Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Director of Cyber Threat Intelligence (CTI)

$162.54k - $243.8k

AstraZeneca

About AstraZeneca AstraZeneca is a global, science-led, patient-focused biopharmaceutical company dedicated to discovering, developing, and commercialising prescription medicines for serious disease. We’re committed to being a Great Place to Work. About the Role The Director of Cyber Threat Intelligence will lead a highly technical CTI function within AstraZeneca’s Cybersecurity Operations division, managing a team of analysts to deliver strategic, operational, and tactical intelligence that measurably reduces risk across the enterprise, including manufacturing, clinical trial platforms, and R&D environments. This role anchors CTI to “intel-to-action” outcomes, partnering closely with Vulnerability Management, Detection Engineering, and Incident Response to harden controls, prioritize patching, improve detections, and accelerate response. Key Responsibilities Program Leadership and Strategy: Define CTI vision, operating model, and roadmap aligned to AstraZeneca’s cyber risk reduction strategy, with special emphasis on manufacturing continuity, clinical data integrity, and R&D IP protection. Adversary Prioritization Framework: Design and operate a scoring rubric that ranks actors based on intent/capability/relevance, TTP emergence and prevalence, organization-specific exposure to known vulnerabilities/CVEs, and global “viral” events, maintaining dynamic watchlists and escalation triggers. MTTI Metric and Analytics: Implement analytic methods to estimate mean time-to-impact per adversary (from initial access to material business impact) using internal telemetry, historical incidents, industry reporting, and confidence levels, performing comparisons with IR’s MTTC to drive control improvements. Attack Path Modeling: Build and maintain end-to-end attack path models from initial access to material impact across IT-to-OT pivots, clinical platforms, and R&D environments, mapping steps to MITRE ATT&CK (Enterprise/ICS), identify control gaps and choke points, derive detections-as-code and hunt hypotheses, and support validation efforts including purple-team exercises and adversary emulation to ensure enterprise hardening and measurable risk reduction. Dark Web and Closed-Source Monitoring: Establish collection and monitoring across dark web forums, marketplaces, breach dumps, and closed channels to identify emerging TTPs, credential leaks, data exposure, access-broker listings, and targeting of manufacturing, clinical, or R&D assets, integrating validated findings into TIP/SIEM pipelines, trigger takedown requests where feasible, and deliver rapid advisories with confidence ratings and specific actions for Vulnerability Management, Detection Engineering, and IR. Third-Party and Ecosystem Intelligence: Deliver risk insights for CROs/CMOs/logistics/technology vendors, monitor credential leakage and domain spoofing, and support/coordinate takedown operations when needed. Structured Threat Actor Attribution (Diamond Model): Lead disciplined attribution using the Diamond Model (adversary, capability, infrastructure, victim) and complementary frameworks, correlating TTPs, tooling lineage, code-reuse, infrastructure overlaps, and victimology with confidence levels and analytic caveats, documenting hypotheses, alternative explanations, and disconfirming evidence, and producing reusable actor profiles and pivot paths that inform prioritization, detections, hunts, and incident response playbooks. Support Vulnerability Management: Partner with Vulnerability Management to contextualize CVEs (exploitability, weaponization, external scanning telemetry, compensating controls) and deliver risk-based patching prioritization across AstraZeneca’s estate including IT/OT, clinical platforms, and lab environments. Support Detection Engineering: Develop detection use cases to feed our detection-as-code pipeline and support detection ATT&CK coverage mapping, content tuning, and false-positive reduction, ensuring feedback loops from hunts and incidents continuously improve detection quality. Support GSOC/Incident Response: Provide real-time adversary context that is highly technical including kill-chain reconstruction, containment recommendations, and countermeasures, producing post-incident intelligence retrospectives and detection/architecture improvements. Operational and Executive Reporting: Produce daily threat intelligence highlights, threat actor/campaign profiles, quarterly threat briefings, and other ad hoc intelligence products, ensuring products include quantified risk narratives for senior leadership that also align findings to regulatory expectations and business impact. Tooling and Automation: Optimize integrations across TIP, SIEM, EDR, case management, and telemetry; manage indicator lifecycle, automate enrichment, and measure source fidelity/bias. External Engagement: Lead participation with sector bodies (e.g., H-ISAC), peer sharing groups, and government/industry partners; track and assess global events and rapidly translate into actionable enterprise guidance. Team Leadership and Development: Recruit, mentor, and grow a diverse team of CTI analysts; build career paths, training plans, and knowledge-sharing practices; foster a culture of technical excellence and clear, actionable communication. Minimum Qualifications Leadership and Strategic Impact: 10+ years in cyber threat intelligence, detection engineering, incident response, or related domains; 5+ years leading technical CTI teams in global enterprises. Demonstrated ability to set vision, influence strategy, and deliver outcomes tied to enterprise risk reduction. Decision Making and Accountability: Proven ownership of adversary-centric CTI programs that directly drive vulnerability prioritization, detections-as-code, hunts, and incident response. Comfortable making