Senior Director, Cyber Exposure Management
$190.96k - $286.44kAstraZeneca
Senior Director, Cyber Exposure ManagementIntroduction to role:Are you ready to turn exposure data into decisive action that protects the science, manufacturing and digital platforms patients rely on every day? Based in Gaithersburg, Maryland, you will own our enterprise understanding of vulnerabilities and weaknesses—and drive closure before an attacker finds them. You will lead three complementary capabilities: Vulnerability Management, Application Security and Penetration Testing/Red Team, operating between builders and defenders to ensure our technology and platforms are resilient when it matters most.This is a build-and-uplift mandate. You will move us from scan-and-ticket to modern, risk-based exposure management; stand up application security as a true assurance function; and evolve offensive testing into a continuous, intelligence-led capability. How would you partner across engineering, cloud, product and operations to prioritize real-world risk at machine speed and validate that our defenses work when it counts?Accountabilities:Unified Exposure Strategy: Own and deliver a multi-year strategy across Vulnerability Management, Application Security and Penetration Testing, with clear roadmaps, budgets and capability plans; set direction with a high degree of autonomy.Risk-Based Vulnerability Management: Evolve from volume-based scanning to prioritized exposure management using asset criticality, exploitability and threat intelligence; implement enterprise remediation governance and SLAs.Attack Surface and Exposure Visibility: Maintain continuous visibility of internal and external attack surfaces—including cloud, SaaS and third-party exposure—and focus effort where real-world risk is highest.Application Security Assurance: Run a secure development assurance program covering SAST, DAST and SCA; drive developer enablement and behaviors for software we build and buy.Software Supply Chain Governance: Oversee software composition risk, SBOM practices and rapid response to widely exploited components; guide investment and policy.Continuous Offensive Testing: Operate a continuous program of penetration testing and adversary emulation across applications, infrastructure, cloud and OT; run purple-team exercises with Threat Management to harden detection and response.AI-Era Exposure Readiness: Prepare for machine-speed exploit generation by automating discovery, prioritization and validation; assess the security of AI and large language model systems.Remediation Through Partners: Drive fixes through accountable asset owners; escalate and govern risk acceptance; keep the reporting honest and defensible.Metrics and Executive Reporting: Own exposure KRIs—mean time to remediate, SLA attainment, recurrence, coverage, critical exposure ageing—and report credibly to senior leadership and risk committees.Assurance Integration: Feed findings from offensive testing and cyber intelligence into prioritization; incorporate incident learnings so testing reflects how we are actually being attacked.Executive Communication and Influence: Translate technical exposure into business risk the CISO, IT leadership and the Board can act on; defend prioritization decisions under scrutiny.Build and Uplift the Function: Lead and uplift a multi-disciplinary team of roughly eighteen across regions; raise posture from operational scanning to strategic exposure management while preserving independence and integrity.Lead Through Leaders: Manage the leaders of Vulnerability Management, Application Security and Penetration Testing; set objectives, review performance and build succession.Talent, Culture and Capability: Recruit inclusively; develop career paths and upskilling in exposure management, cloud and application security, offensive testing and automation; leverage regional and external partnerships.Budget and Tooling Ownership: Own budgets for scanning, application security and offensive tooling and specialist partners; build the investment cases that maximize business risk reduction.Essential Skills/Experience:Risk-based vulnerability management: Prioritization using asset criticality, exploitability and intelligence; remediation governance and SLA management at enterprise scale.Application security: Secure SDLC, SAST/DAST/SCA, threat modelling, API and cloud-native application security, and developer enablement that changes behavior rather than just reporting findings.Offensive security: Penetration testing and adversary emulation across applications, infrastructure, cloud and OT, and the use of purple teaming to improve detection.Attack surface and cloud: External and internal attack surface management across cloud, SaaS and third-party exposure.Software supply chain: Open-source and third-party component risk, SBOM practice and rapid response to widely exploited components.AI-era exploitation: How machine-speed vulnerability discovery and weaponization change prioritization, and the security considerations of the organization’s own AI systems.Regulated and OT context: Exposure management