Cybersecurity Director – IAM Capability Leader ...

AstraZeneca GmbH
Cambridge
2 weeks ago
Applications closed

Related Jobs

View all jobs

Cloud Security Engineer

Network & Security Architect

Head of IAM

Cyber security Analyst

Cyber security Analyst, London

Cyber Security Analyst - L4

Leverage technology to impact patients and save lives.Do you have expertise in, and passion for IAM and cyber security?Would you like to apply your expertise to impact the IAMcapabilities in a company that follows science and turns ideas intolife changing medicines? If so, AstraZeneca might be the one foryou! About Astra Zeneca AstraZeneca is a global, science-led,patient-focused biopharmaceutical company that focuses on thediscovery, development, and commercialization of prescriptionmedicines for some of the world’s most serious diseases. But we aremore than one of the world’s leading pharmaceutical companies. AtAstraZeneca, we are dedicated to being a Great Place to Work. Aboutour Team It is a dynamic and performance-based environment to workin – but that is why we like it. There are countless opportunitiesto learn and grow, whether that’s exploring new technologies inhackathons, or redefining the roles and work of colleagues,forever. Craft your own path, with support all the way. A diverseset of minds that work cross-functionally and broadly together.Introduction to role Identity and Access Management are among themost critical aspects of any modern cyber security program. Threatactors increasingly leverage identity-based attacks for intrusionand lateral movement, and this trend will only accelerate asAI-based attack techniques are adopted by cyber-criminals. We areseeking a strategic and purposeful IAM Capability Leader to leadthe development and delivery of our enterprise IAM capabilities.This role will be responsible for defining the strategic vision,capability roadmaps, and execution plans across all key IAMdomains—including workforce, consumer and machine identity,authentication and authorization platforms and access governance,identity threat management, and IAM-related policies and standards.As a key member of our security leadership team, you will lead ateam of IAM capability owners and collaborate closely with our IAMoperations team, ensuring seamless alignment between strategy,delivery, and day-to-day operations. The ideal candidate will havea solid background in Active Directory, cloud authentication andauthorization flows, privileged access management, identityfederation, and a demonstrable record of building secure andscalable IAM programs in a fast-paced, innovation-drivenenvironment. This role requires both technical expertise andleadership skills to influence technology and product owners andleaders across the enterprise and promote a secure by designculture. Key Responsibilities - Lead IAM Capability Strategy: -Define and lead the strategy and capability roadmap for core IAMfocus areas: - Authentication and Federation - Access Management -Privileged Access Management (PAM) - Identity Governance andAdministration (IGA) - Identity Threat Detection & Response -IAM Policies, Standards, and Lifecycle Management - Development& Execution: - Define multiyear IAM capability roadmaps alignedwith business and security goals. - Lead the delivery of IAMcapabilities through cross-functional teams and initiatives. - Leadproject timelines, resources, and team member communication. - TeamLeadership: - Lead and mentor a distributed team of IAM capabilityowners and domain experts. - Cultivate a collaborative culture ofinnovation, accountability, and continuous improvement. -Collaboration & Stakeholder Engagement: - Partner with the IAMoperations team responsible for tickets, configuration, and BAUactivities - Work closely with infrastructure, cloud, HR, legal,compliance, and application teams to ensure IAM integration acrosssystems. - Communicate effectively with senior leadership on IAMprogress, risks, and performance. - Governance, Compliance &Risk Management: - Establish IAM policies, standards, andprocedures aligned with regulatory and compliance requirements. -Supervise IAM capability maturity and lead continuous improvementefforts. - Ensure alignment with relevant regulatory requirementsand industry standard methodologies related to product security(e.g., GDPR, SOC2, SOX). - Contribute to security risk assessmentsand audits. Essential Skills/Experience: - Bachelor’s degree incomputer science, Information Security, or a related field (orequivalent experience). - 8+ years of experience in cyber security,with at least 3 years in a leadership role focusing on identity andaccess management. - Deep knowledge across the IAM landscapeincluding authentication protocols (OAuth2, SAML, etc.), IGA tools,PAM solutions, and identity-centric threat management. - Experiencein defining and delivering strategic roadmaps for IAM capabilities.- Expertise in cloud platform capabilities, including modernauthentication protocols, credential vaulting, cloud user roles andleast privilege approach. - Solid understanding of IdentityGovernance tools and capabilities (e.g., Sailpoint, Saviynt),joiner/mover/leaver processes and identity proofing. - Experiencewith credential vaulting and rotation tools and capabilities (e.g.,CyberArk, Thycotic) - Expertise in Active Directory securitymonitoring and configuration in a large enterprise - Solidunderstanding of common identity security threats (e.g., credentialharvesting, credential encryption strengths), attack vectors, andmitigation strategies. - Strong problem-solving and analyticalskills with the ability to translate technical concepts to businessleaders and non-technical team members. - Good interpersonalskills, both written and verbal, with the ability to clearly conveycomplex security topics to a wide audience. - Minimum of 3 years ofexperience in a large global organization with 50K+ employeesDesirable Skills/Experience - Master’s degree or equivalentexperience in information security, Computer Science, or a relatedfield. - Industry certifications such as CISSP, CISM, or CEH. -Familiarity with cloud security and DevSecOps practices. -Experience with IAM-related compliance frameworks (SOX, GDPR,HIPAA, etc.) - Knowledge of industry standards and regulations(e.g., ISO 27001, NIST, SOC2). The annual base pay for thisposition ranges from 162,540 - 243,800 USD Annual (80% - 120%).Hourly and salaried non-exempt employees will also be paid overtimepay when working qualifying overtime hours. Base pay offered mayvary depending on multiple individualized factors, including marketlocation, job-related knowledge, skills, and experience. Inaddition, our positions offer a short-term incentive bonusopportunity; eligibility to participate in our equity-basedlong-term incentive program (salaried roles), to receive aretirement contribution (hourly roles), and commission paymenteligibility (sales roles). Benefits offered included a qualifiedretirement program [401(k) plan]; paid vacation and holidays; paidleaves; and, health benefits including medical, prescription drug,dental, and vision coverage in accordance with the terms andconditions of the applicable plans. Additional details ofparticipation in these benefit plans will be provided if anemployee receives an offer of employment. If hired, employee willbe in an “at-will position” and the Company reserves the right tomodify base pay (as well as any other discretionary payment orcompensation program) at any time, including for reasons related toindividual performance, Company or individual department/teamperformance, and market factors. When we put unexpected teams inthe same room, we spark bold thinking with the power to inspirelife-changing medicines. In-person working gives us the platform weneed to connect, work at pace and challenge perceptions. That's whywe work, on average, a minimum of three days per week from theoffice. But that doesn't mean we're not flexible. We balance theexpectation of being in the office while respecting individualflexibility. Join us in our outstanding and ambitious world. Join ateam with the backing and investment to win! You'll be working withinnovative technology. This marriage between our purposeful workand the use of high-tech platforms is what sets us apart. Own theway in digital healthcare. From exploring data and AI to working inthe cloud on new technologies. Join a team at the forefront. Helpshape and define the technologies of the future with the backingyou need from across the business. Ready to make an impact? Applynow! #J-18808-Ljbffr

