Jobs · Engineering · Illinois

Senior Director, Vulnerability Resiliency Engineering

TransUnion · Chicago, IL · 1 wk ago
Engineering$188k–$313k/yrFull-time

TransUnion’s Vulnerability Resiliency Engineering team reduces exploitable risk across TransUnion’s technology environment by transforming traditional vulnerability management into a modern VulnOps operating model. Partnering closely with Security Operations, Incident Response, Threat Intelligence, Product Security, Cloud Infrastructure Security, and Engineering teams, the organization focuses on accelerating vulnerability discovery, disruption, remediation, validation, and risk reduction through automation and engineering-led ownership. This is a hybrid position requiring in-person work at an assigned TU office location a minimum of two days a week.

About the role

Reporting to the SVP of Cyber Defense, this leader will drive one of TransUnion’s most critical cybersecurity transformation initiatives while building a scalable, AI-enabled approach to exposure management across first-party code, third-party dependencies, APIs, endpoints, and infrastructure.

Responsibilities

  • Define and execute TransUnion’s VulnOps transformation strategy, shifting the organization from a traditional scan-and-backlog model to an engineering-led approach focused on eliminating exploitable exposure.
  • Lead the AI Vuln Research and Engineering, Vulnerability Resiliency Engineering, and Traditional Vulnerability Management Operations teams, overseeing a peak organization of approximately 25 engineers while evolving to a highly automated team of 11 to 14 specialized engineers.
  • Own the end-to-end vulnerability operating lifecycle, including discovery, prioritization, disruption, remediation, validation, and measurement to ensure clear accountability and durable risk reduction.
  • Establish and operationalize a patch-plus-disruption response model, including controls such as WAF rules, API protections, network isolation, quarantine capabilities, runtime protections, and virtual patching.
  • Drive consolidation of legacy vulnerability and exposure management platforms into a unified VulnOps ecosystem centered on Wiz, Cogent Security, and a common security data lake.
  • Partner with engineering teams to eliminate vulnerabilities before production through trusted images, CI/CD security controls, approved libraries, and automated remediation capabilities.
  • Scale automation and AI-driven remediation workflows to improve remediation efficiency and reduce mean time to remediate (MTTR) for critical vulnerabilities.
  • Define and manage executive-level operational metrics, including exploitable exposure, disruption effectiveness, remediation performance, vulnerability elimination rates, asset currency, and SLA compliance.
  • Lead cross-functional governance forums that drive accountability, exposure reduction, engineering alignment, technology lifecycle management, and automation adoption.
  • Represent Vulnerability Resiliency Engineering in executive leadership reviews, providing strategic updates on risk reduction outcomes, transformation progress, and operational performance.

Requirements

  • 12+ years of cybersecurity experience, including vulnerability management, security operations, security engineering, or related disciplines, with at least 5 years leading managers and multi-team organizations.
  • Demonstrated success leading large-scale vulnerability management or security transformation initiatives that leverage automation, engineering ownership, and measurable risk reduction outcomes.
  • Deep understanding of vulnerability management frameworks, exposure management, threat-informed prioritization, and exploit disruption strategies within complex enterprise environments.
  • Proven experience driving organizational design, workforce transformation, talent development, and capability building while modernizing operational practices.
  • Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field, or equivalent combination of education and relevant leadership experience. Advanced degree preferred.

Skills

  • Expertise with vulnerability and exposure management platforms, including Wiz, CrowdStrike, JFrog Xray, vulnerability scanners, Endpoint Detection and Response (EDR), Security Information and Event Management (SIEM), Cloud-Native Application Protection Platforms (CNAPP), and Security Orchestration, Automation and Response (SOAR) technologies.
  • Strong knowledge of vulnerability prioritization and risk-based remediation methodologies, including CISA Known Exploited Vulnerabilities (KEV), Exploit Prediction Scoring System (EPSS), and related frameworks.
  • Experience designing and implementing automated remediation, AI-driven security operations, CI/CD security controls, trusted image management, and engineering-owned vulnerability reduction programs.
  • Proven capability leading enterprise-scale platform rationalization, vendor consolidation, and migration initiatives utilizing centralized security data models and reporting platforms.
  • Strong executive communication and data storytelling skills, with the ability to translate technical findings, exposure trends, and operational metrics into actionable business decisions.

Preferred Skills

  • Experience building or scaling AI-native or agentic vulnerability remediation capabilities.
  • Experience with Attack Surface Management (ASM) programs in addition to traditional vulnerability management disciplines.
  • Familiarity with MITRE ATT&CK and threat-informed defense methodologies.
  • Experience operating within financial services, fintech, or other highly regulated enterprise environments.
  • Experience building or scaling enterprise security data lakes, operational reporting platforms, or exposure intelligence programs.

Benefits

TransUnion offers benefits designed to support health, protection, family, future, wellness, and personal growth:

  • For Your Health: Day-one eligibility for medical, dental, and vision coverage, plus supplemental plan options. Spousal, domestic partner, and other eligible dependent coverage available on select plans. Tax-advantaged HSA and FSA accounts.
  • For Your Protection: Company-paid basic life and AD&D insurance, optional voluntary life and AD&D for you and your family, short- and long-term disability, legal plan, pet insurance, and travel accident coverage.
  • For Your Family: Adoption assistance, fertility planning coverage, caregiver support, Dependent Care FSA with potential employer match, complimentary Care@Work membership, and up to 12 weeks of paid parental leave with a gradual return option.
  • For Your Future: 401(k) with employer match, Employee Stock Purchase Plan (ESPP), financial wellness resources, career coaching, and optional long-term care insurance.
  • For You: Tuition reimbursement, flexible/paid time off, up to 12 paid holidays per year, commuter benefits, employee discounts, charitable gift matching, paid volunteer time off, and corporate volunteer events.
  • For Your Wellness: 24/7 support including professional therapy, coaching, emotional well-being programs, guided meditation, and resources supporting physical, mental, social, and financial wellness.

Pay

The U.S. base salary range for this position is $187,500.00 - $312,500 annually. Actual compensation is based on factors such as education, training, work experience, job-related skill set, location, industry knowledge, scope and responsibilities of the position, and market considerations. Regular, full-time non-sales positions may be eligible for TransUnion’s annual bonus plan. Certain positions may also be eligible for long-term incentives and other payments based on company guidance and plan documents.

Similar jobs