Secure by Design - Head of Architecture - Technology Director
Wells FargoAbout the role
About this role:
Wells Fargo is seeking a Technology Director. This individual will server as the Head of Security Architecture will lead the enterprise-wide cybersecurity architecture strategy, ensuring robust, scalable, and compliant security solutions across all technology platforms. This role provides technical leadership, governance, and innovation to safeguard critical assets, reduce risk, and align with regulatory frameworks such as NIST, FFIEC, and GLBA. This is a hands-on, deeply technical, and forward-looking architectural leadership role responsible for shaping the future of the company's security posture.
Enterprise Engineering: Covers strategic roles responsible for technology application development across the enterprise, identifies and resolves abstract, systemic, cross-function issues impacting the effectiveness of the company's technology capability and builds support for strategies with the business and technology leaders
Key Responsibilities
Enterprise Security Architecture Leadership
- Serve as the principal architect and final decision-maker for all enterprise security standards, patterns, and target-state architectures.
- Define, maintain, and own the enterprise security architecture roadmap across all major cybersecurity domains, including Network Security, Cloud Security, Identity and Access Management, Application Security, Data Protection, Cryptography, Threat Management, Vulnerability Management, Endpoint Security, and Security Operations.
- Establish and enforce architecture standards, patterns, and technology disposition policies to ensure consistency and control.
- Manage the architecture for large portfolios of applications and security products, ensuring alignment with current and target state architectures.
Security, Risk & Regulatory Alignment
- Drive and ensure compliance with internal security control requirements and external regulations (e.g., GLBA, PCI DSS, SOX) and industry standards (e.g., NIST, COBIT).
- Serve as the senior technical authority during regulatory exams, audits, and risk committee reviews.
- Architect proactive controls and automation that reduce manual burden and mitigate audit findings.
Technical Strategy & Innovation
- Oversee threat modeling, cryptographic evaluations, and architecture risk assessments for hybrid cloud environments and new data centers.
- Lead the integration of advanced technologies such as AI/ML, Quantum Security, and Zero Trust into the enterprise architecture frameworks.
- Embed security principles into the CI/CD pipeline and champion DevSecOps best practices.
Cross-Functional Leadership & Influence
- Partner with engineering, operations, and business units to embed security by design into all technology initiatives and programs.
- Direct and influence product, engineering, and operations teams on the implementation of security architecture.
- Represent security architecture in executive forums, strategy councils, and enterprise steering committees, effectively communicating complex technical concepts to non-technical stakeholders.
What Success Looks Like
- A unified, modern, and resilient security ecosystem with minimized risk and friction.
- Widespread adoption of architectural guardrails and security standards by all engineering and application teams.
- A demonstrable improvement in security posture, evidenced by a reduction in architectural risk and audit findings.
- Security is recognized as a strategic business enabler and a core component of all technology initiatives.
- Clear and consistent alignment with key regulatory frameworks, including NIST, FFIEC, and GLBA.
Required Qualifications:
- 8+ years of Technology Strategic Leadership experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
- 4+ years of management or leadership experience
Desired Qualifications:
- 10+ years of experience in cybersecurity architecture leadership roles, preferably within financial services or another highly regulated industry.
- Deep expertise across all major cybersecurity domains: Network and Cloud Security, IAM and Privileged Access, Application Security and DevSecOps, Data Security and Encryption, Threat Detection and Incident Response, Vulnerability and Patch Management, and Security Operations/SIEM.
- Strong knowledge of regulatory frameworks (GLBA, PCI DSS, SOX) and industry standards (NIST, COBIT).
- Proven ability to lead large, cross-functional teams and influence executive stakeholders.
- Advanced degree in Cybersecurity, Computer Science, Information Technology, or a related
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s
Similar roles
Secure Web Gateway & Email Security Subject Matter Expert
Dxctechnology
Software Dev Engineer II, Secure Customer Content Storage and Analytics, AWS Applied AI Solution – Core Services
Amazon.com Services LLC
Software Dev Engineer II, Secure Customer Content Storage and Analytics, AWS Applied AI Solution – Core Services
Amazon Web Services, Inc.