Director, Detection Engineering and Automation

Posted Yesterday
Be an Early Applicant
3 Locations
Hybrid
169K-281K Annually
Expert/Leader
Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
The Role
Lead and scale a detection engineering and automation team to develop, deploy, tune, and optimize high-fidelity detections across endpoint, identity, network, and cloud. Drive detection strategy, SIEM/EDR/SOAR integration, cloud-native detection capabilities, automation to reduce analyst toil, cross-functional alignment, metrics reporting, and executive communication of detection posture and risk.
Summary Generated by Built In

TransUnion's Job Applicant Privacy Notice

Personal Information We Collect

Your Privacy Choices

Team Overview

Reporting directly to the SVP, Cyber Defense, the Director of Detection Engineering and Automation will serve as a key member of the Cyber Defense leadership team responsible for advancing TransUnion's detection and automation capabilities across endpoint, identity, network, and cloud environments. The role partners closely with Threat Intelligence, Security Incident Response, Security Operations, Cloud Infrastructure Security, Application Security, and Engineering to strengthen proactive defense, reduce risk, and improve operational response. This is a hybrid position and involves regular performance of job responsibilities virtually as well as in-person at an assigned TU office location for a minimum of two days a week.

Role Overview and Core Responsibilities

  • Lead the Detection Engineering and Automation function, establishing the team as the authoritative center of excellence for prioritized, high-fidelity detections that reduce risk across endpoint, identity, network, and cloud environments.

  • Define and execute the detection engineering and automation strategy, ensuring detection priorities are aligned to the evolving threat landscape, enterprise risk, and organizational priorities.

  • Lead, develop, and scale a team of approximately 14 detection and automation engineers and one manager, building leadership capability, fostering a high-performance culture, and supporting continued team growth.

  • Own the end-to-end detection lifecycle, from ideation and prioritization through development, testing, deployment, tuning, and ongoing optimization to ensure detections remain relevant and actionable.

  • Drive automation and response workflow integration across SOAR, SIEM, and EDR platforms to increase detection coverage, reduce manual effort, and improve operational scalability.

  • Mature the detection platform by evaluating and adopting scalable tooling, simplifying detection authoring, and enabling faster turnaround on new detection capabilities.

  • Lead cloud detection capability development by closing current coverage gaps and building durable cloud-native detection capabilities in partnership with Cloud Infrastructure Security and Engineering.

  • Partner cross-functionally with SecOps, Threat Intelligence, SIRT, and Engineering to ensure detection outputs are actionable, response plans are current, and automation reduces manual response burden.

  • Define, track, and communicate key detection metrics, including detection coverage, detection effectiveness, false positive rates, mean time to detect, and automation throughput.

  • Represent Detection Engineering in senior leadership forums by providing clear, decision-oriented updates on detection posture, platform health, risk coverage, and team progress.

Required Knowledge and Experiences

  • 10+ years of cybersecurity experience, with a strong focus on detection engineering, security operations, or threat intelligence, including at least 3–5 years in a people leadership role managing teams or managers.

  • Demonstrated experience building and scaling detection engineering programs, including detection development, tuning, operationalization, and continuous improvement across enterprise environments.

  • Strong understanding of adversary tactics, techniques, and procedures and experience applying frameworks such as MITRE ATT&CK to guide detection prioritization, coverage, and risk reduction.

  • Proven ability to drive cross-functional alignment across Threat Intelligence, Incident Response, Security Operations, Cloud Infrastructure Security, Application Security, and Engineering teams.

  • Bachelor’s degree in Computer Science, Information Security, or a related field required; equivalent experience may be considered where it demonstrates the technical depth and leadership capability needed for the role.

Required Technical Skills

  • Deep technical expertise with SIEM, EDR, SOAR, and detection-as-code methodologies, including hands-on experience with detection rule development and automation workflow design.

  • Experience developing detections across endpoint, identity, network, and cloud environments, with the ability to prioritize based on risk reduction and operational impact.

  • Experience leading cloud detection initiatives across cloud-native environments such as AWS, GCP, and Azure, including familiarity with cloud-specific telemetry sources and detection challenges.

  • Strong analytical and risk-quantification skills, including the ability to evaluate detection effectiveness, false positive rates, detection coverage, MTTD, and automation throughput.

  • Ability to translate technical detection posture into executive-relevant narratives, including risk trends, coverage gaps, platform health, and program maturity.

We’re also looking for the preferred skills below. Whether you are proficient or could use some brushing up, we’re happy to support your career development and growth in:

  • Experience evaluating and adopting new detection platforms or tooling at enterprise scale.

  • Background building detection systems, automation, threat hunting, or threat intelligence operationalization programs.

