Senior Lead Information Protection Security Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+4 more
Job description
- Provide oversight to the Information Security program for a major line of business
- Consult with line of business on the consistent implementation of the enterprise information security model and solutions to remediate information security risks
- Ensure that risks to all information assets are being managed in a timely and effective manner to meet the Information Security Program requirements and the current threat landscape
- Ensure information security capabilities are included in all aspects of the company’s technology architecture
- Proactively manage the information security risk profile of line of business information assets throughout the lifecycle of the asset
- Provide vision, direction, and expertise to more experienced leadership on implementing innovative and significant business solutions that are large-scale, cross-functional, or companywide strategies
- Ensure the team has the necessary training and is keeping abreast of regulatory and compliance issues
- Engage with all levels of professionals and managers companywide and serve as an experienced advisor to leadership
- Develop, implement, and maintain the enterprise cryptographic governance framework, including policies, standards, and procedures.
- Develop and maintain cryptographic policies, standards, and control requirements (e.g., encryption, key management, certificates), ensuring alignment with applicable regulatory and industry frameworks (e.g., NIST, PCI DSS, ISO 27001).
- Operate governance routines to ensure consistent application of cryptographic controls across the enterprise.
- Review and evaluation new or updated cryptographic new solutions.
- Lead governance forums, reporting, and escalation processes to senior leadership.
- Align governance activities with the enterprise cryptographic strategy, including roadmap initiatives and long-term objectives.
- Participate in periodic reviews of cryptographic strategy and data protection initiatives.
- Ensure governance supports enterprise priorities related to data protection, risk management, and security modernization.
- Establish and maintain visibility into cryptographic risks, including vulnerabilities and non-compliance.
- Define key metrics and reporting mechanisms to monitor cryptographic posture.
- Escalate issues related to non-adherence to cryptographic policy through established governance channels.
- Support the identification, prioritization, and tracking of risk remediation activities.
- Assist with exception management, ensuring appropriate documentation, risk acceptance, and tracking.
- Collaborate regularly with cross-functional stakeholders, including Cybersecurity Architecture, Secure Network Services (SNS), Cloud Security, and application teams, on solutions, strategies, and policies.
- Act as a central point of coordination for cryptographic governance activities.
- Provide guidance and direction to engineering and operational teams on governance expectations.
- Support internal and external audits by providing required documentation, control evidence, and governance artifacts.
- Participate in the evaluation of cryptographic discovery tools and capabilities.
- Develop program to cryptographic discovery tools, capabilities, reporting and metrics.
- Monitor enterprise cryptographic posture and identify risks through tool outputs.
- Demonstrate foundational AI literacy by effectively using approved AI tools to support everyday work
- Apply AI tools for activities such as research, summarization, drafting, analysis, and decision support
- Exercise sound judgment when interpreting and using AI-generated outputs
- Understand basic AI limitations and appropriate use cases within daily workflows
- Adhere to data privacy, security, and data-handling standards when using AI tools
- Use AI ethically and responsibly, in alignment with company policies and guidelines
Requirements
- 7+ years of Information Security Analysis experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education., * Deep expertise in Hardware Security Modules (HSMs), Public Key Infrastructure (PKI), key management, certificate services, encryption technologies, and enterprise cryptographic controls
- Strong experience developing, implementing, and governing enterprise cryptographic programs, including policies, standards, procedures, and control frameworks within highly regulated environments
- Demonstrated experience managing and improving certificate lifecycle management, cryptographic asset inventory, discovery, reporting, and remediation programs across large, complex organizations
- Advanced knowledge of security and regulatory frameworks including NIST Cryptographic Standards, NIST Cybersecurity Framework (CSF), PCI DSS, ISO 27001, FFIEC guidance, and financial services regulatory requirements
- Experience evaluating, planning, or implementing post-quantum cryptography (PQC) strategies, cryptographic modernization initiatives, and emerging encryption technologies
- Proven ability to author and enhance enterprise security policies, standards, governance artifacts, executive communications, and regulatory documentation while influencing senior leaders and cross-functional stakeholders
- Strong technical leadership experience partnering with cybersecurity architecture, engineering, infrastructure, cloud security, application development, legal, privacy, risk, and regulatory teams to drive enterprise-wide cryptographic governance and adoption
- Experience supporting cryptographic discovery tools, defining enterprise cryptographic metrics, monitoring cryptographic posture, and identifying risks associated with non-compliant cryptographic implementations
- Experience leading cryptographic governance, PKI, certificate management, or key management programs within a large-scale financial institution or highly regulated industry
Benefits & conditions
Wells Fargo provides eligible employees with a comprehensive set of benefits, many of which are listed below. Visit Benefits - Wells Fargo Jobs (https://www.wellsfargojobs.com/en/life-at-wells-fargo/benefits) for an overview of the following benefit plans and programs offered to employees.
- Health benefits
- 401(k) Plan
- Paid time off
- Disability benefits
- Life insurance, critical illness insurance, and accident insurance
- Parental leave
- Critical caregiving leave
- Discounts and savings
- Commuter benefits
- Tuition reimbursement
- Scholarships for dependent children
- Adoption reimbursement
Posting End Date:
10 Aug 2026
***** Job posting may come down early due to volume of applicants.
We Value Equal Opportunity
Wells Fargo is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other legally protected characteristic.
Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit’s risk appetite and all risk and compliance program requirements.
About the company
Wells Fargo maintains a drug free workplace. Please see our Drug and Alcohol Policy (https://www.wellsfargojobs.com/en/wells-fargo-drug-and-alcohol-policy) to learn more.
Wells Fargo Recruitment and Hiring Requirements:
a. Third-Party recordings are prohibited unless authorized by Wells Fargo.
b. Wells Fargo requires you to directly represent your own experiences during the recruiting and hiring process.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
What’s the Difference between a Junior, Mid, and Senior Developer?