Wells Fargo - Minneapolis, MN

posted 14 days ago

Full-time - Mid Level
Minneapolis, MN
Credit Intermediation and Related Activities

About the position

Wells Fargo is seeking a Lead Information Security Engineer to design, create, and maintain security systems within the company's network. This role involves leading incident response activities, conducting technical investigations, providing security consulting, and implementing complex security solutions across various domains including networking, cloud, and endpoint security.

Responsibilities

  • Lead computer security incident response activities for highly complex events.
  • Conduct technical investigation of security related incidents and post incident digital forensics to identify causes and recommend future mitigation strategies.
  • Provide security consulting on large projects for internal clients to ensure conformity with corporate information security policy and standards.
  • Design, document, test, maintain, and provide issue resolution recommendations for highly complex security solutions related to networking, cryptography, cloud, authentication and directory services, email, internet, applications, and endpoint security.
  • Review and correlate security logs.
  • Utilize subject matter knowledge in industry leading security solutions and best practices to implement components of information security such as availability, integrity, confidentiality, risk management, threat identification, modeling, monitoring, incident response, access management, and business continuity.
  • Identify security vulnerabilities and issues, perform risk assessments, and evaluate remediation alternatives.
  • Collaborate and influence all levels of professionals including managers.

Requirements

  • 5+ years of Information Security Engineering experience, or equivalent demonstrated through work experience, training, military experience, or education.
  • 3+ years of hands-on software development experience to include working with IaC tools Terraform and GitHub.
  • 2+ years administration and troubleshooting experience in Azure Policy, Sentinel Policy, GCP organization policies, VPC-SC errors, and/or cloud stack.
  • 2+ years of experience in design and implementation experience on Azure or GCP platform security services.

Nice-to-haves

  • Experience in designing, building, and automating solutions utilizing Azure or GCP Platform security services.
  • Proficient on platform security services with hands-on experience in implementation of security solutions like Azure Policy, Organization policies, VPC-SC, Cloud DLP etc.
  • Hands-on experience in writing a Hashicorp Sentinel policy from scratch & enable through policy sets.
  • Understanding of Cloud Security Posture Management, Cloud Control Matrix framework for Security controls.
  • Proficient and understand policy framework concepts like built-in policy, custom policy, remediation, exemptions etc.
  • Well versed with security best practices/standards and familiar with concepts like data protection, compliance tools, preventative, detective & corrective controls etc.
  • Thorough understanding of security concepts like Defender for cloud, App Insights, Monitor & Advisor etc.
  • Awareness of Azure Resource Graph, HCL (Hashicorp Configuration Language) & Prisma.
  • Experience with Agile, CI/CD, DevOps concepts and SRE principles.
  • Experience in scripting (Shell, Python, Bash, PowerShell or equivalent).
  • Excellent verbal, written, and interpersonal communication skills.

Benefits

  • Health benefits
  • 401(k) Plan
  • Paid time off
  • Disability benefits
  • Life insurance, critical illness insurance, and accident insurance
  • Parental leave
  • Critical caregiving leave
  • Discounts and savings
  • Commuter benefits
  • Tuition reimbursement
  • Scholarships for dependent children
  • Adoption reimbursement
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service