Director, Cyber Security Detection Engineering
$169.32k - $253.98kAstraZeneca
About Role The Director, Cyber Security Detection Engineering is a senior leader in the Cyber Operations function, based in Gaithersburg, Maryland, working with the Head of Cyber Operations. The role encompasses command of enterprise detection capabilities across cloud, on‑premises, and OT/ICS environments, ownership of detection governance and validation, and delivery of executive reporting, coverage assessments, and capability maturation in partnership with GSOC, CTI, Vulnerability Management, Offensive Security, IT, Legal, Risk and Compliance, and business customers. What You’ll Do Detection strategy and roadmap: Direct the development and execution of comprehensive detection engineering programs aligned to interpersonal risk appetite and threat landscape; establish capability roadmaps spanning data engineering, detection development, purple teaming, and automation/AI. Data engineering oversight: Ensure robust data pipelines support detection activities through telemetry collection, normalization, and quality assurance across hybrid and OT environments; define data retention, schema standards, and platform configuration to enable effective threat detection. Detection content development: Oversee creation, testing, and deployment of detection logic across SIEM, EDR, and cloud‑native tooling; enforce detection standards, naming conventions, and MITRE ATT&CK mapping; prioritize coverage based on threat intelligence and risk assessments. Purple Team Exercising: Oversee purple team operations to validate detection efficacy systematically; orchestrate adversary emulation exercises across technology domains; drive remediation of detection gaps identified through testing and operational feedback. Automation and AI integration: Operationalise AI agents, machine learning models, and orchestration workflows to enhance detection accuracy, reduce false positives, and augment GSOC analyst capabilities; oversee development of automated enrichment, triage, and investigation playbooks. Metrics and reporting: Own detection engineering targets (e.g., MITRE ATT&CK coverage, mean time to detect, false positive rates, purple team success metrics) and deliver executive‑ready briefings, dashboards, and quarterly maturity assessments. Policy and governance: Develop and enforce detection engineering policies, standards, and quality frameworks; maintain detection content libraries with version control and organizational change field; ensure regulatory compliance in data handling. People Leadership Strategy and planning: Develop and maintain detection engineering area plans aligned to Cyber Operations strategy; set direction and goals with autonomy across data engineering, detection development, purple teaming, and automation functions. Performance and tiers: Define and review reporting and team targets; align objectives to detection outcomes, coverage improvements, and operational efficiency. Talent and capability: Lead inclusive recruitment; build career paths and targeted upskilling in detection development, threat hunting, cloud security, OT/ICS detection, and SOAR/AI through multi‑functional, regional, and external partnerships. Knowledge, Experience, and Understanding Of Detection engineering lifecycle: Proven leadership across detection development, testing, deployment, and tuning at enterprise scale; deep understanding of detection logic design, coverage mapping, and efficacy validation. Threat detection frameworks: Extensive knowledge of MITRE ATT&CK, Cyber Kill Chain, and detection engineering methodologies; experience mapping organisational coverage and prioritising development based on threat intelligence. Purple team operations: Experienced in designing and accomplishing adversary emulation exercises; skilled in translating purple team findings into actionable detection improvements and coverage enhancements. Automation and AI: Experience operationalizing modern detection platforms (SIEM, XDR, SOAR) including integration of artificial intelligence, machine learning models, and agentic features to enable detection at scale. Data engineering and platforms: Proficient with data pipeline architecture, log aggregation, normalisation, and query optimisation; solid grasp of data quality requirements for effective detection. Cloud, identity, and endpoint detection: Deep understanding of detection approaches across multi‑cloud environments, identity systems, endpoints, and network infrastructure; familiar with cloud‑native security services and integration patterns. Manufacturing Operational Technology/Industrial Control Systems: Coordinating detection engineering in industrial/OT environments with safety, availability, and production continuity considerations; knowledge of industrial protocols and OT‑specific threats. Minimum Skills & Experience Required Education: Bachelor's degree in information security, computer science, or related field (or equivalent experience). Enterprise‑scale detection leadership: Over 5 years managing detection engineering or security operations in enterprise‑sized organisations, commanding capabilities across hybrid cloud, on‑premises, and OT environments. Global coordination with distributed teams: Experience integrating and working alongside global, 24×7, geographically dispersed teams to deliver detection capabilities and support security operations missions. Communication and facilitation: Well‑developed skills to explain complex technical concepts in clear business terms; produce concise written material (executive updates, coverage reports); and lead briefings to diverse stakeholders. Analytical decision making: Ability to analyse complex threat landscapes, assess detection gaps, and balance strategic capability development with tactical operational requirements, risk appetite, and resource constraints. Customer orientation and cross‑cultural working: Demonstrated ability to collaborate across regions and functions with a strong service approach and commitment to enabling organisational resilience. Preferred Skills & Experience Certifications: Security certifications preferred (e.g., CISSP, CISM, GIAC such as GCIA/GCDA/GMON; cloud certifications; ITIL). Benefits The annual base pay for this position ranges from $169,320.00 – $253,980.00 USD annually. Eligible employees may participate in a short‑term incentive bonus program, an equity‑based long‑term incentive program (for salaried roles), and a 401(k) retirement plan. Benefits include paid vacation, holidays, and medical, prescription drug, dental, and vision coverage per the company plans. Equal Employment Opportunity Statement AstraZeneca embraces diversity and equality of opportunity. The company is committed to creating an inclusive environment and welcomes applicants from all qualified candidates, regardless of characteristics. AstraZeneca follows all applicable non‑discrimination laws and regulations, and complies with work authorization and employment eligibility verification requirements. Date Posted: 28‑May‑2026 Closing Date: 17‑Jun‑2026 #J-18808-Ljbffr
