Senior Lead Information Protection Security Analyst
IT
Charlotte, NC, USA · Irving, TX, USA · Chandler, AZ, USA · Miami Lakes, FL, USA
About this role:
Wells Fargo is seeking a Senior Lead Information Protection Security Analyst to join the Information Protection Domain within Cybersecurity. This role provides enterprise leadership for information protection strategy, governance, and risk management programs focused on safeguarding the firm's sensitive data assets. The successful candidate will drive initiatives related to data discovery, classification, protection, governance, and regulatory compliance while partnering across technology, cybersecurity, legal, privacy, risk, and business teams to reduce information security risk and improve the firm's overall data protection posture.
In this role, you will:
- Provide oversight to the Information Security program for a major line of business
- Consult with line of business on the consistent implementation of the enterprise information security model and solutions to remediate information security risks
- Ensure that risks to all information assets are being managed in a timely and effective manner to meet the Information Security Program requirements and the current threat landscape
- Ensure information security capabilities are included in all aspects of the company's technology architecture
- Proactively manage the information security risk profile of line of business information assets throughout the lifecycle of the asset
- Provide vision, direction, and expertise to more experienced leadership on implementing innovative and significant business solutions that are large-scale, cross-functional, or companywide strategies
- Ensure the team has the necessary training and is keeping abreast of regulatory and compliance issues
- Engage with all levels of professionals and managers companywide and serve as an experienced advisor to leadership
- Develop, implement, and maintain the enterprise cryptographic governance framework, including policies, standards, and procedures.
- Develop and maintain cryptographic policies, standards, and control requirements (e.g., encryption, key management, certificates), ensuring alignment with applicable regulatory and industry frameworks (e.g., NIST, PCI DSS, ISO 27001).
- Operate governance routines to ensure consistent application of cryptographic controls across the enterprise.
- Review and evaluation new or updated cryptographic new solutions.
- Lead governance forums, reporting, and escalation processes to senior leadership.
- Align governance activities with the enterprise cryptographic strategy, including roadmap initiatives and long-term objectives.
- Participate in periodic reviews of cryptographic strategy and data protection initiatives.
- Ensure governance supports enterprise priorities related to data protection, risk management, and security modernization.
- Establish and maintain visibility into cryptographic risks, including vulnerabilities and non-compliance.
- Define key metrics and reporting mechanisms to monitor cryptographic posture.
- Escalate issues related to non-adherence to cryptographic policy through established governance channels.
- Support the identification, prioritization, and tracking of risk remediation activities.
- Assist with exception management, ensuring appropriate documentation, risk acceptance, and tracking.
- Collaborate regularly with cross-functional stakeholders, including Cybersecurity Architecture, Secure Network Services (SNS), Cloud Security, and application teams, on solutions, strategies, and policies.
- Act as a central point of coordination for cryptographic governance activities.
- Provide guidance and direction to engineering and operational teams on governance expectations.
- Support internal and external audits by providing required documentation, control evidence, and governance artifacts.
- Participate in the evaluation of cryptographic discovery tools and capabilities.
- Develop program to cryptographic discovery tools, capabilities, reporting and metrics.
- Monitor enterprise cryptographic posture and identify risks through tool outputs.
- Demonstrate foundational AI literacy by effectively using approved AI tools to support everyday work
- Apply AI tools for activities such as research, summarization, drafting, analysis, and decision support
- Exercise sound judgment when interpreting and using AI‑generated outputs
- Understand basic AI limitations and appropriate use cases within daily workflows
- Adhere to data privacy, security, and data‑handling standards when using AI tools
- Use AI ethically and responsibly, in alignment with company policies and guidelines
Required Qualifications
- 7+ years of Information Security Analysis experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education.
Desired Qualifications
- Deep expertise in Hardware Security Modules (HSMs), Public Key Infrastructure (PKI), key management, certificate services, encryption technologies, and enterprise cryptographic controls
- Strong experience developing, implementing, and governing enterprise cryptographic programs, including policies, standards, procedures, and control frameworks within highly regulated environments
- Demonstrated experience managing and improving certificate lifecycle management, cryptographic asset inventory, discovery, reporting, and remediation programs across large, complex organizations
- Advanced knowledge of security and regulatory frameworks including NIST Cryptographic Standards, NIST Cybersecurity Framework (CSF), PCI DSS, ISO 27001, FFIEC guidance, and financial services regulatory requirements
- Experience evaluating, planning, or implementing post-quantum cryptography (PQC) strategies, cryptographic modernization initiatives, and emerging encryption technologies
- Proven ability to author and enhance enterprise security policies, standards, governance artifacts, executive communications, and regulatory documentation while influencing senior leaders and cross-functional stakeholders
- Strong technical leadership experience partnering with cybersecurity architecture, engineering, infrastructure, cloud security, application development, legal, privacy, risk, and regulatory teams to drive enterprise-wide cryptographic governance and adoption
- Experience supporting cryptographic discovery tools, defining enterprise cryptographic metrics, monitoring cryptographic posture, and identifying risks associated with non-compliant cryptographic implementations
- Experience leading cryptographic governance, PKI, certificate management, or key management programs within a large-scale financial institution or highly regulated industry
Job Expectations:
- Hybrid schedule - 3 days in office, 2 days remote weekly
- Not available for visa Sponsorship
Locations:
- 300 South Brevard, Charlotte, NC
- 2600 South Price Road, Chandler, AZ
- 194 Wood Ave, Iselin, NJ
- 401 Las Colinas Blvd W, Irving, TX
Pay Range
Reflected is the base pay range offered for this position. Pay may vary depending on factors including but not limited to demonstrated examples of prior performance, skills, experience, or work location. Employees may also be eligible for incentive opportunities.
$159,000.00 - $305,000.00Benefits
Wells Fargo provides eligible employees with a comprehensive set of benefits, many of which are listed below. Visit Benefits - Wells Fargo Jobs for an overview of the following benefit plans and programs offered to employees.
- Health benefits
- 401(k) Plan
- Paid time off
- Disability benefits
- Life insurance, critical illness insurance, and accident insurance
- Parental leave
- Critical caregiving leave
- Discounts and savings
- Commuter benefits
- Tuition reimbursement
- Scholarships for dependent children
- Adoption reimbursement
Posting End Date:
10 Aug 2026*Job posting may come down early due to volume of applicants.
We Value Equal Opportunity
Wells Fargo is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, status as a protected veteran, or any other legally protected characteristic.
Employees support our focus on building strong customer relationships balanced with a strong risk mitigating and compliance-driven culture which firmly establishes those disciplines as critical to the success of our customers and company. They are accountable for execution of all applicable risk programs (Credit, Market, Financial Crimes, Operational, Regulatory Compliance), which includes effectively following and adhering to applicable Wells Fargo policies and procedures, appropriately fulfilling risk and compliance obligations, timely and effective escalation and remediation of issues, and making sound risk decisions. There is emphasis on proactive monitoring, governance, risk identification and escalation, as well as making sound risk decisions commensurate with the business unit’s risk appetite and all risk and compliance program requirements.
Applicants with Disabilities
To request a medical accommodation during the application or interview process, visit Disability Inclusion at Wells Fargo.
Drug and Alcohol Policy
Wells Fargo maintains a drug free workplace. Please see our Drug and Alcohol Policy to learn more.
Wells Fargo Recruitment and Hiring Requirements:
a. Third-Party recordings are prohibited unless authorized by Wells Fargo.
b. Wells Fargo requires you to directly represent your own experiences during the recruiting and hiring process.