Director of Cyber Threat Intelligence (CTI)
$162.54k - $243.8kAstraZeneca
About AstraZeneca AstraZeneca is a global, science-led, patient-focused biopharmaceutical company dedicated to discovering, developing, and commercialising prescription medicines for serious disease. We’re committed to being a Great Place to Work. About the Role The Director of Cyber Threat Intelligence will lead a highly technical CTI function within AstraZeneca’s Cybersecurity Operations division, managing a team of analysts to deliver strategic, operational, and tactical intelligence that measurably reduces risk across the enterprise, including manufacturing, clinical trial platforms, and R&D environments. This role anchors CTI to “intel-to-action” outcomes, partnering closely with Vulnerability Management, Detection Engineering, and Incident Response to harden controls, prioritize patching, improve detections, and accelerate response. Key Responsibilities Program Leadership and Strategy: Define CTI vision, operating model, and roadmap aligned to AstraZeneca’s cyber risk reduction strategy, with special emphasis on manufacturing continuity, clinical data integrity, and R&D IP protection. Adversary Prioritization Framework: Design and operate a scoring rubric that ranks actors based on intent/capability/relevance, TTP emergence and prevalence, organization-specific exposure to known vulnerabilities/CVEs, and global “viral” events, maintaining dynamic watchlists and escalation triggers. MTTI Metric and Analytics: Implement analytic methods to estimate mean time-to-impact per adversary (from initial access to material business impact) using internal telemetry, historical incidents, industry reporting, and confidence levels, performing comparisons with IR’s MTTC to drive control improvements. Attack Path Modeling: Build and maintain end-to-end attack path models from initial access to material impact across IT-to-OT pivots, clinical platforms, and R&D environments, mapping steps to MITRE ATT&CK (Enterprise/ICS), identify control gaps and choke points, derive detections-as-code and hunt hypotheses, and support validation efforts including purple-team exercises and adversary emulation to ensure enterprise hardening and measurable risk reduction. Dark Web and Closed-Source Monitoring: Establish collection and monitoring across dark web forums, marketplaces, breach dumps, and closed channels to identify emerging TTPs, credential leaks, data exposure, access-broker listings, and targeting of manufacturing, clinical, or R&D assets, integrating validated findings into TIP/SIEM pipelines, trigger takedown requests where feasible, and deliver rapid advisories with confidence ratings and specific actions for Vulnerability Management, Detection Engineering, and IR. Third-Party and Ecosystem Intelligence: Deliver risk insights for CROs/CMOs/logistics/technology vendors, monitor credential leakage and domain spoofing, and support/coordinate takedown operations when needed. Structured Threat Actor Attribution (Diamond Model): Lead disciplined attribution using the Diamond Model (adversary, capability, infrastructure, victim) and complementary frameworks, correlating TTPs, tooling lineage, code-reuse, infrastructure overlaps, and victimology with confidence levels and analytic caveats, documenting hypotheses, alternative explanations, and disconfirming evidence, and producing reusable actor profiles and pivot paths that inform prioritization, detections, hunts, and incident response playbooks. Support Vulnerability Management: Partner with Vulnerability Management to contextualize CVEs (exploitability, weaponization, external scanning telemetry, compensating controls) and deliver risk-based patching prioritization across AstraZeneca’s estate including IT/OT, clinical platforms, and lab environments. Support Detection Engineering: Develop detection use cases to feed our detection-as-code pipeline and support detection ATT&CK coverage mapping, content tuning, and false-positive reduction, ensuring feedback loops from hunts and incidents continuously improve detection quality. Support GSOC/Incident Response: Provide real-time adversary context that is highly technical including kill-chain reconstruction, containment recommendations, and countermeasures, producing post-incident intelligence retrospectives and detection/architecture improvements. Operational and Executive Reporting: Produce daily threat intelligence highlights, threat actor/campaign