- ...pharmaceutical companies. At AstraZeneca, we're dedicated to being a Great Place to Work. ABOUT ROLE: The Director, Cyber Security Detection Engineering is a senior leader in the Cyber Operations function, based in Gaithersburg, Maryland, working with the Head of...SuggestedHourly payTemporary workWork at officeFlexible hours3 days per week
$169.32k - $253.98k
...Director, CSIRT Senior individual contributor leader in... ...enterprise response to cyber incidents across cloud,... ...Communications, Physical Security, and Insurance for... ...communications. Drive post‑incident detection and control improvements with Detection Engineering, Identity, Cloud,...SuggestedHourly payTemporary work$180k - $205k
...position is responsible for the development and execution of cyber security engineering strategies and activities in support of plant design and... ...techniques, and procedures as well as indicators of attack to detect adversaries. Develop threat intelligence to detect, respond...SuggestedFull timeWork at office- ...Place to Work. ABOUT ROLE The Senior Detection Engineer is a technical specialist within the Global Security Operations Centre (GSOC), based in Gaithersburg, Maryland, working with the Director, Cyber Security Detection Engineering. The role is...SuggestedHourly payTemporary workWork experience placementWork at officeFlexible hours3 days per week
- ...Industries (FPI). Our depth of experience allows us to provide IT security support for a wide range of IT General Support Systems (GSS)... ...difficult and narrowly defined technical problems in engineering and other scientific applications to arrive at automated solutions...SuggestedContract workWork at office
$120k - $150k
...Information Systems Security Officer Location US-MD-... ...189 Category IT / Cyber Security / Network Systems... ...Evaluation, Program Mission Support, Engineering & Analysis, and Training.... ...security logs and alerts to detect and respond to security incidents...Full timeFor contractorsRemote work- ...government ensure the well being of U.S. citizens. Job Description Seize your opportunity to make a personal impact as a Sr. Cyber Security Analyst supporting our HHS HRSA customer onsite. GDIT is your place to make meaningful contributions to challenging projects and...
$86k - $138k
...Cyber Systems Administration, Lead Associate Job Locations US-MD-Germantown... ...6961 Position Category Cyber Security Clearance CBOSS Agency... ...protection controls Manage and tune Intrusion Detection/Prevention Systems (IDS/IPS) integrated...Contract workShift work- ...Hoplite Solutions is seeking multiple Cyber Security Engineers. This role is responsible for protecting the customer’s information systems... ...software, such as firewalls (Security Groups), intrusion detection/intrusion prevention, anti-virus/malware (HBSS), cryptography...Full timeTemporary workWork experience placement
$86k - $138k
Cyber Systems Administration, Lead Associate Job Locations: US-MD-Germantown Requisition... ...: 2026-165996 Position Category: Cyber Security Clearance: CBOSS Agency Clearance... ...including next-generation firewalls, intrusion detection/prevention systems (IDS/IPS). Manage...Contract workShift work$107.9k - $195.05k
A leading defense contractor is seeking a Senior SCRM Analyst to conduct Cyber Supply Chain Risk Assessments and monitor adherence to security regulations. Candidates should have an active Top Secret clearance, significant experience in cybersecurity and risk management...For contractors$87.1k - $157.45k
...Endpoint Cyber Engineer – Leidos The Leidos Corporate Information Security Office, within the Digital Modernization sector, has an immediate opening for an Endpoint... ...Management, Application Allow Listing, Endpoint Detection and Response, etc.) Applying advanced knowledge...Work at officeImmediate startRemote work$87.1k - $157.45k
...The Leidos Corporate Information Security Office, within the Digital Modernization... ...an immediate opening for an Endpoint Cyber Engineer to join our Cyber Information Security... ...Management, Application Allow Listing, Endpoint Detection and Response , etc.) Advanced...Work at officeLocal areaImmediate startRemote work$150k - $190k
...Senior Cybersecurity Analyst / Information Security Manager We are seeking a highly skilled Senior Cybersecurity Analyst / Information Security Manager with expertise in IT security, risk management, and policy development. The ideal candidate will have a minimum of...Full timeContract workPart timeFor contractorsRemote work$180k - $205k
...Alumni Ventures is seeking a Cyber Security Engineer responsible for development and execution of cyber security strategies in Rockville, Maryland. The role involves integrating cyber security into plant design and reviewing risks associated with security events. Applicants...- ...Regulatory Authority) is the largest independent regulator of securities firms in the U.S. It protects investors and ensures market integrity... ...the financial sector? As a Senior Principal Risk Specialist - Cyber Engagements, you will strengthen the industry's defenses...Local area
$141.92k - $212.89k
...Regulatory Authority) is the largest independent regulator of securities firms doing business in the United States. Our mission is to protect... ...the financial sector? As a Senior Principal Risk Specialist, Cyber Engagements, you'll play a pivotal role in strengthening the...For contractorsFor subcontractorLocal area- Financial Industry Regulatory Authority, Inc. is seeking a Senior Principal Risk Specialist - Cyber Engagements in Rockville, MD. This role is central to reinforcing cybersecurity resilience across the financial sector by leading tabletop exercises that simulate real-world...
