Director of Cyber Threat Intelligence (CTI)
Pharma
Job description
About AstraZeneca AstraZeneca is a global, science-led, patient-focused biopharmaceutical company dedicated to discovering, developing, and commercialising prescription medicines for serious disease. We’re committed to being a Great Place to Work. About the Role The Director of Cyber Threat Intelligence will lead a highly technical CTI function within AstraZeneca’s Cybersecurity Operations division , managing a team of analysts to deliver strategic, operational, and tactical intelligence that measurably reduces risk across the enterprise, including manufacturing, clinical trial platforms, and R&D environments. This role anchors CTI to “intel-to-action” outcomes, partnering closely with Vulnerability Management, Detection Engineering, and Incident Response to harden controls, prioritize patching, improve detections, and accelerate response. Key Responsibilities Program Leadership and Strategy: Define CTI vision, operating model, and roadmap aligned to AstraZeneca’s cyber risk reduction strategy, with special emphasis on manufacturing continuity, clinical data integrity, and R&D IP protection . Adversary Prioritization Framework: Design and operate a scoring rubric that ranks actors based on intent/capability/relevance, TTP emergence and prevalence, organization-specific exposure to known vulnerabilities/CVEs, and global “viral” events , maintain ing dynamic watchlists and escalation triggers. MTTI Metric and Analytics: Implement analytic methods to estimate mean time-to-impact per adversary (from initial access to material business impact ) using internal telemetry, historical incidents, industry reporting, and confidence levels , performing comparisons with IR’s MTTC to drive control improvements. Attack Path Modeling: Build and maintain end-to-end attack path models from initial access to material impact across IT-to-OT pivots, clinical platforms, and R&D environments , map ping steps to MITRE ATT&CK (Enterprise/ICS), identify control gaps and choke points, derive detections-as-code and hunt hypotheses, and support validat ion efforts including purple-team exercises and adversary emulation to ensure enterprise hardening and measurable risk reduction. Dark Web and Closed-Source Monitoring: Establish collection and monitoring across dark web forums, marketplaces, breach dumps, and closed channels to identify emerging TTPs, credential leaks, data exposure, access-broker listings, and targeting of manufacturing, clinical, or R&D assets , integrat ing validated findings into TIP/SIEM pipelines, trigger takedown requests where feasible, and deliver rapid advisories with confidence ratings and specific actions for Vulnerability Management, Detection Engineering, and IR. Third-Party and Ecosystem Intelligence: Deliver risk insights for CROs/CMOs/ logistics /technology vendors, monitor credential leakage and domain spoofing, and support/coordinate takedown operations when needed. Structured Threat Actor Attribution (Diamond Model): Lead disciplined attribution using the Diamond Model (adversary, capability, infrastructure, victim) and complementary frameworks , correlat ing TTPs, tooling lineage, code-reuse, infrastructure overlaps, and victimology with confidence levels and analytic caveats , document ing hypotheses, alternative explanations, and disconfirming evidenc e, and produc ing reusable actor profiles and pivot paths that inform prioritization, detections, hunts, and incident response playbooks. Support Vulnerability Management: Partner with Vulnerability Management to contextualize CVEs (exploitability, weaponization, external scanning telemetry, compensating controls) and deliver risk-based patching prioritization across AstraZeneca’s estate including IT/OT, clinical platforms, and lab environments. Support Detection Engineering: Develop detection use cases to feed our detection-as-code pipeline and support detection ATT&CK coverage mapping, content tuning, and false-positive reduction, ensuring feedback loops from hunts and incidents continuously improve detection quality. Support GSOC/ Incident Response: Provide real-time adversary context that is highly technical including kill-chain reconstruction, containment recommendations, and countermeasures, producing post-incident intelligence retrospectives and detection/architecture improvements. Operational and Executive Reporting: Produce daily threat intelligence highlights , threat actor/campaign profiles, quarterly threat briefings, and other ad hoc intelligence products, ensuring products include quantified risk narratives for senior leadership that also alig n findings to regulatory expectations and business impact. Tooling and Automation: Optimize integrations across TIP, SIEM, EDR, case management, and telemetry; manage indicator lifecycle, automate enrichment, and measure source fidelity/bias. External Engagement: Lead participation with sector bodies (e.g., H-ISAC), peer sharing groups, and government/industry partners; track and assess global events and rapidly translate into actionable enterprise guidance. </
Stand out for this role
NoxPharm tailors your CV to this exact job description — matching the keywords recruiters and ATS systems screen for. Built for pharma & life sciences.
Tailor my CV now — free to trySimilar Pharma jobs
Mechanical Assembler
Thermo Fisher Scientific — Eindhoven, Netherlands
CRA (Level II)
Thermo Fisher Scientific — 2 Locations
Application Scientist
Thermo Fisher Scientific — Shanghai, China
Biostatistician II
Thermo Fisher Scientific — Beijing, China
Sr Project Mgr
Thermo Fisher Scientific — Beijing, China
Programmer Analyst
Thermo Fisher Scientific — Guangdong, China