ForgeApply
Try it free

ForgeApply · Job listing

Senior Principal Architect, Cyber Defense Engineering

Transunion

Chicago, IL, US$188k – $313khybrid

See all 56 open roles at Transunion

Tailor your resume for this Transunion job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Transunion's site. Free trial, no card required.

About this role

TransUnion's Job Applicant Privacy Notice Personal Information We Collect Your Privacy Choices

Team Overview Cyber Defense Engineering is responsible for modernizing TransUnion's detection, response, vulnerability, and endpoint capabilities through scalable architecture, automation, and integrated security platforms.

This individual contributor role will act as the principal technical architect for TransUnion's Cyber Defense organization, owning the reference architecture that underpins modernization across Data Security Posture Management (DSPM), Zero Trust Network Access (ZTNA), Endpoint Strategy, and AI enablement.

Reporting the SVP, Cyber Defense Engineering, this role will partner closely with the AI SOC, VulnOps, Detection Engineering, and Technical Program Manager functions to ensure architectural coherence as Cyber Defense shifts from fragmented, tool-centric operations to a unified, automation-first, agentic security architecture.

This is a hybrid position and involves regular performance of job responsibilities virtually as well as in-person at an assigned TU office location for a minimum of two days a week. Role Overview and Core Responsibilities • Own and evolve the Cyber Defense reference architecture, defining the target-state design for how detection, response, vulnerability management, and endpoint telemetry integrate across a unified data and automation layer.  

• Architect TransUnion's Data Security Posture Management (DSPM) capability, leading technical evaluation, integration design, and rollout planning for cloud-native data discovery, classification, and exposure detection, including Wiz DSPM, across AWS, GCP, and hybrid environments.  

• Define TransUnion's Zero Trust Network Access (ZTNA) architecture, establishing target-state design for identity-aware, least-privilege access to enterprise and cloud workloads in coordination with IAM, network security, and cloud infrastructure teams.  

• Own Endpoint Strategy architecture, defining the target design for endpoint detection and response, exposure management, and telemetry integration across the enterprise fleet while rationalizing overlapping endpoint tooling.  

• Architect the AI enablement layer for Cyber Defense, designing agentic and LLM-based capabilities for triage, investigation, and response, including MCP-based agent orchestration and AI SOC platforms that integrate with existing SIEM, SOAR, and case management systems.  

• Lead the technical architecture for SIEM and security data platform modernization, defining the target design for log ingestion, retention, and analytics as the organization evaluates consolidation of fragmented logging and detection platforms.  

• Define reference architecture for the VulnOps operating model, ensuring vulnerability discovery, prioritization, disruption, and remediation systems integrate cleanly with the broader Cyber Defense data and automation architecture.  

• Evaluate emerging security technologies and vendor platforms against TransUnion's architecture principles, producing build-versus-buy recommendations, integration designs, and proof-of-concept plans for new capabilities before they reach production.  

• Establish architecture governance and design standards for Cyber Defense Engineering, authoring reference diagrams, integration patterns, and technical design documents that guide engineering teams building against the architecture.  

Required Knowledge and Experiences • 15+ years of experience in cybersecurity architecture, security engineering, or related technical roles, with demonstrated ownership of enterprise-scale security reference architectures.  

• Deep technical expertise in cloud security posture and data security tooling, with hands-on experience in DSPM, CNAPP, or related platforms, including Wiz, across AWS, GCP, or Azure environments.  

• Strong understanding of Zero Trust Network Access (ZTNA) architecture and identity-aware access models, including experience designing or implementing ZTNA in an enterprise environment.  

• Hands-on experience with endpoint detection and response (EDR) architecture and tooling, including CrowdStrike Falcon and Microsoft Defender for Endpoint, with exposure management and fleet-wide telemetry design.  

• Experience architecting or building AI-enabled or agentic security capabilities, including familiarity with LLM-based triage and investigation agents, MCP-based tool orchestration, or AI SOC platforms.  

• Strong programming and scripting skills, including Python or Go, with the ability to build architecture prototypes, integration proofs-of-concept, and automation scripts independently.  

• Experience with modern security data platforms and SIEM/log analytics architecture, including Splunk and cloud-native log platforms, with experience evaluating or leading platform consolidation efforts.  

• Proven ability to produce clear architecture documentation, including reference diagrams, integration patterns, and technical design decks that engineering teams can build against.  

• Bachelor's degree in Computer Science, Computer Engineering, Information Security, or a related field required; advanced degree preferred.  

Required Technical Skills   • Expertise designing security reference architectures across DSPM, ZTNA, endpoint security, SIEM, SOAR, case management, vulnerability management, and security data platforms.  

• Hands-on cloud security architecture experience across AWS, GCP, or Azure, including CNAPP, DSPM, cloud-native data discovery, classification, and exposure detection capabilities.  

• Strong endpoint and telemetry architecture expertise, including EDR, exposure management, fleet telemetry, alert normalization, and tool rationalization.  

• Ability to design AI-enabled and agentic security workflows using LLM-based triage, MCP-based tool orchestration, AI SOC platforms, integration scripts, and automation prototypes.  

• Strong programming, scripting, and proof-of-c

Salary insight

The midpoint of this range ($250k) is about 90% above the median disclosed salary for Chicago roles listed on ForgeApply ($132k across 2,657 jobs).

Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.

Tailor your resume for this Transunion role before you apply.

Tailor my resume for this job

Similar jobs

Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)