Senior Information Security Engineer

Wells Fargo BankCharlotte, NC
Hybrid

About The Position

Wells Fargo is seeking a Senior Information Security Engineer to join our Application Security Team. In this role, you will: Design and implement repeatable, scalable, and automated AppSec processes. Provide hands-on technical leadership in tooling integration, automation, and process execution. Implement ongoing product (internal and vendor) enhancements and fine-tuning of rules to increase the precision in identifying and prioritizing application security defects. Manage upgrades, resiliency, continuity, and compliance with enterprise standards. Recommend mitigation strategies for identified application security risks. Serve as an AppSec representative in cross-functional governance and technical forums. Support integration of AppSec controls across enterprise tools and CI/CD pipelines. Support reporting of AppSec processes, execution status, and outcomes. Collaborate with control management and cybersecurity leadership to design new security controls. Support internal and external audits, regulatory reviews, and third-party assessments.

Requirements

  • 4+ years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
  • Expertise across core Application Security domains SAST, DAST, SCA, Secrets management and detection, Infrastructure as Code (IaC)
  • Strong experience integrating SAST, DAST, and SCA tools into SDLC workflows and source code repositories
  • Advanced knowledge of GitHub, Jira, ServiceNow, Jenkins, Harness, and CI/CD ecosystems
  • Strong understanding of OWASP standards and MITRE CVE/CWE frameworks
  • Experience implementing and maturing Secure Software Development Lifecycle (SSDLC) practices across Agile and custom development frameworks
  • Familiarity with AI/LLM-enabled development tooling (e.g., Cursor, GitHub Copilot, custom LLM integrations), including auto-remediation capabilities using AI, and governance considerations

Nice To Haves

  • 4 + years – Development experience in more than one language
  • 3 + years of using the IaC to configure, build, and deploy
  • 2+ years of DevSecOps / Automation experience
  • Hands-on experience with vendor tools Checkmarx, Blackduck, Prisma, Trufflehog, Synk, Socket, Invicti, Qualys
  • Proven experience with GitHub Advanced Security (GHAS), including secret scanning capabilities
  • Experience in API development and custom services

Responsibilities

  • Design and implement repeatable, scalable, and automated AppSec processes
  • Provide hands-on technical leadership in tooling integration, automation, and process execution
  • Implement ongoing product (internal and vendor) enhancements and fine-tuning of rules to increase the precision in identifying and prioritizing application security defects
  • Manage upgrades, resiliency, continuity, and compliance with enterprise standards
  • Recommend mitigation strategies for identified application security risks
  • Serve as an AppSec representative in cross-functional governance and technical forums
  • Support integration of AppSec controls across enterprise tools and CI/CD pipelines
  • Support reporting of AppSec processes, execution status, and outcomes
  • Collaborate with control management and cybersecurity leadership to design new security controls
  • Support internal and external audits, regulatory reviews, and third-party assessments

Benefits

  • Wells Fargo is an equal opportunity employer.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service