Back to search
TransUnion Builtin · Posted today

Security Automation Engineer

Reston, Virginia, USA, Chicago, Illinois, USA, Philadelphia, Pennsylvania, USA USD 112500-187500 / year Full time Remote

FULL_TIME Builtin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

TransUnion's Job Applicant Privacy Notice

Personal Information We Collect

Your Privacy Choices

Team Overview

The SOAR Development team designs and delivers automation capabilities that strengthen Security Operations Center response and reduce manual effort for security analysts. The team works across security operations, detection engineering, and supporting technology teams to build scalable, AI-driven security solutions within a global and distributed environment. This role reports to Information Security Engineering Manager This is a hybrid position and involves regular performance of job responsibilities virtually as well as in-person at an assigned TU office location for a minimum of two days a week.

Role Overview and Core Responsibilities

  • Lead the design, development, and maintenance of security response automations on the agentic AI SOC platform, including the migration of existing Splunk SOAR playbooks.
  • Build agentic workflows from end to end, including prompt and agent design, tool integration, guardrails, output evaluation, and human-in-the-loop review for AI-driven triage and response.
  • Develop and maintain integrations across SIEM, EDR, threat intelligence, case management, and ITSM platforms using REST APIs, webhooks, and event-driven patterns.
  • Build internal tools, services, and APIs primarily in Python to expand platform capabilities and reduce repetitive work for security analysts.
  • Administer and improve the case management platform and its supporting workflows.
  • Partner with detection engineering teams to convert new security detections into automated response workflows.
  • Contribute to shared engineering standards through Git-based development, code reviews, automated testing, and CI/CD practices.
  • Measure the effectiveness of automation through throughput, mean time to respond or remediate, false-positive burden, and analyst time saved.
  • Create clear technical documentation and runbooks while collaborating across a global, distributed team.

Required Knowledge and Experiences

  • 10+ years of experience in security engineering, security automation, or software engineering with a strong cybersecurity focus.
  • Hands-on experience with SOAR or security automation platforms such as Splunk SOAR, Cortex XSOAR, Tines, Torq, or similar technologies.
  • Experience building solutions with modern Large Language Model platforms such as Anthropic Claude, OpenAI, Amazon Bedrock, or similar platforms, including agent design, prompt design, tool-use patterns, and model-output evaluation.
  • Working knowledge of Security Operations Center operations, incident response workflows, and the MITRE ATT&CK framework.
  • Strong software engineering fundamentals, documentation practices, written communication skills, and experience working effectively within a distributed global team.

Required Technical Skills

  • Strong production-level Python development experience.
  • Experience developing and integrating REST APIs, JSON-based services, webhooks, and event-driven solutions.
  • Knowledge of authentication and secure integration patterns, including OAuth, API keys, and secrets management.
  • Experience with Git-based development, code review, automated testing, and Continuous Integration and Continuous Delivery practices.
  • Hands-on experience using APIs, Software Development Kits, and tool-use patterns to build LLM-powered tools, integrations, workflows, or agents.

We’re also looking for the preferred skills below. Whether you are proficient or could use some brushing up, we’re happy to support your career development and growth in:

  • Experience building autonomous or semi-autonomous agent systems or working with agentic AI security platforms in production.
  • Experience with LLM fine-tuning, systematic evaluations, safety testing, or red-teaming.
  • Exposure to Splunk Enterprise Security, Search Processing Language, detection logic, or detection-as-code practices.
  • Experience with ServiceNow or similar case management and ITSM platforms, along with web-service frameworks such as FastAPI or Flask.
  • Knowledge of AWS, Docker, Kubernetes, Terraform, DevOps practices, front-end development, or experience mentoring engineers and leading technical workstreams.

Benefits that support every part of your life:

At TransUnion, we design benefits to help you feel well, do well, and plan well—from day one.

For Your Health: Enjoy day-one eligibility for medical, dental, and vision coverage, plus supplemental plan options. Spousal, domestic partner, and other eligible dependent coverage is available on select plans. Choose tax‑advantaged HSA and FSA accounts to make everyday care more affordable.

For Your Protection: We’ve got your back with company‑paid basic life and AD&D, optional voluntary life and AD&D for you and your family, and short‑ and long‑term disability. You can also opt into a legal plan, pet insurance, and travel accident coverage.

For Your Family: From adoption assistance and fertility planning coverage to caregiver support, we’re here for every chapter. Access Dependent Care FSA for possibility of an employer match, a complimentary Care@Work membership, and up to 12 weeks of paid parental leave with eligibility for a thoughtful, gradual return.

For Your Future: Build toward what’s next with our 401(k) with employer match and Employee Stock Purchase Plan (ESPP). Tap financial wellness resources, career coaching, and optional long‑term care insurance to plan confidently.

For You: Grow and recharge with tuition reimbursement, flexible time off for exempt employees or paid time off for nonexempt employees, up to 12 paid holidays per year, commuter benefits, employee discounts, charitable gift matching, and paid volunteer time off, plus corporate volunteer events that make it easy to give back.

For Your Wellness: Access 24/7 support including professional therapy, coaching, and emotional well‑being programs alongside guided meditation and resources that support physical, mental, social, and financial wellness.

We are committed to being a place where diversity is not only present, it is embraced. As an equal opportunity employer, all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability status, veteran status, genetic information, marital status, citizenship status, sexual orientation, gender identity or any other characteristic protected by law. Additionally, in accordance with Section 503 of the Rehabilitation Act of 1973 and the Vietnam Era Veterans’ Readjustment Assistance Act of 1974, TransUnion takes affirmative action to employ and advance in employment qualified individuals with a disability and protected veterans in all levels of employment and develops annual affirmative action plans. Components of TransUnion’s Affirmative Action Program for individuals with disabilities and protected veterans are available for review to any associate or applicant for employment upon request by contacting [email protected].

Qualified applicants with arrest or conviction records will be considered for employment in accordance with applicable law, including the Los Angeles County Fair Chance Ordinance for Employers, the San Francisco Fair Chance Ordinance, Fair Chance Initiative for Hiring Ordinance, and the California Fair Chance Act.

Adherence to Company policies, sound judgment and trustworthiness, working safely, communicating respectfully, and safeguarding business operations, confidential and proprietary information, and the Company’s reputation are also essential expectations of this position.

Pay Scale Information:

The U.S. base salary range for this position is $112,500.00 - $187,500 annually. *The salary range for this position reflects a reasonable estimate of the range of compensation for this job. At TransUnion, actual compensation is based on careful consideration of additional factors such as (but not limited to) an individual’s education, training, work experience, job-related skill set, location, and industry knowledge, as well as the scope and responsibilities of the position and market considerations. Regular, fulltime non-sales positions may be eligible to participate in TransUnion’s annual bonus plan. Certain positions may be also eligible for long-term incentives and other payments based on applicable company guidance and plan documents.

TransUnion Overview:

At TransUnion, we encourage and are committed to creating a real, positive impact and shared sense of purpose within our Workforce for Good, which empowers our people to grow, innovate and contribute to a better future for our communities and customers. We strive to build an environment where our associates are in the driver’s seat of their professional development— while having access to help along the way. We recognize that success comes when our associates thrive both professionally and personally; that’s why we prioritize work/life flexibility and offer resources for our teams across the globe to collaborate and drive excellence.


Be a part of our Workforce for Good – you’ll work with great people, pioneering products and cutting-edge technology.

TransUnion's Internal Job Title:

Advisor, Cybersecurity

Company:

TransUnion LLC
Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search