Senior Information Security Engineer

Wells FargoCharlotte, NC
$110,000 - $179,000Hybrid

About The Position

Wells Fargo is seeking a Senior Information Security Engineer to join their Application Security Team. In this role, the engineer will be responsible for designing and implementing scalable and automated AppSec processes, providing technical leadership in tooling integration and automation, and enhancing product security by fine-tuning rules to identify and prioritize application security defects. The position also involves managing upgrades, ensuring resiliency and continuity, and maintaining compliance with enterprise standards. The engineer will recommend mitigation strategies for identified risks, represent AppSec in cross-functional forums, and support the integration of AppSec controls across enterprise tools and CI/CD pipelines. Additionally, they will support reporting of AppSec processes and outcomes, collaborate on designing new security controls, and assist with internal and external audits and assessments.

Requirements

  • 4+ years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
  • Expertise across core Application Security domains SAST, DAST, SCA, Secrets management and detection, Infrastructure as Code (IaC)
  • Strong experience integrating SAST, DAST, and SCA tools into SDLC workflows and source code repositories
  • Advanced knowledge of GitHub, Jira, ServiceNow, Jenkins, Harness, and CI/CD ecosystems
  • Strong understanding of OWASP standards and MITRE CVE/CWE frameworks
  • Experience implementing and maturing Secure Software Development Lifecycle (SSDLC) practices across Agile and custom development frameworks
  • Familiarity with AI/LLM-enabled development tooling (e.g., Cursor, GitHub Copilot, custom LLM integrations), including auto-remediation capabilities using AI, and governance considerations

Nice To Haves

  • 4 + years – Development experience in more than one language
  • 3 + years of using the IaC to configure, build, and deploy
  • 2+ years of DevSecOps / Automation experience
  • Hands-on experience with vendor tools Checkmarx, Blackduck, Prisma, Trufflehog, Synk, Socket, Invicti, Qualys
  • Proven experience with GitHub Advanced Security (GHAS), including secret scanning capabilities
  • Experience in API development and custom services

Responsibilities

  • Design and implement repeatable, scalable, and automated AppSec processes
  • Provide hands-on technical leadership in tooling integration, automation, and process execution
  • Implement ongoing product (internal and vendor) enhancements and fine-tuning of rules to increase the precision in identifying and prioritizing application security defects
  • Manage upgrades, resiliency, continuity, and compliance with enterprise standards
  • Recommend mitigation strategies for identified application security risks
  • Serve as an AppSec representative in cross-functional governance and technical forums
  • Support integration of AppSec controls across enterprise tools and CI/CD pipelines
  • Support reporting of AppSec processes, execution status, and outcomes
  • Collaborate with control management and cybersecurity leadership to design new security controls
  • Support internal and external audits, regulatory reviews, and third-party assessments

Benefits

  • Equal opportunity employer status
  • Consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other legally protected characteristic.
  • Support for building strong customer relationships
  • Focus on risk mitigating and compliance-driven culture
  • Accountability for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance)
  • Adherence to Wells Fargo policies and procedures
  • Fulfillment of risk and compliance obligations
  • Timely and effective escalation and remediation of issues
  • Sound risk decision-making
  • Emphasis on proactive monitoring, governance, risk identification and escalation
  • Accommodation for applicants with disabilities is available upon request in connection with the recruitment process.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service