Jobs · Engineering · Illinois

Director, Detection Engineering and Automation

hackajob · Chicago, IL · 1 mo ago
HybridEngineering$169k–$281k/yrFull-time

About the role

The Director of Detection Engineering and Automation will lead the detection engineering and automation function, serving as a key member of the Cyber Defense leadership team. Reporting directly to the SVP, Cyber Defense, this role focuses on advancing TransUnion's detection and automation capabilities across various environments.

Responsibilities

  • Lead the detection engineering and automation function, establishing the team as the authoritative center of excellence for prioritized, high-fidelity detections.
  • Define and execute the detection engineering and automation strategy, ensuring detection priorities align with the evolving threat landscape, enterprise risk, and organizational priorities.
  • Own the end-to-end detection lifecycle, from ideation and prioritization through development, testing, deployment, tuning, and ongoing optimization.
  • Drive automation and response workflow integration across SOAR, SIEM, and EDR platforms to increase detection coverage, reduce manual effort, and improve operational scalability.
  • Mature the detection platform by evaluating and adopting scalable tooling, simplifying detection authoring, and enabling faster turnaround on new detection capabilities.
  • Partner cross-functionally with SecOps, Threat Intelligence, SIRT, and Engineering to ensure detection outputs are actionable, response plans are current, and automation reduces manual response burden.
  • Represent Detection Engineering in senior leadership forums by providing clear, decision-oriented updates on detection posture, platform health, risk coverage, and team progress.

Requirements

  • 10+ years of cybersecurity experience, with a strong focus on detection engineering, security operations, or threat intelligence, including at least 3–5 years in a people leadership role managing teams or managers.
  • Demonstrated experience building and scaling detection engineering programs, including detection development, tuning, operationalization, and continuous improvement across enterprise environments.
  • Strong understanding of adversary tactics, techniques, and procedures and experience applying frameworks such as MITRE ATT&CK to guide detection prioritization, coverage, and risk reduction.
  • Proven ability to drive cross-functional alignment across Threat Intelligence, Incident Response, Security Operations, Cloud Infrastructure Security, Application Security, and Engineering teams.
  • Bachelor’s degree in Computer Science, Information Security, or a related field required; equivalent experience may be considered where it demonstrates the technical depth and leadership capability needed for the role.
  • Deep technical expertise with SIEM, EDR, SOAR, and detection-as-code methodologies, including hands-on experience with detection rule development and automation workflow design.
  • Experience developing detections across endpoint, identity, network, and cloud environments, with the ability to prioritize based on risk reduction and operational impact.
  • Experience leading cloud detection initiatives across cloud-native environments such as AWS, GCP, and Azure, including familiarity with cloud-specific telemetry sources and detection challenges.
  • Strong analytical and risk-quantification skills, including the ability to evaluate detection effectiveness, false positive rates, detection coverage, MTTD, and automation throughput.
  • Ability to translate technical detection posture into executive-relevant narratives, including risk trends, coverage gaps, platform health, and program maturity.

Qualifications

  • Experience evaluating and adopting new detection platforms or tooling at enterprise scale.
  • Background building detection systems, automation, threat hunting, or threat intelligence operationalization programs.
  • Familiarity with version-controlled detection pipelines and detection-as-code practices.
  • Track record of building detection automation that measurably reduces analyst toil and improves response efficiency.

Benefits

  • Healthcare benefits including medical, dental, and vision coverage.
  • Spousal, domestic partner, and other eligible dependent coverage.
  • Tax-advantaged HSA and FSA accounts.
  • Short- and long-term disability coverage.
  • Legal plan, pet insurance, and travel accident coverage.
  • Paid parental leave, caregiver support, and charitable gift matching.
  • Flexible time off, paid holidays, and commuter benefits.
  • Professional therapy, coaching, and emotional well-being programs.

Similar jobs