Senior Director, Digital Forensics & Incident Response
$190.96k - $286.44kAstraZeneca
About the Role:
The Senior Director, Digital Forensics & Incident Response owns AstraZeneca’s global capability to respond to and investigate cyber incidents. This role commands the enterprise response to material incidents across cloud, on-premises and OT/ICS environments; owns incident governance, readiness and the forensic defensibility of all collected evidence; and is accountable for executive reporting, lessons learned and the control hardening that follows.
This is a build role as AstraZeneca matures its internal incident response capability. The successful candidate will compose the function, hire the team and establish the standards under which it operates. The role leads through a Director, Forensics & Malware Analysis, and a global CSIRT working follow-the-sun alongside Regional Security Operations Centers in Macclesfield, Guadalajara, Chennai and Shanghai.
The role partners closely with Detection Engineering, Cyber Threat Intelligence, Threat Exposure Management, Insider Risk & DLP, IT, Legal, Privacy, Risk & Compliance, Corporate Communications, Insurance and Physical Security. Because AstraZeneca’s research and development intellectual property is a primary target for nation-state actors, and its manufacturing estate carries safety and supply consequences, the judgement exercised during an incident has consequences well beyond IT.
What You’ll Do:
Incident Command: Act as the accountable commander for material and crisis-level cyber incidents, driving scoping, containment, eradication, recovery and investigation across hybrid cloud, on-premises and OT/ICS environments.
Service Line Ownership: Own the Incident Response strategy, multi-year roadmap, operating budget and capability plan, setting direction and standards with a high degree of autonomy.
Incident Governance: Define and maintain incident categories, severity definitions, activation criteria, decision authorities, delegation of authority during out-of-hours events and the handoff into enterprise crisis management.
Forensic Defensibility: Through the Director, Forensics & Malware Analysis, ensure that evidence is preserved, collected and analysed with chain-of-custody rigor that stands up to legal and regulatory scrutiny. Own the relationship with Legal regarding litigation hold, privilege and retention.
Readiness and Exercises: Run a calendar of tabletop, functional and purple-team exercises reaching from analyst level to the Executive Committee. Close findings and evidence improvement.
Coverage Model: Guarantee 24x7 response coverage with credible follow-the-sun handoffs, issue paths and surge capacity, including in-country arrangements where data-localisation or sanctions constraints apply.
Automation and AI: Operationalise agentic SIEM capability, XDR and SOAR playbooks, LLM-assisted runbooks and automated triage packages to compress mean time to detect, mean time to contain and mean time to respond without eroding evidentiary quality or human accountability.
Metrics and Reporting: Own Incident Response targets and key risk indicators, including mean time to detect, contain and respond, dwell time, containment quality and business impact. Report these credibly to senior leadership.
Executive and Board Communication: Deliver incident briefings, written updates and quarterly lessons-learned reviews to the CISO and IT leadership and, where warranted, the Audit Committee.
Regulatory and Notification Support: Work with Legal, Privacy and Compliance to support breach-notification assessments and regulatory obligations across the countries in which AstraZeneca operates, including material-incident disclosure considerations.
Controls Hardening: Drive post-incident detection and control improvements with Detection Engineering, Identity, Cloud, Endpoint, Network and OT teams.
Leading the Function:
Build and Organization Design: Design and staff the DFIR function from a near-zero baseline, defining roles, levels, sourcing locations and the balance of permanent and retained capacity.
Leading Through Leaders: Manage a Director-level leader and incident managers; set objectives, review performance and develop successors capable of commanding an incident in the Senior Director’s absence.
Coverage and On-Call: Maintain on-call rotations, surge models and cross-regional handoff standards, and act as the senior critical issue point when severity demands it.
Talent and Capability: Lead inclusive recruitment and build genuine career paths and upskilling in DFIR, cloud and identity forensics, OT/ICS, malware analysis and automation, using regional and external partnerships.
Team Sustainability: Protect the team from the burnout that can follow sustained high-tempo response. Design rotations, recovery and workload distribution deliberately.
Budget and Commercial Management: Own the service line budget, tooling and retainer spend, and build the case for further investment.
Knowledge, Experience and Understanding:
Incident Command and the Incident Response Lifecycle: Proven command across the full lifecycle at enterprise scale, including preparation, detection, scoping, containment, eradication, recovery and post-incident review, supported by appropriate plans and playbooks.
Digital Forensics and Evidence Handling: Experience managing the collection, preservation and analysis of digital evidence; chain of custody; timeline reconstruction; attribution; and concise executive reporting of forensic findings.
