31 Jul
|
Wells Fargo
|
Karnataka
31 Jul
Wells Fargo
Karnataka
Job Summary
About this role: Wells Fargo is seeking a Senior Information Security Engineer.
Responsibilities
- Lead or participate in computer security incident response activities for moderately complex events
- Conduct technical investigation of security related incidents and post incident digital forensics to identify causes and recommend future mitigation strategies
- Provide security consulting on medium projects for internal clients to ensure conformity with corporate information, security policy, and standards
- Design, document, test, maintain, and provide issue resolution recommendations for moderately complex security solutions related to networking, cryptography, cloud, authentication and directory services, email, internet, applications, and endpoint security
- Review and correlate security logs
- Utilize subject matter knowledge in industry leading security solutions and best practices to implement one or more components of information security such as availability, integrity, confidentiality, risk management, threat identification, modeling, monitoring, incident response, access management, and business continuity
- Identify security vulnerabilities and issues, perform risk assessments, and evaluate remediation alternatives
- Collaborate and consult with peers, colleagues and managers to resolve issues and achieve goals
Required Qualifications
- 4+ years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
Desired Qualifications
- 4+ years of Information Security Analysis experience.
- 4+ years of overall Information/Cyber Security experience.
- 2+ years of hands-on experience in Application Security, including:
- Security Requirements
- Application Security Risk Assessments
- Secure SDLC
- Strong knowledge of:
- OWASP Top 10
- Cwe/sans Top 25
- Common application security vulnerabilities and remediation techniques
- Excellent communication, stakeholder management, and consulting skills.
- Strong analytical, problem-solving, and risk assessment capabilities.
- Ability to collaborate effectively with development teams and influence security adoption without direct authority.
Job Expectations
- Partner with Application Security Champions (ASCs), development teams, and architects to promote secure software development practices.
- Act as a security consultant for application teams by providing guidance on secure design, security requirements, and vulnerability remediation.
- Perform threat model reviews and triage identified threats, security concerns, and remediation recommendations.
- Support application teams in addressing vulnerabilities aligned with OWASP Top 10, CWE/SANS Top 25, and organizational security standards.
- Facilitate security consultations and serve as the primary point of contact for application security-related inquiries.
- Drive security awareness initiatives, ASC engagement activities, office hours, and knowledge-sharing sessions.
- Promote secure coding practices and assist teams in integrating security throughout the Software Development Lifecycle (SDLC).
- Collaborate with development, architecture, infrastructure, and security teams to identify and mitigate application security risks.
- Track, prioritize, and follow up on remediation efforts to ensure timely resolution of security findings.
- Support continuous improvement of the Application Security Champion program through process enhancements, metrics, and stakeholder feedback.
- Develop and maintain application security guidance, standards, and best practices.
- Manage multiple priorities while building robust relationships with technical and non-technical stakeholders.
📌 Senior Information Security Engineer - Source Code Review (Karnataka)
🏢 Wells Fargo
📍 Karnataka