Director, Detection Engineering and Automation
Reporting directly to the SVP, Cyber Defense, this role serves as a key member of the Cyber Defense leadership team responsible for advancing TransUnion's detection and automation capabilities across endpoint, identity, network, and cloud environments. The position is hybrid, requiring in-person work at an assigned TU office location a minimum of two days a week.
About the role
The Director of Detection Engineering and Automation will partner closely with Threat Intelligence, Security Incident Response, Security Operations, Cloud Infrastructure Security, Application Security, and Engineering to strengthen proactive defense, reduce risk, and improve operational response.
Responsibilities
- Lead the Detection Engineering and Automation function, establishing the team as the authoritative center of excellence for prioritized, high-fidelity detections that reduce risk across endpoint, identity, network, and cloud environments.
- Define and execute the detection engineering and automation strategy, ensuring detection priorities align with the evolving threat landscape, enterprise risk, and organizational priorities.
- Lead, develop, and scale a team of approximately 14 detection and automation engineers and one manager, building leadership capability and fostering a high-performance culture.
- Own the end-to-end detection lifecycle, from ideation and prioritization through development, testing, deployment, tuning, and ongoing optimization to ensure detections remain relevant and actionable.
- Drive automation and response workflow integration across SOAR, SIEM, and EDR platforms to increase detection coverage, reduce manual effort, and improve operational scalability.
- Mature the detection platform by evaluating and adopting scalable tooling, simplifying detection authoring, and enabling faster turnaround on new detection capabilities.
- Lead cloud detection capability development by closing current coverage gaps and building durable cloud-native detection capabilities in partnership with Cloud Infrastructure Security and Engineering.
- Partner cross-functionally with SecOps, Threat Intelligence, SIRT, and Engineering to ensure detection outputs are actionable, response plans are current, and automation reduces manual response burden.
- Define, track, and communicate key detection metrics, including detection coverage, detection effectiveness, false positive rates, mean time to detect, and automation throughput.
- Represent Detection Engineering in senior leadership forums by providing clear, decision-oriented updates on detection posture, platform health, risk coverage, and team progress.
Requirements
- 10+ years of cybersecurity experience, with a strong focus on detection engineering, security operations, or threat intelligence, including at least 3–5 years in a people leadership role managing teams or managers.
- Demonstrated experience building and scaling detection engineering programs, including detection development, tuning, operationalization, and continuous improvement across enterprise environments.
- Strong understanding of adversary tactics, techniques, and procedures and experience applying frameworks such as MITRE ATT&CK to guide detection prioritization, coverage, and risk reduction.
- Proven ability to drive cross-functional alignment across Threat Intelligence, Incident Response, Security Operations, Cloud Infrastructure Security, Application Security, and Engineering teams.
- Bachelor’s degree in Computer Science, Information Security, or a related field required; equivalent experience may be considered where it demonstrates the technical depth and leadership capability needed for the role.
Skills
- Deep technical expertise with SIEM, EDR, SOAR, and detection-as-code methodologies, including hands-on experience with detection rule development and automation workflow design.
- Experience developing detections across endpoint, identity, network, and cloud environments, with the ability to prioritize based on risk reduction and operational impact.
- Experience leading cloud detection initiatives across cloud-native environments such as AWS, GCP, and Azure, including familiarity with cloud-specific telemetry sources and detection challenges.
- Strong analytical and risk-quantification skills, including the ability to evaluate detection effectiveness, false positive rates, detection coverage, MTTD, and automation throughput.
- Ability to translate technical detection posture into executive-relevant narratives, including risk trends, coverage gaps, platform health, and program maturity.
Preferred Skills
- Experience evaluating and adopting new detection platforms or tooling at enterprise scale.
- Background building detection systems, automation, threat hunting, or threat intelligence operationalization programs.
- Experience working in financial services, fintech, or a similarly regulated industry.
- Familiarity with version-controlled detection pipelines and detection-as-code practices.
- Track record of building detection automation that measurably reduces analyst toil and improves response efficiency.
Benefits
At TransUnion, benefits are designed to support every part of your life:
- For Your Health: Day-one eligibility for medical, dental, and vision coverage, plus supplemental plan options. Spousal, domestic partner, and other eligible dependent coverage available on select plans. Tax-advantaged HSA and FSA accounts.
- For Your Protection: Company-paid basic life and AD&D insurance, optional voluntary life and AD&D for you and your family, short- and long-term disability. Optional legal plan, pet insurance, and travel accident coverage.
- For Your Family: Adoption assistance, fertility planning coverage, caregiver support, Dependent Care FSA with potential employer match, complimentary Care@Work membership, and up to 12 weeks of paid parental leave with a gradual return option.
- For Your Future: 401(k) with employer match and Employee Stock Purchase Plan (ESPP). Financial wellness resources, career coaching, and optional long-term care insurance.
- For You: Tuition reimbursement, flexible or paid time off, up to 12 paid holidays per year, commuter benefits, employee discounts, charitable gift matching, and paid volunteer time off, plus corporate volunteer events.
- For Your Wellness: 24/7 support including professional therapy, coaching, emotional well-being programs, guided meditation, and resources supporting physical, mental, social, and financial wellness.
Pay
The U.S. base salary range for this position is $168,750.00 - $281,250 annually. Actual compensation is based on factors such as education, training, work experience, job-related skill set, location, industry knowledge, scope and responsibilities of the position, and market considerations. Regular, full-time non-sales positions may be eligible for TransUnion’s annual bonus plan. Certain positions may also be eligible for long-term incentives and other payments based on company guidance and plan documents.