Lead Information Security Engineer

Wells Fargo
Charlotte, NC, United States
3 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Configuration Management Cyber Security Network Security CIS Benchmarks Operating System Security

Job description

Experteer Overview In this role you will provide technical leadership for Wells Fargo’s Security Baseline Configuration program, driving security engineering initiatives and scalable automation. You will collaborate with engineering, infrastructure, and governance teams to implement secure-by-default solutions and governance models. You’ll balance security with operational needs, develop risk-based recommendations, and communicate decisions to executives. This is a hands-on leadership role shaping security standards and accelerating delivery at scale. Compensation / Benefits * Lead complex security engineering initiatives from intake to publication and adoption * Establish prioritization and work management practices for predictable delivery * Drive secure-by-default solutions with cross-functional partners * Influence stakeholders on security requirements and risk mitigation without direct authority * Define and maintain security baseline standards, governance models, and lifecycle processes * Develop risk-based recommendations balancing security with operations and business objectives * Advance automation to improve consistency and speed of delivery * Create executive-ready communications, decisions, status reports, and risk briefings * Mentor engineers and contribute to professional development * Act as trusted advisor for complex security engineering decisions and challenges Tasks * 5+ years of Information Security Engineering experience or equivalent * Experience implementing or governing security baselines aligned to CIS Benchmarks * Strong understanding of OS security, network security, encryption, and secure configuration management * Strong stakeholder management with ability to influence senior leaders without direct authority * Experience building organizational consensus around security controls and implementation approaches * Deep expertise in security engineering, architecture, or baseline configuration management * Track record of driving measurable operational improvements through process optimization and automation Key requirements * Health benefits * 401(k) Plan * Paid time off * Parental leave * Tuition reimbursement * Adoption reimbursement

Requirements

Benefits * Develop risk-based recommendations balancing security with operations and business objectives * Advance automation to improve consistency and speed of delivery * Create executive-ready communications, decisions, status reports, and risk briefings * Mentor engineers and contribute to professional development * Act as trusted advisor for complex security engineering decisions and challenges Tasks * 5+ years of Information Security Engineering experience or equivalent * Experience implementing or governing security baselines aligned to CIS Benchmarks * Strong understanding of OS security, network security, encryption, and secure configuration management * Strong stakeholder management with ability to influence senior leaders without direct authority * Experience building organizational consensus around security controls and implementation approaches * Deep expertise in security engineering, architecture, or baseline configuration management * Track record of driving measurable aa baselines improvements through process optimization and automation Key requirements * Health benefits * 401(k) Plan * Paid time off * Parental leave * Tuition reimbursement * Adoption reimbursement

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:16 min

Securing internal pod communication with network security policies

Marc Nimmerrichter · WWC 2022

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · WWC 2023

Videos

See all

Related articles

See all