CareerRiver

Cyber Operations Senior Detection Engineer

AstraZeneca · Maryland

📍 US - Gaithersburg - MDvia workday
Apply on company site ↗
CareerRiver pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to AstraZeneca.
Leverage technology to   impact   patients and   ultimately save   lives   Do you have   expertise   in, and passion   for   information technology ? Would you like to apply your   expertise   to   impact   the IT strategy in a company that follows   the science   and turns ideas into life changing medicines? If so, AstraZeneca might be the one for you!   ABOUT ASTRAZENECA AstraZeneca is a global, science-led, patient-focused biopharmaceutical company that focuses on the discovery,   development   and   commercialization   of prescription medicines for some of the world’s most serious   disease . But   we’re   more than one of the world’s leading pharmaceutical companies. At AstraZeneca,   we’re   dedicated to being a Great Place to Work.   ABOUT ROLE   The Senior Detection Engineer is a technical specialist within the Global Security Operations Centre (GSOC), based in Gaithersburg, Maryland, working with the Director, Cyber Security Detection Engineering. The role is characterised by leadership of detection content development initiatives that protect enterprise assets across cloud, on-premises, and OT/ICS environments. Responsibility is held for the design, implementation, and optimisation of detection logic through which threats are   identified , investigated, and mitigated with precision and efficiency.   WHAT YOU'LL DO Detection engineering initiatives : oversee detection engineering efforts   across multiple projects spanning threat coverage, detection logic development, and efficacy validation; technical guidance is provided to ensure that detection capabilities address the most significant threats across all technology domains.   Advanced detection frameworks and methodologies :   implement   detection engineering frameworks   to enhance the organisation's defensive posture through improved threat coverage, reduced false positives, and accelerated threat identification; industry guidelines for detection engineering are adopted and tailored to organizational requirements.   Enterprise-wide detection content librar y development and   management: design and   optimize   detection   libraries   to ensure comprehensive coverage of adversary tactics, techniques, and procedures as defined by frameworks such as MITRE ATT&CK; detection logic is developed that balances sensitivity with operational efficiency.   Detection development oversight : provide technical guidance of detection development operations   including coordination with external suppliers and platform vendors for comprehensive threat coverage; detection performance is   monitored   and issues are called out and resolved in collaboration with relevant collaborators.   Proactive detection   development and   coverage management :   proactively expand detection coverage   through periodic assessments of threat landscape evolution, detection gaps, and emerging attack techniques; critical coverage deficiencies are   identified   and resolution is driven through systematic detection development.   Stakeholder management :   maintain   engagement with security leadership   to communicate emerging detection requirements driven by threat intelligence and incident findings; strategic action plans are proposed for addressing coverage gaps and enhancing detection capabilities.   External partner relationship   management:   maintain   and   develop   relationships   with external partners, threat intelligence providers, and industry peers to   identify   innovative detection approaches and emerging techniques applicable to enterprise defence.   As a Specialist:   Technical guidance and   expertise : s upport the definition of detection standards, development methodologies, and quality frameworks within the detection engineering domain; critical detection failures are addressed through deep technical knowledge and systematic analysis.   Continuous improvement:   find opportunities to improve and   enhance the performance of detection logic, reduce false positives, and improve threat identification accuracy; opportunities for detection automation and orchestration are pursued   proactive ly.   Implement innovative detection engineering solutions :   identify   and manage new detection engineering solutions including adoption of new   detection techniques, behavioural analytics, and machine learning approaches; training and organizational change activities are led to ensure successful adoption.   Technical guidance and mentorship :   provide   ongoing technical guidance and mentoring   to detection engineering team members and security analysts   regarding   detection logic development, threat hunting techniques, and effective use of detection platforms.   Maintain training and awareness materials : develop and   maintain   training and awareness materials   regarding   detection engineering practices, threat actor TTPs, and effective investigation methodologies; knowledge is shared to enable security operations teams to   leverage   detection capabilities effectively.   Knowledge, Experience, and Understanding of: Detection Engineering Fundamentals : Deep   expertise   in detection logic design, threat modelling, and coverage mapping; extensive experience with detection development across diverse platforms and environments applied to enterprise-scale operations.   Threat detection frameworks : Comprehensive familiarity with MITRE ATT&CK, Cyber Kill Chain, and detection engineering methodologies; understanding of how adversary techniques manifest across different technology domains and how detection logic must be adapted accordingly.   Detection platforms and tooling : Substantial hands-on experience with enterprise detection platforms including SIEM, EDR, NDR, and cloud-native security services; advanced   proficiency   in platform-specific query languages, rule formats, and detection logic development.   Working knowledge of how threat intelligence is consumed and tu

More Maryland jobs

Maryland jobs · Browse all locations