Senior Director, Vulnerability Resiliency Engineering
Listed on 2026-08-22
-
IT/Tech
Cybersecurity, Security Management & Operations
The Vulnerability Resiliency Engineering team is responsible for reducing exploitable risk across Trans Union's technology environment by transforming traditional vulnerability management into a modern Vuln Ops operating model.
Partnering closely with Security Operations, Incident Response, Threat Intelligence, Product Security, Cloud Infrastructure Security, and Engineering teams, the organization focuses on accelerating vulnerability discovery, disruption, remediation, validation, and risk reduction through automation and engineering-led ownership.
Reporting to the SVP of Cyber Defense, this leader will drive one of Trans Union's most critical cybersecurity transformation initiatives while building a scalable, AI-enabled approach to exposure management across first-party code, third-party dependencies, APIs, endpoints, and infrastructure
This is a hybrid position and involves regular performance of job responsibilities virtually as well as in-person at an assigned TU office location for a minimum of two days a week.
Role Overview and Core ResponsibilitiesDefine and execute Trans Union's Vuln Ops transformation strategy, shifting the organization from a traditional scan-and-backlog model to an engineering-led approach focused on eliminating exploitable exposure.
Lead the AI Vuln Research and Engineering, Vulnerability Resiliency Engineering, and Traditional Vulnerability Management Operations teams, overseeing a peak organization of approximately 25 engineers while evolving to a highly automated team of 11 to 14 specialized engineers.
Own the end-to-end vulnerability operating lifecycle, including discovery, prioritization, disruption, remediation, validation, and measurement to ensure clear accountability and durable risk reduction.
Establish and operationalize a patch-plus-disruption response model, including controls such as WAF rules, API protections, network isolation, quarantine capabilities, runtime protections, and virtual patching.
Drive consolidation of legacy vulnerability and exposure management platforms into a unified Vuln Ops ecosystem centered on Wiz, Cogent Security, and a common security data lake.
Partner with engineering teams to eliminate vulnerabilities before production through trusted images, CI/CD security controls, approved libraries, and automated remediation capabilities.
Scale automation and AI-driven remediation workflows to improve remediation efficiency and reduce mean time to remediate (MTTR) for critical vulnerabilities.
Define and manage executive-level operational metrics, including exploitable exposure, disruption effectiveness, remediation performance, vulnerability elimination rates, asset currency, and SLA compliance.
Lead cross-functional governance forums that drive accountability, exposure reduction, engineering alignment, technology lifecycle management, and automation adoption.
Represent Vulnerability Resiliency Engineering in executive leadership reviews, providing strategic updates on risk reduction outcomes, transformation progress, and operational performance.
Required Knowledge and Experiences12+ years of cybersecurity experience, including vulnerability management, security operations, security engineering, or related disciplines, with at least 5 years leading managers and multi-team organizations.
Demonstrated success leading large-scale vulnerability management or security transformation initiatives that leverage automation, engineering ownership, and measurable risk reduction outcomes.
Deep understanding of vulnerability management frameworks, exposure management, threat-informed prioritization, and exploit disruption strategies within complex enterprise environments.
Proven experience driving organizational design, workforce transformation, talent development, and capability building while modernizing operational practices.
Bachelor's degree in Computer Science, Information Security, Engineering, or a related field, or equivalent combination of education and relevant leadership experience. Advanced degree preferred.
Required Technical SkillsExpertise with vulnerability and exposure management platforms, including Wiz, Crowd Strike, JFrog Xray, vulnerability scanners, Endpoint Detection and Response (EDR), Security Information and Event Management (SIEM), Cloud-Native Application Protection Platforms (CNAPP), and Security Orchestration, Automation and Response (SOAR) technologies.
Strong knowledge of vulnerability prioritization and risk-based remediation methodologies, including CISA Known Exploited Vulnerabilities (KEV), Exploit Prediction Scoring System (EPSS), and related frameworks.
Experience designing and implementing automated remediation, AI-driven security operations, CI/CD security controls, trusted image management, and engineering-owned vulnerability reduction programs.
Proven capability leading…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).