profiles, quarterly threat briefings, and other ad hoc intelligence products, ensuring products include quantified risk narratives for senior leadership that also align findings to regulatory expectations and business impact. Tooling and Automation: Optimize integrations across TIP, SIEM, EDR, case management, and telemetry; manage indicator lifecycle, automate enrichment, and measure source fidelity/bias. External Engagement: Lead participation with sector bodies (e.g., H-ISAC), peer sharing groups, and government/industry partners; track and assess global events and rapidly translate into actionable enterprise guidance. Team Leadership and Development: Recruit, mentor, and grow a diverse team of CTI analysts; build career paths, training plans, and knowledge-sharing practices; foster a culture of technical excellence and clear, actionable communication. Minimum Qualifications Leadership and Strategic Impact: 10+ years in cyber threat intelligence, detection engineering, incident response, or related domains; 5+ years leading technical CTI teams in global enterprises. Demonstrated ability to set vision, influence strategy, and deliver outcomes tied to enterprise risk reduction. Decision Making and Accountability: Proven ownership of adversary-centric CTI programs that directly drive vulnerability prioritization, detections-as-code, hunts, and incident response. Comfortable making data-driven decisions with clear trade-offs and confidence levels. Technical Depth (ATT&CK Enterprise/ICS): Deep expertise mapping TTPs to MITRE ATT&CK, defining coverage strategies, and translating gaps into high-fidelity detections and hunt hypotheses; skilled in industrial/OT contexts. Attack Path Modeling and Risk Translation: Hands-on delivery of end-to-end attack paths across IT-to-OT pivots, clinical platforms, and R&D environments; validation via purple-team/adversary emulation; ability to convert findings into prioritized control roadmaps and measurable risk reduction. Adversary Prioritization and Scoring: Designed and operated tailored actor scoring incorporating intent/capability, TTP emergence/prevalence, org exposure to CVEs, and global/viral events; maintained dynamic watchlists and escalation triggers. Structured Attribution Tradecraft: Applied the Diamond Model and complementary frameworks with documented hypotheses, caveats, disconfirming evidence, and confidence statements; produced reusable actor profiles and pivot paths. Metrication (MTTI vs. MTTC): Built mean time-to-impact metrics per actor and operationalized comparisons to IR's mean time-to-containment to guide control improvements and track program effectiveness. Vulnerability Intelligence for Hardening: Delivered contextual CVE analysis (exploitability, weaponization, external scanning telemetry, compensating controls) and risk-based patch recommendations across IT, OT/ICS, clinical, and lab environments. Detection Engineering Collaboration: Co-developed detections-as-code (e.g., Sigma, KQL, SPL), tuned content to reduce false positives, and closed ATT&CK coverage gaps with feedback loops from hunts/incidents. Incident Intelligence Support: Provided real-time adversary context, kill-chain reconstruction, containment recommendations, and post-incident retrospectives that inform detection and architectural improvements. Collection, Tooling, and Automation: Operated dark web/closed-source monitoring; integrated findings into TIP/SIEM/EDR pipelines; managed indicator lifecycle, automated enrichment, and measured source fidelity/bias. Stakeholder Partnership and Communication: Clear, concise communication of complex technical intelligence to executives and cross-functional partners (Vulnerability Management, Detection Engineering, SOC/IR, OT Security, Clinical Ops, Research IT); ability to influence without authority. Education: Bachelor's degree in a relevant field (Computer Science, Information Security, Intelligence Studies, or equivalent experience). Preferred Qualifications Sector Experience and Regulatory Context: Experience in pharmaceuticals, life sciences, healthcare, or manufacturing; familiarity with GMP/CSV, clinical data obligations, and R&D IP protection. OT/ICS and Critical Operations: Hands-on work with MES, SCADA, PLC ecosystems; ATT&CK for ICS usage; understanding of OT-safe response practices and production continuity implications. Clinical/R&D Platforms: Exposure to CTMS, EDC, IRT, ELN, LIMS, HPC, and data lake environments; experience safeguarding