Information Security Engineering Manager - IAM
Wells FargoAbout the role
About this role:
Wells Fargo is seeking an Information Security Engineering Manager to lead a Privileged Access Management (PAM) engineering organization. This role is responsible for securing, modernizing, and evolving enterprise privileged access capabilities, including credential vaulting, secrets management, session control, and least‑privilege enforcement. The manager will oversee risk reduction related to privileged identities while driving automation, DevSecOps integration, and standardized access patterns. This position will guide the team through PAM modernization initiatives, including retiring legacy access models, improving platform architecture, and enabling scalable, cloud‑ready privileged access solutions across hybrid environments.
In this role, you will:
Provide strategic leadership for the Privileged Access Management (PAM) platform, defining vision, roadmaps, and long‑term evolution for credential vaulting, session management, secrets management, and least‑privilege access across the enterprise
Lead teams responsible for securing privileged credentials and access paths, including account onboarding, rotation, session isolation, and policy enforcement for human and non‑human identities
Drive modernization of PAM capabilities, transitioning from legacy, manually managed access models to automated, policy‑driven, and API‑integrated solutions aligned with Zero Trust principles
Guide adoption of DevSecOps and automation patterns for privileged access, including CI/CD integrations, secrets delivery, ephemeral credentials, and infrastructure‑as‑code enablement
Oversee vulnerability reduction and risk mitigation related to privileged access, including elimination of hard‑coded credentials, shared accounts, excessive entitlements, and standing access
Partner closely with security architecture, IAM, cloud, infrastructure, and application teams to embed privileged access controls into platforms, pipelines, and operating models
Manage a team of engineers designing, implementing, documenting, and supporting highly complex PAM solutions spanning CyberArk, secrets management platforms, directory services, cloud IAM, and hybrid environments
Provide security consulting and design oversight for large enterprise initiatives to ensure privileged access patterns conform to information security policy, regulatory requirements, and audit expectations
Serve as a subject matter expert in PAM technologies and best practices, staying current on emerging threats, access models, and platform capabilities
Lead technical investigation and response for privileged access–related incidents, including root cause analysis and remediation recommendations to prevent recurrence
Ensure PAM controls support availability, confidentiality, integrity, access governance, monitoring, and incident response, while enabling business agility and developer productivity
Manage resource planning, prioritization, and financial stewardship for PAM engineering and platform investments
Mentor, develop, and retain engineering talent, building strong technical depth and leadership capability within the PAM organization
- Demonstrate proficiency in using AI‑assisted development and analysis tools (e.g., GitHub Copilot and approved code‑centric agents)
- Leverage AI to accelerate system design, coding, testing, analysis, and troubleshooting
- Apply strong technical judgment when validating and integrating AI‑assisted outputs into solutions
- Understand and account for model limitations, security risks, and operational considerations
- Apply AI responsibly in development and production environments
- Ensure AI usage aligns with security, compliance, privacy, and ethical standards
Required Qualifications:
- 5+ years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
- 2+ years of Leadership experience
Desired Qualifications:
Experience with CyberArk credential management system
Experience with Agentic AI identity frameworks like SPIFFE and SPIRE
Experience managing and developing high‑performing Agile teams focused on Privileged Access Management, identity platforms, and security engineering solutions
Strong knowledge of DevSecOps patterns as they relate to privileged access, including secure CI/CD integration, automated credential delivery, secrets injection, and control enforcement
Hands‑on understanding of Kubernetes and cloud‑native environments from a privileged access perspective, including workload
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s