> Markdown version of [/jobs/ext/2660757-lead-information-security-engineer](https://www.wearedevelopers.com/jobs/ext/2660757-lead-information-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Information Security Engineer - **Company:** Wells Fargo - **Location:** Chandler, AZ, United States - **Experience:** Expert - **Salary:** $119,000.0 - $206,000.0 - **Contract:** Permanent contract - **Skills:** Agile Methodology, Artificial Intelligence, JIRA, Cyber Security, Cursor (Graphical User Interface Elements), Github, Key Management, Open Web Application Security, Prism (Software), Systems Development Life Cycle, Software Engineering, Systems Integration, GitHub Copilot, Large Language Models, Software Security, Infrastructure as Code (IaC), Synopsys Black Duck, Checkmarx, Api Design, Devsecops, Qualys, Jenkins, Servicenow, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=8dec3e75992d66f1 ## About the Role * 5+ years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education * Deep expertise across core Application Security domains SAST, DAST, SCA, Secrets management and detection, Infrastructure as Code (IaC) * Strong experience integrating SAST, DAST, and SCA tools into SDLC workflows and source code repositories * Proven experience evaluating and managing multiple AppSec tooling vendors * Advanced knowledge of GitHub, Jira, ServiceNow, Jenkins, Harness, and CI/CD ecosystems * Strong understanding of OWASP standards and MITRE CVE/CWE frameworks * Experience implementing and maturing Secure Software Development Lifecycle (SSDLC) practices across Agile and custom development frameworks * Familiarity with AI/LLM-enabled development tooling (e.g., Cursor, GitHub Copilot, custom LLM integrations), including auto-remediation capabilities using AI, and governance considerations * Demonstrated ability to lead cross-functional initiatives, drive workflow integration, and prioritize enterprise-level initiatives * Strong leadership skills with the ability to foster a collaborative, high-performance team culture grounded in continuous learning and improvement * Excellent written, verbal, and executive-level presentation skills * Proven leadership in highly regulated environments with strong project and program management capabilities Desired Qualifications: * 5 + years - Development experience in more than one language * 3 + years of using the IaC to configure, build, and deploy * 2+ years of DevSecOps / Automation experience * Relevant industry certifications such as CISM, CISSP, CSSLP, or equivalent * Hands-on experience with vendor tools Checkmarx, Blackduck, Prisma, Trufflehog, GHAS, Synk, Socket, Invicti, Qualys * Experience in API development and custom services ## Description * Strengthen integration of AppSec controls across enterprise tools and CI/CD pipelines * Improve workflow alignment between Security Architecture and Application Security functions * Design and implement repeatable, scalable, and automated AppSec processes * Drive prioritization frameworks aligned with enterprise risk and business objectives * Enhance transparency and reporting of AppSec processes, execution status, and outcomes * Provide hands-on technical leadership in tooling integration, automation, and process execution * Lead implementation of shift-left security strategies while maintaining strong developer experience within Wells Fargo's internal tooling ecosystem * Recommend mitigation strategies for identified application security risks * Serve as an AppSec representative in cross-functional governance and technical forums * Partner with AppSec governance teams to support control development, validation, and testing * Collaborate with control management and cybersecurity leadership to design new security controls * Support internal and external audits, regulatory reviews, and third-party assessments * Implement ongoing product (internal and vendor) enhancements and fine-tuning of rules to increase the precision in identifying and prioritizing application security defects. * Manage upgrades, resiliency, continuity, and compliance with enterprise standards. * Lead a team to achieve objectives, * Demonstrate proficiency in using AI-assisted development and analysis tools (e.g., GitHub Copilot and approved code-centric agents) * Leverage AI to accelerate system design, coding, testing, analysis, and troubleshooting * Apply strong technical judgment when validating and integrating AI-assisted outputs into solutions * Understand and account for model limitations, security risks, and operational considerations * Apply AI responsibly in development and production environments * Ensure AI usage aligns with security, compliance, privacy, and ethical standards ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)