Sr Lead Information Security Analyst, Cloud Security Risk

WELLS FARGO BANK
CHARLOTTE, North Carolina, United States of America
Full-time

About this role :

Wells Fargo is seeking a Sr. Lead Information Security Analyst

The Cloud Security Risk organization leads the strategy, planning and execution of Cybersecurity risk management of WF applications in the cloud.

To achieve its goals, Cloud Security Risk works horizontally and collaboratively across the Cybersecurity domains, Independent Risk Management, Internal Audit, Tech Controls, Applications & Cloud Technology (ACT) and Regulatory Relations through the Risk Management Framework processes designed to identify, assess, disposition, monitor, measure and report risk and control maturity.

In this role, you will :

Evaluate cloud cybersecurity risk and adherence to the cloud security control framework across all service (public, private, hybrid, multi-cloud) and deployment models (SaaS, PaaS.

IaaS) to ensure cloud workloads are secure prior to deployment

  • Identify, analyze and escalate risk across cybersecurity related functions and controls
  • Monitor, measure and report control adherence and the risk profile
  • Implement and manage post-deployment quality assurance of cybersecurity related processes, technologies and controls
  • Develop and monitor cloud security metrics, key risk indicators, key performance indicators to provide an aggregate risk view that informs decision-making
  • Evaluate control environments across the enterprise, platform and application layer, through root cause analysis and solution advice to ensure sustainable mitigation.
  • Oversee and provide cloud expertise for audit, testing and regulatory examinations
  • Create and present cloud specific risk details in relevant risk committees and governance routines
  • Support the continuous enhancement and adoption of the Cloud Security Control Framework
  • Develop requirements for automation capabilities in support of Cloud Security Risk & Control and support launch activities through testing, training and awareness
  • Engage with all levels of professionals and managers companywide and serve as an experienced advisor to leadership
  • Participate in external industry organizations related to cloud security risk and controls

Required Qualifications :

  • 7+ years of Information Security Analysis experience, or equivalent demonstrated through one or a combination of the following : work experience, training, military experience, education
  • 5+ years of cloud cybersecurity, cyber risk management and controls experience;
  • In-depth, practical experience with related industry standards for cloud (i.e. NIST, CSA-CCM, FFIEC, CRI Institute, CIS Profile)

Desired Qualifications :

  • Cloud, Risk and Cybersecurity certification (e.g. CISA, CISM, CISSP, CRISC, CCSK)
  • Understanding of cybersecurity threats, trends and industry best practices and security tools
  • Finance sector security experience or other regulated 'critical infrastructure' industry (e.g. utilities, health care, government)
  • In-depth, practical experience with related industry standards for cloud (i.e. NIST, CSA-CCM, FFIEC, CRI Institute, CIS Profile)
  • Ability to communicate confidentially, professionally, and effectively, in both written and verbal formats, with stakeholders and partners
  • Strong analytical skills and ability to solve complex problems with minimal direct oversight
  • Ability to handle multiple, high priority deliverables concurrently

Job Expectations :

  • Ability to travel up to 20% of the time
  • No relocation assistance
  • This is not a remote position. Candidates are required to work in the office three (3) days per week at the specified location
  • Wells Fargo cannot consider individuals for this role who will require immigration assistance either now or in the future

Pay Range

Reflected is the base pay range offered for this position. Pay may vary depending on factors including but not limited to achievements, skills, experience, or work location.

The range listed is just one component of the compensation package offered to candidates.

$120,400.00 - $287,600.00

Benefits

Wells Fargo provides eligible employees with a comprehensive set of benefits, many of which are listed below. Visit Benefits - Wells Fargo Jobs for an overview of the following benefit plans and programs offered to employees.

  • Health benefits
  • 401(k) Plan
  • Paid time off
  • Disability benefits
  • Life insurance, critical illness insurance, and accident insurance
  • Parental leave
  • Critical caregiving leave
  • Discounts and savings
  • Commuter benefits
  • Tuition reimbursement
  • Scholarships for dependent children
  • Adoption reimbursement

Posting End Date : 10 Oct 2024

10 Oct 2024

Job posting may come down early due to volume of applicants.

