This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Wells Fargo is seeking an Information Security Engineering Manager to lead a Privileged Access Management (PAM) engineering organization. This role is responsible for securing, modernizing, and evolving enterprise privileged access capabilities, including credential vaulting, secrets management, session control, and least‑privilege enforcement. The manager will oversee risk reduction related to privileged identities while driving automation, DevSecOps integration, and standardized access patterns. This position will guide the team through PAM modernization initiatives, including retiring legacy access models, improving platform architecture, and enabling scalable, cloud‑ready privileged access solutions across hybrid environments.
Job Responsibility:
Provide strategic leadership for the Privileged Access Management (PAM) platform, defining vision, roadmaps, and long‑term evolution for credential vaulting, session management, secrets management, and least‑privilege access across the enterprise
Lead teams responsible for securing privileged credentials and access paths, including account onboarding, rotation, session isolation, and policy enforcement for human and non‑human identities
Drive modernization of PAM capabilities, transitioning from legacy, manually managed access models to automated, policy‑driven, and API‑integrated solutions aligned with Zero Trust principles
Guide adoption of DevSecOps and automation patterns for privileged access, including CI/CD integrations, secrets delivery, ephemeral credentials, and infrastructure‑as‑code enablement
Oversee vulnerability reduction and risk mitigation related to privileged access, including elimination of hard‑coded credentials, shared accounts, excessive entitlements, and standing access
Partner closely with security architecture, IAM, cloud, infrastructure, and application teams to embed privileged access controls into platforms, pipelines, and operating models
Manage a team of engineers designing, implementing, documenting, and supporting highly complex PAM solutions spanning CyberArk, secrets management platforms, directory services, cloud IAM, and hybrid environments
Provide security consulting and design oversight for large enterprise initiatives to ensure privileged access patterns conform to information security policy, regulatory requirements, and audit expectations
Serve as a subject matter expert in PAM technologies and best practices, staying current on emerging threats, access models, and platform capabilities
Lead technical investigation and response for privileged access–related incidents, including root cause analysis and remediation recommendations to prevent recurrence
Ensure PAM controls support availability, confidentiality, integrity, access governance, monitoring, and incident response, while enabling business agility and developer productivity
Manage resource planning, prioritization, and financial stewardship for PAM engineering and platform investments
Mentor, develop, and retain engineering talent, building strong technical depth and leadership capability within the PAM organization
Requirements:
5+ years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
2+ years of Leadership experience
Nice to have:
Experience with CyberArk credential management system
Experience with Agentic AI identity frameworks like SPIFFE and SPIRE
Experience managing and developing high‑performing Agile teams focused on Privileged Access Management, identity platforms, and security engineering solutions
Strong knowledge of DevSecOps patterns as they relate to privileged access, including secure CI/CD integration, automated credential delivery, secrets injection, and control enforcement
Hands‑on understanding of Kubernetes and cloud‑native environments from a privileged access perspective, including workload identity, service accounts, secrets distribution, and container access controls
Proficiency with cloud and hybrid architectures requiring secure privileged access, including integration with cloud IAM, secrets management platforms, and enterprise PAM tooling
Ability to drive engineering excellence in PAM through automation, policy‑driven access, observability, and standardized onboarding patterns
Proven collaboration skills with IAM, security architecture, infrastructure, cloud, and application teams to deliver resilient, compliant, and scalable privileged access solutions
Demonstrated leadership in PAM platform engineering, building and operating centralized vaulting, session management, secrets services, and self‑service access models
Experience leading modernization of privileged access for legacy and home‑grown systems, including removal of hard‑coded credentials, reduction of shared accounts, and elimination of standing access
Track record of transformation leadership to establish new privileged access patterns, operating models, and Zero Trust–aligned controls across the enterprise
Expertise in automation and CI/CD enablement for PAM, including policy‑as‑code, secrets management, credential rotation, and integration across on‑prem and cloud environments
Ability to define and execute a cloud and platform readiness roadmap for privileged access, guiding teams through staged adoption or hybrid models while maintaining uptime, auditability, and compliance
What we offer:
Health benefits
401(k) Plan
Paid time off
Disability benefits
Life insurance, critical illness insurance, and accident insurance