in GxP and OT/ICS environments where patching and testing are constrained by validation, safety and uptime.Remediation through others: Driving fixes through asset-owning teams, governing risk acceptance and keeping reporting defensible.Education: Bachelor's degree or equivalent experience in information security, computer science or a related field, or equivalent practical experience.Depth: Ten or more years in cybersecurity, including significant experience across vulnerability, application or offensive security.Leadership scale: Five or more years leading exposure, application security or offensive functions in a large enterprise, including at least two years managing other people leaders.Program credibility: Demonstrable record of maturing a vulnerability or application security program and measurably reducing risk.Cross-functional delivery: Proven track record to drive remediation through teams you do not control, across IT, Cloud, Engineering and business units.Communication and facilitation: Ability to explain exposure and prioritization in clear business terms and to brief senior executives and risk committees.Analytical decision making: Ability to prioritize finite remediation capacity against real-world risk and business pragmatism.Global coordination: Experience leading distributed teams across multiple regions and cultures.Desirable Skills/Experience:Certifications: CISSP, CISM, OSCP, GIAC (GWAPT, GPEN, GXPN, GCPN) or equivalent.Sector experience: Pharmaceutical, life sciences, healthcare or another highly regulated industry with manufacturing OT exposure.Board exposure: Experience briefing an audit committee, board or risk committee on exposure and remediation.Commercial: Experience selecting and governing scanning, application security and offensive tooling and specialist testing partners.Language: Working proficiency in a second language relevant to our delivery hubs.When we put unexpected teams in the same room, we unleash bold thinking with the power to inspire life-changing medicines. In-person working gives us the platform we need to connect, work at pace and challenge perceptions. That's why we work, on average, a minimum of three days per week from the office. But that doesn't mean we're not flexible. We balance the expectation of being in the office while respecting individual flexibility. Join us in our unique and ambitious world.The annual base pay for this position ranges from $190,956.80 - 286,435.20USD Annual and salaried non-exempt employees will also be paid overtime pay when working qualifying overtime hours. Base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. In addition, our positions offer a short-term incentive bonus opportunity; eligibility to participate in our equity-based long-term incentive program. Benefits offered included a qualified retirement program [401(k) plan]; paid vacation and holidays; paid leaves; and, health benefits including medical, prescription drug, dental, and vision coverage in accordance with the terms and conditions of the applicable plans. Additional details of participation in these benefit plans will be provided if an employee receives an offer of employment. If hired, employee will be in an “at-will position” and the Company reserves the right to modify base pay (as well as any other discretionary payment or compensation program) at any time, including for reasons related to individual performance, Company or individual department/team performance, and market factors.Why AstraZeneca:Here, technology and data power scientific discovery and the delivery of life-changing medicines to patients worldwide. You will join at a pivotal moment as we scale a modern, digital enterprise—one that pairs pioneering platforms with a culture that values curiosity, kindness and ambition in equal measure. Expect the room, the resources and the partnerships to move fast: from collaborating with diverse experts to experimenting with new approaches, learning every day and turning bold ideas into impact at global scale. Your leadership will directly shape how we protect critical research, manufacturing and supply so our teams can focus on transforming patient outcomes.If you are ready to build a modern exposure program that measurably reduces risk and safeguards vital science, step forward and show us how you will lead this mission now!Date Posted14-Sept-2026Closing Date10-Oct-2026Our mission is to build an inclusive environment where equal employment opportunities are available to all applicants and employees. In furtherance of that mission, we welcome and consider applications from all qualified candidates, regardless of their protected characteristics. If you have a disability or special need that requires accommodation, please complete the corresponding section in the application form.SummaryLocation: US - Gaithersburg - MDType: Full time
$162.54k - $243.8k
...to Work. About the Role The Director of Cyber Threat Intelligence will lead... ...Operations division, managing a team of analysts to deliver... ...prevalence, organization-specific exposure to known vulnerabilities/... ...quantified risk narratives for senior leadership that also align...CyberFull timeTemporary workWork at officeFlexible hours3 days per week$126.25k - $176.51k
