Senior Information Security Engineer
Wells Fargo Charlotte, North Carolina, United States · $100K–$179K/yr
Financial Services · 10,001+ employees
About the role
The Senior Information Security Engineer will design and implement automated application security processes while providing technical leadership in tooling integration and risk mitigation. They will also collaborate with cross-functional teams to ensure compliance with enterprise standards and support the integration of security controls across CI/CD pipelines.
What they look for
Requirements
Candidates must have at least 4 years of information security engineering experience with expertise in core application security domains like SAST, DAST, and SCA. Proficiency in CI/CD ecosystems, OWASP standards, and AI-enabled development tooling is required to effectively manage security risks and development workflows.
Full description
About this role:
Wells Fargo is seeking a Senior Information Security Engineer to join our Application Security Team.
In this role, you will:
- Design and implement repeatable, scalable, and automated AppSec processes
- Provide hands-on technical leadership in tooling integration, automation, and process execution
- Implement ongoing product (internal and vendor) enhancements and fine-tuning of rules to increase the precision in identifying and prioritizing application security defects.
- Manage upgrades, resiliency, continuity, and compliance with enterprise standards.
- Recommend mitigation strategies for identified application security risks
- Serve as an AppSec representative in cross-functional governance and technical forums
- Support integration of AppSec controls across enterprise tools and CI/CD pipelines
- Support reporting of AppSec processes, execution status, and outcomes
- Collaborate with control management and cybersecurity leadership to design new security controls
- Support internal and external audits, regulatory reviews, and third-party assessments
Required Qualifications:
- 4+ years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
- Expertise across core Application Security domains SAST, DAST, SCA, Secrets management and detection, Infrastructure as Code (IaC)
- Strong experience integrating SAST, DAST, and SCA tools into SDLC workflows and source code repositories
- Advanced knowledge of GitHub, Jira, ServiceNow, Jenkins, Harness, and CI/CD ecosystems
- Strong understanding of OWASP standards and MITRE CVE/CWE frameworks
- Experience implementing and maturing Secure Software Development Lifecycle (SSDLC) practices across Agile and custom development frameworks
- Familiarity with AI/LLM-enabled development tooling (e.g., Cursor, GitHub Copilot, custom LLM integrations), including auto-remediation capabilities using AI, and governance considerations
Desired Qualifications:
- 4 + years – Development experience in more than one language
- 3 + years of using the IaC to configure, build, and deploy
- 2+ years of DevSecOps / Automation experience
- Hands-on experience with vendor tools Checkmarx, Blackduck, Prisma, Trufflehog, Synk, Socket, Invicti, Qualys
- Proven experience with GitHub Advanced Security (GHAS), including secret scanning capabilities
- Experience in API development and custom services
Job Expectations:
- This position offers a hybrid work schedule
- This position is not eligible for Visa sponsorship
- Demonstrate proficiency in using AI‑assisted development and analysis tools (e.g., GitHub Copilot and approved code‑centric agents)
- Leverage AI to accelerate system design, coding, testing, analysis, and troubleshooting
- Apply strong technical judgment when validating and integrating AI‑assisted outputs into solutions
- Understand and account for model limitations, security risks, and operational considerations
- Apply AI responsibly in development and production environments
- Ensure AI usage aligns with security, compliance, privacy, and ethical standards
Salary Ranges:
- $100,000 - $163,000 - Charlotte, NC
- $100,000 - $163,000 - Chandler, AZ
- $100,000 - $163,000- Irving, TX
- $110,000 - $179,000 - Minneapolis, MN
Posting End Date:
10 Sep 2026*Job posting may come down early due to volume of applicants.
We Value Equal Opportunity
Wells Fargo is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other legally protected characteristic.
Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit’s risk appetite and all risk and compliance program requirements.
Candidates applying to job openings posted in Canada: Applications for employment are encouraged from all qualified candidates, including women, persons with disabilities, aboriginal peoples and visible minorities. Accommodation for applicants with disabilities is available upon request in connection with the recruitment process.
Applicants with Disabilities
To request a medical accommodation during the application or interview process, visit Disability Inclusion at Wells Fargo.
Drug and Alcohol Policy
Wells Fargo maintains a drug free workplace. Please see our Drug and Alcohol Policy to learn more.
Wells Fargo Recruitment and Hiring Requirements:
a. Third-Party recordings are prohibited unless authorized by Wells Fargo.
b. Wells Fargo requires you to directly represent your own experiences during the recruiting and hiring process.
Similar roles
-
Cybersecurity Specialist
QBE LLC (Federal) Loudoun County, Virginia, United States · $95K–$135K/yr
-
DevSecOps Security Engineer
Ford Motor Company Chennai, Tamil Nadu, India
-
Application Security Engineer
Moniepoint Nigeria
-
Cloud Security Engineer II
Tripadvisor Needham, Massachusetts, United States · $135K–$155K/yr
-
Cybersecurity Professional CROWS 7.48
Credence Bath Township, Ohio, United States
-
Senior DevOps/FinOps Engineer (Cybersecurity Platform)
Sigma Software Tiranë, Central Albania, Albania