data-driven decisions with clear trade-offs and confidence levels. Technical Depth (ATT&CK Enterprise/ICS): Deep expertise mapping TTPs to MITRE ATT&CK, defining coverage strategies, and translating gaps into high-fidelity detections and hunt hypotheses; skilled in industrial/OT contexts. Attack Path Modeling and Risk Translation: Hands-on delivery of end-to-end attack paths across IT-to-OT pivots, clinical platforms, and R&D environments; validation via purple-team/adversary emulation; ability to convert findings into prioritized control roadmaps and measurable risk reduction. Adversary Prioritization and Scoring: Designed and operated tailored actor scoring incorporating intent/capability, TTP emergence/prevalence, org exposure to CVEs, and global/viral events; maintained dynamic watchlists and escalation triggers. Structured Attribution Tradecraft: Applied the Diamond Model and complementary frameworks with documented hypotheses, caveats, disconfirming evidence, and confidence statements; produced reusable actor profiles and pivot paths. Metrication (MTTI vs. MTTC): Built mean time-to-impact metrics per actor and operationalized comparisons to IR's mean time-to-containment to guide control improvements and track program effectiveness. Vulnerability Intelligence for Hardening: Delivered contextual CVE analysis (exploitability, weaponization, external scanning telemetry, compensating controls) and risk-based patch recommendations across IT, OT/ICS, clinical, and lab environments. Detection Engineering Collaboration: Co-developed detections-as-code (e.g., Sigma, KQL, SPL), tuned content to reduce false positives, and closed ATT&CK coverage gaps with feedback loops from hunts/incidents. Incident Intelligence Support: Provided real-time adversary context, kill-chain reconstruction, containment recommendations, and post-incident retrospectives that inform detection and architectural improvements. Collection, Tooling, and Automation: Operated dark web/closed-source monitoring; integrated findings into TIP/SIEM/EDR pipelines; managed indicator lifecycle, automated enrichment, and measured source fidelity/bias. Stakeholder Partnership and Communication: Clear, concise communication of complex technical intelligence to executives and cross-functional partners (Vulnerability Management, Detection Engineering, SOC/IR, OT Security, Clinical Ops, Research IT); ability to influence without authority. Education: Bachelor's degree in a relevant field (Computer Science, Information Security, Intelligence Studies, or equivalent experience). Preferred Qualifications Sector Experience and Regulatory Context: Experience in pharmaceuticals, life sciences, healthcare, or manufacturing; familiarity with GMP/CSV, clinical data obligations, and R&D IP protection. OT/ICS and Critical Operations: Hands-on work with MES, SCADA, PLC ecosystems; ATT&CK for ICS usage; understanding of OT-safe response practices and production continuity implications. Clinical/R&D Platforms: Exposure to CTMS, EDC, IRT, ELN, LIMS, HPC, and data lake environments; experience safeguarding data integrity and sensitive research/IP. Program Metrics and Outcomes: Built dashboards tracking MTTI by actor, ATT&CK coverage indices, intel-informed patch SLAs, hunter ROI, and executive risk narratives; experience presenting to senior leadership and risk committees. Advanced Tooling/Automation: TIP administration, SIEM/EDR content engineering, enrichment/orchestration pipelines, case management integration, and indicator lifecycle automation at enterprise scale. Threat Modeling and Quantification: Ability to translate attack paths into quantified risk scenarios and prioritized control investments aligned to business objectives and crown jewels. External Partnerships: Active engagement with H-ISAC/ISAOs and government/industry partners; track record of rapidly converting global/viral cyber events into enterprise defenses and executive guidance. Certifications: One or more of GCTI, GREM, GRID, GCIH, CISSP, or equivalent demonstrated expertise. People Leadership: Built diverse, high-performing teams; established career paths, coaching frameworks, and a culture of analytic rigor, technical excellence, and continuous improvement.All roles in IT are expected to demonstrate a mindset of embracing, adopting and appropriately using AI and digital tools in day‑to‑day work to improve outcomes and ways of working.LocationGaithersburg, Maryland. Office Working RequirementsWhen we put unexpected teams in the same room, we unleash bold thinking with the power to inspire life-changing medicines. In-person working gives us the platform we need to connect, work at pace and challenge perceptions. That’s why we work, on average, a minimum of three days per week from the office. But that doesn’t mean we’re not flexible. We balance the expectation of being in the office while respecting individual flexibility. Join us in our unique and ambitious world.The annual base pay for this position ranges from $162.536,00 - $243.804,00 USD Our positions offer eligibility for various incentives—an opportunity to receive short-term incentive bonuses, equity-based awards for salaried roles and commissions for sales roles. Benefits offered include qualified retirement programs, paid time off (i.e., vacation, holiday, and leaves), as well as health, dental, and vision coverage in accordance with the terms of the applicable plans.Date Posted14-sept-2026Closing Date25-sept-2026Our mission is to build an inclusive environment where equal employment opportunities are available to all applicants and employees. In furtherance of that mission, we welcome and consider applications from all qualified candidates, regardless of their protected characteristics. If you have a disability or special need that requires accommodation, please complete the corresponding section in the application form.SummaryLocation: US - Gaithersburg - MDType: Full time

