Jobs · Engineering · Illinois

Senior Principal Architect, Cyber Defense Engineering

TransUnion · Chicago, IL · 1 wk ago
Engineering$188k–$313k/yrFull-time

Cyber Defense Engineering is responsible for modernizing TransUnion's detection, response, vulnerability, and endpoint capabilities through scalable architecture, automation, and integrated security platforms. This individual contributor role will act as the principal technical architect for TransUnion's Cyber Defense organization, owning the reference architecture that underpins modernization across Data Security Posture Management (DSPM), Zero Trust Network Access (ZTNA), Endpoint Strategy, and AI enablement.

This is a hybrid position and involves regular performance of job responsibilities virtually as well as in-person at an assigned TU office location for a minimum of two days a week.

Responsibilities

  • Own and evolve the Cyber Defense reference architecture, defining the target-state design for how detection, response, vulnerability management, and endpoint telemetry integrate across a unified data and automation layer.
  • Architect TransUnion's Data Security Posture Management (DSPM) capability, leading technical evaluation, integration design, and rollout planning for cloud-native data discovery, classification, and exposure detection, including Wiz DSPM, across AWS, GCP, and hybrid environments.
  • Define TransUnion's Zero Trust Network Access (ZTNA) architecture, establishing target-state design for identity-aware, least-privilege access to enterprise and cloud workloads in coordination with IAM, network security, and cloud infrastructure teams.
  • Own Endpoint Strategy architecture, defining the target design for endpoint detection and response, exposure management, and telemetry integration across the enterprise fleet while rationalizing overlapping endpoint tooling.
  • Architect the AI enablement layer for Cyber Defense, designing agentic and LLM-based capabilities for triage, investigation, and response, including MCP-based agent orchestration and AI SOC platforms that integrate with existing SIEM, SOAR, and case management systems.
  • Lead the technical architecture for SIEM and security data platform modernization, defining the target design for log ingestion, retention, and analytics as the organization evaluates consolidation of fragmented logging and detection platforms.
  • Define reference architecture for the VulnOps operating model, ensuring vulnerability discovery, prioritization, disruption, and remediation systems integrate cleanly with the broader Cyber Defense data and automation architecture.
  • Evaluate emerging security technologies and vendor platforms against TransUnion's architecture principles, producing build-versus-buy recommendations, integration designs, and proof-of-concept plans for new capabilities before they reach production.
  • Establish architecture governance and design standards for Cyber Defense Engineering, authoring reference diagrams, integration patterns, and technical design documents that guide engineering teams building against the architecture.

Requirements

  • 15+ years of experience in cybersecurity architecture, security engineering, or related technical roles, with demonstrated ownership of enterprise-scale security reference architectures.
  • Deep technical expertise in cloud security posture and data security tooling, with hands-on experience in DSPM, CNAPP, or related platforms, including Wiz, across AWS, GCP, or Azure environments.
  • Strong understanding of Zero Trust Network Access (ZTNA) architecture and identity-aware access models, including experience designing or implementing ZTNA in an enterprise environment.
  • Hands-on experience with endpoint detection and response (EDR) architecture and tooling, including CrowdStrike Falcon and Microsoft Defender for Endpoint, with exposure management and fleet-wide telemetry design.
  • Experience architecting or building AI-enabled or agentic security capabilities, including familiarity with LLM-based triage and investigation agents, MCP-based tool orchestration, or AI SOC platforms.
  • Strong programming and scripting skills, including Python or Go, with the ability to build architecture prototypes, integration proofs-of-concept, and automation scripts independently.
  • Experience with modern security data platforms and SIEM/log analytics architecture, including Splunk and cloud-native log platforms, with experience evaluating or leading platform consolidation efforts.
  • Proven ability to produce clear architecture documentation, including reference diagrams, integration patterns, and technical design decks that engineering teams can build against.
  • Bachelor's degree in Computer Science, Computer Engineering, Information Security, or a related field required; advanced degree preferred.

Skills

  • Expertise designing security reference architectures across DSPM, ZTNA, endpoint security, SIEM, SOAR, case management, vulnerability management, and security data platforms.
  • Hands-on cloud security architecture experience across AWS, GCP, or Azure, including CNAPP, DSPM, cloud-native data discovery, classification, and exposure detection capabilities.
  • Strong endpoint and telemetry architecture expertise, including EDR, exposure management, fleet telemetry, alert normalization, and tool rationalization.
  • Ability to design AI-enabled and agentic security workflows using LLM-based triage, MCP-based tool orchestration, AI SOC platforms, integration scripts, and automation prototypes.
  • Strong programming, scripting, and proof-of-concept development skills, including Python or Go, with the ability to validate architecture decisions through technical prototypes.

Preferred Skills

  • Experience architecting vulnerability management platforms or exposure-reduction systems.
  • Background in Security Operations Center (SOC) technology architecture, including SOAR, case management, and alert normalization platforms.
  • Experience working in a financial services, fintech, or similarly regulated enterprise environment.
  • Familiarity with infrastructure-as-code and cloud-native deployment tooling, including Terraform, Harness, and Kubernetes.
  • Track record of leading technology evaluations and proof-of-concept programs that informed enterprise security architecture decisions.

Benefits

  • For Your Health: Day-one eligibility for medical, dental, and vision coverage, plus supplemental plan options. Spousal, domestic partner, and other eligible dependent coverage is available on select plans. Choose tax-advantaged HSA and FSA accounts to make everyday care more affordable.
  • For Your Protection: Company-paid basic life and AD&D insurance, optional voluntary life and AD&D for you and your family, and short- and long-term disability. Optional legal plan, pet insurance, and travel accident coverage.
  • For Your Family: Adoption assistance, fertility planning coverage, caregiver support, Dependent Care FSA with possibility of employer match, complimentary Care@Work membership, and up to 12 weeks of paid parental leave with eligibility for a gradual return.
  • For Your Future: 401(k) with employer match and Employee Stock Purchase Plan (ESPP). Financial wellness resources, career coaching, and optional long-term care insurance.
  • For You: Tuition reimbursement, flexible time off for exempt employees or paid time off for nonexempt employees, up to 12 paid holidays per year, commuter benefits, employee discounts, charitable gift matching, and paid volunteer time off, plus corporate volunteer events.
  • For Your Wellness: 24/7 support including professional therapy, coaching, and emotional well-being programs alongside guided meditation and resources that support physical, mental, social, and financial wellness.

Pay

The U.S. base salary range for this position is $187,500.00 - $312,500 annually. Actual compensation is based on careful consideration of factors such as education, training, work experience, job-related skill set, location, and industry knowledge, as well as the scope and responsibilities of the position and market considerations. Regular, full-time non-sales positions may be eligible to participate in TransUnion’s annual bonus plan. Certain positions may be also eligible for long-term incentives and other payments based on applicable company guidance and plan documents.

Schedule

This is a hybrid position requiring in-person work at an assigned TransUnion office location for a minimum of two days a week.

Similar jobs