$131.2k - $238.3k
FINRA is seeking a Senior Principal Risk Specialist focused on cybersecurity in Rockville, Maryland. In this role, you will lead cybersecurity tabletop exercises and workshops, develop formal engagement documentation, and serve as a trusted advisor on incident management...$107.9k - $195.05k
...Modernization sector is seeking an experienced Senior Zero Trust Cyber Security Analyst to support the delivery, enhancement, and adoption... ...In this role, you will work alongside government partners, engineers, and other industry teammates to translate operational and...Local areaImmediate start- ...thrives here. Summary: The Senior Cyber Threat Analyst will lead efforts to... ...a diverse group of teams including engineering, security, and network & system operations to ensure... ...with SIEM, SOAR, and EDR tools for detection and response It is the policy of...Remote workFlexible hours
- Leidos is seeking a Senior Zero Trust Cyber Security Analyst in Gaithersburg, Maryland. The role involves supporting the implementation of Zero Trust architecture and analyzing cybersecurity data to identify vulnerabilities. The ideal candidate must have an active Top...
$105.26k - $197.2k
CNSS • National Security Systems is looking for experienced Computer Science professionals to join our team at Fort George G. Meade. We offer roles like Capability Development Specialist, Software Engineer, and more, focusing on national security interests. Our positions...Trial period- ...Koitecc Solutions in Gaithersburg, MD, is seeking an Endpoint Cyber Engineer to enhance cyber defense strategies and support initiatives... ...cybersecurity, focusing on the design and implementation of endpoint security solutions, while collaborating with teams to achieve security...Remote work
$130k - $170k
...the SOC, responsible for advanced threat detection, incident response, threat hunting, and... ...identify, analyze, and mitigate sophisticated cyber threats impacting Agency systems.... ...Contribute to automation and detection engineering efforts (scripts, playbooks, orchestration...- ...RMS is seeking a Senior Cybersecurity Engineer / Offensive Security Lead to support high‑visibility... ...with federal stakeholders to strengthen cyber resilience across complex infrastructures... ...with defensive teams to validate detections and strengthen security posture. Maintain...
- ...is seeking a motivated Junior Identity Security Metrics Consultant & Databricks Analyst... ...(AI/ML) capabilities to improve fraud detection, identity authentication processes, and... ...Bachelors degree in Computer Science, Engineering, Management Information Systems, Cybersecurity...Full timeRemote workRelocation package
$68k - $119.83k
Description A Lockheed Martin Cyber Intel Analyst Associate will work within a globally... ...Creation and maintenance of resilient detections and countermeasures Consistent and effective... ...Demonstrated experience with in-depth security log analysis Unix/Linux experience and...Full timeTemporary workPart timeRemote workRelocationFlexible hoursShift work3 days per week- ...Description The Security Engineering Lead is responsible for engineering, implementing, and... ...alert tuning, and alignment with incident detection and response objectives. Lead... ...Software Engineering, Cloud Solutions, Cyber Security and IT Managed Services. With...Full timeFlexible hours
$155k - $165k
...level cybersecurity program in Rockville, MD. The role involves assisting the Cybersecurity Program Manager with risk assessment, security policy development, compliance monitoring, and report management. Candidates should have at least six years of experience in cybersecurity...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director, Cyber Security Detection Engineering. Be the first to apply!
- engineering director Gaithersburg, MD
- chief engineer Gaithersburg, MD
- data center chief engineer Gaithersburg, MD
- hotel chief engineer Gaithersburg, MD
- principal developer Gaithersburg, MD
- general engineer Gaithersburg, MD
- principal engineer Gaithersburg, MD
- cyber Gaithersburg, MD
- senior cybersecurity engineer Gaithersburg, MD
- remote cyber security Gaithersburg, MD