Attacker Tradecraft: Deep working knowledge of the attack lifecycle and MITRE ATT&CK, common threat actor tactics, techniques and procedures, and the different behaviours of nation-state and ransomware operators once inside an environment.
Automation and AI in Operations: Experience operationalising modern security tooling, including SIEM, SOAR and XDR, together with artificial intelligence, large language model and agentic capabilities to enable triage, analysis and eradication at scale, with clear human accountability for consequential decisions.
Cloud, Identity and Endpoint Visibility: Understanding of telemetry and logging priorities across major cloud platforms, identity providers, operating systems and security tooling, including the forensic limitations of each.
Operational Technology: Experience coordinating response in manufacturing OT/ICS environments where safety, validated systems and production continuity constrain responder actions.
Regulated-Industry Constraints: Experience working within GxP and validated-system requirements, clinical and patient data sensitivities and third-party exposure considerations.
Legal, Regulatory and Crisis Communications: Ability to build durable partnerships with Legal, Privacy, Risk and Compliance, Communications and Physical Security, and to operate comfortably under privilege.
Vendor and Retainer Readiness: Experience maintaining retainer partner readiness and integrating external specialists during major incidents without losing command of the response.
Minimum Skills and Experience Required
Education: Bachelor’s degree in information security, computer science or a related field, or equivalent practical experience.
Professional Experience: Ten or more years of experience in cybersecurity, including seven or more years in incident response or digital forensics.
Leadership Experience: Five or more years leading incident response in a large, complex enterprise, including at least two years managing other people leaders or managers.
Command Experience: Demonstrable record as the accountable commander for high-severity incidents spanning hybrid cloud, on-premises and OT environments.
Global Coordination: Experience running or integrating distributed 24x7 teams across multiple regions and cultures, including follow-the-sun handoffs.
Communication and Facilitation: Ability to explain complex technical situations in clear business terms, produce concise written material under time pressure and lead briefings for senior executives.
Analytical Decision-Making: Ability to assess incomplete information, weigh risk and balance strategic and tactical demands against business pragmatism and risk appetite.
Cross-Functional Credibility: Demonstrated ability to collaborate across IT, Legal, GRC and Physical Security, with a strong service orientation.
Availability: Willingness to serve as the senior escalation point outside business hours and to travel internationally as incidents and readiness activities require.
Desirable Skills and Experience
Certifications: CISSP, CISM, GIAC certifications such as GCIH, GCFA, GREM or GNFA, and CCSP.
Sector Experience: Experience in pharmaceutical, life sciences, healthcare or another highly regulated industry with significant manufacturing OT exposure.
Board and Regulator Exposure: Experience briefing an audit committee or board, or engaging directly with regulators or law enforcement during a significant incident.
Commercial Experience: Experience negotiating and governing Incident Response retainers and forensic vendor arrangements across multiple jurisdictions.
Language Skills: Working proficiency in a second language relevant to AstraZeneca’s delivery hubs.
When we put unexpected teams in the same room, we unleash bold thinking with the power to encourage life-changing medicines. In-person working gives us the platform we need to connect, work at pace and challenge perceptions. That's why we work, on average, a minimum of three days per week from the office. But that doesn't mean we're not flexible. We balance the expectation of being in the office while respecting individual flexibility. Join us in our unique and ambitious world.
The annual base pay for this position ranges from $190,957 - $286,435 USD Annual. Hourly and salaried non-exempt employees will also be paid overtime pay when working qualifying overtime hours. Base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. In addition, our positions offer a short-term incentive bonus opportunity; eligibility to participate in our equity-based long-term incentive program (salaried roles), to receive a retirement contribution (hourly roles), and commission payment eligibility (sales roles). Benefits offered included a qualified retirement program [401(k) plan]; paid vacation and holidays; paid leaves; and, health benefits including medical, prescription drug, dental, and vision coverage in accordance with the terms and conditions of the applicable plans. Additional details of participation in these benefit plans will be provided if an employee receives an offer of employment. If hired, employee will be in an “at-will position” and the Company reserves the right to modify base pay (as well as any other discretionary payment or compensation program) at any time, including for reasons related to individual performance, Company or individual department/team performance, and market factors.
Are you ready to bring new insights and fresh thinking to the table? Fantastic! We have one seat available, and we hope it’s yours. Apply today.
AstraZeneca embraces diversity and equality of opportunity. We are committed to building an inclusive and diverse team representing all backgrounds, with as wide a range of perspectives as possible, and harnessing industry-leading skills. We believe that the more inclusive we are, the better our work will be. We welcome and consider applications to join our team from all qualified candidates, regardless of their characteristics. We follow all applicable laws and regulations on non-discrimination in employment (and recruitment), as well as work authorization and employment eligibility verification requirements.
