Senior Information Security Engineer Vulnerability Assessment Team Automation Engineer
Wells Fargo views information security as enabling lines of business to mitigate information security risk in accordance with our risk appetite. Through a framework that addresses policy, process, operations, people, and technology, Cybersecurity team protects our infrastructure, company data, and customer assets while ensuring alignment with applicable regulations and laws.Department Overview
About the Role
Our Vulnerability Assessment team is looking for a Senior Information Security Engineer who will support the Vulnerability Assessment Team in their scanning operations by automating multiple tasks to increase efficiency and accuracy. The person filling this position will be responsible for analyzing existing technical tasks performed by engineers and building tools to automate those tasks. This will require identifying areas where efficiencies can be gained, understanding the existing process and writing code/building tools that will automate the tasks. To accomplish these goals, the candidate must possess advanced development/coding skills as well as advanced security/engineering/networking skills.
- Lead efforts to design, create and implement automation to support operational tasks
- Provide security consulting on medium projects for internal clients to ensure conformity with corporate information, security policy, and standards
- Design, document, test, maintain, and provide issue resolution recommendations for moderately complex security solutions related to networking, cryptography, cloud, authentication and directory services, email, Internet, applications, and endpoint security
- Utilize subject matter knowledge in industry leading security solutions and best practices to implement one or more components of information security such as availability, integrity, confidentiality, risk management, threat identification, modeling, monitoring, incident response, access management, and business continuity
- Identify security vulnerabilities and issues, perform risk assessments, and evaluate remediation alternatives
- Collaborate and consult with peers, colleagues and managers to resolve issues and achieve goals
- Provide technical inputs to streamline or automate process and identify risk appropriately.
- Deliver projects to support technical and business solution individually with minimum guidance.
- Manage and monitor infrastructure and ensure it operates at optimal level.
- Participate in and respond reliably to user request/query and support on-call. Understand & analyze business requirements and deliver technical solution.
- Researches new software development methodologies and technologies and analyzes their application to current development and integration needs
- Maintain a broad understanding of security technologies and products
- Demonstrated detailed oriented self-starter and the ability to work independently with limited supervision and limited direction, and in collaborative team environments
- The ability to provide support after normal business hours as needed
- A strong ability to multi-task and manage varying priorities and projects
Essential Qualifications
- 6+ years of information security applications and systems experience
- 4+ years of experience with scripting languages such as Bash, PowerShell, Python, Shell, VBScript, or JavaScript
- 3+ years of TCP/ IP (Transmission Control Protocol/Internet Protocol) experience
- 2+ years of information security experience
- 2+ years of experience engineering and analyzing operating systems such as Windows or Unix
- 2+ years of experience with SAS or SQL, or other data management, reporting and query tools
- Hands-on experience with complex API development and integration efforts
Desired Qualifications
- Bachelor's and/or Master's degree in computer science or information systems
- Demonstrated excellent written and oral communication skills
- Experience with Agile methodology of project delivery
- Knowledge and understanding of Common Vulnerability Exposures (CVE) and Common Vulnerability Scoring System (CVSS) scoring
- Working knowledge of Cloud Platforms in one or a combination of the following Amazon Web Services (AWS), Google Cloud Platform (GCP) or Pivotal Cloud Foundry (PCF)
- Demonstrated Experience with enterprise vulnerabilityassessment solutions (such as Qualys, Guardium, Nmap, Tenable etc.),
- Ability to take initiative, identify opportunities and implement change
- Ability to identify and manage complex issues and negotiate solutions within a geographically dispersed organization
- Advanced Information Security technical skills and solid knowledge and understanding of information security practices and policies
Posting End Date
*Job posting may come down early due to volume of applicants.
We Value Diversity
At Wells Fargo, we believe in diversity, equity and inclusion in the workplace accordingly, we welcome applications for employment from all qualified candidates, regardless of race, color, gender, national origin, religion, age, sexual orientation, gender identity, gender expression, genetic information, individuals with disabilities, pregnancy, marital status, status as a protected veteran or any other status protected by applicable law.
Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit's risk appetite and all risk and compliance program requirements.
Candidates applying to job openings posted in USAll qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other legally protected characteristic.
Candidates applying to job openings posted in Canada Applications for employment are encouraged from all qualified candidates, including women, persons with disabilities, aboriginal peoples and visible minorities. Accommodation for applicants with disabilities is available upon request in connection with the recruitment process.
Applicants with Disabilities
To request a medical accommodation during the application or interview process, visitDisability Inclusion at Wells Fargo
Drug and Alcohol Policy
Wells Fargo maintains a drug free workplace. Please see our Drug and Alcohol Policy