Jobs · Engineering · North Carolina

Senior Lead Information Protection Security Analyst

Wells Fargo · Charlotte, NC · Yesterday
Engineering$159k–$305k/yrFull-time

Wells Fargo is seeking a Senior Lead Information Protection Security Analyst to join the Information Protection Domain within Cybersecurity. This role provides enterprise leadership for information protection strategy, governance, and risk management programs focused on safeguarding the firm's sensitive data assets.

Responsibilities

  • Provide oversight to the Information Security program for a major line of business.
  • Consult with line of business on the consistent implementation of the enterprise information security model and solutions to remediate information security risks.
  • Ensure that risks to all information assets are being managed in a timely and effective manner to meet the Information Security Program requirements and the current threat landscape.
  • Ensure information security capabilities are included in all aspects of the company's technology architecture.
  • Proactively manage the information security risk profile of line of business information assets throughout the lifecycle of the asset.
  • Provide vision, direction, and expertise to more experienced leadership on implementing innovative and significant business solutions that are large-scale, cross-functional, or companywide strategies.
  • Ensure the team has the necessary training and is keeping abreast of regulatory and compliance issues.
  • Engage with all levels of professionals and managers companywide and serve as an experienced advisor to leadership.
  • Develop, implement, and maintain the enterprise cryptographic governance framework, including policies, standards, and procedures.
  • Develop and maintain cryptographic policies, standards, and control requirements (e.g., encryption, key management, certificates), ensuring alignment with applicable regulatory and industry frameworks (e.g., NIST, PCI DSS, ISO 27001).
  • Operate governance routines to ensure consistent application of cryptographic controls across the enterprise.
  • Review and evaluate new or updated cryptographic solutions.
  • Lead governance forums, reporting, and escalation processes to senior leadership.
  • Align governance activities with the enterprise cryptographic strategy, including roadmap initiatives and long-term objectives.
  • Participate in periodic reviews of cryptographic strategy and data protection initiatives.
  • Ensure governance supports enterprise priorities related to data protection, risk management, and security modernization.
  • Establish and maintain visibility into cryptographic risks, including vulnerabilities and non-compliance.
  • Define key metrics and reporting mechanisms to monitor cryptographic posture.
  • Escalate issues related to non-adherence to cryptographic policy through established governance channels.
  • Support the identification, prioritization, and tracking of risk remediation activities.
  • Assist with exception management, ensuring appropriate documentation, risk acceptance, and tracking.
  • Collaborate regularly with cross-functional stakeholders, including Cybersecurity Architecture, Secure Network Services (SNS), Cloud Security, and application teams, on solutions, strategies, and policies.
  • Act as a central point of coordination for cryptographic governance activities.
  • Provide guidance and direction to engineering and operational teams on governance expectations.
  • Support internal and external audits by providing required documentation, control evidence, and governance artifacts.
  • Participate in the evaluation of cryptographic discovery tools and capabilities.
  • Develop programs for cryptographic discovery tools, capabilities, reporting, and metrics.
  • Monitor enterprise cryptographic posture and identify risks through tool outputs.
  • Demonstrate foundational AI literacy by effectively using approved AI tools to support everyday work.
  • Apply AI tools for activities such as research, summarization, drafting, analysis, and decision support.
  • Exercise sound judgment when interpreting and using AI-generated outputs.
  • Understand basic AI limitations and appropriate use cases within daily workflows.
  • Adhere to data privacy, security, and data-handling standards when using AI tools.
  • Use AI ethically and responsibly, in alignment with company policies and guidelines.

Requirements

  • 7+ years of Information Security Analysis experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education.

Qualifications

  • Deep expertise in Hardware Security Modules (HSMs), Public Key Infrastructure (PKI), key management, certificate services, encryption technologies, and enterprise cryptographic controls.
  • Strong experience developing, implementing, and governing enterprise cryptographic programs, including policies, standards, procedures, and control frameworks within highly regulated environments.
  • Demonstrated experience managing and improving certificate lifecycle management, cryptographic asset inventory, discovery, reporting, and remediation programs across large, complex organizations.
  • Advanced knowledge of security and regulatory frameworks including NIST Cryptographic Standards, NIST Cybersecurity Framework (CSF), PCI DSS, ISO 27001, FFIEC guidance, and financial services regulatory requirements.
  • Experience evaluating, planning, or implementing post-quantum cryptography (PQC) strategies, cryptographic modernization initiatives, and emerging encryption technologies.
  • Proven ability to author and enhance enterprise security policies, standards, governance artifacts, executive communications, and regulatory documentation while influencing senior leaders and cross-functional stakeholders.
  • Strong technical leadership experience partnering with cybersecurity architecture, engineering, infrastructure, cloud security, application development, legal, privacy, risk, and regulatory teams to drive enterprise-wide cryptographic governance and adoption.
  • Experience supporting cryptographic discovery tools, defining enterprise cryptographic metrics, monitoring cryptographic posture, and identifying risks associated with non-compliant cryptographic implementations.
  • Experience leading cryptographic governance, PKI, certificate management, or key management programs within a large-scale financial institution or highly regulated industry.

Schedule

Hybrid schedule - 3 days in office, 2 days remote weekly.

Locations

  • 300 South Brevard, Charlotte, NC
  • 2600 South Price Road, Chandler, AZ
  • 194 Wood Ave, Iselin, NJ
  • 401 Las Colinas Blvd W, Irving, TX

Pay

$159,000.00 - $305,000.00

Benefits

  • Health benefits
  • 401(k) Plan
  • Paid time off
  • Disability benefits
  • Life insurance, critical illness insurance, and accident insurance
  • Parental leave
  • Critical caregiving leave
  • Discounts and savings
  • Commuter benefits
  • Tuition reimbursement
  • Scholarships for dependent children
  • Adoption reimbursement

Not available for visa sponsorship.

Similar jobs