We Value Diversity

At Wells Fargo, we believe in diversity, equity and inclusion in the workplace; accordingly, we welcome applications for employment from all qualified candidates, regardless of race, color, gender, national origin, religion, age, sexual orientation, gender identity, gender expression, genetic information, individuals with disabilities, pregnancy, marital status, status as a protected veteran or any other status protected by applicable law.

Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company.

They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions.

There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit's risk appetite and all risk and compliance program requirements.

Candidates applying to job openings posted in US : All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other legally protected characteristic.

Applicants with Disabilities

To request a medical accommodation during the application or interview process, visit Disability Inclusion at Wells Fargo .

Drug and Alcohol Policy

Wells Fargo maintains a drug free workplace. Please see our Drug and Alcohol Policy to learn more.

Wells Fargo Recruitment and Hiring Requirements :

a. Third-Party recordings are prohibited unless authorized by Wells Fargo.

b. Wells Fargo requires you to directly represent your own experiences during the recruiting and hiring process.

7 hours ago
Related jobs
Promoted
VirtualVocations
Charlotte, North Carolina

A company is looking for a Lead Information Security Engineer. ...

RXO
Charlotte, North Carolina

As a Lead Analyst, Information Security (Forensics) at RXO, you’ll serve as the lead of the forensic investigation functions for the information security team. Lead Analyst, Information Security (Forensics). Familiarity with Cloud structure and security monitoring capabilities for GCP, AWS, Azure, a...

Promoted
US Bank
Charlotte, North Carolina

Experience in leading complex information security/cybersecurity audits. Relevant Financial Service Industry and Information Security knowledge (Threat Hunting and Intelligence, Data Loss Prevention, Identity Management, Vulnerability Management, Application Security, etc. The Corporate Audit Servic...

Forrester Research, Inc.
Charlotte, North Carolina

Forrester is currently looking for a Security and Risk (Zero Trust) Principal Analyst to conduct research and deliver practical advice for security and risk leaders and practitioners, as well as other technology roles, like CIOs and enterprise architects. The Security and Risk Principal Analyst will...

Brosnan Risk Consultants
Charlotte, North Carolina

Many of our employees began their careers as Security Officers, and today we are proud to say they have become a part of the Senior Leadership Team (SLT). Brosnan Risk Consultants provides exceptional security services nationwide. Notify supervisors and on-site staff of any irregularities, suspiciou...

Randstad
Charlotte, North Carolina

Expert understanding of the most common application security risks (OWASP Top 10, SANS/CWE Top 25). Experience managing automated application security testing tools, including Static and Dynamic Application Security Testing (SAST/DAST) and Software Composition Analysis (SCA). Design, document, plan,...

Agility Partners LLC
Charlotte, North Carolina

In this role, you will collaborate closely with application development, information security, and IT teams to integrate security measures into existing and new web applications, ensuring that security is a core component of Compass Group North America's applications. Agility Partners is currently s...

SS&C Technologies
NC, US

The Lead Network Security Engineer is a top-level technical position with expertise in networking and security systems. Lead Network Security Engineer. The network security engineer will help identify, research, and evaluate security solutions and emerging technologies that align with the company's ...

Honeywell
Charlotte, North Carolina
Remote

As a Lead Security Integration Engineer specializing in Mergers & Acquisitions (M&A) here at Honeywell, you will play a critical role in the design, implementation, and management of complex security systems and solutions for M&A activities, particularly acquisitions and divestitures. You will work ...

City National Bank
Charlotte, North Carolina

As a member of the Digital Technologies Group, the Full Stack Senior Engineer is responsible for designing, developing and maintaining legacy and "Cloud First" applications written primarily in C# and focused on. Net Core and Azure cloud platforms. Lead & participates with other colleagues in ne...