Wells FargoVerified Source

Lead Information Security Engineer, AppSec

119K–187K
Partially · Dallas, Texas
Posted August 12, 2026
payroll

Overview

As a Lead Information Security Engineer on the Application Security Team, you will own the integration of AppSec controls across enterprise tools and CI/CD pipelines at Wells Fargo. You will design and implement automated, repeatable AppSec processes, drive shift-left security strategies, and enhance reporting for executive visibility. Collaborating with Security Architecture, governance, and control management, you will influence enterprise risk decisions and mentor a team of security engineers. This role offers a chance to shape AppSec at scale in a highly regulated financial environment, with a focus on AI/LLM-enabled tooling and modern DevSecOps practices.

What You'll Do10

  • 1Integrate SAST, DAST, and SCA controls into GitHub, Jenkins, Harness, and other CI/CD platforms within the first 90 days.
  • 2Design and implement automated AppSec workflows that reduce manual effort and improve defect detection precision across the enterprise.
  • 3Lead the adoption of shift-left security practices, embedding AppSec checks early in the developer workflow while maintaining a strong developer experience.
  • 4Drive the prioritization of application security risks using frameworks aligned with enterprise risk appetite and business objectives.
  • 5Provide hands-on technical leadership in tooling integration, automation, and process execution, including vendor tool management (Checkmarx, Blackduck, Prisma, Trufflehog, GHAS, Snyk, Socket, Invicti, Qualys).
  • 6Enhance transparency and reporting of AppSec processes, execution status, and outcomes to senior leadership and governance forums.
  • 7Collaborate with AppSec governance teams to develop, validate, and test security controls, and support internal and external audits and regulatory reviews.
  • 8Manage upgrades, resiliency, continuity, and compliance for AppSec tools, ensuring alignment with enterprise standards.
  • 9Mentor and lead a team of security engineers, fostering a culture of continuous learning and high performance.
  • 10Apply AI/LLM-assisted development tools (e.g., GitHub Copilot) to accelerate analysis, testing, and troubleshooting while ensuring responsible use.

Requirements15

  • 15+ years of Information Security Engineering experience, or equivalent demonstrated through work experience, training, military experience, or education.
  • 2Deep expertise in core AppSec domains: SAST, DAST, SCA, secrets management and detection, and Infrastructure as Code (IaC).
  • 3Proven experience integrating SAST, DAST, and SCA tools into SDLC workflows and source code repositories.
  • 4Advanced knowledge of GitHub, Jira, ServiceNow, Jenkins, Harness, and CI/CD ecosystems.
  • 5Strong understanding of OWASP standards and MITRE CVE/CWE frameworks.
  • 6Experience implementing and maturing SSDLC practices across Agile and custom development frameworks.
  • 7Familiarity with AI/LLM-enabled development tooling (e.g., Cursor, GitHub Copilot, custom LLM integrations), including auto-remediation and governance considerations.
  • 8Demonstrated ability to lead cross-functional initiatives, drive workflow integration, and prioritize enterprise-level initiatives.
  • 9Strong leadership skills and the ability to foster a collaborative, high-performance team culture.
  • 105+ years of development experience in more than one language (preferred).
  • 113+ years using IaC to configure, build, and deploy (preferred).
  • 122+ years of DevSecOps or automation experience (preferred).
  • 13Relevant industry certifications such as CISM, CISSP, CSSLP, or equivalent (preferred).
  • 14Hands-on experience with vendor tools: Checkmarx, Blackduck, Prisma, Trufflehog, GHAS, Snyk, Socket, Invicti, Qualys (preferred).
  • 15Experience in API development and custom services (preferred).

Salary Insight

$119 - $187k per year

Location

Typepartially
LocationDallas, Texas

Required Skills

SASTDASTSCASecrets ManagementInfrastructure as CodeGitHubJiraServiceNowJenkinsHarnessCI/CD
Share:

Similar open positions

Explore active roles that match your skills and interests.

