Senior Lead Information Protection Security...

Wells Fargo
Chandler, AZ, United States
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$159,000.0 - $305,000.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Cloud Computing Security Cyber Security Data Discovery Data Security Decision Support Systems Hardware Security Module Information Security Management Information Systems Security Architecture Professional Key Management Network Security PCI Data Security Standards
+4 more
Public Key Infrastructure Software Engineering SSL Certificate Management Performance Monitor

Job description

Wells Fargo is seeking a Senior Lead Information Protection Security Analyst to join the Information Protection Domain within Cybersecurity. This role provides enterprise leadership for information protection strategy, governance, and risk management programs focused on safeguarding the firm’s sensitive data assets. The successful candidate will drive initiatives related to data discovery, classification, protection, governance, and regulatory compliance while partnering across technology, cybersecurity, legal, privacy, risk, and business teams to reduce information security risk and improve the firm’s overall data protection posture.

In this role, you will:

  • Provide oversight to the Information Security program for a major line of business

  • Consult with line of business on the consistent implementation of the enterprise information security model and solutions to remediate information security risks

  • Ensure that risks to all information assets are being managed in a timely and effective manner to meet the Information Security Program requirements and the current threat landscape

  • Ensure information security capabilities are included in all aspects of the company’s technology architecture

  • Proactively manage the information security risk profile of line of business information assets throughout the lifecycle of the asset

  • Provide vision, direction, and expertise to more experienced leadership on implementing innovative and significant business solutions that are large-scale, cross-functional, or companywide strategies

  • Ensure the team has the necessary training and is keeping abreast of regulatory and compliance issues

  • Engage with all levels of professionals and managers companywide and serve as an experienced advisor to leadership

  • Develop, implement, and maintain the enterprise cryptographic governance framework, including policies, standards, and procedures.

  • Develop and maintain cryptographic policies, standards, and control requirements (e.g., encryption, key management, certificates), ensuring alignment with applicable regulatory and industry frameworks (e.g., NIST, PCI DSS, ISO 27001).

  • Operate governance routines to ensure consistent application of cryptographic controls across the enterprise.

  • Review and evaluation new or updated cryptographic new solutions.

  • Lead governance forums, reporting, and escalation processes to senior leadership.

  • Align governance activities with the enterprise cryptographic strategy, including roadmap initiatives and long-term objectives.

  • Participate in periodic reviews of cryptographic strategy and data protection initiatives.

  • Ensure governance supports enterprise priorities related to data protection, risk management, and security modernization.

  • Establish and maintain visibility into cryptographic risks, including vulnerabilities and non-compliance.

  • Define key metrics and reporting mechanisms to monitor cryptographic posture.

  • Escalate issues related to non-adherence to cryptographic policy through established governance channels.

  • Support the identification, prioritization, and tracking of risk remediation activities.

  • Assist with exception management, ensuring appropriate documentation, risk acceptance, and tracking.

  • Collaborate regularly with cross-functional stakeholders, including Cybersecurity Architecture, Secure Network Services (SNS), Cloud Security, and application teams, on solutions, strategies, and policies.

  • Act as a central point of coordination for cryptographic governance activities.

  • Provide guidance and direction to engineering and operational teams on governance expectations.

  • Support internal and external audits by providing required documentation, control evidence, and governance artifacts.

  • Participate in the evaluation of cryptographic discovery tools and capabilities.

  • Develop program to cryptographic discovery tools, capabilities, reporting and metrics.

  • Monitor enterprise cryptographic posture and identify risks through tool outputs.

  • Demonstrate foundational AI literacy by effectively using approved AI tools to support everyday work

  • Apply AI tools for activities such as research, summarization, drafting, analysis, and decision support

  • Exercise sound judgment when interpreting and using AI-generated outputs

  • Understand basic AI limitations and appropriate use cases within daily workflows, Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit’s risk appetite and all risk and compliance program requirements.

Requirements

  • 7+ years of Information Security Analysis experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education.

Desired Qualifications

  • Deep expertise in Hardware Security Modules (HSMs), Public Key Infrastructure (PKI), key management, certificate services, encryption technologies, and enterprise cryptographic controls

  • Strong experience developing, implementing, and governing enterprise cryptographic programs, including policies, standards, procedures, and control frameworks within highly regulated environments

  • Demonstrated experience managing and improving certificate lifecycle management, cryptographic asset inventory, discovery, reporting, and remediation programs across large, complex organizations

  • Advanced knowledge of security and regulatory frameworks including NIST Cryptographic Standards, NIST Cybersecurity Framework (CSF), PCI DSS, ISO 27001, FFIEC guidance, and financial services regulatory requirements

  • Experience evaluating, planning, or implementing post-quantum cryptography (PQC) strategies, cryptographic modernization initiatives, and emerging encryption technologies

  • Proven ability to author and enhance enterprise security policies, standards, governance artifacts, executive communications, and regulatory documentation while influencing senior leaders and cross-functional stakeholders

  • Strong technical leadership experience partnering with cybersecurity architecture, engineering, infrastructure, cloud security, application development, legal, privacy, risk, and regulatory teams to drive enterprise-wide cryptographic governance and adoption

  • Experience supporting cryptographic discovery tools, defining enterprise cryptographic metrics, monitoring cryptographic posture, and identifying risks associated with non-compliant cryptographic implementations

  • Experience leading cryptographic governance, PKI, certificate management, or key management programs within a large-scale financial institution or highly regulated industry

Benefits & conditions

Wells Fargo provides eligible employees with a comprehensive set of benefits, many of which are listed below. Visit Benefits - Wells Fargo Jobs (https://www.wellsfargojobs.com/en/life-at-wells-fargo/benefits) for an overview of the following benefit plans and programs offered to employees.

  • Health benefits

  • 401(k) Plan

  • Paid time off

About the company

Wells Fargo maintains a drug free workplace. Please see our Drug and Alcohol Policy (https://www.wellsfargojobs.com/en/wells-fargo-drug-and-alcohol-policy) to learn more.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 · WWC 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

2:36 min

Implementing on-premise deep research agentic workflows

Anshul Jindal Anshul Jindal +1 · WWC Europe 2026

1:22 min

Piloting industry optimizations and enforcing post-quantum security updates

Ilie-Daniel Gheorghe-Pop Ilie-Daniel Gheorghe-Pop · WWC Europe 2026

41 sec

Massive client data loss and bio-digital storage

Chris Heilmann +1 · LIVE

Videos

See all

Related articles

See all