud, SaaS, and third-party exposure, focusing effort where real-world risk is highest.
  • Run a secure development assurance program covering SAST, DAST, and SCA; drive developer enablement and behaviors for software built and bought.
  • Oversee software composition risk, SBOM practices, and rapid response to widely exploited components; guide investment and policy.
  • Operate a continuous program of penetration testing and adversary emulation across applications, infrastructure, cloud, and OT; run purple-team exercises with Threat Management to harden detection and response.
  • Prepare for machine-speed exploit generation by automating discovery, prioritization, and validation; assess the security of AI and large language model systems.
  • Drive fixes through accountable asset owners; escalate and govern risk acceptance; keep reporting honest and defensible.
  • Own exposure KRIs (mean time to remediate, SLA attainment, recurrence, coverage, critical exposure ageing) and report credibly to senior leadership and risk committees.
  • Feed findings from offensive testing and cyber intelligence into prioritization; incorporate incident learnings so testing reflects actual attack methods.
  • Translate technical exposure into business risk for the CISO, IT leadership, and the Board; defend prioritization decisions under scrutiny.
  • Lead and uplift a multi-disciplinary team of roughly eighteen across regions, raising posture from operational scanning to strategic exposure management while preserving independence and integrity.
  • Manage the leaders of Vulnerability Management, Application Security, and Penetration Testing; set objectives, review performance, and build succession.
  • Recruit inclusively; develop career paths and upskilling in exposure management, cloud and application security, offensive testing, and automation; leverage regional and external partnerships.
  • Own budgets for scanning, application security, and offensive tooling and specialist partners; build investment cases that maximize business risk reduction.

Benefits

  • Flexibility to balance in-office and remote work
  • Opportunity to work in a unique and ambitious world
  • Access to pioneering platforms and a culture valuing curiosity, kindness, and ambition
  • Room, resources, and partnerships to move fast
  • Collaboration with diverse experts
  • Experimentation with new approaches
  • Continuous learning opportunities
  • Ability to turn bold ideas into impact at global scale
  • Leadership role shaping protection of critical research, manufacturing, and supply chains
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service