  • Experience working in financial services, fintech, or a similarly regulated industry.

  • Familiarity with version-controlled detection pipelines and detection-as-code practices.

  • Track record of building detection automation that measurably reduces analyst toil and improves response efficiency.

#LI-KJ1

Benefits that support every part of your life:

At TransUnion, we design benefits to help you feel well, do well, and plan well—from day one.

For Your Health: Enjoy day-one eligibility for medical, dental, and vision coverage, plus supplemental plan options. Spousal, domestic partner, and other eligible dependent coverage is available on select plans. Choose tax‑advantaged HSA and FSA accounts to make everyday care more affordable.

For Your Protection: We’ve got your back with company‑paid basic life and AD&D, optional voluntary life and AD&D for you and your family, and short‑ and long‑term disability. You can also opt into a legal plan, pet insurance, and travel accident coverage.

For Your Family: From adoption assistance and fertility planning coverage to caregiver support, we’re here for every chapter. Access Dependent Care FSA for possibility of an employer match, a complimentary Care@Work membership, and up to 12 weeks of paid parental leave with eligibility for a thoughtful, gradual return.

For Your Future: Build toward what’s next with our 401(k) with employer match and Employee Stock Purchase Plan (ESPP). Tap financial wellness resources, career coaching, and optional long‑term care insurance to plan confidently.

For You: Grow and recharge with tuition reimbursement, flexible time off for exempt employees or paid time off for nonexempt employees, up to 12 paid holidays per year, commuter benefits, employee discounts, charitable gift matching, and paid volunteer time off, plus corporate volunteer events that make it easy to give back.

For Your Wellness: Access 24/7 support including professional therapy, coaching, and emotional well‑being programs alongside guided meditation and resources that support physical, mental, social, and financial wellness.

We are committed to being a place where diversity is not only present, it is embraced. As an equal opportunity employer, all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability status, veteran status, genetic information, marital status, citizenship status, sexual orientation, gender identity or any other characteristic protected by law. Additionally, in accordance with Section 503 of the Rehabilitation Act of 1973 and the Vietnam Era Veterans’ Readjustment Assistance Act of 1974, TransUnion takes affirmative action to employ and advance in employment qualified individuals with a disability and protected veterans in all levels of employment and develops annual affirmative action plans. Components of TransUnion’s Affirmative Action Program for individuals with disabilities and protected veterans are available for review to any associate or applicant for employment upon request by contacting [email protected].

Qualified applicants with arrest or conviction records will be considered for employment in accordance with applicable law, including the Los Angeles County Fair Chance Ordinance for Employers, the San Francisco Fair Chance Ordinance, Fair Chance Initiative for Hiring Ordinance, and the California Fair Chance Act.

Adherence to Company policies, sound judgment and trustworthiness, working safely, communicating respectfully, and safeguarding business operations, confidential and proprietary information, and the Company’s reputation are also essential expectations of this position.

Pay Scale Information:

The U.S. base salary range for this position is $168,750.00 - $281,250 annually. *The salary range for this position reflects a reasonable estimate of the range of compensation for this job. At TransUnion, actual compensation is based on careful consideration of additional factors such as (but not limited to) an individual’s education, training, work experience, job-related skill set, location, and industry knowledge, as well as the scope and responsibilities of the position and market considerations. Regular, fulltime non-sales positions may be eligible to participate in TransUnion’s annual bonus plan. Certain positions may be also eligible for long-term incentives and other payments based on applicable company guidance and plan documents.

TransUnion Overview:

At TransUnion, we encourage and are committed to creating a real, positive impact and shared sense of purpose within our Workforce for Good, which empowers our people to grow, innovate and contribute to a better future for our communities and customers. We strive to build an environment where our associates are in the driver’s seat of their professional development— while having access to help along the way. We recognize that success comes when our associates thrive both professionally and personally; that’s why we prioritize work/life flexibility and offer resources for our teams across the globe to collaborate and drive excellence.


Be a part of our Workforce for Good – you’ll work with great people, pioneering products and cutting-edge technology.