data integrity and sensitive research/IP. Program Metrics and Outcomes: Built dashboards tracking MTTI by actor, ATT&CK coverage indices, intel-informed patch SLAs, hunter ROI, and executive risk narratives; experience presenting to senior leadership and risk committees. Advanced Tooling/Automation: TIP administration, SIEM/EDR content engineering, enrichment/orchestration pipelines, case management integration, and indicator lifecycle automation at enterprise scale. Threat Modeling and Quantification: Ability to translate attack paths into quantified risk scenarios and prioritized control investments aligned to business objectives and crown jewels. External Partnerships: Active engagement with H-ISAC/ISAOs and government/industry partners; track record of rapidly converting global/viral cyber events into enterprise defenses and executive guidance. Certifications: One or more of GCTI, GREM, GRID, GCIH, CISSP, or equivalent demonstrated expertise. People Leadership: Built diverse, high-performing teams; established career paths, coaching frameworks, and a culture of analytic rigor, technical excellence, and continuous improvement.All roles in IT are expected to demonstrate a mindset of embracing, adopting and appropriately using AI and digital tools in day‑to‑day work to improve outcomes and ways of working.LocationGaithersburg, Maryland. Office Working RequirementsWhen we put unexpected teams in the same room, we unleash bold thinking with the power to inspire life-changing medicines. In-person working gives us the platform we need to connect, work at pace and challenge perceptions. That’s why we work, on average, a minimum of three days per week from the office. But that doesn’t mean we’re not flexible. We balance the expectation of being in the office while respecting individual flexibility. Join us in our unique and ambitious world.The annual base pay for this position ranges from $162.536,00 - $243.804,00 USD Our positions offer eligibility for various incentives—an opportunity to receive short-term incentive bonuses, equity-based awards for salaried roles and commissions for sales roles. Benefits offered include qualified retirement programs, paid time off (i.e., vacation, holiday, and leaves), as well as health, dental, and vision coverage in accordance with the terms of the applicable plans.Date Posted04-ago-2026Closing Date14-ago-2026Our mission is to build an inclusive environment where equal employment opportunities are available to all applicants and employees. In furtherance of that mission, we welcome and consider applications from all qualified candidates, regardless of their protected characteristics. If you have a disability or special need that requires accommodation, please complete the corresponding section in the application form.SummaryLocation: US - Gaithersburg - MDType: Full time
- ...because being YOU thrives here. Summary: The Senior Cyber Threat Analyst will lead efforts to investigate cybersecurity... ...and network security platforms Experience leveraging threat intelligence in security operations Advanced knowledge of cyber attack...CyberIntelligenceRemote workFlexible hours
- ...ABOUT ROLE The Director, CSIRT is a senior individual... ...response to material cyber incidents across cloud,... ...Detection Engineering, CTI, Vulnerability... ...attribution and common threat actor TTPs ~ Automation... ...integration of artificial intelligence, large language models...CyberIntelligenceHourly payFull timeTemporary workWork at officeFlexible hours3 days per week
- ...within the SOC, responsible for advanced threat detection, incident response, threat... .... This role operates at the core of the intelligence-driven SOC model, fusing multi-source data... ...identify, analyze, and mitigate sophisticated cyber threats impacting Agency systems.Salary...CyberIntelligence
$3,000 per month
...WHAT WE’RE DOING Lockheed Martin, Rotary Mission Systems Cyber & Intelligence invites you to step up to one of today’s most daunting challenges... ...you’ll work with cybersecurity experts on the forefront of threat protection and proactive prevention. In this fast-paced,...CyberIntelligence- ActioNet, Inc. is seeking a Tier 3 Cybersecurity Analyst to serve as a senior technical leader within the SOC, focusing on advanced threat detection, incident response, threat hunting, and forensic analysis for Agency systems. The role requires 8+ years in security...Cyber
$154.05k - $278.48k
