Why choose AstraZeneca India?
Help push the boundaries of science to deliver life-changing medicines to patients. After 45 years in India, we’re continuing to secure a future where everyone can access affordable, sustainable, innovative healthcare.
The part you play in our business will be challenging, yet rewarding, requiring you to use your resilient, collaborative and diplomatic skillsets to make connections. The majority of your work will be field based, and will require you to be highly-organised, planning your monthly schedule, attending meetings and calls, as well as writing up reports.
Who do we look for?
Calling all tech innovators, ownership takers, challenge seekers and proactive collaborators. At AstraZeneca, breakthroughs born in the lab become transformative medicine for the world's most complex diseases. We empower people like you to push the boundaries of science, challenge convention, and unleash your entrepreneurial spirit. You'll embrace differences and take bold actions to drive the change needed to meet global healthcare and sustainability challenges.
Here, diverse minds and bold disruptors can meaningfully impact the future of healthcare using cutting-edge technology. Whether you join us in Bengaluru or Chennai, you can make a tangible impact within a global biopharmaceutical company that invests in your future. Join a talented global team that's powering AstraZeneca to better serve patients every day.
Success Profile
Ready to make an impact in your career? If you're passionate, growth-orientated and a true team player, we'll help you succeed. Here are some of the skills and capabilities we look for.
Tech innovators
Make a greater impact through our digitally enabled enterprise. Use your skills in data and technology to transform and optimise our operations, helping us deliver meaningful work that changes lives.
Ownership takers
If you're a self-aware self-starter who craves autonomy, AstraZeneca provides the perfect environment to take ownership and grow. Here, you'll feel empowered to lead and reach excellence at every level — with unrivalled support when you need it.
Challenge seekers
Adapting and advancing our progress means constantly challenging the status quo. In this dynamic environment where everything we do has urgency and focus, you'll have the ability to show up, speak up and confidently take smart risks.
Proactive collaborators
Your unique perspectives make our ambitions and capabilities possible. Our culture of sharing ideas, learning and improving together helps us consistently set the bar higher. As a proactive collaborator, you'll seek out ways to bring people together to achieve their best.
Responsibilities
GCL:E
Introduction to role:
Are you ready to lead a risk-based vulnerability management program that protects the science behind life-changing medicines? As our senior individual contributor in Chennai, you will turn rich threat and asset data into decisive action. You will work across operational technology, virtual environments, and organizational platforms. This role safeguards the systems our scientists, engineers, and clinicians rely on every day.
Here, you will shape how we discover, prioritize, and remediate vulnerabilities at global scale, translating complex realities into clear standards and measurable risk reduction. Do you thrive at the intersection of OT constraints and cloud speed, bringing order to ambiguity and accelerating outcomes that matter to patients and the business?
Accountabilities:
End-to-End Lifecycle Leadership: Maintain and continuously improve the vulnerability management lifecycle spanning operational technology, cloud environments, and on-premises infrastructure to increase coverage, quality, and time-to-remediation.
Risk-Based Prioritisation: Identify, validate, triage, and prioritise vulnerabilities using severity, exploitability, threat intelligence, asset criticality, internet exposure, potential intrusion routes, and business impact to focus effort where it matters most.
Remediation Orchestration: Coordinate mitigation with asset owners, OT engineering, cloud, infrastructure, Security Operations, Cyber Threat Intelligence, and service providers, removing blockers and accelerating durable fixes.
Documentation Ownership: Convert operating practices into clear, controlled policies, guidelines, procedural manuals, detailed instructions, workflow diagrams, RACI charts, templates, and playbooks; drive adoption, training, review cycles, and continuous improvement.
Governance and Exception Management: Run exception and risk-acceptance workflows with complete ownership, rationale, compensating controls, approvals, evidence, target dates, and scheduled reviews.
Metrics and Insight: Build executive-ready dashboards, remediation ageing views, coverage measures, control indicators, and trends that reveal risk reduction and guide operational and governance decisions.
Coverage and Data Quality: Improve asset onboarding, tagging, ownership, and tool configuration across approved platforms; close visibility and control gaps and validate effectiveness.
Process Improvement and Automation: Streamline data ingestion, normalisation, correlation, prioritisation, workflow orchestration, evidence capture, reporting, and closure validation; champion automation to scale.
Threat Monitoring and Rapid Response: Assess emerging vulnerabilities from trusted sources, determine relevance to our estate, and lead accelerated assessment and response where credible exploitation or high business exposure exists.
Collaborator Influence and Enablement: Lead workstreams, workshops, and continuous-improvement initiatives using facilitation and subject-matter expertise. Ensure consistent standards across OT, cloud environments, and infrastructure while respecting detailed operational, safety, regulatory, or technical constraints.
AI and Digital Tooling Adoption: Embrace and appropriately use artificial intelligence and technology-based tools to improve analysis, triage, reporting, and ways of working.
Essential Skills/Experience:
- Significant hands-on experience managing vulnerabilities or coordinating threat exposure within a complex, multinational enterprise.
- Strong practical knowledge in handling vulnerabilities across OT, cloud, and enterprise infrastructure, including differences in asset discovery, scanning, risk assessment, patching, and remediation approaches.
- Demonstrated understanding of OT and industrial environments, including legacy platforms, operational availability, safety, network segmentation, maintenance windows, vendor dependencies, firmware, and compensating controls.
- Experience assessing vulnerabilities and exposure in cloud environments, including public exposure, misconfiguration, identity and privilege context, attack paths, and cloud-native remediation workflows.