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Director of Cyber Threat Intelligence (CTI) in Gaithersburg, MD vacancy
  •  ...AV is seeking a Cyber Threat Intelligence Analyst to identify, analyze, and communicate cyber threats that affect the organization. The role blends traditional threat intelligence with strong technical cybersecurity skills to create actionable intelligence for detections... 
    Cyber
    Intelligence

    A/V Services LLC

    Germantown, MD
    18 hours ago
  • $190.96k - $286.44k

     ...Senior Director, Cyber Exposure Management Introduction to role: Are you ready to turn...  ...evolve offensive testing into a continuous, intelligence-led capability. How would you partner...  ...asset criticality, exploitability and threat intelligence; implement enterprise remediation... 
    Cyber
    Intelligence
    Temporary work
    Work at office
    Worldwide
    Flexible hours
    3 days per week
    Gaithersburg, MD
    17 days ago
  • $62k - $141k

     ...life and work. Innovate with intention Build mission-ready tech that protects the nation. Cyber Threat Intelligence Analyst, Mid The Opportunity: As a cyber threat intelligence (CTI) analyst, you know how to support a Security Operations Center (SOC) by collecting,... 
    Cyber
    Intelligence
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Bethesda, MD
    5 days ago
  •  ...Place to Work. ABOUT ROLE:The Director, Cyber Security Detection...  ...maturation in partnership with GSOC, CTI, Vulnerability Management,...  ...interpersonal risk appetite and threat landscape; establish...  ...prioritise coverage based on threat intelligence and risk assessments. Purple... 
    Cyber
    Intelligence
    Hourly pay
    Full time
    Temporary work
    Work at office
    Flexible hours
    3 days per week

    AstraZeneca

    Gaithersburg, MD
    3 days ago
  • $132.23k - $176.31k

     ...investigate, and scale discovery of evolving malicious threats, provide mission-relevant intelligence, and support mitigations on large networks. Our global...  ...) with a goal of automating detection. Work with cyber operators, when requested, to conduct in-depth investigations... 
    Cyber
    Intelligence
    Full time
    Temporary work
    Work experience placement
    Work at office
    Remote work

    Lumen

    Rockville, MD
    18 hours ago
  • $145.46k - $193.94k

     ...us today. The Role Black Lotus Labs is seeking a remote Threat Intelligence Researcher on the Research & Analysis team focused on...  ...(e.g., netflow, malware and passive DNS,) to track malicious cyber actors, their infrastructure, and campaigns. Build repeatable... 
    Cyber
    Intelligence
    Full time
    Temporary work
    Remote work

    Lumen

    Gaithersburg, MD
    1 day ago
  • $100k - $165k

     ...management processes. Knowledge of cybersecurity principles, cyber threats, and vulnerabilities. Knowledge of cloud computing...  ...data visualization tools (e.g., Power BI) and cyber threat intelligence platforms. Knowledge of AI/ML concepts and tools. Highly... 
    Cyber
    Intelligence
    Full time
    Flexible hours

    Amatriot Group, LLC

    Rockville, MD
    1 day ago
  • $140k - $184k

     ...Conduct malware detonation, static malware disassembly, dynamic/runtime malware analysis, and reverse engineering. Support cyber threat intelligence production, mobile device security investigations, and email/phishing analysis. Collect, preserve, and analyze digital... 
    Cyber
    Intelligence
    Full time
    Flexible hours

