Lead Information Security Engineer - Purple Team
Wells FargoAbout the role
About this role:
Wells Fargo is seeking a Lead Information Security Engineer in Technology as part of Cybersecurity. Learn more about the career areas and lines of business at wellsfargojobs.com
Wells Fargo is seeking a Lead Information Security Engineer with experience in tactical cyber-attack evaluation, exploit testing and analysis, rule creation, and red or purple teaming. The ideal candidate will have experience in exploit testing, and proof-of-concept development and analysis, to identify over-the-horizon cyber-attack vectors that may pose a risk to the company’s information security environment. The candidate will also have experience partnering with cyber defenders to resolve identified capability gaps. The team member will need to have experience in conducting technical research and identifying methods to detect emerging cyber threats, emulating full-life cycle cyber-attack methodologies, and have a deep technical understanding of evolving Advanced Persistent Threat (APT) Tactics, Techniques, and Procedures (TTPs).
The ideal candidate will have a well-rounded understanding of endpoint/network defenses and detection methodologies. As well as the incident response life cycle and expertise in how adversarial cyber threat actors think and attack. Regular collaboration with multiple teams such as the Cyber Threat Fusion Center, Security Content Development, Cyber Threat Intelligence, and Offensive Security teams will be critical to success.
In this role, you will:
- Lead or participate in adversarial engagements with the objective of strengthening detection and response capabilities
- Conduct technical investigation of security related events and produce lessons learned and recommend future mitigation strategies
- Provide security consulting on medium projects for internal clients to ensure conformity with corporate information, security policy, and standards
- Design, document, test, maintain, and provide issue resolution recommendations for moderately complex security solutions related to networking, cryptography, cloud, authentication and directory services, email, internet, applications, and endpoint security
- Review and correlate security logs leveraging a Purple Team approach to map offensive techniques to defensive controls
- Utilize subject matter knowledge in industry leading security solutions and best practices to implement one or more components of information security such as availability, integrity, confidentiality, risk management, threat identification, modeling, detection and monitoring, and access management
- Identify security vulnerabilities and issues, perform risk assessments, and evaluate remediation alternatives
- Collaborate and consult with peers, colleagues, and managers to resolve issues and achieve goals
Required Qualifications:
- 5+ years of Information Security industry experience in any of the following areas of concentration: Security OPs, Threat Hunting, Incident Response, Detection Engineering
- 5+ years of information security experience with SIEM, endpoint and network stack technologies
- 5+ years of experience with technical assessments associated with Red Team, Purple Team, and Blue Team exercises
- 5+ years of experience in security remediation practices to include signature development, log enrichment, and process improvements
Desired Qualifications:
- Knowledge and understanding of banking or financial services industry
- Certifications in one or more of the following: Global Information Assurance Certification (GIAC), Offensive Security Certified Professional (OSCP), Certified Information Systems Security Professional (CISSP)
- Experience conducting project meetings, presentations, and status reporting
- Knowledge and understanding of data security controls including malware protection, firewalls, intrusion detection systems, content filtering, Internet proxies, encryption controls, and log management solutions
- Knowledge of offensive security, with the ability to think like an adversary to drive detection engineering
- Experience with multiple operating systems including Windows, Mac OS, and Unix/Linux
Job Expectations:
- Ability to travel up to 10% of the time
Pay Range
Reflected is the base pay range offered for this position. Pay may vary depending on factors including but not limited to achievements, skills, experience, or work location. The range listed is just one component of the compensation package offered to candidates.
$119,000.00 - $224,000.00Benefits
Wells Fargo provides eligible employees with a comprehensive set of benefits, many of which are listed
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s