...inclusive and collaborative work environment.Brief Job OverviewThe Senior Technical Manager will serve as a technical lead for donor- and program-... ...GMP manufacturing, or advanced manufacturing technologies.Exposure to relevant technical areas such as flow chemistry, process...SeniorFull timeWork at officeWorldwide- ...Leonardo DRS is seeking a Principal Cyber Engineer in Germantown, MD to lead cyber strategy across radar programs. You will own vulnerability management, STIG implementation, and the end-to-end ATO process, guiding audits and mentoring engineers while ensuring DoD security...CyberSenior
$150k - $170k
...focused technology, cybersecurity, and program management solutions supporting critical Federal and... ...integrated, high-impact solutions across cyber operations, enterprise resource... ...’re Looking For (Position Overview:) The Senior Policy Analyst provides policy research,...CyberSeniorContract work- ...Leidos is seeking a proven technical program management leader with deep experience directing large-scale mission software development and... ...leadership across architecture, integration, DevOps, cyber, and cloud environments. This role requires hands-on credibility...CyberSenior
$218.33k - $327.49k
...high-quality market, customer, and competitor analytics. The Senior Director, Global Analytics & Insights, Cell Therapy, will report to the... ...capacity, vein-to-vein time, access, and scalability. Manage relationships and budgets with external market research, forecasting...SeniorHourly payFull timeTemporary work- ...Senior Policy Analyst Position Overview Premier Enterprise Solutions is seeking a... ...Senior Policy Analyst to support Defense Cyber Crime Center (DC3). This position conducts... ...comprehensive research, analysis, development, and management of complex policy initiatives impacting...CyberSeniorFull timeTemporary workLocal areaImmediate start
- ...Senior Technical Manager – Land Development Are you a highly experienced civil engineer who enjoys solving complex technical challenges and influencing engineering quality without managing staff, budgets, or project schedules? Soltesz is seeking a Senior Technical...SeniorLocal area
$257k - $294k
...Clinical program by providing direction, insight, and hands‑on management & leadership covering the statistical content and requirements... ...deliverables. Provides statistical leadership and insight to team as a senior member of the Clinical Development organization. Interacts with...SeniorWork at officeVisa sponsorship$107.9k - $195.05k
Job Id: 0000175299Job Category: Cyber SecurityJob Location: Gaithersburg, MarylandSecurity... ...BuckZachary Piper Solutions is seeking a Senior AI Software Developer to support a... ...modernizing and advancing national air traffic management systems through next-generation...CyberSenior- Advance Engineering Excellence Without Leaving the Technical TrackSoltesz is seeking a highly experienced Senior Technical Manager - Land Development to join our Rockville office. This role is designed for an accomplished civil engineering professional who wants to remain...SeniorWork at officeLocal area
$3,000 per month
Senior Technical Manager | Land Development | PEThis is a Non Managerialposition with no project management, budget accountability, or staff supervision. Ideal for a senior engineer who is looking for technical engineering design support without project or people management...SeniorWork at officeLocal areaFlexible hours$124k - $157k
...[This role will be Remote with 50% onsite requirement] The Senior Human Resources Business Partner provides HR support to assigned... ...programs align to USP’s strategic plans. The Senior Human Resources Manager will drive cross-functional initiatives within the organization...SeniorFull timeWork experience placementWork at officeLocal areaRemote workWorldwide$180k - $220k
...application! \n \n We are currently looking for our: \n Senior Director – Leasing (Westfield Montgomery, Bethesda, MD) \n \n What... ...in a timely fashion. \n \n A SOLUTION SEEKER – You manage conflict effectively and with a minimum of noise. You work out...SeniorPermanent employmentWork at officeLocal areaFlexible hoursShift work$218.33k - $327.49k
...decisions by delivering analysis and insights to Senior Leadership and other key partners to... ...oncology landscape. As a Senior Director, Competitive Intelligence, you will work... ...motivated, decisive and proactive; able to manage multiple priorities in a fast-growing organization...SeniorTemporary workWork at officeRemote workFlexible hoursShift work3 days per week- ...This role provides high-level technical program management with a focus on satellite communication User Terminal (UT) architecture and product... ..., transportation, and government sectors. Operating at a Senior level, you will facilitate collaboration across multi-disciplinary...SeniorContract workTemporary workWork at officeFlexible hours
