Principal Vulnerability & Patch Management Security Engineer
Wells Fargo · Irving, TX · Yesterday
Engineering$159k–$254k/yrFull-time
Wells Fargo is seeking a Principal Vulnerability & Patch Management Security Engineer to provide enterprise leadership for the modernization and transformation of Vulnerability Management (VM) capabilities across the organization. This role will serve as a strategic technical leader driving the evolution of the Vulnerability and Patch Management (VPM) program through automation, platform modernization, cloud-native security engineering, and AI-enabled vulnerability intelligence.
Responsibilities
- Act as a trusted advisor to executive leadership and engineering organizations to develop and influence enterprise-wide vulnerability management, security engineering, cloud security, and automation strategies.
- Lead the transformation of the Vulnerability and Patch Management (VPM) program by identifying opportunities to automate manual processes and implement AI-driven security capabilities.
- Define and execute strategies for decommissioning legacy vulnerability management platforms and transitioning teams to modern vulnerability management technologies and operating models.
- Drive enterprise adoption of next-generation vulnerability management capabilities through technical leadership, stakeholder engagement, and cross-functional partnership.
- Lead the strategy and resolution of highly complex security engineering challenges requiring evaluation across multiple technology domains and business lines.
- Translate advanced technical expertise and deep knowledge of enterprise security architecture into innovative engineering solutions that support long-term business objectives.
- Design and oversee API-first security architectures that enable automation, orchestration, and integration across vulnerability management, cloud security, and enterprise security platforms.
- Develop and influence automation frameworks, scripting solutions, and engineering standards that improve vulnerability identification, prioritization, remediation, and reporting.
- Partner with DevOps, Infrastructure, and Engineering teams to integrate vulnerability management tools and controls into CI/CD pipelines and Infrastructure as Code (IaC) frameworks.
- Establish best practices for implementing and maintaining security controls within modern software development and deployment environments.
- Provide strategic guidance on operating effectively across hybrid and multi-cloud environments, including cloud-native vulnerability management and security monitoring capabilities.
- Lead initiatives that aggregate, correlate, normalize, and enrich vulnerability data from multiple security tools, cloud platforms, and enterprise systems.
- Partner with data engineering teams to develop scalable security data pipelines, leverage enterprise data lakes, and utilize advanced SQL analytics to improve vulnerability intelligence and decision-making.
- Act as a human-in-the-loop technical expert for data-driven vulnerability management capabilities that leverage automated deduplication, correlation, prioritization, and AI-based recommendations.
- Research emerging cyber threats, vulnerability management technologies, and innovative security solutions that enhance organizational security posture and operational efficiency.
- Maintain expert-level knowledge of industry best practices, security architecture trends, cloud technologies, vulnerability management frameworks, and AI-driven security solutions.
- Provide vision, direction, and expertise to senior leadership on implementing significant and innovative cyber security engineering solutions.
- Strategically engage with all levels of professionals and managers across the enterprise, influencing technical decisions, operational priorities, and security roadmaps.
- Drive consensus across multiple organizations and remove organizational and technical barriers that impede security transformation initiatives.
- Serve as a recognized subject matter expert in vulnerability management, security automation, cloud security engineering, and enterprise security architecture.
- Demonstrate proficiency in using AI-assisted development and analysis tools (e.g., GitHub Copilot and approved code-centric agents).
- Leverage AI to accelerate system design, coding, testing, analysis, and troubleshooting.
- Apply strong technical judgment when validating and integrating AI-assisted outputs into solutions.
- Understand and account for model limitations, security risks, and operational considerations.
- Apply AI responsibly in development and production environments.
- Ensure AI usage aligns with security, compliance, privacy, and ethical standards.
Requirements
7+ years of Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education.
Qualifications
- 5+ years of experience in Vulnerability Management, Patch Management, Security Engineering, or Cyber Security Operations.
- Proven success modernizing enterprise vulnerability management programs, including retirement of legacy platforms and implementation of next-generation VM solutions.
- Experience developing API-based integrations, security automation solutions, and scripting using Python, PowerShell, or similar technologies.
- Strong understanding of CI/CD pipelines, DevSecOps practices, and Infrastructure as Code (IaC).
- Experience integrating vulnerability scanning and security controls into software development and cloud engineering workflows.
- Experience securing hybrid and multi-cloud environments, including AWS, Azure, and Google Cloud Platform.
- Knowledge of security data aggregation, data lakes, data correlation, and SQL-based analytics.
- Experience leveraging AI, machine learning, or advanced analytics to improve vulnerability prioritization and risk reduction.
- Strong understanding of vulnerability management frameworks, exposure management, and risk-based remediation strategies.
- Exceptional stakeholder management, executive communication, and cross-functional influence skills.
- Experience leading enterprise-wide initiatives and removing organizational and technical roadblocks in highly matrixed environments.
- Experience within a large, regulated organization, preferably financial services.
Job Expectations
- Ability to travel up to 10% of the time.
- Ability to work a hybrid work schedule - 3 days a week on-site/in office and 2 days a week remote.
- This position is not eligible for Visa sponsorship.
Locations
- Charlotte, NC
- Chandler, AZ
- Irving, TX
Pay
$159,000.00 - $254,000.00
Benefits
- Health benefits
- 401(k) Plan
- Paid time off
- Disability benefits
- Life insurance, critical illness insurance, and accident insurance
- Parental leave
- Critical caregiving leave
- Discounts and savings
- Commuter benefits
- Tuition reimbursement
- Scholarships for dependent children
- Adoption reimbursement