Date Posted
20-Aug-2026Closing Date
02-Sep-2026Our mission is to build an inclusive environment where equal employment opportunities are available to all applicants and employees. In furtherance of that mission, we welcome and consider applications from all qualified candidates, regardless of their protected characteristics. If you have a disability or special need that requires accommodation, please complete the corresponding section in the application form.
$140k - $184k
ActioNet is seeking a Digital Forensics SME in the United States to provide advanced DFIR expertise across investigations... ..., and remediation of complex cybersecurity incidents. The role involves leading SOC response, performing malware analysis, and preserving evidentiary...Senior- ...Services in Germantown, MD is seeking a seasoned leader to head the Incident Response and Digital Forensics team. You will guide DFIR operations, mentor analysts, and coordinate with clients and senior leadership on incident responses. The ideal candidate has 7+ years in...Senior1 day per week
- ...About the Role: The Senior Director, Digital Forensics & Incident Response owns AstraZeneca’s global capability to respond to and investigate cyber incidents. This role commands the enterprise response to material incidents across cloud, on-premises and OT/ICS environments...SeniorHourly payPermanent employmentTemporary workWork at officeFlexible hours3 days per week
- ...Job Description Job Description Incident Response & Digital Forensics Lead Work arrangement: Hybrid (1-2 days a week onsite) Location: Germantown... ...findings into clear briefings and recommendations for senior federal leadership. The role also provides technical...SuggestedFull time2 days per week1 day per week
- Accenture Federal Services in Germantown, MD is seeking a senior cybersecurity professional to lead the Incident Response & Forensics (DFIR) team and drive critical investigations across federal clients. You will coordinate with senior leadership, plan and execute response...Senior1 day per week
- Accenture Federal Services seeks a seasoned Incident Response & Digital Forensics Lead in Germantown, MD. You will lead the IR & Forensics team and coordinate briefings with clients and senior leadership on incident responses. Requirements: 7+ years in IR/forensics, GCFE...Senior1 day per week
$150k - $180k
...expertise and support to maximize cyber fusion across the Client’s SOC. The role requires 8+ years in cybersecurity threat hunting or incident response, with strong SIEM, EDR, and malware analysis skills, and eligibility for US citizenship. On-site in Frederick, MD, with...Senior- Edgewater Federal Solutions is seeking an Incident Response (IR) Manager to lead a team of IR Tier-1, Tier-2, and Forensics specialists on a Federal government contract. The role also serves as the Right-of-Boom Deputy to the Cybersecurity Operations Task Lead. The candidate...SeniorContract work
$140k - $184k
ActioNet, Inc. seeks a Digital Forensics SME with extensive DFIR experience to investigate, analyze... ..., and remediate complex cybersecurity incidents across the agency enterprise. The role... .... The candidate will lead SOC response, ensure proper evidence handling, and...Senior- Edgewater Federal Solutions is seeking a Tier II Incident Response Analyst to support a federal government contract. The role requires US... ...will bring strong incident response, malware analysis, and forensics skills, with cloud, SOC, and CIRT experience, and will contribute...SeniorContract work
- ...Manager to join their team in Bethesda, Maryland. This position involves leading day‑to‑day SOC operations, including monitoring, incident response, and threat analysis. The ideal candidate should have 5+ years in cybersecurity incident response, experience running a SOC,...Senior
- Date: February 2026TITLE:Senior Director, Digital Acceleration & Brand Growth MarketingRESPONSIBLE TO:Chief Marketing OfficerDIVISION/DEPT:Marketing... ...Goodwill® brand for a digital-first world. This role is responsible for advancing how the Goodwill brand is experienced,...SeniorLocal area
- ActioNet, Inc. seeks a senior Tier 3 Cybersecurity Analyst to lead advanced threat detection, incident response, and forensics within a high-sophistication SOC. You will mentor junior staff, craft detection analytics, and coordinate with federal partners on complex investigations...Senior
- ActioNet is seeking a Tier 3 Cybersecurity Analyst in Rockville, MD to lead advanced incident detection, response, and forensic investigations. The role requires extensive expertise in malware analysis, threat hunting, and multi-source data fusion to mitigate sophisticated...Senior
$110k - $260k
...applications. The ideal candidate will possess expertise in various programming languages and experience with cloud environments. Responsibilities include mentoring teams, leading technical initiatives, and ensuring system reliability. Competitive compensation of $110,000...SeniorNight shift$110k - $260k