$170k - $190k
...challenging, and mission-driven work environment for current and future employees. A-TEK is seeking a Cyber Security Operations Center (CSOC) Program Manager to support one of our federal clients. The CSOC PM is a high-level executive responsible for establishing...CyberSeniorContract work- ...commercial effectiveness and maximizing the lifecycle. The Senior Director of Pathology Diagnostics, Global Oncology Diagnostics is... ...industry, and/or academia including experience or substantial exposure to digital and/or computational pathology Preferred Qualifications...SeniorHourly payTemporary workWork at officeLocal areaWorldwideFlexible hours3 days per week
$112.2k - $176.3k
...technologies. Our differentiated battle management and cyber solutions deliver timely, mission-... ...looking for you to join our team as a Senior Principal Contracts Administrator. The... ...results. Employees in Vice President or Director positions may be eligible for Long Term...CyberSeniorContract workRelocationShift work$154.05k - $278.48k
...Leidos is seeking a proven technical program management leader with deep experience leading large... ...architecture, integration, DevOps, cyber, and cloud environments. Candidates must... ...Engagement & Strategy: Serve as the autonomous senior interface to government sponsors, shaping...CyberSenior- ...recruiter for details. Purpose: The Sr. Manager, HR Compliance leads the organization's... ...compliance and reduce risk exposure Direct the North America HR Audit Program... .... Manager, HR Compliance reports to the Director, HR Compliance. Major Interdependencies...SeniorFlexible hours
- ...across physical, electronic, cyber, and communications security for... .... Job Summary: As a senior technician, the Lead Security... ...organizational and leadership skills to manage project sites, ensure quality,... .... This role may involve exposure to varying weather conditions...CyberHourly payNight shift
$102.17k
...visionary company that is transforming the way water resources are managed and protected. By combining cutting-edge digital technologies,... .... Job Description Join the Trinnex Security Team as a Senior Cyber Security Analyst, where you will operate at the intersection...CyberSeniorWork experience placementH1b- About the Role:The Senior Director, Digital Forensics & Incident Response owns AstraZeneca’s... ...capability to respond to and investigate cyber incidents. This role commands the... ...Engineering, Cyber Threat Intelligence, Threat Exposure Management, Insider Risk & DLP, IT, Legal,...CyberSeniorHourly payPermanent employmentFull timeTemporary workWork at officeFlexible hours3 days per week
- ...AV is seeking a Cyber Threat Intelligence Analyst to identify, analyze, and communicate cyber threats that affect the organization. The role blends traditional threat intelligence with strong technical cybersecurity skills to create actionable intelligence for detections...CyberSenior
$132.23k - $176.31k
...meaningful impact, and help shape the future of AI‑ready connectivity, join us today. The Role Lumen is seeking a Senior Lead Technical Program Manager to join the Network Architecture and Engineering organization. In this highly visible role, you will lead complex...SeniorFull timeTemporary workRemote work$47.35 - $76.2 per hour
...Senior Manager Of Risk Management And ComplianceThis is a temporary position.Job SummaryThe Senior Manager of Risk Management and Compliance... ...technology risk mitigation strategies emerging from audits, cyber threats, data privacy regulations and IT operations. You will...CyberSeniorHourly payTemporary workRemote workFlexible hours$218.33k - $327.49k
...Senior Director role leading competitive intelligence and strategic analysis for AstraZeneca's oncology research division. Responsible for delivering clinical and commercial insights to senior leadership that shape portfolio decisions and investment strategy across the...Senior$218.33k - $327.49k
...AstraZeneca seeks a Senior Director to lead analytics and insights for its cell therapy enterprise, driving strategic decisions across clinical development and commercialization. This role requires building market and competitive understanding for emerging cell therapies...SeniorShift work$194.57k - $291.86k
...AstraZeneca seeks a Director of Global Analytics & Insights for its oncology lung cancer... ...communicating insights and recommendations to senior leadership Requirements ~ Bachelor'... ...recommendations ~ Strong capability managing multiple priorities and delivering under...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Director, Cyber Exposure Management. Be the first to apply!
- ai director Gaithersburg, MD
- director of aviation Gaithersburg, MD
- director medical information Gaithersburg, MD
- director talent management Gaithersburg, MD
- director of government affairs Gaithersburg, MD
- director of automation Gaithersburg, MD
- director of billing Gaithersburg, MD
- director of practice management Gaithersburg, MD
- director Gaithersburg, MD
- social impact director Gaithersburg, MD