TransUnion's Internal Job Title:

Director, Cybersecurity

Company:

TransUnion LLC

Skills Required

  • 10+ years of cybersecurity experience focused on detection engineering, security operations, or threat intelligence
  • 3-5 years in a people leadership role managing teams or managers
  • Bachelor's degree in Computer Science, Information Security, or related field (equivalent experience may be considered)
  • Deep technical expertise with SIEM, EDR, SOAR, and detection-as-code methodologies
  • Hands-on experience with detection rule development, automation workflow design, and detection lifecycle (development, testing, deployment, tuning, optimization)
  • Experience developing detections across endpoint, identity, network, and cloud environments
  • Experience leading cloud detection initiatives in AWS, GCP, and Azure and familiarity with cloud telemetry sources
  • Strong understanding of adversary TTPs and experience applying frameworks such as MITRE ATT&CK
  • Strong analytical and risk-quantification skills (detection effectiveness, false positive rates, MTTD, automation throughput)
  • Ability to translate technical detection posture into executive-relevant narratives and represent detection engineering to senior leadership
  • Hybrid work requirement: perform job responsibilities virtually and in-person at an assigned TU office location a minimum of two days per week
  • Experience evaluating and adopting new detection platforms or tooling at enterprise scale
  • Background building detection systems, automation, threat hunting, or threat intelligence operationalization programs
  • Experience working in financial services, fintech, or similarly regulated industry
  • Familiarity with version-controlled detection pipelines and detection-as-code practices
  • Track record of building detection automation that measurably reduces analyst toil and improves response efficiency

What the Team is Saying

Patrick
Tiana
Jason
Lauren
TC
Jay
Aayushi
Paul
Alex Barnett
Sheetal Wathare
TransUnion
TransUnion

TransUnion Compensation & Benefits Highlights

  • Healthcare Strength Day-one eligibility for medical, dental, and vision is paired with HSA/FSA options and robust mental-health resources, including 24/7 support and therapy/EAP. Wellness programming and fitness discounts further reinforce the health offering.
  • Parental & Family Support Paid parental leave of about 12 weeks with a gradual return, adoption and caregiver assistance, a complimentary Care@Work membership, and a dependent-care FSA provide meaningful family coverage. Company materials also reference child and adult care benefits and on-demand EAP access for employees and dependents.
  • Leave & Time Off Breadth Flexible time off or PTO is complemented by paid volunteer time and 10 paid holidays plus two global wellness days. Some postings note “up to 12” holidays, reflecting role/location variability.

TransUnion Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chicago, IL
13,000 Employees
Year Founded: 1968

What We Do

TransUnion is a global information and insights company that makes trust possible by ensuring that each consumer is reliably and safely represented in the marketplace. We do this by having an accurate and comprehensive picture of each person. This picture is grounded in our legacy as a credit reporting agency which enables us to tap into both credit and public record data; our data fusion methodology that helps us link, match and tap into the awesome combined power of that data; and our knowledgeable and passionate team, who stewards the information with expertise, and in accordance with local legislation around the world. Because of our work, organizations can better understand consumers in order to make more informed decisions, and earn their trust through great, personalized experiences, and the proactive extension of the right opportunities, tools and offers. In turn, consumers can be confident that their data identities will result in the opportunities they deserve. We make trust possible, so businesses and consumers can transact with confidence and achieve great things. We call this Information for Good®—it’s our purpose, and what drives us every day.

Why Work With Us

Our culture is welcoming, energetic and innovative. There’s an overall synergy that flows throughout TransUnion, creating a sense of unity in knowing that we’re all working to achieve the same overall goal. We’re dedicated to providing opportunities for our people to get involved and stay connected with their colleagues across the globe.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

TransUnion Teams

Team
Invested in Tech Teams
About our Teams

TransUnion Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Typical time on-site: Flexible
HQChicago, IL
MX
Amsterdam, NL
Bengaluru, IN
Boca Raton, FL
Bogotá, Colombia
Burlington, ON
South Africa
Cerqueira César, Sao Paulo
Chennai, IN
Cherry Hill, NJ
Cork, County Cork
Crum Lynne, PA
Denver, CO
Greenwood Village, CO
Guaynabo, PR
Gurugram, IN
Hamburg, DE
Hyderabad, IN
Johannesburg, ZA
TransUnion UK Head Office
London, GB
Louisville, KY
Madrid, ES
Makati, PH
Mumbai, IN
New York, NY
Pune, IN
Reston, VA
San Luis Obispo, CA
Santiago, CL
Sydney, NSW
Toronto, ON
Ulloa, La Aurora
Washington, US
White Plains, NY
Learn more

Similar Jobs

TransUnion Logo TransUnion

Ping Directory Engineer

Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Hybrid
6 Locations
13000 Employees
79K-131K Annually

TransUnion Logo TransUnion

AI Governance Analyst

Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Hybrid
4 Locations
13000 Employees
79K-131K Annually

TransUnion Logo TransUnion

Vice President, Commercial Operations

Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Hybrid
6 Locations
13000 Employees
194K-407K Annually

TransUnion Logo TransUnion

Technical Product Manager

Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Hybrid
5 Locations
13000 Employees
143K-238K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account