Director of Product Security Engineering

6 months ago


Gaithersburg, United States AstraZeneca Full time

Are you ready to be part of the future of healthcare? Are you able to think big, be bold, and harness the power of digital and AI to tackle longstanding life sciences challenges? Then Evinova, a new health tech business part of the AstraZeneca Group might be for you

As the Director of Product Security Engineering, you have a unique opportunity to join Evinova from the beginning. You will play a key role in implementing innovative cyber security practices that are designed by industry, for industry. You will report directly to the Evinova Head of Cyber Security, and focus collaborating with application development and platform engineering teams to deliver high quality application security services and expertise (, code scanning, remediation prioritization and support). Additionally, you will collaborate across the entire Chief Technology Officer (CTO) organization to define and implement a multi-year application security and DevSecOps roadmap. You will have ample opportunity for program ownership, increased levels of accountability, and significant visibility within the CTO Leadership Team. You will collaborate with globally dispersed technology teams. Success in this role requires leading by influence, strong emotional intelligence, and a natural disposition towards precision and accuracy. The ideal candidate will think holistically and proactively deliver on strategic initiatives to ensure our digital solutions and platform are secured against emerging threats.

Key Responsibilities include:

Develop and operationalize a standardized Application Security and DevSecOps program which encompasses the core activities of Threat Modeling, Security Tools and Testing (, SAST, SCA, DAST, IAST, etc.), and incorporating “privacy by design” and “secure by default” design processes into the CI / CD pipeline. 

Leverage a variety of AppSec and DevSecOps oriented tools to identify, assess, and prioritize security vulnerabilities across our products and platform. Additionally, automating, and standardizing system configurations with a secure-by-default disposition. This role will also be a key influencer for the selection of program enabling tools / solutions. 

 Execute in-depth analysis and provide assurance over application code, infrastructure, architecture, and configuration posturing.

Establish strong and productive relationships to ensure cyber security is viewed as an enabler and market differentiator. Providing expert level advisory and guidance on secure coding practices and addressing potential security risks. 

Establish and operationalize an application security vulnerability management program which includes steps to validate, analyze, and prioritize vulnerabilities. Additionally, driving remediation efforts. 

Develop secure development standards and related trainings to raise awareness of secure coding practices, threat actor tactics, and regulatory requirements. Leading efforts to automate infrastructure provisioning and application deployments. 

Providing cyber expertise in the definition and implementation of Infrastructure as Code patterns and practices. 

Partner with cyber security colleagues to deliver on continuous improvement objectives and deepen adjacent team’s awareness of product and application security risks and threat actor trends. 

Execute security architecture reviews for major product changes, providing assurance over security standards alignment, and driving security enhancements across existing solutions.

Lead co-sourced engagements to conduct application penetration testing, and other simulated “hacking” activities to proactively identify weaknesses and developing actionable remediation strategies. 

Collaborates with the Cyber GRC Lead to develop and report on related Key Performance Indicators and Key Risk Indicators, and the continuous improvement of security controls, processes, policies, standards, and other governing documents.

Together with the Security Operations Lead, manage and respond to product and application security alerts – guiding platform and product teams through high severity incidents. 

Provide support to external audit and customer due diligence requests, and providing training to adjacent colleagues on security awareness and best practices. 

Essential Skills/Experience:

6 + years of relevant experience and Bachelor’s degree or 10+ years of relevant experience and High School Diploma. Relevant experience may include work in the areas of software development, application and API security, penetration and vulnerability scanning, and ethical hacking.

Prior experience providing AppSec capabilities for a SaaS / cloud service provider.

Expert level understanding of security standards (, ISO 27001, GDPR, OWASP), DevSecOps practices / tools (, CI/CD, Infrastructure as Code, SAST, DAST), and agile methodologies.

Deep understanding of application security related frameworks, securing applications on the AWS cloud platform, containerization technologies, and security best practices (, API, Containers, AWS Cloud).

Strong familiarity and past experiences conducting Open-Source Software Clearance and Threat Modelling.

Prior experiences conducting web and mobile application penetration testing, documenting results, and presenting remediation strategies to a diverse stakeholder group.

Prior experiences successfully driving “secure by default” / shift left buy in across multiple teams.

Ability to make pragmatic decisions by analyzing highly complex situations, assessing risks and balancing strategic and tactical compliance/quality requirements.

Ability to work independently in a fast-paced environment with a proven ability to manage competing priorities.

Excellent written and verbal communication skills (English), project management, process improvement, attention to detail, and strategic thinking skills are highly preferred.

At least one of the following professional certifications: Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), AWS Solutions Architect, and / or Certified Ethical Hacker (CEH).

Knowledge of at least 2 programming languages used in web-based applications.

Desirable Skills/Experience:

Master’s degree in Technology, Computer Science, Software Engineering, or a related field.

