CrawlJobs Logo

Senior Information Security Engineer for Application Security Scanning Process

https://www.wellsfargo.com/ Logo

Wells Fargo

Location Icon

Location:
India, Hyderabad

Category Icon
Category:
IT - Software Development

Job Type Icon

Contract Type:
Not provided

Salary Icon

Salary:

Not provided

Job Description:

Wells Fargo is seeking Senior Information Security Engineer. This role is part of application security engineering team responsible for scanning code following the Wells Fargo established guidelines, secure development policies and procedures. This role will focus heavily on building and enhancing Software composition analysis (SCA) practice, help software developers at various Wells Fargo CIO teams to build faster, more securely, fine-tuning the tools, leveraging AI where possible to improve processes and services for optimal developer experience.

Job Responsibility:

  • Manage security automation tools with main focus on SCA (i.e. Checkmarx One, BlackDuck) and other tools in the ecosystem along with supporting operational management with regularly scheduled upgrade of the tools
  • Interface with various internal teams ServiceNow AVR, DevOps and vulnerability operations team to make sure SCA vulnerabilities are identified and recorded per the application security policies and guidance
  • Focus heavily on building and enhancing Software composition analysis (SCA) practice, help software developers at various Wells Fargo CIO teams to build faster, more securely, fine-tuning the tools, leveraging AI where possible to improve processes and services for optimal developer experience
  • Collaborate with security architecture teams to design vulnerability management workflow, establish best practices and design guidance to optimize experience for developers
  • Security training and outreach as needed for internal development teams
  • Adversarial security analysis on various application security requirements as requested from various CIO teams, research and recommend cutting-edge tools and industry best practices
  • Work with application security governance teams, risk & compliance partners on audits (e.g., SOC 2, PCI-DSS) and recommending relevant policies
  • Collaborate with CTO pipeline teams to improve code quality and vulnerability detection on Open Source, code signing and SBOM creation
  • Analyze, enhance, architect and support container security tools and platforms
  • Design and build advanced security solutions to strengthen open-source software supply chains for effective automation and management

Requirements:

  • 4+ years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
  • Experience in Security automation tools with main focus on SCA (i.e. Checkmarx One, BlackDuck)
  • Solid Experience in OWASP Top 10 or CWE
  • Good Knowledge in software development, experience in one or more of programming languages, .Net C#, Java, RUST, C++
  • Ability to write automation scripts in Python, PowerShell to support internal projects
  • Experience with CI/CD pipelines and related technologies (e.g., GitHub, Jenkins, Maven, Artifactory, Harness, Xray, Curation)
  • Good understanding of Secure Software development lifecycle
  • Demonstrated experience of communicating secure development concepts to non-technical audiences and the ability to achieve results through prolific communication skills
  • Demonstrated knowledge on Information Security related requirements in applications, secure development standards, and best practices
  • Demonstrated ability in publishing secure coding standards
  • Experience in Collaborating with cross functional teams to achieve results
  • Demonstrated experience in stakeholder management
  • Demonstrated experience of problem identification and solving skills
  • Superior Knowledge of AppSec security products

Nice to have:

  • Familiarity and experience with AI tools supporting false positives reduction, auto code remediation, open-source threat intelligence would be preferred
  • Experience with Jira/Confluence is required
  • Strong problem-solving and analytical skills
  • Certification in information security (CISSP, CISM, CEH, etc.)
  • Experience with container security working with technologies like k8s and container technologies such as OpenShift
  • Experience generating Software Bill of Materials (SBOMs) using CycloneDX or SPDX, managing or utilizing dependency track
  • From an application security perspective, knowledge of AI/ML and GenAI is essential for building robust defenses

Additional Information:

Job Posted:
July 18, 2025

Expiration:
August 25, 2025

Employment Type:
Fulltime
Job Link Share:
Welcome to CrawlJobs.com
Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.