...mission software capabilities in the areas of cyber, logistics, security operations, and... ...’ mission to defend against evolving threats around the world. Our team’s focus is to... ...strategy across a high-visibility geospatial intelligence initiative.The Chief Systems Architect...CyberIntelligenceFull timeContract workFor contractors- ...aerospace and defense company that's shaping the future of cyber and intelligence. We're committed to innovating at the Edge: Harnessing the... ..., and machine learning to stay ahead of emerging threats and opportunities. This Program is seeking a full stack...CyberIntelligence
$136k - $231.2k
...BAE Systems is looking for a talented Cyber Security Engineer to support the development... ...Audit & Compliance Analytics & Intelligence Firewall/IDS/IPS Skills Intrusion... ...government to recognize, manage and defeat threats inspires us to push ourselves and our technologies...CyberIntelligenceFull timeLocal area- ...Cyber Threat Hunter Bethesda, MD Role Summary: Mid-level hunter conducting proactive threat hunts, identifying behavioral anomalies, and maturing the NIH enterprise threat hunting program. Must-Have Skills: ~3–5 years threat hunting, SOC, IR, or detection...Cyber
$142.79k - $178.25k
...verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You... ...leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we...CyberIntelligenceFull timeTemporary workPart timeWork at officeImmediate startRemote workWork from homeWorldwideFlexible hours- ...mission software capabilities in the areas of cyber, logistics, security operations, and... ...’ mission to defend against evolving threats around the world. Our team’s focus is to... ...protect people and critical assets. The Intelligence Production Solutions Division (IPSD), part...CyberIntelligenceContract workWorldwide
$130k - $135k
...response, security operations, and security initiatives. Background in SOC operations, detection engineering, threat hunting, or cyber threat intelligence. Must be comfortable supporting a weekend schedule. ( 2 nd Shift WEEKEND schedule, Wednesday – Sunday OR...CyberIntelligenceFull timeRemote workFlexible hoursShift workWeekend workAfternoon shift$107.9k - $195.05k
Overview Leidos Intelligence Sector combines technology-enabled services... ...in the areas of cyber, logistics, security operations... ...to defend against evolving threats around the world. Our team's... ...Geospatial Analyst Solutions Directorate, part of the National Solutions...CyberIntelligenceContract workLocal areaImmediate start$118.1k - $200.76k
.../or job specifics. About BAE Systems Intelligence & Security BAE Systems, Inc. is the... ...everything we do-from intelligence analysis, cyber operations and IT expertise to systems... ...to recognize, manage and defeat threats inspires us to push ourselves and our technologies...CyberIntelligenceFull timeFor contractorsWork experience placementFor subcontractorLocal area$131.3k - $237.35k
...Analytical Methods and Modeling, Signals Intelligence (SIGINT), and Cryptographic Key... ...endpoint security systems engineer to join our Cyber Security Engineering team. The focus of... ...protection of mission systems from external threats.Primary ResponsibilitiesMaintaining and...CyberIntelligenceFull timeImmediate startFlexible hours$154.05k - $278.48k
...Mission Software, Analytical Methods and Modeling, Signals Intelligence (SIGINT), and Cryptographic Key Management. At Leidos, we offer... ...’s information systems, networks, and infrastructure from cyber threats and vulnerabilities. This role supports the design, implementation...CyberIntelligenceFull timeImmediate startFlexible hours- ...Log analysis for incident remediation/threat hunting. Troubleshooting security and... ...security monitoring, incident response, cyber security, and cyber threat analysis.... ...(SIEM) pattern analysis based on threat intelligence feeds Requirements Bachelor's...CyberIntelligenceFull timeWork at officeRemote work
$154.05k - $278.48k
Leidos has an exciting opportunity for Cyber Security Engineer—Technical Lead in our Intel... ...Methods and Modeling, Signals Intelligence (SIGINT), and Cryptographic Key Management... ...security advisories, bulletins, and industry threat intelligence to stay informed of current...CyberIntelligenceFull timeImmediate startFlexible hours$170k - $200k
