Senior Information Security Engineer, AppSec & CI/CD
Overview
You will own application security engineering for Wells Fargo's enterprise portfolio, designing and automating AppSec processes across SAST, DAST, SCA, and IaC. You will drive technical leadership in tooling integration and rule tuning to boost defect detection precision. Collaborate with cross-functional teams to embed security controls into GitHub, Jenkins, and Harness pipelines. This role stands out for its focus on AI-assisted development security and governance.
What You'll Do8
- 1Design and implement repeatable, scalable, and automated AppSec processes for the enterprise.
- 2Lead hands-on integration of SAST, DAST, and SCA tools into CI/CD pipelines and source code repositories.
- 3Fine-tune internal and vendor product rules to increase precision in identifying and prioritizing application security defects.
- 4Manage upgrades, resiliency, continuity, and compliance with enterprise standards for AppSec tooling.
- 5Recommend mitigation strategies for identified application security risks and communicate them to stakeholders.
- 6Represent AppSec in cross-functional governance and technical forums, aligning with control management and cybersecurity leadership.
- 7Support integration of AppSec controls across enterprise tools and CI/CD pipelines, including GitHub and Jenkins.
- 8Drive reporting of AppSec process execution status and outcomes, supporting audits and regulatory reviews.
Requirements10
- 14+ years of Information Security Engineering experience, or equivalent demonstrated through work, training, military, or education.
- 2Expertise across core Application Security domains: SAST, DAST, SCA, secrets management and detection, and Infrastructure as Code (IaC).
- 3Strong experience integrating SAST, DAST, and SCA tools into SDLC workflows and source code repositories.
- 4Advanced knowledge of GitHub, Jira, ServiceNow, Jenkins, Harness, and CI/CD ecosystems.
- 5Strong understanding of OWASP standards and MITRE CVE/CWE frameworks.
- 6Experience implementing and maturing Secure Software Development Lifecycle (SSDLC) practices across Agile and custom frameworks.
- 7Familiarity with AI/LLM-enabled development tooling (e.g., Cursor, GitHub Copilot, custom LLM integrations), including auto-remediation capabilities and governance considerations.
- 8Desired: 4+ years of development experience in more than one language; 3+ years using IaC to configure, build, and deploy; 2+ years of DevSecOps or automation experience.
- 9Hands-on experience with vendor tools: Checkmarx, Blackduck, Prisma, Trufflehog, Synk, Socket, Invicti, Qualys.
- 10Proven experience with GitHub Advanced Security (GHAS), including secret scanning capabilities.
Salary Insight
$100 - $179k per year
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.
Wells Fargo
VerifiedLead Information Security Engineer, AppSec
As a Lead Information Security Engineer on the Application Security Team, you will own the integration of AppSec controls across enterprise tools and CI/CD pipelines at Wells Fargo. You will design and implement automated, repeatable AppSec processes, drive shift-left security strategies, and enhance reporting for executive visibility. Collaborating with Security Architecture, governance, and control management, you will influence enterprise risk decisions and mentor a team of security engineers. This role offers a chance to shape AppSec at scale in a highly regulated financial environment, with a focus on AI/LLM-enabled tooling and modern DevSecOps practices.
Wells Fargo
VerifiedLead Information Security Engineer Wells Fargo
We seek a Lead Information Security Engineer to strengthen integration of AppSec controls across enterprise tools and CI/CD pipelines. You will improve workflow alignment between Security Architecture and Application Security functions. This role drives design and implementation of repeatable scalable automated AppSec processes. You will prioritize frameworks aligned with enterprise risk and business objectives. Transparency and reporting of AppSec processes will be enhanced. Technical leadership in tooling integration automation and process execution is required. Shift-left security strategies will be led while maintaining strong developer experience. Mitigation strategies for application security risks will be provided. Cross-functional governance participation is expected. Collaboration with control management and cybersecurity leadership is essential. Internal and external audit support is needed. Product enhancements and rule fine-tuning for defect identification are managed. Upgrades resilience continuity and compliance with enterprise standards are overseen. A team will be led to achieve objectives.
Wells Fargo
VerifiedLead Information Security Engineer at Wells Fargo
We seek a Lead Information Security Engineer to lead technical strategy for our Security Baseline Configuration program. The role drives automation and standardization across multiple organizations to enhance security posture. This position influences stakeholders without direct authority and defines baseline standards aligned with CIS Benchmarks. It creates scalable solutions while differentiating through deep expertise in security engineering and automation.

Motion Recruitment Partners, LLC
VerifiedPrincipal Application Security Engineer
You will own application security for a major financial services firm with over 150 years of market presence, hardening Java and .NET applications across a global portfolio. You will lead security reviews, threat modeling, and code analysis while partnering with DevOps to embed security into CI/CD pipelines. This hybrid role in Charlotte, NC offers direct impact on high-velocity releases and access to cutting-edge cloud infrastructure.
Wells Fargo
VerifiedSenior Lead Digital Product Owner Cybersecurity Information Protection
Wells Fargo seeks a Senior Lead Digital Product Owner focused on cybersecurity information protection reporting to the Cybersecurity Governance Product Management Director. The role drives end-to-end delivery for unstructured scanning and governance across on-prem cloud SaaS and M365 environments. You will translate strategic direction into measurable outcomes while coordinating cross-functional teams and stakeholders.
Wells Fargo
VerifiedPrincipal Engineer, Secure Network Services
This role owns the strategy, architecture, and delivery of secure network solutions across Wells Fargo data centers and Secure Network Interconnect sites. You will lead end-to-end lifecycle ownership from planning through integration of next-generation secure network technologies. As a Principal Engineer, you will influence senior stakeholders and mentor engineers to elevate technical depth and operational maturity. This position drives measurable improvements in network reliability and service resilience at enterprise scale.