Senior Information Security Engineer - Threat Disruptions
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+5 more
Job description
- Play a major role in phishing disruption efforts, including creation of new logic and procedures to identify phishing attacks impacting Wells Fargo customers and employees
- Lead or participate in computer security incident response activities for moderately complex events
- Conduct technical investigation of security related incidents and post incident digital forensics to identify causes and recommend future mitigation strategies
- Provide security consulting on projects for internal clients to ensure conformity with corporate information, security policy, and standards
- Design, document, test, maintain, and provide issue resolution recommendations for moderately complex security solutions related to networking, cryptography, cloud, authentication and directory services, email, internet, applications, and endpoint security
- Utilize subject matter knowledge in industry leading security solutions and best practices to implement one or more components of information security such as availability, integrity, confidentiality, risk management, threat identification, modeling, monitoring, incident response, access management, and business continuity
- Identify security vulnerabilities and issues, perform risk assessments, and evaluate remediation alternatives
- Collaborate and consult with peers, colleagues and managers to resolve issues and achieve goals, Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit’s risk appetite and all risk and compliance program requirements.
Requirements
Do you have experience in Splunk?, The ideal candidate should demonstrate strong hands-on proficiency with Splunk to effectively investigate and correlate logs related to email activity reported as phishing or spam. They should possess the necessary skills to thoroughly investigate incidents, respond appropriately, and follow up on various escalations. Have a solid foundation in core cyber security areas and exhibit strong problem-solving abilities and collaborate effectively to resolve complex issues in fast-paced environments. Starting off the primary responsibility will be phishing disruption efforts, including creation of new logic and procedures to identify phishing attacks impacting Wells Fargo customers and employees. However, responsibilities will expand as the individual learns the Wells Fargo environment., * 4+ years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
- 1+ year of splunk experience
Desired Qualifications:
- Advanced Information Security technical skills
- Experience detecting and mitigating phishing attacks directed towards employees and the company brand
- Experience creating regular expressions and YARA rules
- Ability to manage complex issues and develop solutions
- Experience in one or more of the following security disciplines: information security monitoring; incident response; vulnerability management; host/network forensics; cyber-crime investigations; Domain-based Message Authentication, Reporting and Conformance (DMARC); or cyber threat intelligence.
- Ability to execute in a fast paced, high demand, environment while balancing multiple priorities
- Certifications in one or more of the following: Global Information Assurance Certification (GIAC); Offensive Security Certified Professional (OSCP); or equivalent
- Hands-on experience with information security tools such as an enterprise SIEM solution, IDS/IPS, endpoint security solutions, email/web security gateways, and other security detection/mitigation devices
- Experience with host and/or network log analysis as applied to incident response / threat hunting
- Knowledge of offensive security, with the ability to think like an adversary when hunting and responding to incidents
- Strong experience in operating system and application security hardening and best practices
- Strong investigative mindset with an attention to detail
- Advanced problem solving skills, ability to develop effective long-term solutions to complex problems
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
Is Software Engineering Over-Saturated?
How Much FAANG Companies Actually Pay Software Engineers in 2025
Walking Into The Era of Supply Chain Risks