...level of education. The role is bonus eligible.#LI-JB1 #DIRECTOR #LEGALWhat You Can Expect from UsAt ISS STOXX, our people... ...services cover corporate governance, sustainability, cyber risk, and fund intelligence. Majority-owned by Deutsche Börse Group, ISS STOXX has over...CyberIntelligenceFull timeLocal areaWorldwide$110k - $130k
...and government stakeholders to identify threats, contain incidents, conduct root cause analyses... .... Correlate logs, alerts, threat intelligence, and forensic evidence to identify... ...response, SOC operations, threat detection, or cyber defense. Experience supporting...CyberIntelligenceContract workRemote work- ...Job Description Summary: The Senior Director, Cybersecurity Architecture serves as... ...that enable secure adoption of artificial intelligence, advanced analytics, cloud platforms, data... ...architectures, design patterns, threat modeling, and exception management aligned...IntelligenceHourly payContract workTemporary workCasual workWork at officeRemote workFlexible hours3 days per week
$75 - $85 per hour
...access, modification, or loss. This role requires expertise in cyber security, email platforms, cloud environments, and data... ...subject to criminal penalties and civil liability.Use of Artificial Intelligence (AI): We may use Artificial Intelligence (AI) to support parts...CyberIntelligenceContract workTemporary work$115k - $160k
...multiple Software Developers to help enable NGA's Geospatial Intelligence (GEOINT) mission collecting sciences, technology and tradecraft... ...Our capabilities include IT Infrastructure & Cloud Services, Cyber Security, Software Integration & Development, Data Solution &...CyberIntelligenceFull timePart timeWork experience placement$50.46k - $187.09k
...independently while collaborating effectively within NSA and with other intelligence community analysts. Job Summary Use your foreign language... ...studies, quantitative/statistical analysis, data modeling, cyber security, computer science, or networking. Previous military...CyberIntelligenceFull timeImmediate startMonday to FridayFlexible hours- ..., cloud environments, and security infrastructure. Perform proactive threat hunting and identify, collect, and document Indicators of Compromise (IOCs). Support Cyber Threat Intelligence (CTI) activities through research, correlation, and dissemination. Assist...CyberIntelligenceLocal area
$80k - $95k
...empower capital market participants with confidence. Our expertise spans indices, corporate governance, sustainability, cyber risk, and fund intelligence, giving clients the tools they need to uncover opportunities, manage risks, and navigate evolving regulations. ISS is...CyberIntelligenceLocal areaFlexible hours$138.75k - $231.25k
Associate Director Regulatory Affairs, OncologyAt GSK, we have bold ambitions for patients, aiming to positively impact the health of... ...stages of product life.• Ideally assess precedent, regulatory intelligence and competitive environment from a regulatory perspective for...IntelligenceFull timeLocal area- ...Precigen is seeking a highly motivated and experienced Associate Director/Senior Manager, Regulatory Affairs(level based on candidate... ...IND/BLA preparation, labeling, operations, and/or regulatory intelligence. The Associate Director/Senior Manager will interact with all...IntelligenceWork at office
- The Associate Regulatory Affairs Director (ARAD) is an experienced regulatory specialist with strong project management experience and... ...and processesExperience and expertise using Artificial intelligence toolsSkills and CapabilitiesExcellent written and verbal communication...IntelligenceHourly payFull timeTemporary work
$118.1k - $200.76k
...FISMA, etc.). You will: Review DoD, DON cyber security alerts, notices, IAVMs, etc.... ...researching new technologies to counter evolving threats. About BAE Systems and the U.S. Navy'... ...and/or job specifics. About BAE Systems Intelligence & Security BAE Systems, Inc. is the U...CyberIntelligenceFull timeFor contractorsWork experience placementLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director of Cyber Threat Intelligence (CTI). Be the first to apply!
- director biology Gaithersburg, MD
- ehs director Gaithersburg, MD
- director medical information Gaithersburg, MD
- director of radiology Gaithersburg, MD
- director of aviation Gaithersburg, MD
- director learning Gaithersburg, MD
- director of mental health Gaithersburg, MD
- director private equity Gaithersburg, MD
- director of assessment Gaithersburg, MD
- nonprofit director Gaithersburg, MD


