TransUnion Logo

TransUnion

Information Security Analyst _ penetration testing

Reposted An Hour Ago
Be an Early Applicant
Hybrid
2 Locations
Mid level
Hybrid
2 Locations
Mid level
The role involves conducting penetration testing, vulnerability assessments, and application security scans, while collaborating with development teams to enhance security within CI/CD pipelines and ensure compliance with security standards.
The summary above was generated by AI

TransUnion's Job Applicant Privacy Notice

What We'll Bring:

We are seeking a security analyst to join CIBIL Information Security team to support annual penetration testing, ongoing vulnerability assessments, and application security scanning across our environment. The role will collaborate closely with development teams to embed DevSecOps practices, drive timely remediation of vulnerabilities, and ensure compliance with regulatory and threat‑intelligence advisories. Responsibilities include maintaining security baselines for infrastructure and leveraging tools such as Rapid7, Burp Suite, Checkmarx, and Seeker to strengthen our overall security posture.

What You'll Bring:

  • Support the annual penetration testing program for both existing systems and new go‑live applications, ensuring timely remediation of identified risks.

  • Execute periodic internal and external vulnerability assessment (VA) scans, analyze discovered vulnerabilities, and provide clear reporting to stakeholders for timely closure.

  • Support Static Application Security Testing (SAST) and Interactive Application Security Testing (IAST) scans, driving application teams to identify, prioritize, and resolve security weaknesses.

  • Collaborate with development teams to embed security controls into CI/CD pipelines (DevSecOps) and promote secure coding practices across the SDLC.

  • Support regulatory and compliance-driven security advisories, ensuring vulnerabilities identified through external mandates are remediated within required timelines.

  • Assist in remediation activities triggered by threat intelligence and VTM advisories, including evaluation of reported exploits, zero-day vulnerabilities, and their applicability to the organization.

  • Conduct periodic security baseline reviews for network devices, operating systems, and infrastructure components to ensure configuration compliance.

  • Utilize and maintain proficiency with key security tools such as Rapid7, Burp Suite, Checkmarx, and Seeker, using them to strengthen the organization’s vulnerability management and application security posture.

Impact You'll Make:

  • Maintain and enhance dashboards, reporting mechanisms, and metrics for vulnerability management, providing leadership with visibility into risk trends, remediation progress, and compliance adherence.
  • Assist in establishing and continuously improving secure coding standards, development guidelines, and security guardrails aligned with industry best practices.
  • Contribute to audit and compliance programs (e.g., ISO, SOC 2, regulatory reviews) by providing evidence, documentation, and remediation tracking for security‑related controls.
  • Stay updated with emerging threats, new tools, and evolving security techniques, advising teams on adoption of modern, efficient, and scalable security practices.

This is a hybrid position and involves regular performance of job responsibilities virtually as well as in-person at an assigned TU office location for a minimum of two days a week.

TransUnion Job Title

Analyst, InfoSec Risk Management & Governance

Top Skills

Burp Suite
Checkmarx
Rapid7
Seeker

Similar Jobs at TransUnion

Yesterday
Hybrid
Pune, Mahārāshtra, IND
Senior level
Senior level
Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
The Senior Analyst, Indirect Tax will leverage experience in Indirect Tax across India, APAC, and EMEA regions while working predominantly in a hybrid role.
Top Skills: Peoplesoft
Yesterday
Hybrid
Pune, Mahārāshtra, IND
Mid level
Mid level
Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
The Full Stack Developer will design and develop backend and frontend applications using Java and Vue.js, with a focus on cloud infrastructure, CI/CD, and microservices architecture.
Top Skills: CSS3DockerGCPGitGradleHarnessHibernateHTML5JavaJavaScriptJdbcJpaJunitMavenMicroservicesMockitoNoSQLNpmSassScssSpringSQLTailwind CssViteVueWebpackYarn
Yesterday
Hybrid
3 Locations
Senior level
Senior level
Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Lead the design and development of Adobe Experience Manager solutions, focusing on website customization, API integration, and performance tuning.
Top Skills: Adobe AnalyticsAdobe Experience ManagerAdobe TargetApi IntegrationDispatcherHtlJavaJcrOsgiSling

What you need to know about the Kolkata Tech Scene

When considering the industries shaping India's tech scene, gaming might not immediately come to mind. However, in the last decade, increased internet usage and greater access to mobile devices have catapulted the industry to new heights, with Kolkata-based companies like Virtualinfocom, Red Apple Technologies and Digitoonz, at the forefront, driving the design and animation of new gaming titles for players.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account