> Markdown version of [/jobs/ext/1363942-director-detection-engineering-and-automation](https://www.wearedevelopers.com/jobs/ext/1363942-director-detection-engineering-and-automation). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director, Detection Engineering and Automation - **Company:** TransUnion LLC - **Location:** Chicago, IL, United States - **Experience:** Experienced - **Salary:** $168,750.0 - $281,250.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Intrusion Detection and Prevention, Performance Tuning, Security Information and Event Management, Workflow Management Systems, Google Cloud, Cloud Platform System, Software Security, Mitre Att&ck, Cyber Threat Analysis, Information Technology, Cybercrime, Cyber Warfare, Security Orchestration, Automation & Response - **Published:** July 21, 2026 - **Apply:** https://transunion.wd5.myworkdayjobs.com/TransUnion/job/Chicago-Illinois/Director--Detection-Engineering-and-Automation_19041296-1 ## About the Role * 10+ years of cybersecurity experience, with a strong focus on detection engineering, security operations, or threat intelligence, including at least 3-5 years in a people leadership role managing teams or managers. * Demonstrated experience building and scaling detection engineering programs, including detection development, tuning, operationalization, and continuous improvement across enterprise environments. * Strong understanding of adversary tactics, techniques, and procedures and experience applying frameworks such as MITRE ATT&CK to guide detection prioritization, coverage, and risk reduction. * Proven ability to drive cross-functional alignment across Threat Intelligence, Incident Response, Security Operations, Cloud Infrastructure Security, Application Security, and Engineering teams. * Bachelor's degree in Computer Science, Information Security, or a related field required; equivalent experience may be considered where it demonstrates the technical depth and leadership capability needed for the role. Required Technical Skills * Deep technical expertise with SIEM, EDR, SOAR, and detection-as-code methodologies, including hands-on experience with detection rule development and automation workflow design. * Experience developing detections across endpoint, identity, network, and cloud environments, with the ability to prioritize based on risk reduction and operational impact. * Experience leading cloud detection initiatives across cloud-native environments such as AWS, GCP, and Azure, including familiarity with cloud-specific telemetry sources and detection challenges. * Strong analytical and risk-quantification skills, including the ability to evaluate detection effectiveness, false positive rates, detection coverage, MTTD, and automation throughput. * Ability to translate technical detection posture into executive-relevant narratives, including risk trends, coverage gaps, platform health, and program maturity. We're also looking for the preferred skills below. Whether you are proficient or could use some brushing up, we're happy to support your career development and growth in: * Experience evaluating and adopting new detection platforms or tooling at enterprise scale. * Background building detection systems, automation, threat hunting, or threat intelligence operationalization programs. * Experience working in financial services, fintech, or a similarly regulated industry. * Familiarity with version-controlled detection pipelines and detection-as-code practices. * Track record of building detection automation that measurably reduces analyst toil and improves response efficiency. ## Description Reporting directly to the SVP, Cyber Defense, the Director of Detection Engineering and Automation will serve as a key member of the Cyber Defense leadership team responsible for advancing TransUnion's detection and automation capabilities across endpoint, identity, network, and cloud environments. The role partners closely with Threat Intelligence, Security Incident Response, Security Operations, Cloud Infrastructure Security, Application Security, and Engineering to strengthen proactive defense, reduce risk, and improve operational response. This is a hybrid position and involves regular performance of job responsibilities virtually as well as in-person at an assigned TU office location for a minimum of two days a week. Role Overview and Core Responsibilities * Lead the Detection Engineering and Automation function, establishing the team as the authoritative center of excellence for prioritized, high-fidelity detections that reduce risk across endpoint, identity, network, and cloud environments. * Define and execute the detection engineering and automation strategy, ensuring detection priorities are aligned to the evolving threat landscape, enterprise risk, and organizational priorities. * Lead, develop, and scale a team of approximately 14 detection and automation engineers and one manager, building leadership capability, fostering a high-performance culture, and supporting continued team growth. * Own the end-to-end detection lifecycle, from ideation and prioritization through development, testing, deployment, tuning, and ongoing optimization to ensure detections remain relevant and actionable. * Drive automation and response workflow integration across SOAR, SIEM, and EDR platforms to increase detection coverage, reduce manual effort, and improve operational scalability. * Mature the detection platform by evaluating and adopting scalable tooling, simplifying detection authoring, and enabling faster turnaround on new detection capabilities. * Lead cloud detection capability development by closing current coverage gaps and building durable cloud-native detection capabilities in partnership with Cloud Infrastructure Security and Engineering. * Partner cross-functionally with SecOps, Threat Intelligence, SIRT, and Engineering to ensure detection outputs are actionable, response plans are current, and automation reduces manual response burden. * Define, track, and communicate key detection metrics, including detection coverage, detection effectiveness, false positive rates, mean time to detect, and automation throughput. * Represent Detection Engineering in senior leadership forums by providing clear, decision-oriented updates on detection posture, platform health, risk coverage, and team progress., We are committed to being a place where diversity is not only present, it is embraced. As an equal opportunity employer, all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability status, veteran status, genetic information, marital status, citizenship status, sexual orientation, gender identity or any other characteristic protected by law. Additionally, in accordance with Section 503 of the Rehabilitation Act of 1973 and the Vietnam Era Veterans' Readjustment Assistance Act of 1974, TransUnion takes affirmative action to employ and advance in employment qualified individuals with a disability and protected veterans in all levels of employment and develops annual affirmative action plans. Components of TransUnion's Affirmative Action Program for individuals with disabilities and protected veterans are available for review to any associate or applicant for employment upon request by contacting ERCoE@transunion.com. Qualified applicants with arrest or conviction records will be considered for employment in accordance with applicable law, including the Los Angeles County Fair Chance Ordinance for Employers, the San Francisco Fair Chance Ordinance, Fair Chance Initiative for Hiring Ordinance, and the California Fair Chance Act. Adherence to Company policies, sound judgment and trustworthiness, working safely, communicating respectfully, and safeguarding business operations, confidential and proprietary information, and the Company's reputation are also essential expectations of this position. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Cloud Run- the rise of serverless and containerization](https://www.wearedevelopers.com/videos/106-cloud-run-the-rise-of-serverless-and-containerization) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)