Senior Director, Digital Forensics & Incident Response

AstraZenecaGaithersburg, MD
$190,957 - $286,435Hybrid

About The Position

The Senior Director, Digital Forensics & Incident Response owns AstraZeneca’s global capability to respond to and investigate cyber incidents. This role commands the enterprise response to material incidents across cloud, on-premises and OT/ICS environments; owns incident governance, readiness and the forensic defensibility of all collected evidence; and is accountable for executive reporting, lessons learned and the control hardening that follows. This is a build role as AstraZeneca matures its internal incident response capability. The successful candidate will compose the function, hire the team and establish the standards under which it operates. The role leads through a Director, Forensics & Malware Analysis, and a global CSIRT working follow-the-sun alongside Regional Security Operations Centers in Macclesfield, Guadalajara, Chennai and Shanghai. The role partners closely with Detection Engineering, Cyber Threat Intelligence, Threat Exposure Management, Insider Risk & DLP, IT, Legal, Privacy, Risk & Compliance, Corporate Communications, Insurance and Physical Security. Because AstraZeneca’s research and development intellectual property is a primary target for nation-state actors, and its manufacturing estate carries safety and supply consequences, the judgement exercised during an incident has consequences well beyond IT.

Requirements

  • Proven command across the full lifecycle at enterprise scale, including preparation, detection, scoping, containment, eradication, recovery and post-incident review, supported by appropriate plans and playbooks.
  • Experience managing the collection, preservation and analysis of digital evidence; chain of custody; timeline reconstruction; attribution; and concise executive reporting of forensic findings.
  • Deep working knowledge of the attack lifecycle and MITRE ATT&CK, common threat actor tactics, techniques and procedures, and the different behaviours of nation-state and ransomware operators once inside an environment.
  • Experience operationalising modern security tooling, including SIEM, SOAR and XDR, together with artificial intelligence, large language model and agentic capabilities to enable triage, analysis and eradication at scale, with clear human accountability for consequential decisions.
  • Understanding of telemetry and logging priorities across major cloud platforms, identity providers, operating systems and security tooling, including the forensic limitations of each.
  • Experience coordinating response in manufacturing OT/ICS environments where safety, validated systems and production continuity constrain responder actions.
  • Experience working within GxP and validated-system requirements, clinical and patient data sensitivities and third-party exposure considerations.
  • Ability to build durable partnerships with Legal, Privacy, Risk and Compliance, Communications and Physical Security, and to operate comfortably under privilege.
  • Experience maintaining retainer partner readiness and integrating external specialists during major incidents without losing command of the response.
  • Bachelor’s degree in information security, computer science or a related field, or equivalent practical experience.
  • Ten or more years of experience in cybersecurity, including seven or more years in incident response or digital forensics.
  • Five or more years leading incident response in a large, complex enterprise, including at least two years managing other people leaders or managers.
  • Demonstrable record as the accountable commander for high-severity incidents spanning hybrid cloud, on-premises and OT environments.
  • Experience running or integrating distributed 24x7 teams across multiple regions and cultures, including follow-the-sun handoffs.
  • Ability to explain complex technical situations in clear business terms, produce concise written material under time pressure and lead briefings for senior executives.
  • Ability to assess incomplete information, weigh risk and balance strategic and tactical demands against business pragmatism and risk appetite.
  • Demonstrated ability to collaborate across IT, Legal, GRC and Physical Security, with a strong service orientation.
  • Willingness to serve as the senior escalation point outside business hours and to travel internationally as incidents and readiness activities require.

Nice To Haves

  • CISSP, CISM, GIAC certifications such as GCIH, GCFA, GREM or GNFA, and CCSP.
  • Experience in pharmaceutical, life sciences, healthcare or another highly regulated industry with significant manufacturing OT exposure.
  • Experience briefing an audit committee or board, or engaging directly with regulators or law enforcement during a significant incident.
  • Experience negotiating and governing Incident Response retainers and forensic vendor arrangements across multiple jurisdictions.
  • Working proficiency in a second language relevant to AstraZeneca’s delivery hubs.

Responsibilities

  • Act as the accountable commander for material and crisis-level cyber incidents, driving scoping, containment, eradication, recovery and investigation across hybrid cloud, on-premises and OT/ICS environments.
  • Own the Incident Response strategy, multi-year roadmap, operating budget and capability plan, setting direction and standards with a high degree of autonomy.
  • Define and maintain incident categories, severity definitions, activation criteria, decision authorities, delegation of authority during out-of-hours events and the handoff into enterprise crisis management.
  • Through the Director, Forensics & Malware Analysis, ensure that evidence is preserved, collected and analysed with chain-of-custody rigor that stands up to legal and regulatory scrutiny. Own the relationship with Legal regarding litigation hold, privilege and retention.
  • Run a calendar of tabletop, functional and purple-team exercises reaching from analyst level to the Executive Committee. Close findings and evidence improvement.
  • Guarantee 24x7 response coverage with credible follow-the-sun handoffs, issue paths and surge capacity, including in-country arrangements where data-localisation or sanctions constraints apply.
  • Operationalise agentic SIEM capability, XDR and SOAR playbooks, LLM-assisted runbooks and automated triage packages to compress mean time to detect, mean time to contain and mean time to respond without eroding evidentiary quality or human accountability.
  • Own Incident Response targets and key risk indicators, including mean time to detect, contain and respond, dwell time, containment quality and business impact. Report these credibly to senior leadership.
  • Deliver incident briefings, written updates and quarterly lessons-learned reviews to the CISO and IT leadership and, where warranted, the Audit Committee.
  • Work with Legal, Privacy and Compliance to support breach-notification assessments and regulatory obligations across the countries in which AstraZeneca operates, including material-incident disclosure considerations.
  • Drive post-incident detection and control improvements with Detection Engineering, Identity, Cloud, Endpoint, Network and OT teams.
  • Design and staff the DFIR function from a near-zero baseline, defining roles, levels, sourcing locations and the balance of permanent and retained capacity.
  • Manage a Director-level leader and incident managers; set objectives, review performance and develop successors capable of commanding an incident in the Senior Director’s absence.
  • Maintain on-call rotations, surge models and cross-regional handoff standards, and act as the senior critical issue point when severity demands it.
  • Lead inclusive recruitment and build genuine career paths and upskilling in DFIR, cloud and identity forensics, OT/ICS, malware analysis and automation, using regional and external partnerships.
  • Protect the team from the burnout that can follow sustained high-tempo response. Design rotations, recovery and workload distribution deliberately.
  • Own the service line budget, tooling and retainer spend, and build the case for further investment.

Benefits

  • short-term incentive bonus opportunity
  • equity-based long-term incentive program
  • retirement contribution
  • commission payment eligibility
  • qualified retirement program [401(k) plan]
  • paid vacation and holidays
  • paid leaves
  • health benefits including medical, prescription drug, dental, and vision coverage
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service