- Experience with vulnerability assessment and exposure-management platforms such as Qualys, Claroty, Wiz,MS Defender or comparable technologies, together with supporting CMDB, ticketing, reporting, and workflow tools.
- Demonstrable ability to author, restructure, and maintain high-quality standards, SOPs, work instructions, process flows, RACI models, control descriptions, and evidence requirements for technical and regulated processes.
- Solid comprehension of document governance, including ownership, approval routes, version control, controlled publication, periodic review, change records, retention, and preparedness for audits.
- Good understanding of risk-based vulnerability prioritisation, remediation governance, exception management, security controls, and recognised industry practices for IT, cloud, and OT environments.
- Ability to analyse complex technical and operational situations, balance risk reduction with service continuity and business constraints, and make clear, evidence-based recommendations.
- Experience developing meaningful metrics, trend analysis, control reporting, and executive-ready insights for programme performance, coverage, risk reduction, and remediation progress.
- Strong written, verbal, facilitation, and stakeholder-management skills, with the ability to explain technical risk and procedural requirements to technical and non-technical audiences.
- A collaborative working style, sound judgement, personal accountability, attention to detail, and the ability to deliver independently within a team environment.
- Relevant technical degree or equivalent professional experience; recognised cybersecurity, cloud, OT, risk, or service-management certifications are advantageous.
Desirable Skills/Experience:
- Experience integrating vulnerability data with SIEM/SOAR and ticketing platforms to automate triage and remediation workflows.
- Proficiency with scripting or data tooling (for example, Python, PowerShell, APIs, SQL) to normalise, correlate, and report at scale.
- Knowledge of security and risk frameworks and benchmarks (for example, NIST CSF, NIST 800-53/82, ISO 27001, CIS Controls, IEC 62443).
- Background in highly regulated or safety-critical industries, such as pharmaceuticals, medical devices, or manufacturing, including validation and audit readiness.
- Hands-on exposure to OT security tooling and constraints, including passive discovery, safe scanning practices, and firmware risk management.
- Experience building executive dashboards and storytelling with data using tools such as Power BI or Tableau.
- Familiarity with cloud-native controls and pipelines (for example, IaC scanning, CI/CD integration, identity governance) to accelerate secure remediation.
- Ability to mentor and upskill peers and partner teams in vulnerability management practices.
#Cyber
When we put unexpected teams in the same room, we unleash bold thinking with the power to inspire life-changing medicines. In-person working gives us the platform we need to connect, work at pace and challenge perceptions. That's why we work, on average, a minimum of three days per week from the office. But that doesn't mean we're not flexible. We balance the expectation of being in the office while respecting individual flexibility. Join us in our unique and ambitious world.
Why AstraZeneca:
Your work protects the digital backbone of breakthrough science, connecting engineers, data innovators, and clinicians who are pushing the boundaries of medicine. You will collaborate in environments where experimentation is encouraged, where unexpected teams spark new ideas, and where investment in modern platforms lets you solve problems at enterprise scale. We value kindness alongside ambition, pairing brand new technology with a clear mission to reach patients faster—so your contribution translates into real-world impact.
Call to Action:
Step into a role where your expertise reduces real risk and safeguards the platforms behind our next breakthroughs—send your CV and lead the evolution of vulnerability management from Chennai.
Date Posted
08-Oct-2026Closing Date
15-Oct-2026AstraZeneca embraces diversity and equality of opportunity. We are committed to building an inclusive and diverse team representing all backgrounds, with as wide a range of perspectives as possible, and harnessing industry-leading skills. We believe that the more inclusive we are, the better our work will be. We welcome and consider applications to join our team from all qualified candidates, regardless of their characteristics. We comply with all applicable laws and regulations on non-discrimination in employment (and recruitment), as well as work authorization and employment eligibility verification requirements.
Reasons to Join
Thomas Mathisen
There are many things I enjoy when working at AstraZeneca, mainly the Speak up culture, the great colleagues that are in my teams, the great products that AstraZeneca provides to our patients and the challenging conversations I have around our medicines.
Christine Recchio
Working at AstraZeneca has impacted my life in such a positive way. I now have an improved work-life balance through creating my own schedule and time management, I feel a balance that I didn’t have before.
Stephanie Ling
There are a lot of reasons why I enjoy working in AstraZeneca, my colleagues being one of them. My team members and the managers have provided a great deal of guidance in helping me to be more confident in my daily work.
What we offer
We're driven by our shared values of serving people, society and the planet. Our people make this possible, which is why we prioritise diversity, safety, empowerment and collaboration. Discover what a career at AstraZeneca could mean for you.
Lifelong learning
Our development opportunities are second to none. You'll have the chance to grow your abilities, skills and knowledge constantly as you accelerate your career. From leadership projects and constructive coaching to overseas talent exchanges and global collaboration programmes, you'll never stand still.
Autonomy and reward
Experience the power of shaping your career how you want to. We are a high-performing learning organisation with autonomy over how we learn. Make big decisions, learn from your mistakes and continue growing — with performance-based rewards as part of the package.
Health and wellbeing
An energised work environment is only possible when our people have a healthy work-life balance and are supported for their individual needs. That's why we have a dedicated team to ensure your physical, financial and psychological wellbeing is a top priority.
Inclusion and diversity
Diversity and inclusion are embedded in everything we do. We're at our best and most creative when drawing on our different views, experiences and strengths. That's why we're committed to creating a workplace where everyone can thrive in a culture of respect, collaboration and innovation.
Join our Talent Network
Be the first to receive job updates and news from AstraZeneca
Sign up