TransUnion's Job Applicant Privacy Notice
Team Overview
TransUnion’s Global Technology team engineers secure, reliable, and market-ready products that deliver exceptional experiences to customers, consumers, and colleagues. As part of theProduct Security team, this role bridges product engineering and cybersecurity, ensuring security is embedded throughout the development lifecycle and across business unit operations.

This is a remote position which may require occasional in-person attendance at work-related events at the discretion of management.
Role Overview And Core Responsibilities
How you will contribute:
The Product Security Advisor is responsible for ensuring Product Engineering maintains full lifecycle product security through adherence to secure-by-design principles and compliance with policy, regulations, and industry best practices. This person works with Information Security management to create and implement a program for championing strong security practices across products within the TransUnion portfolio, including:
- Advises and contributes to product development teams on secure coding practices, vulnerability management, and secure software development lifecycle (SSDLC) processes
- Assists Product Engineering teams with adoption of application security tooling (SAST, SCA, IAST, CNAPP) and analysis of its results to ensure vulnerabilities are addressed on a timely basis and prevented from deployment into production
- Works with engineering and development teams to ensure products comply with relevant security standards, regulations, and industry certifications, such as OWASP, CIS, or PCI-DSS to ensure security is prioritized throughout the development lifecycle
- Conducts Threat Modeling of products using standard frameworks (STRIDE, PASTA, MAESTRO) within the organization to identify potential control gaps and application weaknesses
- Partner with architecture teams to embed secure-by-design principles into product development; lead security design reviews and maintain secure application architecture guidelines aligned with best practices and industry standards.
- Builds relationships and partners with functional areas and leadership across the business and Global Technology to raise awareness and support for Product Security
- Collaborate with audit and compliance teams to ensure product security controls are documented, traceable, and audit-ready. Ensure evidence quality and oversee stakeholder response to findings for regulatory and customer audits (e.g., CIS, SOC 2, PCI-DSS, FedRAMP).
- Provides periodic updates, education and presentations to staff and management on various aspects of product security
- Stays up to date with emerging threats, technologies, and industry trends to proactively identify and address potential risks to the organization's products
- Mentors and educates colleagues and stakeholders on secure coding practices and secure product architecture patterns
Required Knowledge And Experiences
What you will bring:
The duties and responsibilities described above are essential functions of the job. The qualifications below represent the knowledge, skills, and/or abilities of the ideal candidate for a Product Security Advisor and include:
- 5+ years of experience in cybersecurity, product security, or security architecture in a technology-related industry
- 3+ years of information security experience in a hybrid cloud environment
- In depth experience secure coding practices, threat modeling, secure architecture design, and secure SDLC/CICD pipelines
- Prior experience in software development or engineering
- In-depth technical experience identifying and advising on the remediation of application security vulnerabilities on cloud and web-based applications
- Demonstrated ability as a proactive action-oriented problem solver in complex technology and organizational environments
- Experience in presenting to senior technology and information security executives and in influencing stakeholders to achieve strategic objectives
- Experience in working with industry frameworks and standards such as OWASP, PCI, CIS, and NIST
- A BA/BS degree in a computer science or technology related field
- Information Security certifications including CISSP, SSCP, CSSLP are preferred
- Ability to travel domestically up to 15% of time
TransUnion Overview:
At TransUnion, we encourage and are committed to creating a real, positive impact and shared sense of purpose within our Workforce for Good, which empowers our people to grow, innovate and contribute to a better future for our communities and customers. We strive to build an environment where our associates are in the driver’s seat of their professional development— while having access to help along the way. We recognize that success comes when our associates thrive both professionally and personally; that’s why we prioritize work/life flexibility and offer resources for our teams across the globe to collaborate and drive excellence.
Be a part of our Workforce for Good – you’ll work with great people, pioneering products and cutting-edge technology.
TransUnion Job Title
Advisor, InfoSec Risk Management & Governance