Jobs and Careers
WE

Lead Third Party Information Security Analyst

Wells Fargo
United Statesfull_timeVerifiedPosted 12 Aug 2025

About the role

About this role:

Wells Fargo is seeking a Lead Third-Party Information Security Analyst to join our Information Security team. This role will focus on risk assessments of third-party vendors and partners, identifying security gaps, and driving remediation efforts to ensure alignment with our security policies and regulatory requirements.

In this role, you will

• Perform in-depth third-party risk assessments, including evaluating security controls, reviewing documentation (e.g., SOC reports, SIG questionnaires, policy, and procedure documents), and identifying potential risks.

• Collaborate with business stakeholders, procurement, legal, and third-party vendor contacts to gather necessary information and ensure timely completion of assessments.

• Track and manage remediation efforts for identified findings, ensuring third-party vendors implement appropriate corrective actions within agreed timelines.

• Collaborate and consult with peers, LOB, procurement, and mid-level managers up to executives to resolve issues and achieve goals

• Maintain and enhance third-party risk management processes, tools, and documentation.

• Provide subject matter expertise on third-party security risks,

• Understanding of regulatory requirements (e.g., GDPR, HIPAA, GLBA),  and industry best practices.

• Support internal and external audits related to third-party risk management.

• Contribute to continuous improvement initiatives within the broader Information Security Risk Management program.

•  Lead projects and teams

•  Serve as a mentor and guide to junior analysts

Required Qualifications:

•  5+ years of Information Security Analysis experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education

Desired Qualifications:

•  Bachelor’s degree in information security, Computer Science, Risk Management, or a related field (or equivalent experience)

•  Knowledge and understanding of information security management, audit, compliance, and risk

•  Experience with third-party risk assessment tools, products, and GRC platforms (e.g., Archer, ServiceNow, OneTrust, KY3P)

•  Proficient knowledge of security frameworks and standards (e.g., NIST, ISO 27001, SIG, SOC 2)

•  Excellent communication and interpersonal skills, with the ability to influence and collaborate across teams

•  Knowledge of with cloud security and SaaS vendor risk

•  Ability to manage multiple assessments and remediation efforts simultaneously

•  Knowledge and understanding of financial services industry: compliance, risk management or audit operations

•  Knowledge of Microsoft offices tools such as PowerPoint, Excel, Outlook, and Word

•  Relevant certifications such as CISSP, CISA, CRISC, or CTPRP are a plus

Job Expectations:

•  Travel up to 10% of the time.

•  Ability to work onsite in the office in a hybrid model.

•  This position is not eligible for Visa Sponsorship

Locations:

•  Charlotte (CIC)

•  Chandler, AZ

Posting End Date: 

21 Aug 2025

*Job posting may come down early due to volume of applicants.

We Value Equal Opportunity

Wells Fargo is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other legally protected characteristic.

Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit’s risk appetite and all risk and compliance program requirements.

Candidates applying to job openings posted in Canada: Applications for employment a

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Wells Fargo

View company profile →