About the Role Wells Fargo is seeking a Lead Information Security Engineer for our Inbound Web Application Security (iWAS) team that safeguards the public edge for enterprise web assets—including wellsfargo.com - against sophisticated Layer‑7 (application-layer) attacks. The team leverages a modern, hybrid control plane spanning SaaS providers to protect critical web applications. You will design and operate Layer‑7 DDoS protections, implement and tune WAF policies and signatures, apply bot management/mitigation, and enforce API security and rate limiting to preserve availability, integrity, and performance. This role is hands-on and customer‑facing with partner application teams. You’ll work to provide security for apps, with a particular emphasis on minimizing false positives/negatives, applying virtual patches, and accelerating onboarding/offboarding for protected applications. What You’ll Do Lead incident response for moderately complex events affecting public web applications, with emphasis on Layer‑7 attack detection, triage, containment, and recovery. Provide security consulting to internal application stakeholders, ensuring conformance with enterprise security policies and standards. Design, document, test, and maintain security controls for web applications at the edge. Engineer, deploy, and tune WAF policies/signatures (e.g., cross‑site scripting, injection, protocol anomalies), bot detection/mitigation, API protection (rate limiting, schema/behavior enforcement), and Layer‑7 DDoS defenses. Implement and refine rate limiting for web and API endpoints to ensure resiliency, performance, and abuse prevention. Review and correlate security logs and telemetry across edge providers and on‑prem platforms; distinguish real attacks from false positives. Apply industry best practices in availability, integrity, confidentiality, risk management, threat modeling, monitoring, incident response, access management, and business continuity. Collaborate across security engineering, networking, application owners, and operations to resolve issues and achieve shared goals. Support application onboarding/offboarding to the SaaS providers, using knowledge of DNS, WAF, L7 DDoS, bot policies, and GLB/routing considerations.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Education Level
No Education Listed