    ActioNet

    Rockville, MD
    2 days ago
  •  ..., cloud environments, and security infrastructure. Perform proactive threat hunting and identify, collect, and document Indicators of Compromise (IOCs). Support Cyber Threat Intelligence (CTI) activities through research, correlation, and dissemination. Assist... 
    Cyber
    Intelligence
    Local area

    System One

    Bethesda, MD
    a month ago
  • $63k - $83.8k

     ...24/7 enterprise security monitoring and threat response. Key Details Location: Remote (...  ...operations. Keep up-to-date with emerging cyber threats and adjust security measures...  ...knowledge of cybersecurity principles, threat intelligence, and vulnerability management. Hands-on... 
    Cyber
    Intelligence
    Temporary work
    Remote work
    Night shift
    Afternoon shift

    Blu Omega LLC

    Rockville, MD
    1 day ago
  •  ...mission software capabilities in the areas of cyber, logistics, security operations, and...  ...’ mission to defend against evolving threats around the world. Our team’s focus is to...  ...protect people and critical assets. The Intelligence Production Solutions Division (IPSD),... 
    Cyber
    Intelligence
    Contract work
    Worldwide

    Leidos

    Gaithersburg, MD
    3 days ago
  • $112k - $179k

     ...opportunity to work at the forefront of cyber investigations, digital forensics, cyber threat analysis, and mission support...  ...requirement of the program's directorates and the integration of these...  ...with National Cyber Intelligence programs to identify our customer... 
    Cyber
    Intelligence
    Contract work
    Work at office
    Shift work

    Peraton

    Rockville, MD
    1 day ago
  • $82.78k - $140.72k

     .../or job specifics. About BAE Systems Intelligence & Security BAE Systems, Inc. is the...  ...everything we do-from intelligence analysis, cyber operations and IT expertise to systems...  ...to recognize, manage and defeat threats inspires us to push ourselves and our technologies... 
    Cyber
    Intelligence
    Full time
    Contract work
    For contractors
    Work experience placement
    Local area

    BAE Systems USA

    Rockville, MD
    3 days ago
  • $80k - $130k

     ...through cutting-edge technology. As a leader in Artificial Intelligence, Cybersecurity and Self-Healing Infrastructure , we are...  ...operational procedural guides Track, respond to and remediate cyber security threats Collaborate with other engineers, analysts, data... 
    Cyber
    Intelligence
    Live in
    Work at office

    US AI

    Rockville, MD
    6 days ago
  •  ...About the Role: The Senior Director, Digital Forensics & Incident Response owns AstraZeneca...  ...to respond to and investigate cyber incidents. This role commands the enterprise...  ...with Detection Engineering, Cyber Threat Intelligence, Threat Exposure Management, Insider Risk... 
    Cyber
    Intelligence
    Hourly pay
    Permanent employment
    Temporary work
    Work at office
    Flexible hours
    3 days per week
    Gaithersburg, MD
    22 days ago
  •  ...alignment with Department of Defense (DoD) and Intelligence Community (IC) security frameworks while...  ...secure, resilient, and compliant cyber operations. RESPONSIBILITIES • Provide...  ..., security operations improvements, and threat mitigation strategies. • Develop... 
    Cyber
    Intelligence
    Full time

    Synertex LLC

    Bethesda, MD
    15 days ago
  • $150k - $170k

     ...specialize in delivering integrated, high-impact solutions across cyber operations, enterprise resource management, and mission...  ..., interpret, and apply policy guidance from federal, DoD, and Intelligence Community sources, ensuring alignment with applicable directives... 
    Cyber
    Intelligence
    Contract work

    Method Products

    Rockville, MD
    3 days ago
  • $124.09k - $149.5k

     ...NAT, routing, VPN, application controls, threat prevention, and URL filtering. ·...  ...leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against...  ...-ready capabilities in AI, cloud, cyber and software development.Join our Talent... 
    Cyber
    Intelligence
    Full time
    Temporary work
    Immediate start
    Remote work
    Worldwide
    Flexible hours

    General Dynamics Information Technology

    Rockville, MD
    9 hours ago
  •  ...Review system architectures to ensure compliance with federal and intelligence community standards. Minimum Qualifications Active TS/...  ...Mission Footbridge Federal delivers engineering, cyber, mission IT, analytics, and cleared program support for defense... 
    Cyber
    Intelligence
    Flexible hours

