Skip to main content
AstraZeneca logo

Senior Director, Cyber Exposure Management

AstraZeneca
September 12, 2026
Full-time
Remote friendly (Gaithersburg, MD)
Worldwide
IT
Role: Senior cybersecurity leader responsible for enterprise exposure management, application security, and offensive testing within a biopharma context, focusing on protecting research, manufacturing, and digital assets. Responsibilities include developing a multi-year strategy, advancing risk-based vulnerability management, maintaining attack surface visibility, enforcing application security assurance, overseeing software supply chain governance, and conducting continuous penetration testing and adversary emulation. The role involves integrating offensive findings into risk prioritization, managing cross-functional teams, establishing metrics and reporting to senior leadership, and building the exposure management function. Qualifications: Bachelor's degree or equivalent in security, computer science, or related field; 10+ years in cybersecurity with extensive experience in vulnerability, application, or offensive security; 5+ years leading exposure/security teams in large organizations, including leadership of managers. High-Value: Experience with risk-based vulnerability prioritization, application security (SAST, DAST, SCA), cloud attack surface management, supply chain risk, AI security considerations, and exposure management in regulated environments such as GxP or OT. Certifications like CISSP, CISM, OSCP, or GIAC preferred. Sector experience in pharma, healthcare, or highly regulated industries advantageous. Leadership involves cross-region team management, executive communication, and governance of security tooling and partners. Location: On-site with regional coordination; flexible with a minimum of three days in the office per week.