Senior Information Security Engineer

Wells Fargo
Charlotte, United States of America
yesterday

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior

Job location

Charlotte, United States of America

Tech stack

Microsoft Windows
Agile Methodologies
Artificial Intelligence
Data analysis
Apple Mac Systems
Unix
Computer Security
Data Security
Digital Forensics
Identity and Access Management
Information Security Management
Intrusion Detection and Prevention
Intrusion Detection Systems
Log Analysis
Scrum
Regular Expressions
Security Information and Event Management
GitHub Copilot
Malware
Firewalls (Computer Science)
Web Filtering
Cybercrime
Performance Monitor

Job description

  • Lead or participate in computer security incident response activities for moderately complex events
  • Conduct technical investigation of security related incidents and post incident digital forensics to identify causes and recommend future mitigation strategies
  • Provide security consulting on medium projects for internal clients to ensure conformity with corporate information, security policy, and standards
  • Design, document, test, maintain, and provide issue resolution recommendations for moderately complex security solutions related to networking, cryptography, cloud, authentication and directory services, email, internet, applications, and endpoint security
  • Review and correlate security logs
  • Utilize subject matter knowledge in industry leading security solutions and best practices to implement one or more components of information security such as availability, integrity, confidentiality, risk management, threat identification, modeling, monitoring, incident response, access management, and business continuity
  • Identify security vulnerabilities and issues, perform risk assessments, and evaluate remediation alternatives
  • Collaborate and consult with peers, colleagues and managers to resolve issues and achieve goals
  • Create and build content based on identified security use cases
  • Effectively communicate observations and development deliverables to a wide audience
  • Provide security consulting on medium projects for internal clients to ensure conformity with corporate information, security policy, and standards
  • Design, document, test, maintain, and provide issue resolution recommendations for moderately complex security solutions related to networking, cryptography, cloud, authentication and directory services, email, internet, applications, and endpoint security
  • Review and correlate security logs
  • Utilize subject matter knowledge in industry leading security solutions and best practices to implement one or more components of information security such as availability, integrity, confidentiality, risk management, threat identification, modeling, monitoring, incident response, access management, and business continuity
  • Identify security vulnerabilities and issues, perform risk assessments, and evaluate remediation alternatives
  • Collaborate and consult with peers, colleagues and managers to resolve issues and achieve goals
  • Demonstrate proficiency in using AI-assisted development and analysis tools (e.g., GitHub Copilot and approved code-centric agents)
  • Leverage AI to accelerate system design, coding, testing, analysis, and troubleshooting
  • Apply strong technical judgment when validating and integrating AI-assisted outputs into solutions
  • Understand and account for model limitations, security risks, and operational considerations
  • Apply AI responsibly in development and production environments
  • Ensure AI usage aligns with security, compliance, privacy, and ethical standards, Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit's risk appetite and all risk and compliance program requirements.

Requirements

Wells Fargo is seeking a Senior Information Security Engineer with experience in identification, development, and prioritization of security events and automated content. The ideal candidate will have experience in the development lifecycle, identification of logged events to support security use case development and be able to research and use critical thinking to understand over the horizon detection capabilities through automated alerting.

The successful candidate will have a well-rounded understanding of on premises servers, network, endpoint and cloud detections among other, broad range technologies. The successful candidate will also be able to effectively convey observations and development deliverables to a wide audience., * 4+ years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education

  • 1+ years of Regular Expression (regex) experience
  • 2+ years of SIEM development experience

Desired Qualifications:

  • Experience working in a security operations center
  • Advanced Information Security technical skills and understanding of information security practices and policies
  • Understanding of Agile practices
  • Experience working on a Scrum team
  • Ability to manage complex issues and develop solutions
  • Ability to execute in a fast paced, high demand, environment while balancing multiple priorities
  • Knowledge and understanding of data security controls including malware protection, firewalls, intrusion detection systems, content filtering, Internet proxies, encryption controls, and log management solutions
  • Experience analyzing large data sets
  • Experience with host and/or network log analysis as applied to incident response / threat hunting
  • Knowledge of offensive security, with the ability to think like an adversary when hunting and responding to incidents
  • Strong investigative mindset with an attention to detail
  • Experience with multiple operating systems to include Windows, Mac OS, and Unix/Linux

About the company

Wells Fargo maintains a drug free workplace. Please see our Drug and Alcohol Policy (https://www.wellsfargojobs.com/en/wells-fargo-drug-and-alcohol-policy) to learn more. Wells Fargo Recruitment and Hiring Requirements: a. Third-Party recordings are prohibited unless authorized by Wells Fargo. b. Wells Fargo requires you to directly represent your own experiences during the recruiting and hiring process.

Apply for this position