ForgeApply · Job listing
Senior Director, Vulnerability Resiliency Engineering
Transunion
See all 56 open roles at Transunion →
Tailor your resume for this Transunion job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Transunion's site. Free trial, no card required.
About this role
TransUnion's Job Applicant Privacy Notice Personal Information We Collect Your Privacy Choices
Team Overview The Vulnerability Resiliency Engineering team is responsible for reducing exploitable risk across TransUnion's technology environment by transforming traditional vulnerability management into a modern VulnOps operating model.
Partnering closely with Security Operations, Incident Response, Threat Intelligence, Product Security, Cloud Infrastructure Security, and Engineering teams, the organization focuses on accelerating vulnerability discovery, disruption, remediation, validation, and risk reduction through automation and engineering-led ownership.
Reporting to the SVP of Cyber Defense, this leader will drive one of TransUnion's most critical cybersecurity transformation initiatives while building a scalable, AI-enabled approach to exposure management across first-party code, third-party dependencies, APIs, endpoints, and infrastructure

This is a hybrid position and involves regular performance of job responsibilities virtually as well as in-person at an assigned TU office location for a minimum of two days a week. Role Overview and Core Responsibilities • Define and execute TransUnion's VulnOps transformation strategy, shifting the organization from a traditional scan-and-backlog model to an engineering-led approach focused on eliminating exploitable exposure.
• Lead the AI Vuln Research and Engineering, Vulnerability Resiliency Engineering, and Traditional Vulnerability Management Operations teams, overseeing a peak organization of approximately 25 engineers while evolving to a highly automated team of 11 to 14 specialized engineers.
• Own the end-to-end vulnerability operating lifecycle, including discovery, prioritization, disruption, remediation, validation, and measurement to ensure clear accountability and durable risk reduction.
• Establish and operationalize a patch-plus-disruption response model, including controls such as WAF rules, API protections, network isolation, quarantine capabilities, runtime protections, and virtual patching.
• Drive consolidation of legacy vulnerability and exposure management platforms into a unified VulnOps ecosystem centered on Wiz, Cogent Security, and a common security data lake.
• Partner with engineering teams to eliminate vulnerabilities before production through trusted images, CI/CD security controls, approved libraries, and automated remediation capabilities.
• Scale automation and AI-driven remediation workflows to improve remediation efficiency and reduce mean time to remediate (MTTR) for critical vulnerabilities.
• Define and manage executive-level operational metrics, including exploitable exposure, disruption effectiveness, remediation performance, vulnerability elimination rates, asset currency, and SLA compliance.
• Lead cross-functional governance forums that drive accountability, exposure reduction, engineering alignment, technology lifecycle management, and automation adoption.
• Represent Vulnerability Resiliency Engineering in executive leadership reviews, providing strategic updates on risk reduction outcomes, transformation progress, and operational performance.
Required Knowledge and Experiences • 12+ years of cybersecurity experience, including vulnerability management, security operations, security engineering, or related disciplines, with at least 5 years leading managers and multi-team organizations.
• Demonstrated success leading large-scale vulnerability management or security transformation initiatives that leverage automation, engineering ownership, and measurable risk reduction outcomes.
• Deep understanding of vulnerability management frameworks, exposure management, threat-informed prioritization, and exploit disruption strategies within complex enterprise environments.
• Proven experience driving organizational design, workforce transformation, talent development, and capability building while modernizing operational practices.
• Bachelor's degree in Computer Science, Information Security, Engineering, or a related field, or equivalent combination of education and relevant leadership experience. Advanced degree preferred.
Required Technical Skills • Expertise with vulnerability and exposure management platforms, including Wiz, CrowdStrike, JFrog Xray, vulnerability scanners, Endpoint Detection and Response (EDR), Security Information and Event Management (SIEM), Cloud-Native Application Protection Platforms (CNAPP), and Security Orchestration, Automation and Response (SOAR) technologies.
• Strong knowledge of vulnerability prioritization and risk-based remediation methodologies, including CISA Known Exploited Vulnerabilities (KEV), Exploit Prediction Scoring System (EPSS), and related frameworks.
• Experience designing and implementing automated remediation, AI-driven security operations, CI/CD security controls, trusted image management, and engineering-owned vulnerability reduction programs.
• Proven capability leading enterprise-scale platform rationalization, vendor consolidation, and migration initiatives utilizing centralized security data models and reporting platforms.
• Strong executive communication and data storytelling skills, with the ability to translate technical findings, exposure trends, and operational metrics into actionable business decisions.
We're also looking for the preferred skills below. Whether you are proficient or could use some brushing up, we're happy to support your career development and growth in:
• Experience building or scaling AI-native or agentic vulnerability remediation capabilities.
• Experience with Attack Surface Management (ASM) programs in addition to traditional vulnerability management disciplines.
• Familiarity with MITRE ATT&CK and threat-informed defense methodologies.
• Experience operating within financial services, fintech, or other highly regulated enterprise environment
Salary insight
The midpoint of this range ($250k) is about 90% above the median disclosed salary for Chicago roles listed on ForgeApply ($132k across 2,657 jobs).
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Transunion role before you apply.
Tailor my resume for this jobSimilar jobs
- Senior Vulnerability Management Engineer — Celonis · Raleigh, US, North Carolina
- Sr. Vulnerability Advisor — Taketwo · Austin, Texas, United States
- Senior Director, Security Engineering — Ripple · San Francisco, CA, United States
- Senior Director, Security Engineering — Ripple · New York, NY, United States
- Senior Director, Security Engineering — Ripple · Chicago, Illinois, United States
- Senior Director, Security Engineering — Ripple · Washington, D.C., United States
- Sr. Vulnerability Analyst — Cboe · Chicago, IL
- Senior Security Software Engineer, Vulnerability Management — Roblox · San Mateo, CA, United States
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)