Wells Fargo Logo

Wells Fargo

Senior Information Security Engineer

Reposted 10 Days Ago
Be an Early Applicant
Hybrid
Hyderabad, Telangana
Senior level
Hybrid
Hyderabad, Telangana
Senior level
About this role:
Wells Fargo is seeking a Senior Information Security Engineer.
In this role, you will:
  • Lead or participate in computer security incident response activities for moderately complex events
  • Conduct technical investigation of security related incidents and post incident digital forensics to identify causes and recommend future mitigation strategies
  • Provide security consulting on medium projects for internal clients to ensure conformity with corporate information, security policy, and standards
  • Design, document, test, maintain, and provide issue resolution recommendations for moderately complex security solutions related to networking, cryptography, cloud, authentication and directory services, email, internet, applications, and endpoint security
  • Review and correlate security logs
  • Utilize subject matter knowledge in industry leading security solutions and best practices to implement one or more components of information security such as availability, integrity, confidentiality, risk management, threat identification, modeling, monitoring, incident response, access management, and business continuity
  • Identify security vulnerabilities and issues, perform risk assessments, and evaluate remediation alternatives
  • Collaborate and consult with peers, colleagues and managers to resolve issues and achieve goals

Required Qualifications:
  • 4+ years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education

Desired Qualifications:
  • Bachelor's degree in computer science, Information Security, or a related field - or equivalent work experience
  • 4+ years of Penetration testing, offensive security or Red teaming experience
  • Good understanding of OWASP top 10, SANS top 25 and application security testing, threats, vulnerabilities and attacks
  • 4+ years of experience in at least one of the following practices like Security requirements, Threat Modeling, static Analysis/Code Review, Application Security Risk Assessments, Security Design Requirements
  • 4+ years of experience in initiating scan using scanners like HCL AppScan or Invicti or WebInspect and troubleshooting any scanner related issues
  • Understanding of one or more programming languages and ability to analyze vulnerabilities and perform false positive analysis as part of DAST is a must
  • Comfortable in scripting in Python or PowerShell
  • Ability to performing cloud security assessments
  • Ability to work on Git hub
  • Ability to manage multiple priorities in a fast-paced dynamic environment
  • Advanced problem solving skills, ability to develop effective long- term solutions to problems
  • Excellent verbal and written communications skills
  • Excellent inter-personal skills contributing to cordial team environment
  • Certified in Industry recognized certifications such as CEH, SANS GIAC - GWAPT or GPEN or GMOB, Cloud Certification: AZ-900
  • Industry recognized certifications like Offensive Security Certified Professional (OSCP) or Certified Penetration Tester (CPT) or CISSP
  • Good understanding of networking concepts like ICMP, DNS, TCP/IP, DHCP
  • Knowledge and understanding of secure SDLC (System Development Life Cycle) methodologies.
  • Application security experience with banking/financial services applications.
  • Ability to manage highly complex issues and negotiate solutions.
  • High quality engagements delivered within expected timelines
  • Demonstrate advancements in Penetration testing capabilities of self and team

Job Expectations:
  • Perform application security assessments / penetration testing engagements on web, mobile, thick client applications and API/web services covering multiple techniques and procedures
  • Scan the applications using automated scanners like HCL AppScan, Invicti or Web Inspect and perform false positive analysis.
  • Identify and exploit vulnerabilities on web, mobile, thick client applications and API/web services using manual testing tools like Burp Suite.
  • On a regular basis, provide subject matter expertise to the team on technical issues (Automated test & Manual test), reporting and conduct peer review.
  • Writing security test cases to check for vulnerabilities or broken/missing security controls
  • Develop tools and exploits to support application security automation and penetration testing
  • Stay current with the latest cybersecurity threats, attack vectors and penetration testing techniques
  • Lead DAST projects and initiatives and participate in computer security incident response activities for moderately complex events. Asist with stakeholder's requests for net-new and enhancements to existing solutions
  • Contribute to Newsletter/blogs, articles and presentation for internal or other audiences
  • Collaborate and consult with peers, colleagues and managers to resolve issues and achieve goals
  • Maintain seamless communication with stateside and India stakeholders to ensure smooth delivery of goals.

Top Skills

Burp Suite
Git
Hcl Appscan
Invicti
Powershell
Python
Webinspect

Similar Jobs at Wells Fargo

5 Days Ago
Hybrid
Senior level
Senior level
Fintech • Financial Services
The Senior Information Security Engineer leads incident response, conducts investigations, provides security consulting, and implements security solutions while collaborating to enhance data analytics capabilities.
Top Skills: AIAlteryxApplicationsAuthenticationCloudCryptographyData ModellingDirectory ServicesEltEmailEndpoint SecurityETLInformation SecurityInternetMachine LearningNetworkingPower BISQLTableau
4 Days Ago
Hybrid
Senior level
Senior level
Fintech • Financial Services
Lead security incident response, conduct investigations, provide security consulting, design and maintain security solutions, assess risks, and manage vulnerabilities.
Top Skills: ApplicationsAuthenticationAzure CloudCloudCryptographyDirectory ServicesEmailEndpoint SecurityGCPInternetJava ScriptNetworkingPython
8 Hours Ago
Hybrid
Senior level
Senior level
Fintech • Financial Services
Lead product initiatives including market research, program and change delivery, risk management, stakeholder collaboration, and mentoring teams to deliver product enhancements and meet regulatory obligations.

What you need to know about the Chennai Tech Scene

To locals, it's no secret that South India is leading the charge in big data infrastructure. While the environmental impact of data centers has long been a concern, emerging hubs like Chennai are favored by companies seeking ready access to renewable energy resources, which provide more sustainable and cost-effective solutions. As a result, Chennai, along with neighboring Bengaluru and Hyderabad, is poised for significant growth, with a projected 65 percent increase in data center capacity over the next decade.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account