    Footbridge Federal

    Rockville, MD
    1 day ago
  • $154.05k - $278.48k

     ...customer’s information systems, networks, and infrastructure from cyber threats and vulnerabilities. This role supports the design,...  ...monitor security advisories, bulletins, and industry threat intelligence to stay informed of current vulnerabilities, threats, and trends... 
    Cyber
    Intelligence

    Leidos

    Bethesda, MD
    18 hours ago
  • $135k - $216k

     ...026-170360 Position Category Cyber Security Clearance Top Secret...  ...verification and identifying known threat artifacts. Experience conducting static...  ...Prior experience working within the Intelligence Community (IC). Demonstrated experience... 
    Cyber
    Intelligence
    Contract work
    Shift work

    Peraton

    Bethesda, MD
    2 days ago
  • $218.33k - $327.49k

     ...fundamentally shift the way cancer is treated. The Competitive Intelligence and Analysis team sits at the heart of developing commercial...  ...of the constantly evolving oncology landscape. As a Senior Director, Competitive Intelligence, you will work with a team of... 
    Intelligence
    Temporary work
    Work at office
    Remote work
    Flexible hours
    Shift work
    3 days per week
    Gaithersburg, MD
    6 days ago
  • $107.9k - $195.05k

    Job Id: 0000175299Job Category: Cyber SecurityJob Location: Gaithersburg, MarylandSecurity Clearance: Public Trust or UnclearedBusiness...  ...Development, Software Architect, Technical Lead, Artificial Intelligence, Machine Learning, Enterprise Applications, Government... 
    Cyber
    Intelligence

    ZP Group

    Gaithersburg, MD
    1 day ago
  •  ...protect and save lives by enhancing digital investigations and intelligence gathering to accelerate justice in communities around the...  ...National Guard and Air Force. Experience in selling forensics, cyber security, analytics, software products is a plus. BS/BA... 
    Cyber
    Intelligence
    Work at office
    Local area
    Remote work

    Cellebrite

    Gaithersburg, MD
    4 days ago
  •  ...Employment Type: Full-Time Reports to: Director of People, Culture, and Marketing...  ...Qualifications • Experience supporting DoJ, DoD, Intelligence Community, and/or Civilian Agency...  ...) in cloud computing, virtualization, cyber security, software development and data... 
    Cyber
    Intelligence
    Full time
    Contract work
    Temporary work
    For contractors
    Work at office
    Local area
    Remote work

    E-InfoSol LLC

    Derwood, MD
    3 days ago
  • $108.48k - $184.41k

     ...public-sector clients, and we’re looking for an Associate Creative Director, Art to help lead it.You’ll lead major assignments across...  ...knowledge. As part of this commitment, the use of artificial intelligence (AI) tools to generate or assist with responses during interviews... 
    Intelligence
    Full time
    Contract work
    Work experience placement
    Work at office
    Remote work

    ICF

    Rockville, MD
    1 day ago
  • $27.69 - $35.39 per hour

     ...Concepts, Digital Receiver Technology, Tampa Microwave, and Trusted Cyber Technologies), supports U.S. Joint Services, special...  ...partners with a variety of communication, visualization, signal intelligence/electronic warfare, and sensor/sonar capabilities. TDSI's key... 
    Cyber
    Intelligence
    Hourly pay
    Work experience placement
    Immediate start
    Overseas
    Day shift

    Thales Defense & Security, Inc.

    Germantown, MD
    18 hours ago
  • $107.9k - $185k

     ...it's architecting critical IT solutions, producing actionable intelligence, or developing cutting edge technology, we succeed because of...  ...people work? Are you interested in helping to protect our nation's cyber interests? Join our growing team as a Senior Systems Engineer,... 
    Cyber
    Intelligence

    teKnoluxion

    Gaithersburg, MD
    4 days ago
  • $154.05k - $278.48k

     ...authoritative leadership across architecture, integration, DevOps, cyber, and cloud environments. Candidates must bring hands‑on...  ...delivering mission‑critical systems for the Department of Defense and Intelligence Community. This role requires meaningful technical... 
    Cyber
    Intelligence
    Local area
    Immediate start

    Leidos

    Gaithersburg, MD
    3 days ago
  • Senior Director Of eDiscovery Employment Type: Full Time, Executive Level Department: eDiscovery and Litigation Contact Government...  ...or contact: Email: ****@*****.*** We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing... 
    Intelligence
    Full time
    Flexible hours
    Night shift
    Weekend work

    CGS Federal (Contact Government Services)

    Rockville, MD
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Director of Cyber Threat Intelligence (CTI). Be the first to apply!