Demonstrable experience presenting to external customers and senior levels of management.

Prior experience as a Software Developer, Infrastructure Engineer, and / or Product Security Officer.

Expert knowledge on threat actors targeting the Healthtech sector and SaaS solution providers.

Experience providing AppSec capabilities within a highly regulated sophisticated global business environment, particularly in the healthcare and / or clinical research industry. 

Demonstrate initiative, strong customer orientation, and cross-cultural working. 

In Office Requirement:

When we put unexpected teams in the same room, we unleash bold thinking with the power to inspire life-changing medicines. In-person working gives us the platform we need to connect, work at pace and challenge perceptions. That’s why we work, on average, a minimum of three days per week from the office. This role is based in Gaithersburg MD. Remote or alterative arrangements are not available for this role.

Why Evinova?

Evinova draws on AstraZeneca’s deep experience developing novel therapeutics, informed by insights from thousands of patients and clinical researchers. Together, we can accelerate the delivery of life-changing medicines, improve the design and delivery of clinical trials for better patient experiences and outcomes, and think more holistically about patient care before, during and after treatment. We know that regulators, healthcare professionals and care teams at clinical trial sites do not want a fragmented approach. They do not want a future where every pharmaceutical company provides their own, different digital solutions. They want solutions that work across the sector, simplify their workload and benefit patients broadly. By bringing our solutions to the wider healthcare community, we can help build more unified approaches to how we all develop and deploy digital technologies, better serving our teams, physicians and ultimately patients. Evinova represents a unique opportunity to deliver meaningful outcomes with digital and AI to serve the wider healthcare community and create new standards for the sector. Join us on our journey of building a new kind of health tech business to reset expectations of what a bio-pharmaceutical company can be. This means we’re opening new ways to work, pioneering cutting edge methods and bringing unexpected teams together. Interested? Come and join our journey

Date Posted

24-Jun-2024

Closing Date

27-Jun-2024Our mission is to build an inclusive and equitable environment. We want people to feel they belong at AstraZeneca and Alexion, starting with our recruitment process. We welcome and consider applications from all qualified candidates, regardless of characteristics. We offer reasonable adjustments/accommodations to help all candidates to perform at their best. If you have a need for any adjustments/accommodations, please complete the section in the application form.AstraZeneca requires all US employees to be fully vaccinated for COVID-19 but will consider requests for reasonable accommodations as required by applicable law.

  • Gaithersburg, Maryland, United States Housing Opportunity Com Full time

    About the RoleWe are seeking an experienced Safety and Security Director to join our team at Housing Opportunity Commission. This critical role involves planning, organizing, and directing the activities of the Security Division, ensuring the deployment and effective enforcement of a comprehensive security program. The successful candidate will have a strong...


  • Gaithersburg, United States AstraZeneca Full time

    If you have the passion and the drive to accelerate growth and make people’s lives better – then AstraZeneca is the place for you. In Operations we have a big ambition – to deliver more medicines to patients, quicker and more affordably. Backed by the investment, leadership and a clear plan to get there, we bring personal dedication and out of the box...


  • Gaithersburg, United States AstraZeneca Full time

    If you have the passion and the drive to accelerate growth and make peoples lives better then AstraZeneca is the place for you. In Operations we have a big ambition to deliver more medicines to patients, quicker and more affordably. Backed by the investment, leadership and a clear plan to get there, we bring personal dedication and out of the box...


  • Gaithersburg, Maryland, United States Redport Full time

    Job DescriptionWe are seeking a highly skilled Splunk Security Engineer to join our team at Redport. In this role, you will be responsible for automating threat feeds and integrating them with our Splunk Enterprise Security platform. You will also develop Splunk modules to support implementation and deployment activities, as well as integrate Splunk with...

  • Product Engineer

    2 weeks ago


    Gaithersburg, United States Booz Allen Hamilton Full time

    Job Number: R0209688Microelectronics Product EngineerKey Role:Research, design, develop, test, or supervise the manufacturing and installation of electrical equipment, components, or systems for commercial, industrial, military, or scientific use. Employ knowledge of electrical theory and materials properties. Apply advanced consulting skills or extensive...


  • Gaithersburg, United States Connsci Full time

    Connsci is seeking an experienced Director of Solutions Architecture (Data and Cyber Security) to join our growing organization. This person will report directly to our CEO and will be responsible for leading the technical side of our Data and Cyber Security practices inside the Department of Defense. This individual will work closely with business...


  • Gaithersburg, Maryland, United States Leidos Full time

    Leidos is a leading provider of innovative technology solutions to government and commercial customers. Our team is comprised of experts who share a passion for delivering high-quality services that meet the evolving needs of our clients.About the JobWe are seeking a highly skilled Cyber Security Engineer to join our team in Bethesda, MD. As a Cyber Security...


