Technology Director - BISO

Wells Fargo
Charlotte, NC, United States
14 days ago
Apply on www.juju.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Cyber Security Decision Support Systems Identity and Access Management Software Vulnerability Management Software Security Cybercrime Performance Monitor Data Management

Job description

Wells Fargo is seeking a Business Information Security Officer (BISO). The BISO is the senior cybersecurity leader accountable for aligning cyber risk outcomes to the objectives, priorities, and risk appetite of an assigned Line of Business (LOB).

The successful candidate will partner across business, technology, risk, compliance, audit, and cybersecurity functions to translate complex security issues into business decisions, drive remediation of priority risks, and provide clear executive visibility into the LOB’s cyber posture.

Key Responsibilities

Cyber Risk Leadership

  • Own the cybersecurity risk posture for the assigned business unit, including risk identification, prioritization, mitigation planning, and ongoing control effectiveness.

  • Partner with business and technology leaders to translate cyber threats, vulnerabilities, and control gaps into actionable business risk decisions.

  • Monitor emerging threats and material risk trends to proactively inform risk acceptance, remediation, and investment priorities.

Strategic Business Partnership

  • Serve as the trusted cybersecurity advisor to executive leadership by framing risk tradeoffs, business impacts, and recommended actions.

  • Embed security guidance into business initiatives, digital transformation efforts, and strategic programs without slowing delivery.

  • Align cybersecurity priorities with LOB objectives, enterprise standards, and defined risk appetite.

Governance and Executive Reporting

  • Lead concise executive reporting for governance forums, risk committees, and senior leadership decision-making.

  • Present risk trends, control effectiveness, remediation progress, and emerging threats through clear dashboards, scorecards, and briefings.

  • Represent cybersecurity priorities in governance forums and drive accountability for timely risk decisions.

Regulatory and Compliance Oversight

  • Partner with Risk, Compliance, Audit, and Regulatory Relations teams to address cybersecurity requirements.

  • Support internal and external audits, examinations, and regulatory reviews.

  • Ensure alignment with enterprise policies, standards, risk frameworks, and regulatory obligations.

  • Facilitate issue management and remediation activities.

Stakeholder Engagement

  • Build relationships across business units, CIO organizations, risk teams, and cybersecurity domains.

  • Coordinate with security architecture, application security, vulnerability management, identity and access management, and other cyber teams.

  • Act as an escalation point for significant cyber risks and security concerns.

  • Drive accountability and ownership for security outcomes across business stakeholders.

Artificial Intelligence

  • Demonstrate foundational AI literacy by effectively using approved AI tools to support everyday work

  • Apply AI tools for activities such as research, summarization, drafting, analysis, and decision support

  • Exercise sound judgment when interpreting and using AI-generated outputs

  • Understand basic AI limitations and appropriate use cases within daily workflows

  • Adhere to data privacy, security, and data-handling standards when using AI tools

  • Use AI ethically and responsibly, in alignment with company policies and guidelines

Success Measures

During the first 12 months, the BISO will be expected to:

  • Establish trusted advisor relationships with key business and technology executives.

  • Develop and maintain a comprehensive cyber risk profile for the assigned business.

  • Improve visibility of cyber risk through executive reporting and governance., Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit’s risk appetite and all risk and compliance program requirements.

Requirements

  • 10+ years of Technology Strategic Leadership experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education

  • 10+ years of cybersecurity, technology risk, or information security experience, including significant leadership responsibility

  • 4+ years of management or leadership experience

  • 3+ years in a senior security leadership role such as BISO, CISO, Deputy CISO, or equivalent.

Desired Qualifications:

  • Demonstrated ability to influence without direct authority and lead cross-functional initiatives in a complex, matrixed environment.

  • Exceptional executive communication skills, including the ability to translate complex technical issues into business language for C-level executives, regulators, and senior stakeholders.

  • Strong comfort operating through ambiguity, quantifying risk concepts, brokering agreement across competing priorities, and managing multiple stakeholder demands.

  • Financial services cybersecurity experience or comparable experience in another highly regulated industry such as utilities, health care, or government.

  • Deep knowledge of cybersecurity frameworks, technology risk management, regulatory requirements, security governance, incident response, and threat management

  • Industry certifications such as: CISSP, CISM, CRISC, CISA, CGEIT

  • Experience supporting regulatory examinations

  • Experience working with enterprise risk management frameworks

  • Experience developing executive cybersecurity reporting and metrics

Job Expectations:

  • Ability to work outside of normal business hours as needed

  • Ability to travel up to 10% of the time

About the company

Wells Fargo maintains a drug free workplace. Please see our Drug and Alcohol Policy (https://www.wellsfargojobs.com/en/wells-fargo-drug-and-alcohol-policy) to learn more.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:43 min

Data management for stateful cloud-native workloads

Michael Cade · World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

5:39 min

Transitioning from technical engineering into corporate project leadership

Peter Busch · LIVE

Videos

See all

Related articles

See all