Wells Fargo

Wells Fargo

23h agoCharlotte, North Carolinapayroll

Senior Information Security Engineer, AppSec & CI/CD

You will own application security engineering for Wells Fargo's enterprise portfolio, designing and automating AppSec processes across SAST, DAST, SCA, and IaC. You will drive technical leadership in tooling integration and rule tuning to boost defect detection precision. Collaborate with cross-functional teams to embed security controls into GitHub, Jenkins, and Harness pipelines. This role stands out for its focus on AI-assisted development security and governance.

100K–179K
SASTDASTSCA+5 more
Wells Fargo

Wells Fargo

1d agoCharlotte, North Carolinapayroll

Lead Information Security Engineer Wells Fargo

We seek a Lead Information Security Engineer to strengthen integration of AppSec controls across enterprise tools and CI/CD pipelines. You will improve workflow alignment between Security Architecture and Application Security functions. This role drives design and implementation of repeatable scalable automated AppSec processes. You will prioritize frameworks aligned with enterprise risk and business objectives. Transparency and reporting of AppSec processes will be enhanced. Technical leadership in tooling integration automation and process execution is required. Shift-left security strategies will be led while maintaining strong developer experience. Mitigation strategies for application security risks will be provided. Cross-functional governance participation is expected. Collaboration with control management and cybersecurity leadership is essential. Internal and external audit support is needed. Product enhancements and rule fine-tuning for defect identification are managed. Upgrades resilience continuity and compliance with enterprise standards are overseen. A team will be led to achieve objectives.

119K–206K
Application SecuritySASTDAST+6 more
Wells Fargo

Wells Fargo

5d agoPhoenix, Arizonapayroll

Lead Information Security Engineer at Wells Fargo

We seek a Lead Information Security Engineer to lead technical strategy for our Security Baseline Configuration program. The role drives automation and standardization across multiple organizations to enhance security posture. This position influences stakeholders without direct authority and defines baseline standards aligned with CIS Benchmarks. It creates scalable solutions while differentiating through deep expertise in security engineering and automation.

119K–206K
Information Security EngineeringCIS BenchmarksOperating System Security+9 more
Wells Fargo

Wells Fargo

23h agoColumbus, Ohiopayroll

Principal Engineer, Secure Network Services

This role owns the strategy, architecture, and delivery of secure network solutions across Wells Fargo data centers and Secure Network Interconnect sites. You will lead end-to-end lifecycle ownership from planning through integration of next-generation secure network technologies. As a Principal Engineer, you will influence senior stakeholders and mentor engineers to elevate technical depth and operational maturity. This position drives measurable improvements in network reliability and service resilience at enterprise scale.

159K–305K
pythonansibleterraform+2 more
Wells Fargo

Wells Fargo

21d agoDallas, Texaspayroll

Senior Lead Digital Product Owner Cybersecurity Information Protection

Wells Fargo seeks a Senior Lead Digital Product Owner focused on cybersecurity information protection reporting to the Cybersecurity Governance Product Management Director. The role drives end-to-end delivery for unstructured scanning and governance across on-prem cloud SaaS and M365 environments. You will translate strategic direction into measurable outcomes while coordinating cross-functional teams and stakeholders.

159K–279K
pythonawsreact+2 more
Innova Solutions, Inc

Innova Solutions, Inc

23h agoCharlotte, North Carolinacontract

Lead Application Security Engineer AI

As a Lead Application Security Engineer, you will own the application security strategy for DCMS in-scope applications, defining tier-based control models that scale across the portfolio. You will evaluate existing AppSec control coverage, establish baseline mappings, and drive remediation of critical gaps. Reporting to the security leadership, you will collaborate with engineering teams to embed security into the SDLC, focusing on cloud-native environments and AI applications. This role offers the chance to shape security posture for a major financial client, with a 12+ month contract and hybrid work in Charlotte, NC.

Competitive salary
Application SecurityAI