> Markdown version of [/jobs/ext/3435050-senior-information-security-engineer](https://www.wearedevelopers.com/jobs/ext/3435050-senior-information-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Security Engineer - **Company:** Wells Fargo - **Location:** Irving, TX, United States - **Experience:** Expert - **Salary:** $100,000.0 - $179,000.0 - **Contract:** Permanent contract - **Skills:** Agile Methodology, Artificial Intelligence, JIRA, Cyber Security, Cursor, Github, Key Management, Open Web Application Security, Prism (Software), Systems Development Life Cycle, Software Engineering, Systems Integration, GitHub Copilot, Large Language Models, Software Security, Infrastructure as Code (IaC), Synopsys Black Duck, Checkmarx, Api Design, Devsecops, Qualys, Jenkins, Servicenow, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 13, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=5da9b1f5357998ba ## About the Role * 4+ years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education * Expertise across core Application Security domains SAST, DAST, SCA, Secrets management and detection, Infrastructure as Code (IaC) * Strong experience integrating SAST, DAST, and SCA tools into SDLC workflows and source code repositories * Advanced knowledge of GitHub, Jira, ServiceNow, Jenkins, Harness, and CI/CD ecosystems * Strong understanding of OWASP standards and MITRE CVE/CWE frameworks * Experience implementing and maturing Secure Software Development Lifecycle (SSDLC) practices across Agile and custom development frameworks * Familiarity with AI/LLM-enabled development tooling (e.g., Cursor, GitHub Copilot, custom LLM integrations), including auto-remediation capabilities using AI, and governance considerations Desired Qualifications: * 4 + years - Development experience in more than one language * 3 + years of using the IaC to configure, build, and deploy * 2+ years of DevSecOps / Automation experience * Hands-on experience with vendor tools Checkmarx, Blackduck, Prisma, Trufflehog, Synk, Socket, Invicti, Qualys * Proven experience with GitHub Advanced Security (GHAS), including secret scanning capabilities * Experience in API development and custom services ## Description * Design and implement repeatable, scalable, and automated AppSec processes * Provide hands-on technical leadership in tooling integration, automation, and process execution * Implement ongoing product (internal and vendor) enhancements and fine-tuning of rules to increase the precision in identifying and prioritizing application security defects. * Manage upgrades, resiliency, continuity, and compliance with enterprise standards. * Recommend mitigation strategies for identified application security risks * Serve as an AppSec representative in cross-functional governance and technical forums * Support integration of AppSec controls across enterprise tools and CI/CD pipelines * Support reporting of AppSec processes, execution status, and outcomes * Collaborate with control management and cybersecurity leadership to design new security controls * Support internal and external audits, regulatory reviews, and third-party assessments, * Demonstrate proficiency in using AI-assisted development and analysis tools (e.g., GitHub Copilot and approved code-centric agents) * Leverage AI to accelerate system design, coding, testing, analysis, and troubleshooting * Apply strong technical judgment when validating and integrating AI-assisted outputs into solutions * Understand and account for model limitations, security risks, and operational considerations * Apply AI responsibly in development and production environments * Ensure AI usage aligns with security, compliance, privacy, and ethical standards ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [GitOps for the people](https://www.wearedevelopers.com/videos/461-gitops-for-the-people) - [".Net is too slow" was not an option](https://www.wearedevelopers.com/videos/100176-net-is-too-slow-was-not-an-option) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)