...scale, leveraging expertise in coding and large-scale system design. You will also participate in on‑call rotations, providing incident response, troubleshooting, and post-mortem analysis to improve system reliability and minimize operational impact. Position...SeniorWork experience placementLocal areaFlexible hoursNight shift$167.34k - $238.46k
...and regulatory leader for its Digital Standards Business Unit who... ...quality standards. Internally, the Director will work highly cross-... ...Standards steering committee and senior stakeholders.2) Regulatory,... ...agencies and is not responsible for fees from recruiters or other...Full timeWork at officeWorldwide- ...the Enterprise Data, Analytics & AI organization, which leads digital data strategy to optimize guest-facing and internal digital... ...booking engines and loyalty platforms. What Will You Do? As a Senior Director, Digital Data Products at Marriott International, you will...SeniorWorldwide
$139.45k - $198.72k
...work environment.Brief Job OverviewThe Cloud Operations Senior Manager is responsible for the strategy, reliability, performance, and continuous... ...practices, driving platform stability, automation, monitoring, incident response, and continuous improvement across critical...SeniorFull timeFor contractorsWork at officeWorldwide$122k - $184k
The Associate Director, Digital & Business Process Strategy leads the vision... ..., MD and report to the Senior Director of Digital & Business Process Strategy. Key responsibilities 1. Product vision and roadmap... ...posture; manage incidents, problem remediation, and continuous...Contract workTemporary work- Get notified about new Director Of Web Services jobs in United States . 142 Director Of Web... ...& App) Director, Mobile/Web Engineering (Digital Experience) Director of Web Development -... ...Development Manager - Web & Cloud Integration Senior Assistant Director of Communications &...Senior
- ...DC).Technical Summary:We are seeking a Director, Digital Products Strategy & Marketing to... ...Permanente's digital ecosystem. This role is responsible for developing end-to-end strategies... ...who can navigate ambiguity, influence senior leaders, and translate enterprise priorities...Work experience placementFlexible hours
- ...Pharmacopeial Convention, seeks a Cloud Operations Senior Manager to lead AWS cloud services, data... ...for enterprise and customer-facing applications. Responsibilities include leadership of cloud operations teams, incident management, and DevOps practices, with a focus...Senior
- ...Standards and Technology seeks a lead official to oversee the Fire Protection and Emergency Response Program, directing responses to emergency medical, fire, and hazmat incidents. The role requires coordinating incident actions within the ICS and ensuring tactical...Senior
$141.42k - $157.14k
Director of Digital Products and User Experience Design Posting Date: 7/06/2026 Cluster/Team: Digital Communications Cluster / Digital Product... ...Director of Digital Products and User Experience Design is responsible for developing an exemplary digital customer experience...Temporary workWork at office- ...Regulatory Authority, Inc. is seeking a Senior Principal Risk Specialist - Cyber Engagements... ...exercises that simulate real-world incidents. Qualified candidates should possess advanced... ...in cybersecurity risks and incident response. A competitive compensation package and...Senior
$130k - $216k
...a Scientific Systems Operations Lead to oversee day-to-day computing platform operations in Rockville, MD. The role includes incident response, performance monitoring, capacity planning, and maintaining documentation. A Bachelor's degree in IT or related field and 7 years...Senior- Jobtailor seeks an IT Project Manager to lead digital transformation efforts, drive system design, and oversee delivery across multiple projects. The role requires strong client communication, budget planning, and data-driven decision making to ensure on-time, quality results...Senior
- The Office of Nuclear Security and Incident Response at Exigentservicesllc is seeking a Sr. Document Reviewer / Project Manager to lead critical efforts in document review and ensure compliance with classification policies. This role involves working with sensitive materials...SeniorWork at office
- ...Senior Safety Specialist Reports to: Safety Manager Job Summary: The Senior Safety Specialist... ...the Safety Manager or their designee. Responsibilities include purchasing supplies, equipment,... ...Conduct impartial investigations of incidents, near‑misses, and injuries; perform...SeniorFor contractorsFor subcontractorLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Director, Digital Forensics & Incident Response. Be the first to apply!
- senior lead project manager Gaithersburg, MD
- senior robotics software engineer Gaithersburg, MD
- senior devops engineer remote Gaithersburg, MD
- sr project manager Gaithersburg, MD
- senior windows systems engineer Gaithersburg, MD
- senior network engineer remote Gaithersburg, MD
- senior accountant controller Gaithersburg, MD
- senior manager accenture Gaithersburg, MD
- senior devops Gaithersburg, MD
- senior brand designer Gaithersburg, MD



