Lead Vulnerability & Patch Management Information Security Engineer
About the role
Wells Fargo is seeking a Lead Vulnerability & Patch Management Information Security Engineer to help modernize and transform enterprise Vulnerability and Patch Management (VPM) capabilities through advanced automation, cloud security engineering, data analytics, and AI-driven solutions. This role will serve as a technical leader responsible for designing and implementing scalable security solutions that enhance vulnerability management, incident response, security monitoring, and risk reduction across a complex hybrid and multi-cloud environment. The ideal candidate will bring a blend of information security engineering, automation, cloud security, data engineering, and vulnerability management expertise to support the evolution of VPM 2.0—an initiative focused on replacing manual processes with API-driven automation, intelligent data correlation, and AI-enabled decision support capabilities.
Responsibilities
- Provide security consulting on large-scale technology initiatives to ensure alignment with Wells Fargo information security policies, standards, and regulatory requirements.
- Design, document, test, maintain, and provide issue resolution recommendations for highly complex security solutions related to cloud security, application security, networking, authentication, cryptography, and enterprise security platforms.
- Lead efforts to modernize Vulnerability and Patch Management (VPM) processes through automation and engineering-driven solutions.
- Develop and support API-first integrations, automation frameworks, and scripting solutions that improve vulnerability discovery, analysis, reporting, and remediation workflows.
- Partner with engineering and DevOps teams to integrate vulnerability management capabilities into CI/CD pipelines and Infrastructure as Code (IaC) environments.
- Review, correlate, and analyze security logs and vulnerability data from multiple security tools and cloud platforms to identify risks and emerging threats.
- Design and optimize security data pipelines, aggregation processes, and normalization workflows that consolidate vulnerability intelligence across the enterprise.
- Utilize advanced SQL querying, data analytics, and data correlation techniques to improve vulnerability visibility, prioritization, and reporting.
- Support AI-driven initiatives focused on enhancing vulnerability management through intelligent recommendations, automated analysis, and risk-based decision support.
- Provide technical leadership in hybrid and multi-cloud environments, ensuring security controls and vulnerability management processes operate effectively across diverse cloud platforms.
- Identify security vulnerabilities and risks, perform security assessments, and evaluate remediation alternatives based on business and technical requirements.
- Utilize deep subject matter expertise in information security principles including threat identification, monitoring, vulnerability management, risk management, incident response, confidentiality, integrity, availability, and access management.
- Conduct research and evaluation of emerging technologies, security tools, and industry best practices to address evolving cyber threats and business needs.
- Collaborate and influence all levels of professionals, including engineers, architects, managers, and senior leaders.
- Lead cross-functional teams and initiatives to achieve strategic security objectives and improve enterprise security posture.
- Demonstrate proficiency in using AI-assisted development and analysis tools (e.g., GitHub Copilot and approved code-centric agents).
- Leverage AI to accelerate system design, coding, testing, analysis, and troubleshooting.
- Apply strong technical judgment when validating and integrating AI-assisted outputs into solutions.
- Understand and account for model limitations, security risks, and operational considerations.
- Apply AI responsibly in development and production environments.
- Ensure AI usage aligns with security, compliance, privacy, and ethical standards.
Requirements
5+ years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education.
Qualifications
- 3+ years of cybersecurity experience within a large financial institution or highly regulated environment.
- 3+ years of experience in vulnerability management and/or patch management tools and techniques.
- Experience developing automation solutions utilizing APIs, scripting, and programming languages such as Python, PowerShell, or similar technologies.
- Experience integrating security controls and scanning solutions into CI/CD pipelines and Infrastructure as Code (IaC) environments.
- Strong understanding of vulnerability management lifecycle processes, vulnerability scanners, and remediation workflows.
- Experience working across hybrid and multi-cloud environments, including AWS, Azure, and Google Cloud Platform.
- Experience with security data aggregation, data lakes, data normalization, and vulnerability intelligence platforms.
- Strong SQL and data analysis skills, including the ability to build and optimize complex queries supporting vulnerability management programs.
- Experience leveraging AI, machine learning, or advanced analytics to enhance security operations and risk management processes.
- Knowledge of security logging, monitoring, threat detection, and incident response best practices.
- Excellent verbal, written, and executive communication skills with the ability to translate complex technical concepts into actionable business outcomes.
- Strong leadership, strategic thinking, and problem-solving skills.
Job Expectations
- Ability to travel up to 10% of the time.
- Ability to work a hybrid work schedule - 3 days a week on-site/in office and 2 days a week remote.
- This position is not eligible for Visa sponsorship.
Locations: Charlotte, NC; Chandler, AZ; Irving, TX
Pay
$119,000.00 - $187,000.00
Benefits
Wells Fargo provides eligible employees with a comprehensive set of benefits, including:
- Health benefits
- 401(k) Plan
- Paid time off
- Disability benefits
- Life insurance, critical illness insurance, and accident insurance
- Parental leave
- Critical caregiving leave
- Discounts and savings
- Commuter benefits
- Tuition reimbursement
- Scholarships for dependent children
- Adoption reimbursement