Consumer Technology Lead Software Engineer

Wells Fargo
Charlotte, NC, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
1 year minimum
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Java (Programming Language) JavaScript (Programming Language) .NET Framework Application Programming Interfaces (APIs) C Sharp (Programming Language) Cloud Computing Security Continuous Integration Software Debugging Human-Computer Interaction Identity and Access Management Python (Programming Language)
+27 more
Key Management MongoDB OAuth OpenID Open Web Application Security Role-Based Access Control Oop Languages JSON Web Token Secure Coding Software Deployment Software Engineering Software Vulnerability Management ReactJS Grafana Software Security Software Application Programming Event Driven Architecture AngularJS Kubernetes Performance Monitor Apache Kafka Virtual Agents Splunk Appdynamics Static Application Security Testing Microservices Dynamic Application Security Testing

Job description

Wells Fargo is seeking a Lead Software Engineer with Consumer Technology team to design, develop, and lead scalable applications and reduce vulnerability risk by embedding secure code automation and proactive security initiatives into delivery pipelines. By shifting security controls earlier in the lifecycle, the role mitigates the growing frequency and impact of Zero Day and Heightened Awareness events before they reach production. This role requires deep expertise in current technologies, strong architectural skills, and the ability to mentor engineers while partnering closely with product, design, and engineering teams.

Learn more about the career areas and lines of business at wellsfargojobs.com.

In this role, you will:

  • Lead complex technology initiatives including those that are companywide with broad impact
  • Act as a key participant in developing standards and companywide best practices for engineering complex and large scale technology solutions for technology engineering disciplines
  • Design, code, test, debug, and document for projects and programs
  • Review and analyze complex, large-scale technology solutions for tactical and strategic business objectives, enterprise technological environment, and technical challenges that require in-depth evaluation of multiple factors, including intangibles or unprecedented technical factors
  • Make decisions in developing standard and companywide best practices for engineering and technology solutions requiring understanding of industry best practices and new technologies, influencing and leading technology team to meet deliverables and drive new initiatives
  • Collaborate and consult with key technical experts, senior technology team, and external industry groups to resolve complex technical issues and achieve goals
  • Lead projects, teams, or serve as a peer mentor, Acts as the security advocate within the team Embeds secure-by-design practices into development Enables developer education and maturity Supports automation and guardrails, Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit’s risk appetite and all risk and compliance program requirements.

Requirements

  • 5+ years of Software Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
  • 4+ years of Java and Python development experience
  • 3+ years of SAST/DAST/SCA tooling experience
  • 3+ years of User interface framework experience, Angular, ReACT.
  • 4+ years of Kubernetes based software deployment and development experience, * 3+ years of CI/CD Security integration (pipeline scanning, gating)
  • 2+ years of Kafka experience
  • 2+ years of OWASP Top 10 (injection, auth issues, deserialization, etc.)
  • 2+years of Container security (image scanning, runtime protection)
  • 2+ years of Mongo experience
  • 3+ Years of implementing resilient software leveraging Event Driven Architecture, Microservices, Back pressure or bulkhead software designs
  • 3+ Years of observability experience (ELK, Splunk, AppDynamics, Grafana)
  • 1+ years of Agentic AI delivery experience.
  • Recommended application security certifications (one or more): CISSP, CSSLP, CASE, OSWE, CISM
  • Experience in developing applications in Java, .NET (preferred), C#, JavaScript, Python, or other modern OOP languages.
  • Strong technical and business writing skills, plus the ability to effectively explain plans and solutions verbally to both technology and business units.
  • Experience with vulnerability management, including triage, remediation tracking, SLA adherence, and exception handling processes *
  • Experience with API and identity security (OAuth2, OIDC, JWT, RBAC)
  • Experience with cloud security principles, including IAM, least privilege, and secrets management
  • Experience conducting threat modeling and secure design reviews
  • Experience implementing security automation and policy enforcement within CI/CD pipelines

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · WWC 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all