Wells Fargo - York, PA

posted 3 months ago

Part-time - Mid Level
Hybrid - York, PA
Credit Intermediation and Related Activities

About the position

The Cloud Security Risk organization at Wells Fargo is pivotal in leading the strategy, planning, and execution of Cybersecurity risk management for applications hosted in the cloud. This role is essential for ensuring that cloud workloads meet established risk tolerance levels and comply with the necessary cloud security requirements across various service and deployment models. The Cloud Security Risk Lead Analyst will be responsible for executing risk and controls identification, assessment, monitoring, measurement, and governance activities. This includes ensuring that all cloud workloads, including those utilizing AI and Generative AI models, adhere to the cloud security control framework both prior to deployment and throughout their lifecycle. In this position, the analyst will oversee and challenge cloud workload and service functions across all types of cloud services—public, private, hybrid, and multi-cloud—as well as deployment models such as SaaS, PaaS, and IaaS. The role requires a thorough evaluation of control environments across the enterprise, platform, and application layers, conducting risk assessments, root cause analyses, and ensuring sustainable remediation efforts are in place. The analyst will also support audit processes, independent risk testing, and regulatory examinations, engaging with relevant governance and control management bodies to ensure adherence to control monitoring. Additionally, the Cloud Security Risk Lead Analyst will develop and monitor metrics and key risk indicators that reflect the threat and risk environment, ensuring alignment with Wells Fargo's policies and control frameworks. Continuous enhancement and adoption of the Cloud Security Control Framework will be a key focus, along with developing requirements for automation to support Cloud Security Risk initiatives. Candidates for this role should possess a strong understanding of industry-standard frameworks for cybersecurity, cloud computing, and artificial intelligence, as well as risk management principles and analytics, enabling them to provide valuable insights for executive decision-making.

Responsibilities

  • Oversee and challenge cloud workload/services functions for all cloud service types (public, private, hybrid, multi-cloud) and deployment models (SaaS, PaaS, IaaS) including AI and Generative AI models to understand residual risk and ensure adherence to the cloud security control framework.
  • Identify, analyze and monitor risk to ensure cloud workloads, including AI/GenAI models are secure prior to deployment and maintain control framework adherence post-deployment.
  • Evaluate control environments across the enterprise, platform and application layer, conduct risk assessments, root cause analysis and ensure sustainable remediation.
  • Support audit, independent risk testing and regulatory examinations.
  • Engage with relevant governance and control management bodies and routines in support of control monitoring and adherence.
  • Develop and monitor metrics and key risk indicators of the threat and risk environment, and Wells Fargo policy and control frameworks to understand the aggregate impact and ensure coverage of the control framework.
  • Support the continuous enhancement and adoption of the Cloud Security Control Framework.
  • Develop requirements for automation in support of Cloud Security Risk and support adoption.

Requirements

  • 5+ years of Information Security Analysis experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education.
  • 3+ years of information security risk and controls management experience.

Nice-to-haves

  • Knowledge of Cybersecurity, Cloud Computing, Cloud Security, Artificial Intelligence/Machine Learning.
  • Demonstrated experience with industry standards (ie NIST, CSA, FFIEC, CIS, CRI Profile).
  • Cloud, Risk and Cybersecurity certification (eg CISA, CISM, CISSP, CRISC, CCSK).
  • Understanding of information security threats, trends and industry best practices and security tools.
  • Ability to communicate effectively, with peers, stakeholders, partners, senior management, auditors and regulators.
  • Strong analytical skills and ability to solve complex problems with minimal direct oversight, and the ability to handle multiple, high priority deliverables simultaneously.
  • Experience with standard Microsoft Office tools (ie Advanced Excel, Powerpoint, Word).
  • Finance sector security experience or other regulated industry (eg utilities, health care, government).

Benefits

  • 401(k) Plan
  • Paid Time Off
  • Parental Leave
  • Critical Caregiving Leave
  • Discounts and Savings
  • Health Benefits
  • Commuter Benefits
  • Tuition Reimbursement
  • Scholarships for dependent children
  • Adoption Reimbursement
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service