Get the latest insights and jobs direct. Sign up for our newsletter.

By subscribing you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Top 10 Best UK Universities for Cyber Security Degrees (2025 Guide)

Discover ten of the strongest UK universities for Cyber Security degrees in 2025. Compare entry requirements, course content, research strength and industry links to choose the right programme for you. Cyber Security has moved from IT back-room concern to critical national infrastructure. With growing threats from ransomware, state-sponsored attacks and supply-chain compromise, demand for well-trained cyber professionals has never been higher. The UK is home to a clutch of universities recognised globally for excellence in this field. Below, we profile ten institutions offering robust undergraduate or postgraduate cyber-security pathways. While league tables shift year on year, these universities have a consistent record of first-class teaching, research and industry collaboration.

How to Write a Winning Cover Letter for Cyber Security Jobs: Proven 4-Paragraph Structure

Learn how to craft the perfect cover letter for cyber security jobs with this proven 4-paragraph structure. Ideal for entry-level candidates, career switchers, and professionals looking to advance in the cyber security sector. When applying for a cyber security job, your cover letter is an essential component of your application. The cyber security industry is continuously evolving, and organisations are always seeking professionals who can protect their networks, systems, and data. Your cover letter provides an opportunity to demonstrate your technical expertise, your enthusiasm for cyber security, and your ability to contribute to the protection of sensitive information. Whether you're just entering the field, transitioning from another career, or looking to advance in cyber security, this article will guide you through a proven four-paragraph structure to create a compelling cover letter. We’ll provide sample lines and tips to help you stand out in the competitive cyber security job market.

Quantum-Enhanced AI in Cyber Security: Guarding the Digital Frontier

The cyber security landscape has evolved dramatically over the past decade. Long gone are the days when businesses primarily worried about simplistic phishing or basic website defacements. Today’s threats include nation-state attacks, sophisticated ransomware, AI-generated phishing campaigns, and a wide array of stealthy intrusion methods. Organisations must defend vast digital ecosystems that include cloud infrastructure, IoT devices, and critical operational technology—any of which can become high-value targets for malicious actors. Amid these escalating challenges, a new technological wave is emerging: quantum computing. Although still in its infancy, quantum computing promises capabilities that could surpass even the most advanced classical supercomputers for specific tasks. Simultaneously, in the world of Artificial Intelligence (AI)—where data volumes and model complexity are exploding—quantum’s parallelism could significantly boost analysis, training, and decision-making. What unfolds when quantum computing and AI converge in the realm of cyber security? On one hand, quantum technologies could introduce stronger encryption and faster threat detection. On the other, adversaries armed with quantum power might break today’s cryptographic protocols or develop more potent attacks at unimaginable speeds. This article explores the phenomenon of quantum-enhanced AI for cyber security: the possibilities it unlocks, the challenges it poses, and the reasons it could reshape both defensive and offensive operations in the digital world.