Director, Product Security

TransUnionChicago, IL
$168,750 - $281,250Remote

About The Position

The Product Security team embeds secure engineering practices throughout the product lifecycle and partners with product, platform, and engineering leaders to reduce security risk across regulated financial data products. The team enables developers through scalable security controls, reusable capabilities, and practical guidance that improve both security outcomes and engineering efficiency. This role reports to the Sr. Director, Product Security & Architecture. This is a remote position which may require occasional in-person attendance at work-related events at the discretion of management.

Requirements

  • 10+ years of experience in security engineering, application security, or closely related security disciplines, including at least 5 years leading and developing technical teams.
  • Deep expertise in Secure Software Development Lifecycle (SSDLC), secure coding practices, and cloud-native application architectures to establish and enforce secure product development standards across large-scale engineering environments.
  • Demonstrated success influencing product and engineering leadership to drive security outcomes across complex, matrixed organizations.
  • Hands-on software engineering experience with the ability to review, assess, and contribute code in support of secure product development initiatives.
  • Experience implementing and operationalizing security frameworks such as SSDF (Secure Software Development Framework), OWASP SAMM (Software Assurance Maturity Model), SAFECode, or similar industry-recognized frameworks.
  • Application Security (AppSec) program leadership and Secure Software Development Lifecycle (SSDLC) implementation.
  • Threat modeling methodologies and secure architecture review practices.
  • Cloud security principles, controls, and architectures for modern cloud-native environments.
  • Security tooling integration within CI/CD (Continuous Integration/Continuous Delivery) pipelines and automated security validation processes.
  • Software development and code review capabilities across modern programming languages, frameworks, and development platforms.

Nice To Haves

  • Experience in regulated financial services, credit, banking, fintech, or similarly regulated industries.
  • Experience managing vulnerability disclosure programs and Product Security Incident Response activities.
  • Experience building reusable security services, libraries, frameworks, or platform capabilities.
  • Strong understanding of developer experience principles and strategies for reducing friction in secure software delivery.
  • Experience building cross-functional security governance and engineering enablement programs.

Responsibilities

  • Lead and build a high-performing, hands-on Product Security team responsible for secure software development lifecycle (SSDLC) practices, threat modeling, and product vulnerability management in coordination with Attack Surface Management.
  • Partner with engineering leadership to embed security throughout the software development lifecycle while improving developer productivity and delivery velocity.
  • Define, implement, and maintain product security standards, security guardrails, and required security gates across the product development ecosystem.
  • Drive vulnerability remediation programs, service-level objectives, and vulnerability disclosure workflows in partnership with security and engineering stakeholders.
  • Develop and execute a Product Security maturity roadmap aligned to industry frameworks, including NIST, CIS, PCI, and internal control requirements.
  • Establish and monitor security metrics that measure program effectiveness, security adoption, remediation performance, and risk reduction.
  • Lead and scale a Security Champions program that equips engineering teams with security knowledge, tooling, and best practices.
  • Contribute to the development of reusable security services, controls, frameworks, and software components that support secure product development.
  • Participate in architecture reviews, product reviews, and technology decision-making processes to ensure security requirements are incorporated early in the development lifecycle.
  • Drive measurable outcomes including increased security gate coverage, improved remediation timelines, reduced critical vulnerabilities, and enhanced developer adoption of secure engineering practices.

Benefits

  • Day-one eligibility for medical, dental, and vision coverage
  • Supplemental plan options
  • Spousal, domestic partner, and other eligible dependent coverage is available on select plans
  • Tax‑advantaged HSA and FSA accounts
  • Company‑paid basic life and AD&D
  • Optional voluntary life and AD&D for you and your family
  • Short‑ and long‑term disability
  • Legal plan
  • Pet insurance
  • Travel accident coverage
  • Adoption assistance
  • Fertility planning coverage
  • Caregiver support
  • Dependent Care FSA for possibility of an employer match
  • Complimentary Care@Work membership
  • Up to 12 weeks of paid parental leave with eligibility for a thoughtful, gradual return
  • 401(k) with employer match
  • Employee Stock Purchase Plan (ESPP)
  • Financial wellness resources
  • Career coaching
  • Optional long‑term care insurance
  • Tuition reimbursement
  • Flexible time off for exempt employees or paid time off for nonexempt employees
  • Up to 12 paid holidays per year
  • Commuter benefits
  • Employee discounts
  • Charitable gift matching
  • Paid volunteer time off
  • Corporate volunteer events
  • 24/7 support including professional therapy, coaching, and emotional well‑being programs
  • Guided meditation and resources that support physical, mental, social, and financial wellness
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service