  • Gaithersburg, United States AstraZeneca, plc Full time

    Are you ready to be part of the future of healthcare? Are you able to think big, be bold and harness the power of digital and AI to take on longstanding life sciences challenges? Then Evinova, a new healthtech business, part of the AstraZeneca Group Director, Pipeline, Product, Management, Enterprise, Leadership, Technology


  • Gaithersburg, United States AstraZeneca, plc Full time

    Are you ready to be part of the future of healthcare? Are you able to think big, be bold and harness the power of digital and AI to take on longstanding life sciences challenges? Then Evinova, a new healthtech business, part of the AstraZeneca Group Director, Pipeline, Product, Management, Enterprise, Leadership, Technology


  • Gaithersburg, Maryland, United States Leidos Full time

    Leidos is a leading provider of technology-enabled services and mission software solutions to government agencies and commercial clients. With over 40 years of experience, we have established ourselves as a trusted partner in the defense and intelligence communities.Salary and BenefitsThe estimated salary range for this position is $101,400 - $183,300 per...


  • Gaithersburg, United States Noetic Strategies, Inc. Full time

    Job Title: Mid-Level Software Engineer (MUST HAVE ACTIVE TS/SCI) Location : Gaithersburg, MD Clearance : Current Active TS/SCI MINIMUM SKILLS REQUIRED: Strong proficiency with the following technologies: Frontend Web Development: REACT, Angular, Vue.js, or similar JavaScript frameworks Backend Development: Java including Java Spring Boot Cloud...


  • Gaithersburg, United States National Black MBA Association Full time

    Are you ready to be part of the future of healthcare? Are you able to think big, be bold and harness the power of digital and AI to take on longstanding life sciences challenges? Then Evinova, a new healthtech business, part of the AstraZeneca Group might be for you! Transform billions of patients’ lives through technology, data and groundbreaking ways of...


  • Gaithersburg, United States AstraZeneca GmbH Full time

    Are you ready to be part of the future of healthcare? Are you able to think big, be bold and harness the power of digital and AI to take on longstanding life sciences challenges? Then Evinova, a new healthtech business, part of the AstraZeneca Group might be for you! Transform billions of patients’ lives through technology, data and groundbreaking ways of...


  • Gaithersburg, United States Noetic Strategies, Inc. Full time

    Job Title: Mid-Level Software Engineer (MUST HAVE ACTIVE TS/SCI) Location: Gaithersburg, MD Clearance: Current Active TS/SCI MINIMUM SKILLS REQUIRED: Strong proficiency with the following technologies: Frontend Web Development: REACT, Angular, Vue.js, or similar JavaScript frameworks Backend Development: Java including Java Spring Boot Cloud Development:...


  • Gaithersburg, United States Noetic Strategies, Inc. Full time

    Job Title: Mid-Level Software Engineer (MUST HAVE ACTIVE TS/SCI)  Location: Gaithersburg, MD Clearance: Current Active TS/SCI MINIMUM SKILLS REQUIRED: Strong proficiency with the following technologies: Frontend Web Development: REACT, Angular, Vue.js, or similar JavaScript frameworks Backend Development: Java including Java Spring Boot Cloud Development:...


  • Gaithersburg, United States Noetic Strategies, Inc. Full time

    Job Title: Mid-Level Software Engineer (MUST HAVE ACTIVE TS/SCI) Location: Gaithersburg, MD Clearance: Current Active TS/SCI MINIMUM SKILLS REQUIRED: Strong proficiency with the following technologies: Frontend Web Development: REACT, Angular, Vue.js, or similar JavaScript frameworks Backend Development: Java including Java Spring Boot Cloud Development:...


  • Gaithersburg, United States Quadrant Inc Full time

    Job ID: 24-04250Make your application after reading the following skill and qualification requirements for this position. Estimator Security Systems Gaithersburg, MD Pay From: $38.00 per hour MUST: Must be able to obtain a US Government Security clearance Experienced Security System Estimator 3+ years of experience in estimating for security systems,...


  • Gaithersburg, United States Quadrant Full time

    Estimator Security Systems Gaithersburg, MD Pay From: $38.00 per hour MUST: Must be able to obtain a US Government Security clearance Experienced Security System Estimator 3+ years of experience in estimating for security systems, including video surveillance, intrusion detection, and access control Strong familiarity with blueprints and security system...


  • Gaithersburg, United States AstraZeneca Full time

    The Executive Director, Cell Culture and Fermentation Sciences position will be responsible for all aspects of upstream development and strategic direction to support the advancement of AstraZeneca’s (AZ’s) biologics pipeline projects from pre-clinical to commercial stage. The successful candidate will also drive the development and implementation of...


  • Gaithersburg, Maryland, United States Leidos Full time

    At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success. We empower our teams, contribute to our communities, and operate sustainably.About the RoleThis exciting opportunity for an IT Security Specialist is part of our Digital Modernization Sector in the Leidos...